云盾智巡

原名:detecting-cloud-threats-with-guardduty

部署并运营 Amazon GuardDuty,包括保护计划。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-09-06
TRACE 评分
3.4 / 5

内容概览

- When establishing continuous threat detection for new or existing AWS accounts - When investigating GuardDuty findings related to compromised instances, credential abuse, or data exfiltration - When building automated incident response playbooks triggered by GuardDuty findings - When extending threat coverage to container workloads running on EKS, ECS, or Fargate - When enabling malware scanning for EBS volumes attached to suspicious EC2 instances Do not use for Azure or GCP threat detection (see securing-azure-with-microsoft-defender or auditing-gcp-security-posture), for static code analysis, or for compliance posture monitoring (see implementing-aws-security-hub). - AWS account with GuardDuty administrative permissions (guardduty: ) - AWS CloudTrail, VPC Flow Logs, and DNS query logs enabled (GuardDuty consumes these automatically) - AWS Organizations configured if deploying GuardDu…

查看 SKILL 详情