云盾智巡
原名:detecting-cloud-threats-with-guardduty
部署并运营 Amazon GuardDuty,包括保护计划。
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-06
- TRACE 评分
- 3.4 / 5
内容概览
- When establishing continuous threat detection for new or existing AWS accounts - When investigating GuardDuty findings related to compromised instances, credential abuse, or data exfiltration - When building automated incident response playbooks triggered by GuardDuty findings - When extending threat coverage to container workloads running on EKS, ECS, or Fargate - When enabling malware scanning for EBS volumes attached to suspicious EC2 instances Do not use for Azure or GCP threat detection (see securing-azure-with-microsoft-defender or auditing-gcp-security-posture), for static code analysis, or for compliance posture monitoring (see implementing-aws-security-hub). - AWS account with GuardDuty administrative permissions (guardduty: ) - AWS CloudTrail, VPC Flow Logs, and DNS query logs enabled (GuardDuty consumes these automatically) - AWS Organizations configured if deploying GuardDu…