What AWS native service for AWS account anomaly detection and intrusion detection?



Do we have any turnkey functionality enabling anomaly-based intrusion detection in AWS accounts? if yes which service offers that? It's not super-clear to me what capability is present in GuardDuty and Detective (docs say "use rule set and ML [...] and analyze data like VPC flow logs, DNS, Cloudtrail").

1 Answer
Accepted Answer

First I suggest to share this whitepaper with the customer https://d1.awsstatic.com/whitepapers/aws_security_incident_response.pdf

Secondly: https://aws.amazon.com/blogs/security/why-we-reduce-complexity-and-rapidly-iterate-on-amazon-guardduty-twelve-new-detections-added/

AWS Guarduty combined with AWS Cloud Trail is the options available natively for now, or you could use Alert Logic a partner on the marketplace.

answered 3 years ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions