Amazon GuardDuty
Managed intelligent threat detection
- Best answer when the question asks for automatic threat detection with minimal setup.
- Analyzes foundational sources such as CloudTrail management events, VPC Flow Logs, and Route 53 DNS query logs.
- Detects compromised credentials, suspicious API calls, crypto-mining, malware-style behavior, and data exfiltration patterns.
- Supports multi-account administration through AWS Organizations.