- Newest
- Most votes
- Most comments
GuardDuty Extended Threat Detection represents a significant enhancement to the existing GuardDuty service, leveraging advanced AI and machine learning capabilities to provide more comprehensive and sophisticated threat detection. Here are the key differences:
-
Multi-stage attack detection: The new AI-powered GuardDuty can identify complex, multi-stage attack sequences targeting AWS accounts, workloads, and data. It correlates security signals across multiple AWS services, time periods, and resources within an account to detect sophisticated cloud attacks.
-
Attack sequence findings: GuardDuty now generates new "attack sequence findings" that represent multiple steps taken by an adversary, such as privilege discovery, API manipulation, persistence activities, and data exfiltration. These findings are presented as a single, critical-severity alert.
-
Critical severity level: For the first time, GuardDuty introduces a critical severity level for its findings, reserved for threats with the utmost confidence and urgency.
-
Improved actionability: The new capabilities provide more actionable insights, including a natural language summary of the threat, observed activities mapped to MITRE ATT&CK® tactics and techniques, and prescriptive remediation recommendations based on AWS best practices.
-
Automatic correlation: GuardDuty Extended Threat Detection automatically correlates disparate signals to provide high-confidence insights into potentially compromised resources, reducing the time and effort required for security teams to triage events.
-
Enhanced coverage: While the existing GuardDuty already offers comprehensive protection, the Extended Threat Detection capability expands this further by considering multiple events across all foundational data sources and additional protection plans when enabled.
-
AI/ML-driven analysis: The new capability uses artificial intelligence and machine learning algorithms trained at AWS scale to identify both known and previously unknown attack patterns.
These enhancements allow security teams to focus on the most critical threats and streamline their response to active events, providing a more proactive and comprehensive approach to cloud security compared to the previous version of GuardDuty.
Sources
Introducing Amazon GuardDuty Extended Threat Detection: AI/ML attack sequence identification for enhanced cloud security | AWS News Blog
Amazon GuardDuty introduces GuardDuty Extended Threat Detection - AWS
Intelligent Threat Detection – Amazon GuardDuty Features – AWS
GuardDuty Extended Threat Detection - Amazon GuardDuty
Relevant content
asked 3 years ago
asked 3 years ago
asked 3 years ago
