All Services

Security & IAM

Amazon GuardDuty

Amazon GuardDuty continuously analyzes supported AWS data sources with threat intelligence, anomaly detection, and machine learning to generate findings for suspected credential, workload, data, network, and malware threats.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with Amazon GuardDuty.

Amazon GuardDuty pricing and cost programs

Pricing model: Security telemetry analysis usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: CloudTrail events · Network and DNS logs · Data volume · Protection-plan resources

Programs and modes: Foundational data sources · S3 Protection · Runtime Monitoring · Malware Protection

Enabled protection plans and analyzed resource volumes determine charges.

Free Tier: Available — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement Amazon GuardDuty?

  • Adds threat detection across supported control-plane, network, DNS, S3, EKS, runtime, database, and malware signals without deploying a general SIEM or host agent for foundational coverage.
  • Produces severity-rated findings with affected-resource and evidence context that can flow to Security Hub, Detective, EventBridge, and response automation.
  • Supports centralized multi-account administration through AWS Organizations and a delegated security account.

How to implement Amazon GuardDuty

  1. Designate a delegated administrator, enable GuardDuty in every required account and Region, set organization auto-enable policy deliberately, and opt into applicable protection plans after reviewing data coverage and cost.
  2. Send findings to Security Hub and EventBridge, enrich alerts with asset ownership and business criticality, route by severity, and create documented containment playbooks with guarded automation.
  3. Generate sample findings and use the tester only in a dedicated non-production account, validate on-call delivery and permissions, measure response, and close findings only after investigation and remediation.

Amazon GuardDuty best practices

  • Cover all active Regions and new organization accounts, monitor detector and protection-plan status, and treat disabled or unavailable data sources as visibility gaps.
  • Prioritize by severity plus asset context, preserve evidence before containment, suppress only narrow known-benign patterns, and never interpret absence of findings as proof of safety.
  • Use EventBridge automation for reversible, well-tested steps, keep humans in destructive containment decisions, and review trends, recurring root causes, and protection-plan cost.

Amazon GuardDuty use cases and server impact

  • Compromised credential and account detection
  • Workload, container, and malware threat detection
  • S3, database, DNS, and network anomaly detection

Replaces parts of a custom cloud threat-detection pipeline, while responders, evidence collection, business context, containment, root-cause analysis, and preventive fixes remain customer responsibilities.

Official implementation resources

Commonly paired AWS services

Architecture patterns using this service

Planning guides that use Amazon GuardDuty