Amazon GuardDuty logo

Amazon GuardDuty

Amazon GuardDuty

UpOpen Sourcecloudby Amazon Web Services62· JavaScript· MIT

Amazon GuardDuty is a continuous security monitoring service that analyzes and processes the following data sources: VPC flow logs, Amazon Web Services CloudTrail management event logs, CloudTrail S3 data event logs, EKS audit logs, DNS logs, and Amazon EBS volume data.

Visit site ↗Source ↗Health checked 15h ago
Use it when

Continuous security monitoring

Watch for

Check the docs depth and real endpoint shape before assuming production fit.

First check

To start using Amazon GuardDuty, configure your AWS environment to enable GuardDuty and provide necessary permissions. Authentication is managed through AWS credentials and IAM roles.

Auth
CORS
No
HTTPS
Yes
Signup
?
Latency
39 ms
Protocol
REST
Pricing
Stars
62

Uptime · 30-day window

Probes: 4Uptime: 100%Avg latency: 56ms

GitHub activity

62JavaScriptMIT17 open issuesLast commit 114d ago
01

About this API

Amazon GuardDuty is a security monitoring service designed to continuously analyze and process various AWS data sources such as VPC flow logs, CloudTrail management and data event logs, EKS audit logs, DNS logs, and Amazon EBS volume data. It helps identify potential security threats by detecting suspicious activities and anomalies within these logs.

This service is primarily used by security teams and developers managing AWS environments who need to maintain visibility into their cloud infrastructure's security posture. By automating the analysis of multiple log sources, GuardDuty reduces the manual effort required to detect and respond to threats.

GuardDuty's relevance lies in its integration with core AWS logging services and its ability to provide ongoing threat detection without requiring extensive setup. It supports continuous monitoring, making it a valuable tool for maintaining cloud security compliance and operational awareness.

02

What you can build

  • 1Monitor AWS network traffic for security threats
  • 2Analyze CloudTrail logs for suspicious activity
  • 3Process EKS audit logs for compliance
  • 4Detect anomalies in DNS and VPC flow logs
03

Strengths & limitations

Strengths

  • Continuous security monitoring
  • Supports multiple AWS log sources
  • Automates threat detection
04

Example request

Generic template — replace <endpoint> with the real path from the docs.
curl https://github.com/mermade/aws2openapi/<endpoint>
05

Getting started

To start using Amazon GuardDuty, configure your AWS environment to enable GuardDuty and provide necessary permissions. Authentication is managed through AWS credentials and IAM roles.

06

FAQ

Do I need an API key to use Amazon GuardDuty?+

Amazon GuardDuty uses AWS credentials and IAM roles for authentication, not separate API keys.

What types of data does GuardDuty analyze?+

It analyzes VPC flow logs, CloudTrail management and data event logs, EKS audit logs, DNS logs, and Amazon EBS volume data.

Is there a free tier available for GuardDuty?+

Pricing details are managed by AWS; check AWS official documentation for current offerings.

Can I use GuardDuty from a browser directly?+

GuardDuty is accessed via AWS APIs and the AWS Management Console, which is browser-based.

Is HTTPS required to interact with GuardDuty APIs?+

AWS APIs, including GuardDuty, require HTTPS for secure communication.

07

Technical details

CORS: NoHTTPS: YesSignup: ?Open source: Yes
Auth type
unknown
Pricing
unknown
Protocols
REST
Response time
39 ms
Last health check
5/15/2026, 2:52:42 PM
08

Tags

09

More from Amazon Web Services