How to Investigate a GuardDuty Finding With Amazon Detective
Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.
Amazon Detective helps you answer the key questions after a GuardDuty finding: is it real, what did the identity do, and how far did it go? Here is a practical investigation workflow.
Prerequisites
- Detective enabled in the same delegated administrator account and regions as GuardDuty.
- Member accounts enrolled (Detective needs GuardDuty to have been running for at least 48 hours).
Step 1: Start from the finding
From the GuardDuty or Security Hub console, choose Investigate in Detective on the finding. This opens the profile for the involved entity — for example, an IAM role or an EC2 instance.
Step 2: Establish the scope time
Set the scope time to cover a window before and after the finding (for example, 24 hours before, 24 hours after). Detective highlights activity during that window compared with the entity's baseline.
Step 3: Review the identity's behavior
For an IAM role or user, check:
- New geolocations and IP addresses compared with historical activity.
- API call volume and new API methods used.
- Resources accessed during the window.
Step 4: Review related entities
Pivot to related IP addresses, EC2 instances or S3 buckets. Look for other identities using the same IP — a sign of broader compromise.
Step 5: Use finding groups
Detective groups related findings into finding groups that may represent a single attack across multiple resources. Review the group, not just the single finding.
Step 6: Decide and document
Decide: false positive, benign, or incident. Record evidence and next steps. For incidents, move to containment (disable keys, isolate instances) and preserve logs.
Tip
Detective retains up to a year of graph data. Use it during post-incident reviews to confirm you've found everything.
- Amazon Detective Goes GA (Mar 2020): Investigation Graphs for AWS Security Findings Platform Changes
- Cloud Incident Investigation Runbook for AWS How-To & Hardening
- CIO Brief: Faster Investigations Mean Smaller Breaches CIO Briefings