Amazon GuardDuty
  • 08 Dec 2024
  • 1 Minute to read
  • Contributors
  • Dark
    Light

Amazon GuardDuty

  • Dark
    Light

Article summary

Amazon GuardDuty is a threat detection service that continuously monitors AWS accounts and workloads for malicious activity and delivers detailed security findings for visibility and remediation.

Integration Method: API

Tables: Detection Finding

Event Types: Unauthorized Access, Backdoor Activity, Data Exfiltration, CryptoMining, Portscan

AWS Keys

DataBee fetches findings logs via API. AWS client access key and secret key are required for configuration. Follow the instructions mentioned here to get access and secret key.

DataBee Configuration

  1. Log into the DataBee console, navigate to Data > Data Sources and click on Add New Data Source.

A screenshot of a computer  Description automatically generated

  1. Search for AWS GuardDuty and click it

  1. Select API Ingest

A screenshot of a phone  Description automatically generated

  1. Enter contact information for this data source and click Next

  2. In the configuration dialog box, fill in the following:

  • Authorization Method: AWS Signature

  • Access key: Paste the AWS client access key

  • Secret key: Paste the AWS client secret key

  • Session token can be left empty

  • AWS region – region

  • Service name: “guardduty”

  • API_URL: Replace the <aws-region> placeholder with the region

  1. Click Submit


Was this article helpful?

What's Next
Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Eddy AI, facilitating knowledge discovery through conversational intelligence