logo

Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment

ID: 8dbd14a5-4db1-579a-9bcf-e357b7a65719

STIX ID: report--8dbd14a5-4db1-579a-9bcf-e357b7a65719

Feed Name: AWS Security Blog

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Allan Holmes

...
...

Amazon GuardDuty's investigation agent (public preview) automates the analysis of GuardDuty findings by correlating evidence across accounts and services and producing structured assessments that include risk level, confidence, MITRE ATT&CK technique mappings, resource mapping, and prioritized remediation actions. The post explains how to enable and use the agent via the AWS Console, CLI, APIs, and the AWS MCP server, details required IAM permissions and the authorization model, describes cross-Region inference and expected investigation timings, provides example workflows for integrating with SIEMs and automation, and notes preview availability and quota limits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.