Lesson 06 — Amazon GuardDuty, Intelligent Threat Detection & Enterprise Security Monitoring
Learning Path
☁️ Phase 02 – AWS Cloud Security
📘 Module 13 – Enterprise Security Operations, Logging, Monitoring & Threat Detection
🎯 Lesson Objectives
Section titled “🎯 Lesson Objectives”By the end of this lesson, you will be able to:
- Explain Amazon GuardDuty architecture.
- Understand intelligent threat detection.
- Enable GuardDuty across an AWS Organization.
- Configure delegated administrator accounts.
- Understand GuardDuty findings.
- Interpret GuardDuty severity levels.
- Investigate GuardDuty alerts.
- Configure S3 Protection.
- Configure EKS Protection.
- Configure Runtime Monitoring.
- Configure Malware Protection.
- Integrate GuardDuty with Security Hub.
- Integrate GuardDuty with EventBridge.
- Design enterprise threat detection architectures.
- Build SOC investigation workflows.
- Reduce false positives.
- Design enterprise governance.
- Secure GuardDuty.
- Respond to GuardDuty findings.
- Apply GuardDuty best practices.
📚 Lesson Information
Section titled “📚 Lesson Information”| Area | Details |
|---|---|
| Estimated Time | 8–10 Hours |
| Difficulty | Advanced |
| Prerequisites | Lesson 05 – AWS Config |
| Hands-on Labs | Yes |
| AWS Services | Amazon GuardDuty, AWS Organizations, Security Hub, EventBridge, CloudTrail, VPC Flow Logs, Route 53 Resolver |
💼 Business Scenario
Section titled “💼 Business Scenario”CloudNova Technologies has successfully implemented:
- Enterprise CloudTrail
- CloudWatch Monitoring
- AWS Config Compliance
- Centralised Logging
- Security Operations Centre (SOC)
However, the SOC team still faces a major challenge.
Although security events are collected, analysts must manually review thousands of CloudTrail events, VPC Flow Logs and DNS logs every day.
Recent security incidents include:
- EC2 instances communicating with malicious IP addresses.
- IAM credentials used from unusual geographic locations.
- Cryptocurrency mining malware running on EC2 instances.
- Public S3 buckets accessed by suspicious identities.
- Kubernetes clusters communicating with command-and-control servers.
- IAM privilege escalation attempts.
- Reconnaissance activity across multiple AWS accounts.
- API calls originating from Tor exit nodes.
The security team cannot manually analyse this volume of telemetry.
The Chief Information Security Officer (CISO) asks:
“How can we automatically detect malicious behaviour across all AWS accounts using AWS-native intelligence and respond before attackers cause significant damage?”
As CloudNova’s Cloud Security Architect, you are responsible for deploying Amazon GuardDuty as the enterprise threat detection platform.
1. Introduction to Amazon GuardDuty
Section titled “1. Introduction to Amazon GuardDuty”Topics:
- What is Amazon GuardDuty?
- Why GuardDuty matters.
- Threat Detection as a Service.
- Continuous monitoring.
- Machine learning.
- AWS threat intelligence.
- Behavioural analytics.
- Managed detection.
2. GuardDuty Architecture
Section titled “2. GuardDuty Architecture”Explain:
- Detector
- Findings
- Delegated Administrator
- Member Accounts
- Threat Intelligence
- Machine Learning
- Event Sources
- Security Hub Integration
Architecture Diagram
CloudTrail
↓
VPC Flow Logs
↓
DNS Logs
↓
EKS Audit Logs
↓
S3 Events
↓
Amazon GuardDuty
↓
Security Hub
↓
EventBridge
↓
SOC
↓
Incident Response3. How GuardDuty Works
Section titled “3. How GuardDuty Works”Explain:
- Data ingestion.
- Threat analysis.
- Behaviour modelling.
- AWS threat intelligence.
- Anomaly detection.
- Finding generation.
- Continuous monitoring.
4. GuardDuty Data Sources
Section titled “4. GuardDuty Data Sources”GuardDuty analyses:
- AWS CloudTrail
- VPC Flow Logs
- Route 53 Resolver DNS Logs
- S3 Data Events
- Kubernetes Audit Logs
- Runtime Monitoring telemetry
- Malware Protection scans
5. GuardDuty Findings
Section titled “5. GuardDuty Findings”Understand:
- Finding ID
- Severity
- Resource
- Region
- Account
- Description
- Evidence
- Recommendation
Finding lifecycle.
6. Finding Severity Levels
Section titled “6. Finding Severity Levels”Cover:
- Low
- Medium
- High
- Critical
Enterprise response priorities.
7. Threat Categories
Section titled “7. Threat Categories”Examples include:
- Credential compromise
- Privilege escalation
- Malware
- Cryptocurrency mining
- Backdoor activity
- Reconnaissance
- Persistence
- Exfiltration
- Impact
- Defence evasion
8. IAM Threat Detection
Section titled “8. IAM Threat Detection”Examples:
- Impossible travel
- Unusual API activity
- Root account usage
- Privilege escalation
- Credential compromise
- Suspicious AssumeRole activity
9. EC2 Threat Detection
Section titled “9. EC2 Threat Detection”Examples:
- CryptoCurrency mining
- Backdoor communication
- Command and Control
- Port Scanning
- SSH Brute Force
- Reconnaissance
10. Amazon S3 Protection
Section titled “10. Amazon S3 Protection”Topics:
- S3 Protection
- Object access monitoring
- Public bucket detection
- Unusual access patterns
- Data exfiltration
11. Amazon EKS Protection
Section titled “11. Amazon EKS Protection”Explain:
- Kubernetes Audit Logs
- Suspicious Kubernetes API calls
- Cluster compromise
- Privilege abuse
- Container threats
12. Runtime Monitoring
Section titled “12. Runtime Monitoring”Monitor:
- EC2 Runtime
- EKS Runtime
- Container activity
- Process execution
- Network behaviour
- File system activity
13. Malware Protection
Section titled “13. Malware Protection”Explain:
- Malware scanning
- EBS Snapshot analysis
- File scanning
- Investigation workflow
- Incident response
14. Multi-Account Deployment
Section titled “14. Multi-Account Deployment”Topics:
- AWS Organizations
- Delegated Administrator
- Auto-enable new accounts
- Regional deployment
- Enterprise governance
15. GuardDuty Integration
Section titled “15. GuardDuty Integration”Integrate with:
- Security Hub
- EventBridge
- CloudWatch
- SNS
- Lambda
- Systems Manager
- Security Lake
16. SOC Investigation Workflow
Section titled “16. SOC Investigation Workflow”Threat Activity
↓
Amazon GuardDuty
↓
Finding Generated
↓
Security Hub
↓
EventBridge
↓
SOC Analyst
↓
Incident Response
↓
Containment
↓
Recovery17. Enterprise Threat Hunting
Section titled “17. Enterprise Threat Hunting”Use GuardDuty findings to investigate:
- Credential abuse
- Data exfiltration
- Malware
- Lateral movement
- Command and Control
- Insider threats
18. Enterprise Governance
Section titled “18. Enterprise Governance”Govern:
- Detector ownership
- Finding triage
- Severity classification
- Escalation procedures
- Regional deployment
- Compliance reporting
- Finding retention
- Investigation documentation
19. GuardDuty Threat Model
Section titled “19. GuardDuty Threat Model”Threats include:
- Credential theft
- API abuse
- Malware infection
- Suspicious DNS activity
- Lateral movement
- Privilege escalation
- Data exfiltration
- Insider threats
- Command-and-control traffic
20. Enterprise GuardDuty Architecture
Section titled “20. Enterprise GuardDuty Architecture”AWS Organizations
↓
Delegated Administrator
↓
Member Accounts
↓
Amazon GuardDuty
↓
Security Hub
↓
Security Lake
↓
EventBridge
↓
SOC Dashboard
↓
Incident Response🛠 Enterprise Labs
Section titled “🛠 Enterprise Labs”Lab 01
Section titled “Lab 01”Enable Amazon GuardDuty Across AWS Organizations
Lab 02
Section titled “Lab 02”Configure Delegated Administrator
Lab 03
Section titled “Lab 03”Investigate IAM Threat Findings
Lab 04
Section titled “Lab 04”Investigate EC2 Malware Findings
Lab 05
Section titled “Lab 05”Configure Amazon S3 Protection
Lab 06
Section titled “Lab 06”Configure Amazon EKS Protection
Lab 07
Section titled “Lab 07”Enable Runtime Monitoring
Lab 08
Section titled “Lab 08”Investigate Malware Protection Findings
Lab 09
Section titled “Lab 09”Integrate GuardDuty with Security Hub
Lab 10
Section titled “Lab 10”Enterprise GuardDuty Threat Assessment
💻 AWS Console Walkthrough
Section titled “💻 AWS Console Walkthrough”Students should configure:
- Detector
- Delegated Administrator
- Member Accounts
- Findings
- S3 Protection
- EKS Protection
- Runtime Monitoring
- Malware Protection
- Trusted IP Lists
- Threat Lists
💻 AWS CLI Exercises
Section titled “💻 AWS CLI Exercises”# List GuardDuty detectorsaws guardduty list-detectors
# Get detector detailsaws guardduty get-detector \ --detector-id DETECTOR_ID
# List GuardDuty findingsaws guardduty list-findings \ --detector-id DETECTOR_ID
# Get finding detailsaws guardduty get-findings \ --detector-id DETECTOR_ID \ --finding-ids FINDING_ID
# List organisation configurationaws guardduty describe-organization-configuration \ --detector-id DETECTOR_ID
# List membersaws guardduty list-members \ --detector-id DETECTOR_ID✅ Verification Checklist
Section titled “✅ Verification Checklist”Students should be able to:
- Explain GuardDuty architecture.
- Enable GuardDuty.
- Configure delegated administration.
- Interpret GuardDuty findings.
- Investigate IAM threats.
- Investigate EC2 threats.
- Configure S3 Protection.
- Configure EKS Protection.
- Enable Runtime Monitoring.
- Integrate GuardDuty with Security Hub.
- Build enterprise threat detection architectures.
🏢 Enterprise Best Practices
Section titled “🏢 Enterprise Best Practices”CloudNova standards:
- Enable GuardDuty in every AWS account and Region.
- Use a delegated administrator account for central management.
- Automatically enrol new AWS accounts.
- Integrate GuardDuty with Security Hub and EventBridge.
- Investigate all High and Critical findings immediately.
- Tune suppression rules to reduce alert fatigue.
- Review findings daily as part of SOC operations.
- Correlate GuardDuty findings with CloudTrail, AWS Config and CloudWatch data.
- Store findings in Security Lake for long-term investigation and analytics.
🚫 Common Mistakes
Section titled “🚫 Common Mistakes”- Enabling GuardDuty in only one Region.
- Ignoring Medium severity findings.
- Not enabling S3 Protection.
- Forgetting Runtime Monitoring.
- Failing to investigate recurring findings.
- Not integrating GuardDuty with Security Hub.
- Disabling GuardDuty to reduce costs.
- Ignoring suppression rule tuning.
- Treating GuardDuty as a replacement for incident response.
- Failing to review delegated administrator settings.
🧪 DIY Enterprise Challenge
Section titled “🧪 DIY Enterprise Challenge”Design CloudNova’s enterprise GuardDuty deployment supporting:
- 500 AWS accounts
- Multi-Region monitoring
- Delegated administration
- S3 Protection
- Kubernetes protection
- Runtime Monitoring
- Malware Protection
- Security Hub integration
- Security Lake integration
- 24×7 SOC operations
Prepare:
- Enterprise GuardDuty architecture
- Finding severity model
- SOC investigation workflow
- Escalation matrix
- Integration architecture
- Governance framework
- Threat-hunting strategy
- Operational runbook
📊 Knowledge Check
Section titled “📊 Knowledge Check”Create and answer 50 enterprise-level questions covering:
- GuardDuty architecture
- Data sources
- Findings
- Severity levels
- IAM threats
- EC2 threats
- S3 Protection
- EKS Protection
- Runtime Monitoring
- Malware Protection
- Multi-account deployment
- Security Hub integration
- Enterprise governance
- Threat detection workflows
- SOC operations
💡 Key Takeaways
Section titled “💡 Key Takeaways”After completing this lesson, you should be able to:
- Deploy Amazon GuardDuty across enterprise AWS environments.
- Detect suspicious activity using AWS threat intelligence and machine learning.
- Investigate GuardDuty findings and prioritise responses based on severity.
- Configure S3 Protection, EKS Protection, Runtime Monitoring and Malware Protection.
- Integrate GuardDuty with Security Hub, EventBridge and Security Lake.
- Build enterprise threat detection workflows that support proactive Security Operations and Incident Response.
🚀 Next Lesson
Section titled “🚀 Next Lesson”➡️ Lesson 07 — AWS Security Hub, Centralised Security Posture Management & Enterprise Compliance