
It quickly raises an alert shortly after it detects an incident. While almost all warnings, when investigated, result from innocuous activities, the actions triggering them are precisely the sort that an attacker would be taking. The number of alerts is also low, so exploring false positives does not take long. When Guarduty is in the same AWS account as the entity that is the alert source, the alert can be clicked on to go directly to the entity, which results in a time-saving. Review collected by and hosted on G2.com.
Having to log in to GuardDuty to see the alerts will likely result in missed warnings. To get the most out of GuardDuty, integrate it with a monitored platform so that the alerts can be seen and acted upon. Review collected by and hosted on G2.com.





