تابعنا على
AWS Introduces GuardDuty Investigation Agent Preview for Automated Threat Analysis

Dev News

AWS Introduces GuardDuty Investigation Agent Preview for Automated Threat Analysis

AWS Introduces GuardDuty Investigation Agent Preview for Automated Threat Analysis

AWS has released a public preview of the Amazon GuardDuty Investigation Agent, a new tool designed to automate the triage of security threats. The announcement was made by the company on April 2, 2025, and is relevant for organizations using AWS cloud services to improve their security operations efficiency.

The agent centralizes and correlates multiple data sources, including GuardDuty findings, 90-day activity logs, and resource topology information. It then synthesizes this data into structured investigation reports that include risk ratings, confidence scores, and classifications aligned with the MITRE ATT&CK framework, a widely used knowledge base of cyber adversary tactics and techniques.

Availability and Access

According to the official release by AWS, the investigation agent is accessible through the AWS Management Console and the AWS MCP Server. This integration allows security teams to initiate and run investigations directly from agentic tooling environments, streamlining workflows for automated threat response.

The preview is currently subject to usage quotas. AWS has set a default limit of 10 investigations per AWS account per day during this preview phase. These quotas are intended to manage system load and provide a controlled testing environment for early adopters.

Technical Capabilities and Workflow

The agent operates by ingesting findings from Amazon GuardDuty, which is AWS’s managed threat detection service. It enriches these findings with historical activity logs covering a 90-day period and current resource topology, which maps the relationships and configurations of cloud assets. The output is a structured report that helps security analysts prioritize threats based on quantitative risk and confidence metrics.

By automating the correlation of disparate data points, the tool aims to reduce the manual effort required for initial threat assessment. The inclusion of MITRE ATT&CK classifications further enables organizations to map threats to known attack patterns, aiding in consistent and standardized incident response.

The agent does not replace existing security investigation tools but is designed to integrate into existing workflows, providing a structured starting point for deeper analysis. AWS has not disclosed specific performance benchmarks or comparison data against manual triage methods at this time.

Implications for Security Operations

The introduction of an automated investigation agent addresses a common challenge in cloud security: the volume of alerts generated by detection systems. By quickly producing risk-rated reports, the tool can help security teams focus on the most critical incidents, potentially reducing response times.

Security professionals should note that the agent operates within the context of the GuardDuty service and requires an active GuardDuty configuration. Additionally, the 90-day activity log scope means the tool is best suited for investigations where historical context within that window is relevant.

AWS has not announced a specific date for general availability of the agent. The company typically provides public previews for a period of months before making features widely available, based on customer feedback and performance testing.

Click to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

More Articles in Dev News