Amazon GuardDuty — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
December 10, 2025
Last Seen
June 29, 2026

Amazon GuardDuty is a technology platform tracked across 6 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 10, 2025; most recent activity June 29, 2026.

Overview

Amazon GuardDuty is AWS's managed threat-detection service for cloud environments. It continuously analyzes data from sources such as VPC Flow Logs, CloudTrail (Management and Data events), and DNS logs to identify malicious or unauthorized activity using machine learning and threat intelligence. Findings are surfaced in the AWS Console and can be integrated with SIEMs or automation tools to accelerate incident response.

Related Threat Clusters

Recent Intelligence Reports

  • What the June 2026 Threat Technique Catalog update means for your AWS environment — Aws.Amazon · June 29, 2026
  • CIRT insights: How to help prevent unauthorized account removals from AWS Organizations — Aws.Amazon · May 19, 2026
  • The AWS AI Security Framework: Securing AI with the right controls, at the right layers, at the right phases — Aws.Amazon · May 15, 2026
  • Security Engineer I (SEC), AWS Security Incident Response - Job ID — Amazon.Jobs · April 1, 2026
  • Building an AI-powered defense-in — Aws.Amazon · February 16, 2026
  • Trend Vision One™ Integration with AWS Security Hub CSPM: Unifying Cloud Security — Feeds.Trendmicro · December 10, 2025

CVSS v3.1 Breakdown