Amazon Detective supports investigations for GuardDuty EC2 Runtime Monitoring
Share
Services
Amazon Detective, a managed security service that helps analysts investigate potential security issues across AWS, has introduced a new feature to support investigating threats detected by Amazon GuardDuty's EC2 Runtime Monitoring capability. This expansion enhances Detective's ability to provide visualizations and context for investigating runtime threats targeting EC2 instances.
With this new capability, Detective simplifies the analysis process by correlating EC2 runtime findings from GuardDuty with other GuardDuty and AWS Security Hub alerts. Analysts can now leverage Detective to accelerate their security response and improve investigations for potential security issues involving their EC2 workloads. Amazon GuardDuty continuously monitors for unauthorized activity and threats across AWS accounts and services. Its recently launched EC2 Runtime Monitoring feature can detect runtime threats such as instances querying cryptocurrency IPs or connecting to Tor networks. By integrating with this feature, Detective empowers analysts to gain deeper insights and quickly investigate suspicious activities related to their EC2 instances.
To get started you can enable the new threat detection plan in the GuardDuty console, and Detective will automatically ingest the findings into your behavior graph.
The expanded investigation capabilities are available today for all existing and new Detective accounts and in all AWS Regions where Detective is available excluding AWS GovCloud. You can start your 30-day free trial of Detective in the AWS Management console. To learn more, visit the [Amazon Detective product page](https://aws.amazon.com/detective/).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share