Making sense of Amazon GuardDuty alerts
ID: accc9f96-843d-58f5-92df-4437070a1ce9
STIX ID: report--accc9f96-843d-58f5-92df-4437070a1ce9
Feed Name: Expel Blog
This post explains how Amazon GuardDuty operates—ingesting CloudTrail, VPC flow logs, and DNS to produce EC2- and IAMUser-based findings—highlights limitations of vendor threat lists, and recommends enriching alerts with passive DNS, WHOIS, and OSINT for better decision support; it also walks through sample and real-world alerts (including an IAM compromise and suspicious Tor-based access) and provides four practical takeaways for reviewing GuardDuty alerts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
