ALL LESSONS Module 27

Amazon GuardDuty Threat Detection

Apr 5, 2026 1 min read

Managed Threat Detection

ML-powered threat detection using CloudTrail/VPC Flow Logs.

Detection Types

Reconnaissance:
- Port scanning
- Infrastructure discovery

Instance Compromise:
- Cryptojacking
- Backdoor access

Account Compromise:
- IAM credential abuse
- Suspicious API calls

S3 Data Access:
- Unusual data access patterns
- Data exfiltration

Findings Format

  • JSON format with severity (Low/Med/High)
  • EventBridge/SNS integration
  • Suppression rules
  • Multi-account aggregation

Need help with this lesson? Visit the Discussion Forum