Amazon Detective Goes GA (Mar 2020): Investigation Graphs for AWS Security Findings
Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.
In March 2020, Amazon Detective became generally available. It helps security teams investigate findings from GuardDuty and other sources by automatically building a graph of activity across AWS accounts.
What it does
Detective ingests CloudTrail logs, VPC Flow Logs, GuardDuty findings and, later, EKS audit logs and other sources. It builds a behavior graph linking IAM users and roles, IP addresses, EC2 instances, S3 buckets and other entities over time. Investigators can then pivot from a finding to see:
- What else that role or user did before and after the finding.
- Which IP addresses it connected from, and whether they were new.
- Whether activity volume or API usage changed from its normal baseline.
Why it mattered
GuardDuty told you something suspicious had happened. Answering "how bad is it?" meant writing many CloudTrail queries across accounts and regions. Detective made that investigation visual and fast, which mattered most for small teams without dedicated analysts.
How it fits
Detective is not a SIEM or detection tool; it is an investigation tool. Organizations using Microsoft Sentinel or another SIEM may run similar investigations there. For AWS-centric teams, Detective became the natural companion to GuardDuty and Security Hub, and later added generative AI summaries of finding groups.
In hindsight
Detection without fast investigation leads to two bad outcomes: real incidents dismissed as noise, or every alert escalated because nobody can tell the difference. Detective's value is in shortening the time between "alert" and "decision."
- How to Investigate a GuardDuty Finding With Amazon Detective How-To & Hardening
- Cloud Incident Investigation Runbook for AWS How-To & Hardening
- CIO Brief: Faster Investigations Mean Smaller Breaches CIO Briefings