Skip to content

GuardDuty Findings

Analyzing GuardDuty Findings

GuardDuty continuously monitors your AWS environment for malicious activity, unauthorized access, and vulnerabilities, generating findings that require analysis. Effective analysis involves interpreting the structure of findings, prioritizing threats based on severity and context, and leveraging AWS Security Hub to centralize and correlate findings from multiple sources. This section guides you through these processes.


Interpreting GuardDuty Findings

Each GuardDuty finding includes metadata that describes the potential threat. Key components include:
- Title: A summary of the finding (e.g., Unusual outbound traffic from EC2 instance).
- Description: Detailed explanation of the detected activity.
- Severity: Rated as HIGH, MEDIUM, or LOW based on risk.
- Resource: The AWS resource involved (e.g., an EC2 instance or S3 bucket).
- Type: Categorizes the finding (e.g., Network, Account, or Behavioral).

Example: A Network.AmazonEC2.InstanceUnauthorizedAccess finding might indicate an EC2 instance was accessed using stolen credentials.

Command to Retrieve Findings

Use the AWS CLI to fetch findings:

aws guardduty list-findings --detector-id <detector-id> --max-results 10
Replace <detector-id> with your GuardDuty detector ID. Filter results by severity using the --finding-ids parameter or AWS Security Hub.


Prioritizing Threats

Prioritization depends on severity, context, and business impact.
1. Severity Filtering:
- HIGH: Immediate action required (e.g., data exfiltration).
- MEDIUM: Investigate promptly (e.g., suspicious IP activity).
- LOW: Monitor for patterns (e.g., unusual API calls).
Use AWS Security Hub rules to trigger actions (e.g., alerts or remediation workflows) for HIGH-severity findings. These rules require explicit configuration to flag findings.

Example Rule Configuration:
Create a rule in Security Hub to flag HIGH-severity findings:

aws securityhub update-finding --finding-id <finding-id> --note "Severity: HIGH" --note-target "Severity"
This example demonstrates how to manually update a finding's severity, but automated rules (e.g., using AWS Lambda or CloudWatch) can streamline this process.

  1. Contextual Analysis:
    Cross-reference findings with AWS CloudTrail logs, VPC flow logs, or AWS Config compliance status. For example, a MaliciousIP finding might correlate with a CloudTrail.UnauthorizedAPIAction event.

Example Command:

aws securityhub get-findings --filters "FindingTypes=['GuardDuty.MaliciousIP']" --max-results 5


Centralizing Findings with AWS Security Hub

AWS Security Hub aggregates findings from GuardDuty, AWS Config, and third-party tools, enabling unified analysis.

Key Features:

  • Standardized Findings: Security Hub normalizes findings into a consistent format for easier correlation.
  • Automation Rules: Define rules to auto-remediate or alert on specific patterns (e.g., multiple low-severity findings from the same IP).
  • Correlation Rules: Use AWS managed or custom rules to identify cross-service threats. For example, a rule might link a GuardDuty.MaliciousIP finding with a CloudTrail.UnauthorizedAPIAction event.

Command to Create a Finding Type in Security Hub

aws securityhub create-finding-type --finding-type '{"Id": "<finding-type-id>", "Name": "Suspicious Outbound Traffic", "Description": "Detected unusual outbound traffic patterns", "Severity": "HIGH", "Types": ["Network"], "ProductArn": "<product-arn>"}'
Note: AWS generates the Id and ProductArn values automatically. Do not hardcode these identifiers in CLI commands.


Key takeaways

  • Interpret findings by analyzing severity, resource, and type to understand the threat context.
  • Prioritize threats using severity levels and cross-service correlation to focus on high-impact risks.
  • Leverage Security Hub to centralize findings, apply automation rules, and identify patterns across AWS services.
  • Combine GuardDuty with CloudTrail and Config for deeper contextual analysis and faster remediation.