Features
Automatic data collection across all your AWS accounts
Integration with Organizations
Administrator account
Detective administrator account
Member account
Delegated administrator account (AWS Organizations)
Simplify setup with AWS Organizations
Consolidates disparate events into a graph model
Interactive visualizations for efficient investigation
Seamless integration for investigating a security finding
Simple deployment with no upfront data source integration or complex configurations to maintain
Partner integrations
Pivot from Splunk into Amazon Detective
Use cases
Incident investigation
Triage
Scoping
Response
(Demo Video)
Threat hunting
Root cause analysis
Behavior graph
Entities & relationships
AWS account
What API calls has the account used?
What user agents has the account used?
What autonomous system organizations (ASOs) has the account used?
In what geographic locations has the account been active?
AWS role
What API calls has the role used?
What user agents has the role used?
What ASOs has the role used?
In what geographic locations has the role been active?
What resources have assumed this role?
What roles has this role assumed?
What role sessions have involved this role?
AWS user
What API calls has the user used?
What user agents has the user used?
In what geographic locations has the user been active?
What roles has this user assumed?
What role sessions have involved this user?
Federated user
What identity provider did the federated user authenticate with?
What was the audience of the federated user? The audience identifies the application that requested the web identity token of the federated user.
In what geographic locations has the federated user been active?
What user agents has the federated user used?
What ASOs has the federated user used?
What roles has this federated user assumed?
What role sessions have involved this federated user?
EC2 instance
What IP addresses have communicated with the instance?
What ports have been used to communicate with the instance?
What volume of data has been sent to and from the instance?
What VPC contains the instance?
What API calls has the EC2 instance used?
What user agents has the EC2 instance used?
What ASOs has the EC2 instance used?
In what geographic locations has the EC2 instance been active?
What roles has the EC2 instance assumed?
Role session
What resources were involved in this role session? In other words, what role was assumed, and what resource assumed the role?
What API calls has the role session used?
What user agents has the role session used?
What ASOs has the role session used?
In what geographic locations has the role session been active?
What user or role started this role session?
What role sessions started from this role session?
IP address
What API calls has the address used?
What ports has the address used?
What users and user agents have used the IP address?
In what geographic locations has the IP address been active?
What EC2 instances has this IP address been assigned to and communicated with?
S3 bucket
What principals interacted with the S3 bucket?
What API calls were made to the S3 bucket?
From what geographic locations did principals make API calls to the S3 bucket?
What user agents were used to interact with the S3 bucket?
What ASOs were used to interact with the S3 bucket?
User agent
What API calls has the user agent used?
What users and roles have used the user agent?
What IP addresses have used the user agent?
Finding (from Amazon GuardDuty)
Type
Origin
Time window
Finding overview
Entity details
Scope time
Summary findings
Newly observed geolocations in the past 24 hours
Roles and users with the most API call volume in the past 24 hours
EC2 instances with the most traffic volume in the past 24 hours
Security in Amazon Detective
Prerequisites and recommendations
Account must have Amazon GuardDuty enabled
Account data volume must be within the Detective quota
Recommended alignment with GuardDuty and AWS Security Hub
Granting the required Detective permissions
Recommended update to the GuardDuty CloudWatch notification frequency
Detective source data
CloudTrails logs
VPC Flow logs
Amazon GuardDuty findings
Archiving an Amazon GuardDuty finding
Amazon Detective FAQs
Amazon Detective Partners
Amazon Detective Security Blogs
AWS re:Post questions for Amazon Detective
Amazon Detective Pricing
Free Cybersecurity Training