- Newest
- Most votes
- Most comments
Thank you for your feedback on Amazon GuardDuty. Let me address each of your points:
-
Regarding finding status management: GuardDuty currently focuses on detection rather than case management. While you can archive findings, GuardDuty doesn't have built-in status tracking like "In Progress" or "Pending." This is by design, as AWS Security Hub is intended to serve as the centralized platform for security finding management. Security Hub can aggregate GuardDuty findings and provides more robust case management capabilities.
-
On IP reputation information: GuardDuty is designed to detect suspicious activity based on its own threat intelligence and behavioral analysis rather than integrating with third-party reputation services like VirusTotal. This is a limitation in the current implementation.
-
Regarding resolution tracking: GuardDuty uses a finding aggregation approach where it updates existing findings with new information rather than creating new ones for the same issue. However, it doesn't automatically track remediation status. For configuration-related security issues like S3 bucket permissions, Security Hub's compliance checks would be more appropriate as they continuously evaluate resource configurations against security standards.
-
About attack context details: GuardDuty focuses on detecting specific threat patterns rather than providing comprehensive attack attribution or risk assessment. While it can identify certain types of suspicious activities, it doesn't currently provide the level of granular context you're looking for regarding attack origins or attribution.
GuardDuty is primarily a threat detection service that monitors for malicious activity and unauthorized behavior, while Security Hub is designed to provide a more comprehensive security posture management solution. For the most effective security monitoring, AWS recommends using GuardDuty in conjunction with other AWS security services like Security Hub, Amazon Detective, and AWS Config.
Sources
Managing Amazon GuardDuty findings - Amazon GuardDuty
Security Hub Findings don't match Guard Duty findings | AWS re:Post
GuardDuty finding aggregation - Amazon GuardDuty
How to use the Amazon Detective API to investigate GuardDuty security findings and enrich data in Security Hub | AWS Security Blog
answered a year ago
Relevant content
asked 3 years ago
asked 4 years ago
