logo

Making sense of Amazon GuardDuty alerts

ID: accc9f96-843d-58f5-92df-4437070a1ce9

STIX ID: report--accc9f96-843d-58f5-92df-4437070a1ce9

Feed Name: Expel Blog

Date Published: 2019-10-15

Date Updated: 2026-04-27

Author: Anthony Randazzo

...
...

This post explains how Amazon GuardDuty operates—ingesting CloudTrail, VPC flow logs, and DNS to produce EC2- and IAMUser-based findings—highlights limitations of vendor threat lists, and recommends enriching alerts with passive DNS, WHOIS, and OSINT for better decision support; it also walks through sample and real-world alerts (including an IAM compromise and suspicious Tor-based access) and provides four practical takeaways for reviewing GuardDuty alerts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.