AWS Guardduty Detector

Deploys an Amazon GuardDuty Detector to an AWS region as a threat detection service that continuously monitors your AWS accounts and workloads for malicious activity and sends emails about security findings for visibility and remediation.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Deployments

32

Made by

Massdriver

Official

Yes

No

Compliance
Tags

Operator Guide

This is the guide for your bundle. It will appear under the guide button in Massdriver.

Use it to describe to users how the bundle works, use cases for the bundle, and examples.

VariableTypeDescription
detector.regionstringAWS Region to provision in.
features.ebs_malwarebooleanEnable scanning of EBS volumes for malware
features.eks_auditbooleanEnable monitoring of EKS audit logs to detect suspicious activity in your EKS clusters
features.eks_runtimebooleanEnable monitoring of EKS runtimes to detect suspicious activity in EKS workloads
features.lambda_networkbooleanEnable monitoring of AWS lambda invocations
features.rds_loginbooleanEnable monitoring successful and unsuccessful login attempts to RDS databases
features.s3_databooleanEnable monitoring of S3 get/put/list/delete events
monitoring.modestringEnable and customize CloudWatch metric alarms.
notifications.emailstringSpecify email to be notified at in case of findings
notifications.frequencystringSelect the frequency to export events to EventHub for notifications
notifications.severity.highbooleanA High severity level indicates that the resource in question is compromised and is actively being used for unauthorized purposes.
notifications.severity.lowbooleanA low severity level indicates attempted suspicious activity that did not compromise your network
notifications.severity.mediumbooleanA Medium severity level indicates suspicious activity that deviates from normally observed behavior and, depending on your use case, may be indicative of a resource compromise.
No items found.