For those of you who are unfamiliar with GuardDuty, it is a fully managed, intelligent threat-detection service, powered by machine learning, that continually provides insights into unusual and/or unexpected behavioral patterns that could be considered malicious within your account. Amazon GuardDuty can process and analyze millions of events that are captured through your AWS CloudTrail logs, DNS logs, and VPC flow logs from multiple accounts. These events are then referenced against numerous threat detection feeds, many of which contain known sources of malicious activity, including specific URLs and IP addresses.
Amazon GuardDuty is continually learning, based on the day-to-day activity of operations within your account, to understand and differentiate between normal behavior and what could be considered abnormal behavior, thereby indicating a threat within your infrastructure. This behavioral-based analysis allows GuardDuty to detect potential vulnerabilities...