Skip to main content

AWS - GuardDuty

Download With Dependencies

Amazon Web Services Guard Duty Service (gd)

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts, workloads, and data stored in Amazon S3.

What does this pack do

This integration enables you to:

  • Create an AWS GuardDuty detector on the integration instance specified AWS account.
  • Retrieve, update, or delete Amazon GuardDuty detectors.
  • Create, retrieve, update, or delete a list of IP addresses that are trusted for secure communication with AWS infrastructure and applications.
  • Create, retrieve, or delete a set of known malicious IP addresses.
  • Retrieve lists or descriptions of Amazon GuardDuty findings (a potential security issue detected within your network).
  • Archive Amazon GuardDuty findings.
  • Retrieve a description of the Amazon GuardDuty members.

Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts, workloads, and data stored in Amazon S3.

What does this pack do

This integration enables you to:

  • Create an AWS GuardDuty detector on the integration instance specified AWS account.
  • Retrieve, update, or delete Amazon GuardDuty detectors.
  • Create, retrieve, update, or delete a list of IP addresses that are trusted for secure communication with AWS infrastructure and applications.
  • Create, retrieve, or delete a set of known malicious IP addresses.
  • Retrieve lists or descriptions of Amazon GuardDuty findings (a potential security issue detected within your network).
  • Archive Amazon GuardDuty findings.
  • Retrieve a description of the Amazon GuardDuty members.

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedNovember 9, 2020
Last ReleaseMay 3, 2026
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
By downloading or using Marketplace content, you agree to the applicable Terms of Use and End User License Agreement. Third-party content is provided by its publisher, and Palo Alto Networks does not warrant, endorse, support, or assume responsibility for content not expressly identified as owned by Palo Alto Networks.