AWS GuardDuty
AWS GuardDuty is Amazon Web Services' intelligent threat detection and continuous security monitoring service that analyzes and identifies malicious activity, unauthorized behavior, and potential security threats across AWS accounts and workloads. This managed threat intelligence service provides comprehensive security monitoring and anomaly detection for cloud infrastructure and applications.
| Category | Vulnerability management |
| Direction | Query source |
| Sign-in | AWS IAM Credentials |
| Query languages | STIX |
| Website | http://aws.com |
Before you start
Huntbase signs in to AWS GuardDuty with AWS IAM Credentials. Create the credential in AWS GuardDuty first, then keep it to hand for the Connect step.
- In the IAM console, attach the AWS managed policy
AmazonGuardDutyReadOnlyAccessto the IAM user that Huntbase will use, or to the role it will assume. - Choose Users, choose the user name, and on the Security credentials tab, in the Access keys section, choose Create access key.
- Choose Other, then choose Next and Create access key.
- On the Retrieve access key page, choose Show and copy the access key ID and secret access key.
- If you use a role, allow the user to call
sts:AssumeRoleon it, and make sure the role's trust policy names the user as a principal.
Permissions:
AmazonGuardDutyReadOnlyAccess(AWS managed policy)
- The secret access key is shown only once, when you create the key.
For the vendor's own instructions, see AmazonGuardDutyReadOnlyAccess policy reference.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect AWS GuardDuty
- Go to Connections and click New connection, or click New connection on the AWS GuardDuty product page.
- On Product, pick AWS GuardDuty and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your AWS GuardDuty lives:
| Field | Required | Notes |
|---|---|---|
| Region | Yes | The AWS Region where GuardDuty is enabled, such as us-east-1. |
| Detector IDs | No | Optional, comma-separated. You can find the detector ID for the current Region on the Settings page of the GuardDuty console. |
Credentials
The only Method is AWS IAM Credentials. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| AWS Access Key ID | Yes | AWS Access Key ID is required for both AWS key-based and role-based authentication. Secret — not shown again after you save it. |
| AWS Secret Access Key | Yes | AWS Secret Access Key ID is required for both AWS key-based and role-based authentication. Secret — not shown again after you save it. |
| AWS IAM Role | No | Optional. The ARN of the role to assume, in the format arn:aws:iam::ACCOUNT-ID:role/ROLE-NAME. The access keys are still required. Secret — not shown again after you save it. |
Query it
Once connected, AWS GuardDuty can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog