intermediate~3h
Advanced Threat Detection: GuardDuty, Macie & Security Hub
The three services that turn raw AWS activity logs and stored data into actionable security findings — continuous threat detection, sensitive-data discovery, and a single aggregated dashboard for both.
0
Subtopics
🎓 Learning objectives
- •Explain what GuardDuty actually analyzes (VPC Flow Logs, DNS logs, CloudTrail) and the kind of finding it produces
- •Explain what Macie scans for and why it specifically targets S3
- •Describe how Security Hub aggregates findings from GuardDuty, Macie, Inspector, and third-party tools into one place
- •Distinguish these three detective-control services from the preventive controls covered in IAM and WAF & Shield
Advanced Threat Detection: GuardDuty, Macie & Security Hub is a Pro topic
Sign in, then upgrade to Pro or Power to unlock this topic and the full AWS curriculum.
Related concepts
cloudtrail-configinspector-trusted-advisorwaf-shield