All Exam Questions
Back to All Posts
Cybersecurity

Amazon GuardDuty Guide: Features, Threat Detection and AWS Security Monitoring

September 4, 2026
Amazon GuardDuty Guide: Features, Threat Detection and AWS Security Monitoring

What Is GuardDuty

Amazon GuardDuty is AWS's managed threat detection service. It continuously analyzes activity across your AWS account, including CloudTrail management events, VPC Flow Logs, DNS query logs, and a growing list of service specific data sources, looking for patterns that suggest compromise, reconnaissance, or misuse.

The core idea behind GuardDuty is that you do not need to stand up your own log pipeline or write custom detection logic to get meaningful security coverage. You enable it, and it starts analyzing data sources that AWS already generates in the background, correlating them against threat intelligence feeds and machine learning models trained to spot suspicious behavior.

How Amazon GuardDuty Threat Detection Works

GuardDuty combines a few different detection techniques rather than relying on a single method.

  • Threat intelligence feeds, including lists of known malicious IP addresses and domains, sourced from AWS Security and trusted third parties

  • Anomaly detection, which builds a baseline of what normal activity looks like for your account and flags deviations from it

  • Machine learning models, trained to recognize patterns associated with credential compromise, privilege escalation, and data exfiltration

  • Signature based detection, catching known attack techniques and malware behavior directly

When GuardDuty identifies something suspicious, it generates a finding. Each finding includes a severity rating, details about the resource involved, and enough context to start an investigation immediately, without needing to dig through raw logs first.

AWS GuardDuty Features and Protection Plans

GuardDuty's foundational detection, covering CloudTrail, VPC Flow Logs, and DNS logs, is enabled the moment you turn the service on. Beyond that baseline, GuardDuty offers several optional protection plans, each targeting a specific AWS service, that you can toggle on independently depending on what you actually run.

S3 Protection

S3 Protection monitors S3 data events for signs of suspicious access patterns, such as unusual API calls, requests from known malicious IP addresses, or access patterns consistent with data exfiltration attempts against your buckets.

EKS Protection

EKS Protection analyzes Kubernetes audit logs from your EKS clusters, looking for suspicious activity like unauthorized access attempts, unusual permission changes, or behavior consistent with a compromised container trying to escalate privileges within the cluster.

Runtime Monitoring

Runtime Monitoring extends detection into the actual runtime behavior of workloads running on EKS, Amazon ECS including Fargate, and EC2. Rather than only watching logs about what happened, it observes process activity, file access, and network connections happening live inside the workload itself, which catches threats that never show up in audit logs at all.

Malware Protection

Malware Protection scans for malicious files in two places: EBS volumes attached to EC2 instances and container workloads when GuardDuty spots suspicious behavior, and objects uploaded to S3 buckets. Rather than continuously scanning everything, it triggers scans based on suspicious signals, which keeps the cost proportional to actual risk rather than total data volume.

RDS Protection

RDS Protection monitors database login activity across supported Amazon Aurora and RDS engines, looking for patterns like brute force login attempts, logins from unusual locations, or suspicious access by database users that suggest credential compromise.

Lambda Protection

Lambda Protection analyzes network activity generated by your Lambda functions, watching for functions that start communicating with known malicious IP addresses or domains, which can indicate a function has been compromised or is being used as part of an attack.

Extended Threat Detection

Extended Threat Detection goes a step further than individual findings by correlating multiple signals across services into a single, higher confidence finding that represents a likely attack sequence, rather than leaving you to manually connect a handful of separate alerts into a coherent picture yourself.

Setting Up GuardDuty AWS Security Monitoring

Enabling GuardDuty is intentionally simple, though rolling it out properly across an organization takes a bit more planning.

  1. Enable GuardDuty in the AWS console for your account and region. Every new account gets a 30 day free trial with full feature access.

  2. Review which protection plans apply to you. If you are not running EKS, there is no reason to enable EKS Protection, since it adds cost without adding value.

  3. Set up a delegated administrator account if you are managing multiple AWS accounts through AWS Organizations, so findings across your entire organization funnel into one place.

  4. Configure finding notifications through Amazon EventBridge, routing high and medium severity findings to a Slack channel, ticketing system, or security team inbox.

  5. Establish a response process for common finding types before you need it, so your team is not improvising during an actual incident.

  6. Periodically review suppression rules to make sure you are not accidentally silencing findings that matter, especially after infrastructure changes.

Multi Account Management

For organizations running many AWS accounts, GuardDuty supports a delegated administrator model through AWS Organizations. One account can view and manage GuardDuty findings across every member account, which avoids the alternative of logging into dozens of accounts individually to check for threats.

Amazon GuardDuty Pricing

GuardDuty uses a pay as you go model, and cost depends entirely on which protection plans you enable and how much data they analyze. Foundational detection is billed by the volume of CloudTrail events, VPC Flow Log data, and DNS query volume analyzed, while each optional protection plan has its own billing metric, whether that is events analyzed, vCPUs monitored, or data scanned.

A small environment running just foundational detection and S3 Protection across a handful of accounts might land in the range of $10 to $100 per month. Larger environments running every protection plan across dozens of accounts, including EKS Runtime Monitoring and Malware Protection at scale, can run into the thousands per month. The practical takeaway is to enable only the protection plans relevant to services you actually run, since an unused EKS Protection plan adds cost without adding any detection value.

Every new GuardDuty account, and each protection plan individually, includes a 30 day free trial, which is worth using deliberately to estimate your actual cost before committing long term.

Conclusion

Amazon GuardDuty gives you continuous, automated threat detection across your AWS environment without requiring you to build detection logic from scratch. Foundational detection covers the basics the moment you turn it on, and the optional protection plans let you extend coverage to exactly the services you run, whether that is S3, EKS, RDS, Lambda, or EC2 workloads, without paying for coverage you do not need. If you have not enabled it yet, start with the 30 day free trial on a single account, review the findings it generates, and use that as your baseline before deciding which protection plans make sense for your environment going forward.

Frequently Asked Questions

AllExamQuestions Editorial Team

AllExamQuestions Editorial Team

AllExamQuestions Editorial Team creates high-quality exam preparation content, practice resources, and certification guides to help learners achieve their goals.

Our content is carefully researched, regularly updated, and reviewed for accuracy and relevance.