AWSPlatform ChangesRetrospectives

Amazon GuardDuty Launches at re:Invent 2017: Managed Threat Detection for AWS

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2017, written in 2026 with the benefit of hindsight.

At re:Invent in November 2017, AWS launched Amazon GuardDuty, a managed threat detection service. With one click, it began analyzing an account's activity for signs of compromise — no agents, no log pipelines, no SIEM required.

What it did

GuardDuty analyzed three data sources AWS already had: CloudTrail management events, VPC Flow Logs and DNS query logs. It combined them with threat intelligence and anomaly detection to produce findings such as:

  • EC2 instances communicating with known command-and-control servers or crypto-mining pools.
  • API calls from known malicious IP addresses or anonymizing networks.
  • Credentials used in unusual ways, such as reconnaissance from a new location.

Why it mattered

Before GuardDuty, threat detection in AWS meant building your own log collection and correlation, which most small and mid-sized teams never did. GuardDuty made baseline detection affordable and nearly effortless. Pricing was based on data volume analyzed, and most smaller accounts paid little.

How it evolved

GuardDuty steadily added protection plans: S3 data events, EKS audit logs and runtime monitoring, malware scanning of EBS volumes, RDS login activity, Lambda network activity and more. Multi-account management through AWS Organizations made it easy to enable everywhere.

In hindsight

GuardDuty is a reminder that the first step in detection is turning it on. Many incident investigations still find GuardDuty disabled in the affected account or region — or enabled, generating findings nobody read. The service is only as good as the process that responds to it.

amazon guardduty2017

More on this story