Skip to main content

Threat Detection & Response

24/7 Threat Detection That Auditors Accept

Continuous monitoring, Security Hub AI inventory, agentless vulnerability scanning, OCSF data lakes, and automated remediation.

AWS-native threat detection is enough for most workloads — once it is configured correctly. These guides cover GuardDuty across CloudTrail, VPC, EKS, S3, RDS, Lambda, and EC2 Runtime; Security Hub Essentials on resource-based pricing — including the Jul 2026 AI inventory that catalogs managed Bedrock/AgentCore/SageMaker assets, self-hosted stacks via Inspector SBOM, and external model APIs via GuardDuty DNS; Amazon Inspector with agentless EC2, Lambda code scanning, and CI/CD repo scanning; Amazon Detective for graph-based forensics; and Security Lake with OCSF 1.1. Plus the automation that turns findings into remediation runbooks instead of dashboard noise.

Part of the AWS Security & Compliance hub.

10
Guides
2
Related Services
Select Tier
AWS Consulting Partner

Guides

10 guides in this subtopic

FAQ

Frequently asked questions about threat detection & response

Do we still need GuardDuty if Security Hub is already on?
Yes — they are complementary, not redundant. Security Hub Essentials is the aggregator: it ingests findings from AWS services and partner tools, runs continuous standards checks (AWS Foundational Security Best Practices, CIS, PCI DSS, NIST 800-53 r5), and emits a normalized severity score. GuardDuty is one of those finding sources — it produces threat-detection findings (cryptocurrency mining, anomalous CLI activity, credential exfiltration, malware, EKS runtime threats) by analyzing CloudTrail, VPC Flow Logs, DNS logs, S3 data events, EKS audit logs, RDS login events, and Lambda invocations. Without GuardDuty, Security Hub still runs the standards checks but has no behavioral threat-detection feed — and AI inventory loses the DNS path that surfaces third-party model API calls.
What is Security Hub AI inventory, and do we need to enable it?
AI inventory (generally available 14 July 2026) is a continuously updated, organization-wide catalog of AI assets inside Security Hub Essentials — included at no additional cost and with no separate enablement step. It discovers managed AI via AWS Config (Amazon Bedrock, Bedrock AgentCore, Amazon SageMaker), self-hosted AI via Amazon Inspector SBOM analysis on EC2 and ECR (frameworks such as Ollama, vLLM, Hugging Face TGI), and external AI API endpoints via GuardDuty DNS telemetry. Each asset maps to underlying infrastructure and correlates with security findings so you remediate AI under active threat first. Filter and group by account, resource type, discovery method, and model identity.
When should we add Amazon Detective on top of GuardDuty?
Add Detective when finding triage takes more than a few minutes per investigation. Detective ingests GuardDuty, VPC Flow Logs, CloudTrail, Route 53, and EKS audit logs and pre-builds the entity graph (IPs, principals, resources, finding chains) so you click into a finding and see the linked behaviour over the prior 30 days without writing CloudWatch Logs Insights queries. Most teams hit the threshold once they cross ~50 GuardDuty findings/week or once a security analyst is dedicated to AWS investigations. Below that, jumping straight to CloudTrail Lake or Athena on Security Lake is acceptable.
Amazon Inspector vs third-party CSPM tools?
Amazon Inspector is best-in-class for AWS-native vulnerability and code scanning: agentless EC2 via EBS snapshots, container image scanning in ECR, Lambda function and Lambda code scanning, and (since 2025) CI/CD scanning of supported code repositories. It is the right call for AWS-only estates because findings flow directly to Security Hub with one CVSS + KEV-aware severity — and its SBOM analysis now feeds Security Hub AI inventory for self-hosted inference stacks. A third-party CSPM (Wiz, Lacework, Orca, Rapid7) earns its line item when you span multi-cloud, need posture findings beyond vulnerability (data exposure, attack-path graphs), or have a SOC that already lives in that console. We do not recommend duplicating findings — pick one source of truth per finding type.

Need expert help on AWS security and compliance?

Our consulting engagements apply this guidance to your specific environment, regulatory scope, and threat model.