GuardDuty Findings
Analyzing GuardDuty Findings¶
GuardDuty continuously monitors your AWS environment for malicious activity, unauthorized access, and vulnerabilities, generating findings that require analysis. Effective analysis involves interpreting the structure of findings, prioritizing threats based on severity and context, and leveraging AWS Security Hub to centralize and correlate findings from multiple sources. This section guides you through these processes.
Interpreting GuardDuty Findings¶
Each GuardDuty finding includes metadata that describes the potential threat. Key components include:
- Title: A summary of the finding (e.g., Unusual outbound traffic from EC2 instance).
- Description: Detailed explanation of the detected activity.
- Severity: Rated as HIGH, MEDIUM, or LOW based on risk.
- Resource: The AWS resource involved (e.g., an EC2 instance or S3 bucket).
- Type: Categorizes the finding (e.g., Network, Account, or Behavioral).
Example: A Network.AmazonEC2.InstanceUnauthorizedAccess finding might indicate an EC2 instance was accessed using stolen credentials.
Command to Retrieve Findings¶
Use the AWS CLI to fetch findings:
<detector-id> with your GuardDuty detector ID. Filter results by severity using the --finding-ids parameter or AWS Security Hub.
Prioritizing Threats¶
Prioritization depends on severity, context, and business impact.
1. Severity Filtering:
- HIGH: Immediate action required (e.g., data exfiltration).
- MEDIUM: Investigate promptly (e.g., suspicious IP activity).
- LOW: Monitor for patterns (e.g., unusual API calls).
Use AWS Security Hub rules to trigger actions (e.g., alerts or remediation workflows) for HIGH-severity findings. These rules require explicit configuration to flag findings.
Example Rule Configuration:
Create a rule in Security Hub to flag HIGH-severity findings:
aws securityhub update-finding --finding-id <finding-id> --note "Severity: HIGH" --note-target "Severity"
- Contextual Analysis:
Cross-reference findings with AWS CloudTrail logs, VPC flow logs, or AWS Config compliance status. For example, aMaliciousIPfinding might correlate with aCloudTrail.UnauthorizedAPIActionevent.
Example Command:
Centralizing Findings with AWS Security Hub¶
AWS Security Hub aggregates findings from GuardDuty, AWS Config, and third-party tools, enabling unified analysis.
Key Features:¶
- Standardized Findings: Security Hub normalizes findings into a consistent format for easier correlation.
- Automation Rules: Define rules to auto-remediate or alert on specific patterns (e.g., multiple low-severity findings from the same IP).
- Correlation Rules: Use AWS managed or custom rules to identify cross-service threats. For example, a rule might link a
GuardDuty.MaliciousIPfinding with aCloudTrail.UnauthorizedAPIActionevent.
Command to Create a Finding Type in Security Hub¶
aws securityhub create-finding-type --finding-type '{"Id": "<finding-type-id>", "Name": "Suspicious Outbound Traffic", "Description": "Detected unusual outbound traffic patterns", "Severity": "HIGH", "Types": ["Network"], "ProductArn": "<product-arn>"}'
Id and ProductArn values automatically. Do not hardcode these identifiers in CLI commands.
Key takeaways¶
- Interpret findings by analyzing severity, resource, and type to understand the threat context.
- Prioritize threats using severity levels and cross-service correlation to focus on high-impact risks.
- Leverage Security Hub to centralize findings, apply automation rules, and identify patterns across AWS services.
- Combine GuardDuty with CloudTrail and Config for deeper contextual analysis and faster remediation.