GuardDuty Setup
GuardDuty Setup and Configuration¶
Configuring AWS GuardDuty is the foundational step to enabling threat detection across your AWS environment. This section guides you through enabling GuardDuty, integrating it with AWS Security Hub for centralized findings management, and setting up member accounts for multi-account architectures.
1. Enabling GuardDuty¶
GuardDuty must be explicitly enabled in your AWS account. By default, it is not active, and you must configure it to monitor your AWS resources.
Step-by-Step Configuration¶
-
Console Setup:
Navigate to the GuardDuty console. Select the AWS account and region, then click Enable.
Note: Replace# AWS CLI command to enable GuardDuty (requires AWS CLI v2) aws guardduty update-detector --detector-id <detector-id> --threatintelligence-configuration '{"Enabled": true}'<detector-id>with the ID of your detector (e.g.,d-1234567890abcdef). -
Customizing Detection Settings:
This example sets findings to be published hourly.
Adjust sensitivity thresholds for different threat types (e.g.,UNRECOGNIZEDfor low,HIGHfor critical).
-
Region-Specific Configuration:
Ensure GuardDuty is enabled in all regions where your workloads reside. Each region requires a separate detector.
2. Integrating with AWS Security Hub¶
Integrating GuardDuty with Security Hub centralizes threat detection findings, enabling unified analysis and remediation.
Enabling Integration¶
-
Security Hub Setup:
Ensure Security Hub is enabled in your master account. Navigate to the Security Hub console and verify the Standards section includes the GuardDuty Standard. -
Enable GuardDuty Integration:
This ensures findings are automatically published to Security Hub.
Use the AWS CLI to activate the integration:
-
Region Alignment:
GuardDuty and Security Hub must operate in the same region for seamless integration. If using a central Security Hub account, ensure the master account is configured to receive findings from all member accounts.
3. Setting Up Member Accounts for Multi-Account Architectures¶
In a multi-account environment, GuardDuty must be enabled in each member account and linked to a central master account for centralized management.
Step-by-Step Configuration¶
-
Enable GuardDuty in Member Accounts:
Replace
For each member account, use the AWS CLI to activate GuardDuty:
<region>with the AWS region (e.g.,us-east-1). -
Link Member Accounts to Master Account:
This grants the master account access to GuardDuty findings from member accounts.
In the master account, associate member accounts using AWS Organizations:
-
IAM Permissions:
Ensure the master account has theAWSGuardDutyAdminAccesspolicy attached to its IAM role for cross-account access.
4. Configuring Detection Criteria¶
Fine-tune GuardDuty’s behavior to align with your security policies:
-
Adjust Sensitivity:
Modify the sensitivity level for specific threat types (e.g.,UNRECOGNIZED,LOW,MEDIUM,HIGH).
-
Exclude Specific Resources:
Use theexcludeparameter to avoid scanning certain resources (e.g., internal VPCs).
Key takeaways¶
- Enable GuardDuty in all relevant AWS accounts and regions to start threat detection.
- Integrate with Security Hub for centralized findings management and automated analysis.
- Configure member accounts in a multi-account architecture to centralize threat visibility.
- Customize detection criteria to align with your organization’s security policies and operational needs.