AWS GuardDuty - 4 Use cases
Transcript
hey thanks for joining I'm Joe Peterson I'm the vice president of cloud and security for clarify 360. and I'm here today on behalf of the CTO advisor and their serious and their series AWS every day so today I'm going to talk about AWS guard Duty what's it used for guard duty is a threat detection service that continually monitors for malicious activity and unauthorized Behavior to protect your AWS accounts Amazon elect to compute ec2 workloads container applications Amazon Aurora databases and data stored in Amazon simple storage or S3 so what are some use cases well here's four you can improve security visibility operationally you can gain Insight of compromised credentials unusual data access in Amazon simple storage S3 buckets suspicious logins to Aurora and API calls from known malicious IP addresses you can assist security analysts in their investigations so you can receive security event findings with context metadata impact or resource details and you can determine the root cause using guard Duty console integration with Amazon Detective you can identify files containing malware so you can scan elastic block storage EBS for files that might have malware creating suspicious behavior on instance and container workloads running over the Amazon elastic compute cloud ec2 you can route insightful information on security findings so route findings to your preferred operational tools using Integrations with AWS security Hub and Amazon event Bridge thanks for joining