intermediate~3h

Advanced Threat Detection: GuardDuty, Macie & Security Hub

The three services that turn raw AWS activity logs and stored data into actionable security findings — continuous threat detection, sensitive-data discovery, and a single aggregated dashboard for both.

0
Subtopics

🎓 Learning objectives

  • Explain what GuardDuty actually analyzes (VPC Flow Logs, DNS logs, CloudTrail) and the kind of finding it produces
  • Explain what Macie scans for and why it specifically targets S3
  • Describe how Security Hub aggregates findings from GuardDuty, Macie, Inspector, and third-party tools into one place
  • Distinguish these three detective-control services from the preventive controls covered in IAM and WAF & Shield

Advanced Threat Detection: GuardDuty, Macie & Security Hub is a Pro topic

Sign in, then upgrade to Pro or Power to unlock this topic and the full AWS curriculum.

Related concepts

cloudtrail-configinspector-trusted-advisorwaf-shield