Threat intelligence Anomaly detection (ML) Amazon Detective • Alert • Remediation • Send to SIEM • Solutions technology partners CloudWatch Event Type of findings • Bitcoin mining • Command & Control • Anonymous connections • Recognition Unusual Behavior Example: • Launch instances • Changes in network permissions • Anomalies in the behavior of he network • Anomalous patterns of access to the data in Amazon S3 Amazon GuardDuty Data source Detection type HIGH MEDIUM LOW AWS SecurityHub S3 DataPlane Events