Security & IAM
Amazon GuardDuty
Amazon GuardDuty continuously analyzes supported AWS data sources with threat intelligence, anomaly detection, and machine learning to generate findings for suspected credential, workload, data, network, and malware threats.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with Amazon GuardDuty.
Amazon GuardDuty pricing and cost programs
Pricing model: Security telemetry analysis usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: CloudTrail events · Network and DNS logs · Data volume · Protection-plan resources
Programs and modes: Foundational data sources · S3 Protection · Runtime Monitoring · Malware Protection
Enabled protection plans and analyzed resource volumes determine charges.
Free Tier: Available — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement Amazon GuardDuty?
- Adds threat detection across supported control-plane, network, DNS, S3, EKS, runtime, database, and malware signals without deploying a general SIEM or host agent for foundational coverage.
- Produces severity-rated findings with affected-resource and evidence context that can flow to Security Hub, Detective, EventBridge, and response automation.
- Supports centralized multi-account administration through AWS Organizations and a delegated security account.
How to implement Amazon GuardDuty
- Designate a delegated administrator, enable GuardDuty in every required account and Region, set organization auto-enable policy deliberately, and opt into applicable protection plans after reviewing data coverage and cost.
- Send findings to Security Hub and EventBridge, enrich alerts with asset ownership and business criticality, route by severity, and create documented containment playbooks with guarded automation.
- Generate sample findings and use the tester only in a dedicated non-production account, validate on-call delivery and permissions, measure response, and close findings only after investigation and remediation.
Amazon GuardDuty best practices
- Cover all active Regions and new organization accounts, monitor detector and protection-plan status, and treat disabled or unavailable data sources as visibility gaps.
- Prioritize by severity plus asset context, preserve evidence before containment, suppress only narrow known-benign patterns, and never interpret absence of findings as proof of safety.
- Use EventBridge automation for reversible, well-tested steps, keep humans in destructive containment decisions, and review trends, recurring root causes, and protection-plan cost.
Amazon GuardDuty use cases and server impact
- Compromised credential and account detection
- Workload, container, and malware threat detection
- S3, database, DNS, and network anomaly detection
Replaces parts of a custom cloud threat-detection pipeline, while responders, evidence collection, business context, containment, root-cause analysis, and preventive fixes remain customer responsibilities.
Official implementation resources
Commonly paired AWS services
- AWS Security Hub — Security posture
- Amazon Detective — Security investigation
- Amazon Security Lake — Centralized security data lake
- Amazon EventBridge — Event bus
- AWS Lambda — Run code without servers
- Amazon Simple Notification Service — Pub/sub messaging
- AWS Organizations — Multi-account mgmt
- AWS CloudTrail — API audit logging
Architecture patterns using this service
- Scan uploaded objects for malware and quarantine them on AWS — Land untrusted uploads in a private Amazon S3 bucket, scan them with GuardDuty Malware Protection for S3, route scan results through EventBridge and SQS, and promote only clean objects to a bucket consumers can read.
Planning guides that use Amazon GuardDuty
- Amazon Detective planning guide — Pivot from GuardDuty findings into Detective entity and behavior context.