Amazon GuardDuty's AI investigations spot real threats in minutes!
Hi everyone, it's Shiichan! Today I have a treat for security fans.
AWS What's NewWhat was announced?
The source is AWS's What's New. Amazon GuardDuty just got AI-powered investigations in preview. It automatically analyzes your GuardDuty findings and accounts to help you quickly tell true threats apart from benign ones.
Why it matters
In security operations, investigating a mountain of alerts by hand, one at a time, is exhausting. That effort fuels alert fatigue and slows down incident response. This is exactly the investigation work that the AI now takes off your plate.
What changes
Because each investigation comes back in minutes, your team can focus on the threats that are genuinely dangerous. It also works across individual AWS accounts or entire AWS Organizations, so you can shrink your mean time to resolution.
Dive Deep
The AI examines the finding's context, related activity from the last 90 days, affected resources, and threat indicators, using knowledge graphs and threat intelligence, all within minutes.
Each investigation returns a disposition assessment with confidence scoring, a MITRE ATT&CK technique classification, supporting evidence, and actionable recommendations for suppression, containment, or remediation. With all of that in hand, it's easier to decide your next move.
The preview is available in 10 AWS Regions: US East (N. Virginia, Ohio), US West (Oregon), Canada (Central), Europe (Ireland, London, Frankfurt, Paris, Stockholm), and Asia Pacific (Tokyo). You can reach it through the Amazon GuardDuty console, CLI, API, or AWS's MCP Server, so folks on the Tokyo Region can try it too. To learn more, take a look at the Amazon GuardDuty User Guide.
Wrap-up
- Amazon GuardDuty gains AI-powered investigations in preview
- Automatically analyzes findings to sort true threats from benign ones in minutes
- Uses 90 days of related activity, knowledge graphs, and threat intelligence
- Delivers a confidence-scored disposition, MITRE ATT&CK classification, and recommended actions
- Preview across 10 Regions including Tokyo, via console, CLI, API, or MCP Server
This one lands first for SOC teams and cloud security folks buried in alerts!