Amazon GuardDuty Advanced Threat Detection: AWS Security, Features and Monitoring

What Is Amazon GuardDuty
Amazon GuardDuty is AWS's managed threat detection service, continuously analyzing account activity, network traffic, and DNS queries across your AWS environment to identify potential security threats. It requires no infrastructure to deploy for its foundational detection, since it works directly against data sources like CloudTrail, VPC Flow Logs, and DNS logs that AWS already generates.
What Is GuardDuty Actually Looking For
At its foundation, GuardDuty compares activity against known threat intelligence, such as lists of malicious IP addresses and domains, while also applying machine learning models trained to recognize patterns associated with compromised credentials, reconnaissance, and unauthorized access. Each time it identifies something suspicious, it produces a finding, complete with severity, affected resources, and enough context to begin investigating right away.
Amazon GuardDuty Advanced Threat Detection: Extended Threat Detection Explained
The genuinely advanced part of GuardDuty's detection is a capability called Extended Threat Detection, generally available since December 2024. Rather than treating every suspicious event as an isolated alert, Extended Threat Detection correlates a sequence of related events across services, resources, and time, and represents the entire sequence as a single, critical severity finding called an attack sequence.
AWS describes the underlying inputs to this correlation as weak signals, individual events that on their own do not look clearly malicious, but that become meaningful once viewed together. A privileged container getting deployed unexpectedly might not raise an alarm by itself. Neither might an unusual outbound connection a few minutes later. Extended Threat Detection is built specifically to notice when several of these weak signals line up into a coherent attack pattern that no single event would have revealed.
Why This Matters More Than a Standard Finding
Without this correlation layer, a security analyst is left manually piecing together a timeline from dozens of separate findings scattered across different services and time windows, often after the fact. Extended Threat Detection does that correlation automatically, and the resulting finding includes an incident summary, a detailed timeline of the events involved, mapping to MITRE ATT&CK tactics and techniques, and concrete remediation recommendations, which meaningfully shortens the time between detection and response.
Attack Sequence Finding Types
GuardDuty currently generates several distinct attack sequence finding types, each representing a specific multi-stage compromise pattern.
AttackSequence:EKS/CompromisedCluster identifies patterns like an anomalous privileged container deployment followed by persistence attempts, cryptomining, or reverse shell activity within that container.
AttackSequence:EC2/CompromisedInstanceGroup identifies coordinated compromise across a group of EC2 instances, such as credentials being used outside the account they were issued to, combined with malicious tool execution or communication with suspicious endpoints.
AttackSequence:ECS/CompromisedCluster identifies similar multi-stage compromise patterns specifically within ECS cluster environments.
AWS has continued expanding this capability, including a set of new indicator types added in 2026, covering malicious packages, misconfigurations, network reachability issues, sensitive data exposure, and known vulnerabilities, which broadens the range of weak signals Extended Threat Detection can factor into an attack sequence.
Extended Threat Detection Is Enabled by Default
Unlike GuardDuty's optional protection plans, Extended Threat Detection is automatically enabled for every new and existing GuardDuty customer at no additional cost, and you do not need every protection plan turned on to benefit from it. That said, enabling additional protection plans, particularly EKS Protection and Runtime Monitoring, meaningfully widens the range of signals available for correlation, which directly improves how much of an actual attack sequence GuardDuty can piece together.
How AWS GuardDuty Threat Detection Builds a Complete Picture
Extended Threat Detection works best when it has more data sources feeding into it, so understanding which protection plans strengthen which attack sequences helps you prioritize what to enable.
Protection Plan | Data Source | Strengthens Detection Of |
|---|---|---|
EKS Protection | Kubernetes audit logs | Control plane compromise, unauthorized access, privilege escalation |
Runtime Monitoring | Live process, file, and network activity | Cryptomining, reverse shells, malware execution inside workloads |
S3 Protection | S3 data event logs | Data exfiltration attempts, suspicious bucket access patterns |
Malware Protection | EBS and S3 scan triggers | Confirmed malicious files tied to a broader compromise |
Enabling EKS Protection alone gives GuardDuty visibility into control plane activity, but pairing it with Runtime Monitoring is what allows GuardDuty to connect a suspicious container deployment to what that container actually did afterward, which is the difference between a partial signal and a complete attack sequence finding.
Understanding a GuardDuty Finding
Each finding, whether a standard finding or an attack sequence, follows a structured format that is worth understanding before you are staring at one during an actual incident.
Severity Levels
GuardDuty assigns each finding a severity level, low, medium, or high, based on how confident the detection is and how serious the potential impact appears. Attack sequence findings are always classified as critical severity, reflecting that they represent a correlated, multi-stage pattern rather than a single ambiguous event.
Finding Anatomy
A typical finding includes the resource affected, the specific finding type describing what was detected, the action observed, and supporting evidence such as the source IP address or API call involved. Attack sequence findings go further, adding a narrative incident summary, an ordered timeline of every event in the sequence, and mapped MITRE ATT&CK tactics, which gives a security analyst immediate context instead of raw log fragments to interpret manually.
Responding to Amazon GuardDuty Threat Detection Findings
Detection only creates value if it leads to action, so having a clear response process matters as much as the detection capability itself.
Triage by severity first, prioritizing attack sequence and high severity findings over lower severity, isolated events that may reflect normal but unusual activity.
Review the timeline for attack sequence findings before taking action, since understanding the full sequence prevents an incomplete response that only addresses part of the compromise.
Isolate affected resources where appropriate, such as revoking compromised credentials or quarantining an affected instance, before beginning deeper investigation.
Route findings automatically through Amazon EventBridge to a ticketing system or security team channel, so response time does not depend on someone manually checking the console.
Feed findings into AWS Security Hub or a SIEM if you need centralized visibility across GuardDuty and other security tools rather than working within GuardDuty alone.
Document the response once resolved, since the details of a real attack sequence finding are valuable input for tuning detection and response processes going forward.
AWS Threat Detection: GuardDuty vs Manual Log Analysis
Factor | GuardDuty Advanced Threat Detection | Manual Log Analysis |
|---|---|---|
Correlation across services | Automatic, built in | Manual, analyst dependent |
Time to detect multi-stage attacks | Often near real time | Can take hours or days to piece together |
MITRE ATT&CK mapping | Included automatically | Requires manual mapping by the analyst |
Setup effort | Minimal, foundational detection is automatic | Requires building custom log pipelines and queries |
Cost model | Pay per data volume analyzed | Requires dedicated analyst time and tooling |
Conclusion
Amazon GuardDuty's advanced threat detection, built around Extended Threat Detection and its attack sequence findings, addresses a real limitation of traditional alerting: single events rarely tell the whole story, but a sequence of them often does. By correlating weak signals across services and time into one critical severity finding, complete with a timeline and MITRE ATT&CK context, GuardDuty meaningfully reduces the manual work of piecing together a real attack from scattered alerts. Since this capability runs automatically at no added cost, the most useful next step for most teams is reviewing which optional protection plans, particularly EKS Protection and Runtime Monitoring, would widen the signals available and strengthen detection across your specific environment.
Frequently Asked Questions

AllExamQuestions Editorial Team
AllExamQuestions Editorial Team creates high-quality exam preparation content, practice resources, and certification guides to help learners achieve their goals.
Our content is carefully researched, regularly updated, and reviewed for accuracy and relevance.
