shiichan

Amazon GuardDuty's AI investigations spot real threats in minutes!

Hi everyone, it's Shiichan! Today I have a treat for security fans.

AWS What's New aws.amazon.com

What was announced?

The source is AWS's What's New. Amazon GuardDuty just got AI-powered investigations in preview. It automatically analyzes your GuardDuty findings and accounts to help you quickly tell true threats apart from benign ones.

Why it matters

In security operations, investigating a mountain of alerts by hand, one at a time, is exhausting. That effort fuels alert fatigue and slows down incident response. This is exactly the investigation work that the AI now takes off your plate.

What changes

Because each investigation comes back in minutes, your team can focus on the threats that are genuinely dangerous. It also works across individual AWS accounts or entire AWS Organizations, so you can shrink your mean time to resolution.

Dive Deep

The AI examines the finding's context, related activity from the last 90 days, affected resources, and threat indicators, using knowledge graphs and threat intelligence, all within minutes.

Each investigation returns a disposition assessment with confidence scoring, a MITRE ATT&CK technique classification, supporting evidence, and actionable recommendations for suppression, containment, or remediation. With all of that in hand, it's easier to decide your next move.

The preview is available in 10 AWS Regions: US East (N. Virginia, Ohio), US West (Oregon), Canada (Central), Europe (Ireland, London, Frankfurt, Paris, Stockholm), and Asia Pacific (Tokyo). You can reach it through the Amazon GuardDuty console, CLI, API, or AWS's MCP Server, so folks on the Tokyo Region can try it too. To learn more, take a look at the Amazon GuardDuty User Guide.

Wrap-up

  • Amazon GuardDuty gains AI-powered investigations in preview
  • Automatically analyzes findings to sort true threats from benign ones in minutes
  • Uses 90 days of related activity, knowledge graphs, and threat intelligence
  • Delivers a confidence-scored disposition, MITRE ATT&CK classification, and recommended actions
  • Preview across 10 Regions including Tokyo, via console, CLI, API, or MCP Server

This one lands first for SOC teams and cloud security folks buried in alerts!