GuardDuty PNG and SVG Icon
Amazon GuardDuty is a threat detection service that continuously monitors for malicious or unauthorized behavior to help protect your AWS accounts and workloads.
Last Modified: August 10, 2025

16px
32px
48px
64px
Details
Key Features
- Detects threats using machine learning and AWS data sources.
- Monitors VPC flow logs, CloudTrail, and DNS logs.
- Generates actionable security findings.
- Operates without additional security infrastructure.
Common Use Cases
- Detect suspicious network traffic in AWS
- Identify compromised IAM credentials
- Alert on unusual API calls from unfamiliar locations
Explore More Icons
Infrastructure Composer
AWS Infrastructure Composer is a visual tool that helps developers create and deploy infrastructure using AWS CloudFormation templates more easily.
Timestream
Amazon Timestream is a fast, scalable, serverless time series database service for IoT and operational applications.
App Mesh
AWS App Mesh is a service mesh that provides application-level networking to make it easy to monitor and control microservices running on AWS.
Database Migration Service
AWS Database Migration Service (DMS) helps you migrate databases quickly and securely to AWS with minimal downtime.
CodeGuru
Amazon CodeGuru is a developer tool that provides intelligent code reviews and performance recommendations using machine learning.
Thinkbox Sequoia
Thinkbox Sequoia is a point cloud meshing application that enables users to create 3D meshes from point cloud data.
Alexa For Business
Alexa for Business is an AWS service that enables organizations to use Alexa-powered devices to improve productivity and manage workplace tasks via voice interaction.
Identity and Access Management
AWS Identity and Access Management (IAM) enables you to manage access to AWS services and resources securely with fine-grained permissions.
WorkMail
Amazon WorkMail is a secure, managed business email and calendar service that supports existing desktop and mobile email clients.
WAF
AWS Web Application Firewall (WAF) helps protect web applications from common exploits and bots that can affect availability, security, or consume resources.
SQS Queue
Amazon SQS Queue is a scalable message queuing service that enables decoupling and communication between microservices, distributed systems, and serverless applications.
Professional Services
AWS Professional Services is a global team of experts that helps customers realize their desired business outcomes using the AWS Cloud through specialized engagements.
Elastic Block Store
Amazon Elastic Block Store (EBS) provides block-level storage volumes for use with Amazon EC2, designed for high availability and durability.
CloudSearch
Amazon CloudSearch is a managed service that makes it simple to set up, manage, and scale a search solution for your website or application.
File System
File System represents AWS-managed or integrated file storage solutions like EFS, FSx, and on-premises gateways for structured file access.
Managed Blockchain
Amazon Managed Blockchain is a fully managed service that makes it easy to create and manage scalable blockchain networks using popular open-source frameworks like Hyperledger Fabric and Ethereum.
Inspector
Amazon Inspector automatically assesses applications for vulnerabilities and deviations from best practices, helping improve the security of AWS workloads.
Simple Notification Service
Amazon Simple Notification Service (SNS) is a fully managed pub/sub messaging service for sending messages to subscribers over SMS, email, or other protocols.
SageMaker AI
Amazon SageMaker is a fully managed service that enables developers and data scientists to build, train, and deploy ML models at scale.
OpenSearch Service
Amazon OpenSearch Service is a fully managed search and analytics service for log analytics, real-time application monitoring, and website search.
Pinpoint
Amazon Pinpoint is a flexible and scalable outbound and inbound marketing communications service for sending targeted messages to customers across multiple channels.
EMR Engine
Amazon EMR Engine is the processing engine component within Amazon EMR that enables scalable, distributed big data processing using frameworks like Spark and Hadoop.
App Runner
AWS App Runner is a fully managed service that makes it easy to build, deploy, and run containerized web applications and APIs at scale without managing infrastructure.
HDFC Cluster
Amazon EMR on HDFC Cluster refers to the use of Hadoop Distributed File System (HDFS) within Amazon EMR for distributed data storage and processing.