Questions tagged with Amazon GuardDuty

Content language: English

Sort by most recent

Browse through the questions and answers listed below or filter and sort to narrow down your results.

I am using AWS GuardDuty and EKS. Recently I got couple of alerts from AWS GuardDuty for DefenseEvasion:EC2/UnusualDNSResolver mentioning one of the EKS nodes are connecting to 1.1.1.1. When I check...
1
answers
0
votes
93
views
asked 16 days ago
I'm using our Management account to do this. The main GuardDuty service is enabled on a vast majority of our Organization accounts already. I do not need to enable GuardDuty itself, just turn on the...
0
answers
0
votes
44
views
asked 22 days ago
I'm working on analyzing CloudTrail events as they come in and when I was setting up a filter ( ignore events that are readOnly ) I was surpised to see the above events coming through. is that...
1
answers
0
votes
35
views
asked a month ago
Hi Team, Im aware Guardduty is used for threat detection based on the API calls. Im struck where not all logs are appearing in the Guardduty. I have a control tower setup with organization enabled...
1
answers
0
votes
37
views
asked 2 months ago
Hello Team, I want to import our internal third-party intelligence feeds into guard duty. Is there any manual way or automated way to do so? Please let me know if any unconventional solutions are...
1
answers
0
votes
42
views
unknown
asked 3 months ago
I have a task where I'm required to make sure all my GuardDuty logs from multiple accounts are logged to one account using a centralized logging solution. At the moment, I'm trying to find a way...
3
answers
0
votes
149
views
asked 4 months ago
Hello, I am trying to export GuardDuty logs to S3 and I am getting errors with the policy. I am receiving message above **'findings export options' to an S3 bucket`**. I am following the...
1
answers
0
votes
67
views
asked 5 months ago
I am using AWS GuardDuty integration to Slack. Integration works like this, Cloudwatch Event --> SNS --> Lambda --> Slack. Last week I got an alert for one finding and I did take action on that. But...
1
answers
0
votes
79
views
asked 5 months ago
Hi, all, New to the community so will do my best to follow the dos and don't but a bit of a AWS novice so bear with me. It was noticed that the new "Malware Protection" trial had started in our AWS...
1
answers
0
votes
83
views
asked 6 months ago
Hi, AWS Guardduty is reporting: "ec2 instance is communicating with a remote host on an unusual server port 43582" from and EC2 instance that does not exist. We have autoscaling group that terminates...
2
answers
0
votes
190
views
asked 7 months ago
Hi, We're going through an Audit (It is my first year at this company) and I'm trying to find evidence, if we have any, that we monitor for data exfiltration attempts specifically (or other intrusion...
1
answers
0
votes
158
views
asked 7 months ago
We enabled GuardDuty at the Org-level and delegated the primary/management Account. However, in the GD console at the delegated account, the primary/management Account isn't listed. It seems as though...
1
answers
0
votes
76
views
asked 8 months ago