All Services
Security & IAM
Amazon Detective
Amazon Detective organizes supported AWS telemetry into a behavior graph and provides linked entities, timelines, visualizations, and finding context to investigate suspicious activity and determine scope and root cause.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with Amazon Detective.
Security investigation scope and pricing
Amazon Detective Pricing & Investigation Guide
Use Detective to investigate and correlate suspicious AWS activity after a detector or analyst surfaces a lead. It builds investigation context and behavior graphs; it does not replace primary detection, a SIEM, authoritative logs, or the systems that perform containment and remediation.
Official AWS sources reviewed 2026-08-07.
What is Amazon Detective?
Detective aggregates supported AWS telemetry into behavior graphs, entity profiles, timelines, finding groups, and visualizations that help investigators understand the scope and likely root cause of suspicious activity.
What is Amazon Detective?
What drives Amazon Detective pricing?
Detective uses tiered data-ingestion pricing across supported sources. Estimate telemetry volume by account and Region, review the service's usage estimates, and include separate charges for integrated services such as Security Lake where applicable.
Official Amazon Detective pricing
How does Detective work with GuardDuty?
GuardDuty can provide the finding that starts an investigation; Detective helps analysts pivot across related entities and historical activity. Confirm conclusions in authoritative evidence, then use separate incident-response controls for containment and remediation.
Detective investigation guide
Related AWS services for this plan
- Amazon GuardDuty — Pivot from GuardDuty findings into Detective entity and behavior context.
- AWS Security Hub — Use Security Hub findings and workflows to centralize investigation intake and status.
- AWS CloudTrail — Confirm investigative hypotheses against authoritative CloudTrail activity.
- Amazon Security Lake — Evaluate Security Lake integration and its separate data and cost boundaries where applicable.
Amazon Detective pricing and cost programs
Pricing model: Security telemetry ingestion and analysis
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Data ingested · Source services · Retention
Programs and modes: Behavior graph · Investigation
Data-volume charges and trial terms are maintained on the pricing page.
Free Tier: Available — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS pricing
Official AWS sources reviewed 2026-07-21.
Why implement Amazon Detective?
- Preprocesses and correlates supported cloud activity so analysts can investigate relationships without manually joining every underlying log.
- Provides entity profiles, behavior baselines, timelines, finding groups, and visual context for GuardDuty and Security Hub investigations.
- Supports delegated multi-account administration so a security team can investigate organization activity from a central behavior graph.
How to implement Amazon Detective
- Designate a delegated administrator, enable organization accounts and required Regions, confirm data-source coverage and graph-population timing, and document retention and access boundaries.
- Integrate GuardDuty and Security Hub workflows, train analysts to pivot from findings to users, roles, IPs, instances, clusters, buckets, and related activity, and record evidence outside ad hoc console notes.
- Use timelines and baselines to form and test hypotheses, verify suspicious actions in authoritative logs, then invoke separate containment and remediation playbooks and document scope and root cause.
Amazon Detective best practices
- Use Detective for investigation and correlation, not as a primary detector, SIEM replacement, or automatic remediation service.
- Confirm coverage, Region, membership, data-source and retention limits before concluding that activity is absent; correlate with CloudTrail, workload, identity, and application evidence.
- Restrict graph access to investigators, preserve chain-of-custody for exported evidence, avoid premature attribution from correlations, and turn lessons into preventive controls and detections.
Amazon Detective use cases and server impact
- GuardDuty finding investigation
- Credential and role activity scoping
- Entity timelines and incident root-cause analysis
Replaces much custom security-telemetry joining and investigation UI work, while detection coverage, analyst judgment, evidence preservation, containment, and remediation remain yours.
Official implementation resources
Commonly paired AWS services