M ManySignal
MS
GD
Integration

Aws Guardduty Integration

Native AWS threat detections fused with your full alert queue.

What this integration does

AWS GuardDuty meets agentic SOC

AWS GuardDuty uses machine learning and threat intelligence to detect threats within your AWS environment. ManySignal ingests GuardDuty findings via EventBridge and enriches each finding with entity graph context — account ownership, blast radius, and correlated signals from Okta, CrowdStrike, and other sources — before routing verdicts to your SOC.

Real-time finding ingestion via EventBridge (sub-60s latency)

Finding de-duplication across suppressed and active states

Entity graph enrichment: account → owner → access pattern

Data collected

  • GuardDuty threat findings with full JSON detail
  • Finding severity, type, and MITRE ATT&CK mapping
  • Affected resource metadata (EC2, IAM, S3, EKS)
  • Actor IP and threat intelligence tags

Actions supported

  • Archive GuardDuty finding on benign verdict
  • Escalate to Security Hub with custom severity
  • Isolate affected EC2 instance via security group rule
  • Disable IAM principal associated with finding actor
  • Notify on-call via PagerDuty or Opsgenie

Getting started

Set up in minutes

  1. 1

    Enable GuardDuty in all regions

  2. 2

    Create an EventBridge rule

  3. 3

    Connect ManySignal

  4. 4

    Configure verdict routing

Aws Guardduty Integration: frequently asked questions

Does GuardDuty cover EKS and container workloads?

Yes. GuardDuty Runtime Monitoring for EKS and ECS findings are ingested by ManySignal and enriched with Kubernetes RBAC context when the Kubernetes connector is also enabled.

How does ManySignal reduce GuardDuty alert volume?

ManySignal applies behavioural baselining and entity graph context to suppress known-good patterns (e.g., a CI/CD role invoking Lambda). Analysts see only findings with corroborating signals.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.