In this recipe, we will learn to set up and use Amazon GuardDuty. GuardDuty analyzes data from sources such as CloudTrail, VPC flow logs, and DNS logs, and uses machine learning, anomaly detection, and integrated threat intelligence to find malicious activities and unauthorized behavior. GuardDuty can be integrated with CloudWatch and SNS to raise alarms and send notifications. GuardDuty can also aggregate data from multiple accounts.
Setting up and using Amazon GuardDuty
Getting ready
We need a working AWS account.
How to do it...
We can enable GuardDuty for our account...