Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
セキュリティ運用エージェントGuardDuty-Operatorを作って社内に配ってみた @ ...
Search
SimSta
May 26, 2026
210
2
Share
セキュリティ運用エージェントGuardDuty-Operatorを作って社内に配ってみた @ JAWS-UG SRE支部
SimSta
May 26, 2026
More Decks by SimSta
See All by SimSta
祝日にも対応なコスト節約ツールNAT-Schedulerの紹介 @ JAWS-UG 札幌×秋田コラボ
shimagaji
1
130
AgentCore RuntimeのCDKデプロイにdeploy-time-buildを使ってみよう @ JAWS-UG Sapporo
shimagaji
2
150
AWSの2025年最新トレンドをフル活用してフルサーバーレスな司書エージェントを作ってみた @ JAWS-UG Sapporo
shimagaji
3
330
AWS Media Servicesを使ってAmazon IVSとYouTubeへの同時配信を試してみた @ JAWS-UG千葉支部 x Media-JAWS
shimagaji
1
150
AWSアップデートまとめ #しむそく をFun Done Learnで振り返る @ JAWS-UG Tokyo
shimagaji
2
330
Amazon Q DeveloperでMCP Serverを使ってKnowledge Baseを呼び出してみた @ JAWS-UG 彩の国埼玉支部#1
shimagaji
1
530
KAG社内のPlatform Engineeringをちょっとだけ紹介します @ Sapporo Engineer Base
shimagaji
0
62
日本からre:Inventを支えた活動報告&ミニre:Cap @ JAWS-UG Sapporo
shimagaji
0
140
Step FunctionsとInfrastructure Composerで挑むローコード × Platform Engineering @ JAWS-UG 青森
shimagaji
1
380
Featured
See All Featured
Ruling the World: When Life Gets Gamed
codingconduct
0
240
For a Future-Friendly Web
brad_frost
183
10k
Imperfection Machines: The Place of Print at Facebook
scottboms
270
14k
Claude Code のすすめ
schroneko
67
220k
Fireside Chat
paigeccino
42
3.9k
Visualization
eitanlees
151
17k
Making Projects Easy
brettharned
120
6.6k
Discover your Explorer Soul
emna__ayadi
2
1.1k
How to Align SEO within the Product Triangle To Get Buy-In & Support - #RIMC
aleyda
2
1.5k
We Are The Robots
honzajavorek
0
230
Bioeconomy Workshop: Dr. Julius Ecuru, Opportunities for a Bioeconomy in West Africa
akademiya2063
PRO
1
120
Amusing Abliteration
ianozsvald
1
180
Transcript
ηΩϡϦςΟӡ༻ΤʔδΣϯτ (VBSE%VUZ0QFSBUPSΛ ࡞ͬͯࣾʹͬͯΈͨ 4JN4UB !TIJNBHBKJ +"846(43& ू·ΕʂԶͨͪͷ࡞ͬͨ࠷ڧͷӡ༻"HFOUେ-5େձ KBXTVH@TSF
ࣗݾհ +BQBO"845PQ&OHJOFFS +BQBO"MM"84$FSUJGJDBUJPOT&OHJOFFS "84$PNNVOJUZ#VJMEFS ࡛ۄˠࡳຈˠਆಸˠࡳຈ 4JN4UBʢΦϯϥΠϯͷ͕ͨ͢ʣ ,%%*ΞδϟΠϧ։ൃηϯλʔגࣜձࣾʢ,"(ʣ ϓϥοτϑΥʔϜΤϯδχΞϦϯά෦ ઓུاը෦ 4FSWFSMFTT
ΧάΧά !TIJNBHBKJ 5XJUUFS
ۙͷొஃ༧ఆ ίετݮπʔϧ/"54DIFEVMFSͷ ηΩϡϦςΟӡ༻ΤʔδΣϯτ (VBSE%VUZ0QFSBUPSͷ ʢԾʣ৴தʹۓٸใΛड৴ͨ͠Βʜͳ
"HFOEB • (VBSE%VUZʹؔ͢ΔΈ • ,"(ͷ1MBUGPSN&OHJOFFSJOHͱLBHUPPMT • (VBSE%VUZ4VNNBSJ[FSͷհ • #FESPDL"HFOU$PSFͷొ •
(VBSE%VUZ0QFSBUPSͷհ • ࡞͔ͬͯͬͯͬͨ՝ • ·ͱΊ
(VBSE%VUZ ͪΌΜͱӡ༻Ͱ͖ͯ·͔͢ʁ
(VBSE%VUZͱͦͷ௨ • $MPVE5SBJMͳͲͷΞΫςΟϏςΟͳͲΛݩʹҟৗΛࢹ͠ɺ "84ΞΧϯτʹ࣮ࡍʹى͖͍ͯΔڴҖΛݕग़ͯ͠௨ • 4FDVSJUZ)VCͱ͍ͬͨʮΞΧϯτͷηΩϡϦςΟෆඋʯͰͳ͘ ʮΞΧϯτʹൃੜͨ͠ڴҖͦͷͷʯ͕ಧ͘ͷͰɺ ௨͞ΕͨΒ͙͢ʹରԠ͠ͳ͚ΕͳΒͳ͍ ˠͰ(VBSE%VUZ͔Βͷ௨ͲΜͳײ͡Ͱಧ͘ʁ
ʮ&$ͷϩʔϧೝূใ͕"84֎͔Βར༻͞Εͨʯ ͱ͍͏ڴҖͷ௨ ΠϕϯτΛͦͷ··௨͢Δͱ ˡͷΑ͏ͳ͍͍+40/͕ಧ͘ &WFOU#SJEHF -BNCEBͳͲͰܗͰ͖Δ͕ ։ൃऀʹͱͬͯೝෛՙ͕ߴ͘ ʮԿ͕ى͖͍ͯͯɺͲ͏͢Ε͍͍ʁʯΛ அɾ࣮ߦͰ͖Δਓগͳ͍ ˣ
ೝෛՙΛԼ͛ͯ ୭ͰཧղɾରԠͰ͖ΔΑ͏ʹ͍ͨ͠ʂ ͜Μͳײ͡
,"(ͷ 1MBUGPSN&OHJOFFSJOHͱ LBHUPPMT
,"(ͷ1MBUGPSN&OHJOFFSJOHͱLBHUPPMT • ։ൃνʔϜͷೝෛՙΛܰݮ͢ΔηϧϑαʔϏεπʔϧΛ LBHUPPMTͱͯࣾ͠Ͱల։ • (JU)VC&OUFSQSJTFͷϦϙδτϦʹͯΠϯφʔιʔεͱͯ͠ఏڙ • ୭ͰίϯτϦϏϡʔτ0, • ηΩϡϦςΟɺΨόφϯεɺίετݮɺ։ൃڥͳͲ͍Ζ͍Ζ
• ίετݮܥπʔϧͷͭ/"54DIFEVMFSʹ͍ͭͯ Ұࡢʢ݄ʣͷ+"846(ࡳຈºळాࢧ෦ίϥϘʹ͓ͯ͠·ͨ͠ • ຊհͷ(VBSE%VUZ4VNNBSJ[FS0QFSBUPSηΩϡϦςΟܥͷπʔϧ
(VBSE%VUZ0QFSBUPSͷલ (VBSE%VUZ4VNNBSJ[FSͷհ
(VBSE%VUZ4VNNBSJ[FSͷ֓ཁ • (VBSE%VUZͷݕ༰Λ#FESPDLʢ$MBVEF4POOFUʣʹͯ͠ ཁ͔ͤͯ͞ΒϢʔβʔʹ௨͢Δπʔϧ • มΛೖΕͯγΣϧεΫϦϓτΛ࣮ߦ͢Δ͚ͩͰ୭Ͱ؆୯ʹσϓϩΠ • 4UFQ'VODUJPOTͰ݁ɺ-BNCEBϨεͰϝϯςφϯεָ͕ • 4FDVSJUZ)VCͰϚϧνΞΧϯτͷ(VBSE%VUZΛू͍ͯ͠Ε
୯ҰͷཧΞΧϯτʹσϓϩΠ͢Δ͚ͩͰ0, • #FESPDLͷϞσϧ୯७ʹݺͼग़͚ͩ͢ͳͷͰɺϞσϧͷࣝʹґଘ ʢ3"("84υΩϡϝϯτͷࢀর͠ͳ͍ʣ
AWS Cloud GuardDuty Step Functions Bedrock SNS Invoke Execute EventBridge
User Threats E-Mail Publish Slack Security Hub ᶃ(VBSE%VUZͷΠϕϯτΛर͏ ᶄ4FDVSJUZ)VCʹू͞ΕͨΠϕϯτΛर͏ ͷͲͪΒ͔Λબͯ͠σϓϩΠՄೳ (VBSE%VUZ4VNNBSJ[FSͷߏ (VBSE%VUZͷݕ༰Λཁͯ͠4MBDLʹ௨
#FESPDL"HFOU$PSFͷొ
#FESPDL"HFOU$PSF ࡞ͨ͠ੜ"*ΤʔδΣϯτΛσϓϩΠ͢ΔͨΊͷϓϥοτϑΥʔϜ 4USBOETͳͲΛ ίϯςφԽ ձͷهԱ Մ؍ଌੑ˕ ଟ࠼ͳπʔϧͱ ҆શͳར༻ IUUQTHJUIVCDPNBXTMBCTBNB[POCFESPDLBHFOUDPSFTBNQMFTCMPCNBJOUVUPSJBMTJNBHFTBHFOUDPSF@PWFSWJFXQOH
#FESPDL"HFOU$PSFͷొʹΑΔϞνϕʔγϣϯ • (VBSE%VUZʹΑΔݕͷ୯७ͳཁ͚ͩͰͳ͘ɺʮࠓͲΜͳঢ়ଶʁʯ ʮͲ͏ରॲ͢Ε͍͍ͷʁʯ·Ͱ"*͕౿ΈࠐΊΔΑ͏ʹͳΓͦ͏ • 4USBOET"HFOUT #FESPDL"HFOU$PSFͷΈ߹Θ͕ͤ ࠓޙελϯμʔυʹͳΔ͜ͱΛݟӽ͠ɺ൚༻తʹ࠶ར༻Ͱ͖Δ "*ΤʔδΣϯτͷςϯϓϨʔτΛ࡞͓͖͍ͬͯͨ •
ಛʹΠϕϯτۦಈΤʔδΣϯτʢ"NCJFOU"HFOUʣ͕ྲྀߦͬͯͨͷͰ ϊϋͷशಘͱࣾͷڞ༗Λ͍ͨ͠ ˠηΩϡϦςΟӡ༻ΤʔδΣϯτ(VBSE%VUZ0QFSBUPSΛ։ൃɾࣾల։
(VBSE%VUZ0QFSBUPSͷհ
(VBSE%VUZ0QFSBUPSͷ֓ཁ • (VBSE%VUZͷݕ༰Λ#FESPDL"HFOU$PSFʢ4USBOETʣʹͯ͠ ௐࠪ͠ɺৄࡉਪ͞ΕΔίϚϯυΛؚΊͯϢʔβʔʹ௨͢Δπʔϧ • ϩʔΧϧ·ͨ$MPVE4IFMMͰ$%,Λͬͯ୭Ͱ؆୯ʹσϓϩΠ ˠEFQMPZUJNFCVJMEࡌͰίϯςφΠϝʔδͷϏϧυΛΦϑϩʔυ • 4FDVSJUZ)VCͰϚϧνΞΧϯτͷ(VBSE%VUZΛू͍ͯ͠Ε ୯ҰͷཧΞΧϯτʹσϓϩΠ͢Δ͚ͩͰ0,
• ݱࡏͷϦιʔεͷঢ়گ࠷৽ͷ"84υΩϡϝϯτΛࢀর͠ɺ ΑΓৄࡉͰ࣮֬ͳใΛ௨͢Δ͜ͱ͕Ͱ͖Δ
(VBSE%VUZ0QFSBUPSͷߏ AWS Cloud ECR AgentCore Runtime AWS API MCP Slack
Lambda AWS Knowledge MCP SNS Strands Agents GuardDuty EventBridge (VBSE%VUZͷݕ༰Λৄࡉௐࠪͯ͠4MBDLʹ௨ SNS Security Hub ᶃ(VBSE%VUZͷΠϕϯτΛर͏ ᶄ4FDVSJUZ)VCʹू͞ΕͨΠϕϯτΛर͏ ͷͲͪΒ͔Λબͯ͠σϓϩΠՄೳ
(VBSE%VUZͷݕ༰Λৄࡉௐࠪͯ͠4MBDLʹ௨ %FW0QT"HFOUͷΑ͏ʹਪ$-*ίϚϯυͳͲΛग़ྗ (VBSE%VUZ0QFSBUPSͷߏ
࡞ͬͨ"*ΤʔδΣϯτΛ ࣾͰͬͯΈͨ
ηϧϑαʔϏεπʔϧͱͯ͠εΫϥϜνʔϜʹల։ Platform Team User User User GitHub Enterprise (JU)VC&OUFSQSJTFͰ$%,ςϯϓϨʔτΛ ཧ
ηϧϑαʔϏεπʔϧͱͯ͠εΫϥϜνʔϜʹల։ Platform Team User User User GitHub Enterprise (JU)VC&OUFSQSJTFͰ$%,ςϯϓϨʔτΛ ݱ࣮
ͬͯ͘ΕΔνʔϜ͕ ͍ͳ͍ʜ ʢ࣌ʣ
࡞͔ͬͯͬͯͬͨ՝ • πʔϧ࡞ͬͯͬͨΒऴΘΓͰͳ͘ɺΘΕͳ͍ͱՁ͕ͳ͍ • (VBSE%VUZͷݕػձͷগͳ͞ˍϑΟʔυόοΫͷෆͰ վળϧʔϓ͕ճΒͳ͘ͳͬͯ͠·͏ • ΒͤΔରʢʹࣾϚʔέςΟϯάʣ͍ͩ͡ • ฉ͖ʹ͍͘ରʢʹ֤νʔϜͱʮ՝ײʯʮຊʹඞཁͳͷʯ
ʮηΩϡϦςΟ؍ʯΛ͢Γ߹ΘͤΔ͜ͱʣ͍ͩ͡ • ηϧϑαʔϏεͷ"*ΤʔδΣϯτπʔϧΛల։͢Δࡍ ʮ࠷ॳͷҰาΛ౿Έग़ͤ͞ΔͨΊͷಋઢʯͷઃܭ͕ॏཁ
·ͱΊ
·ͱΊ • ηΩϡϦςΟ໘Ͱॏཁ͕ͩೝෛՙͷߴ͍(VBSE%VUZͷݕ༰Λ "*ʢΤʔδΣϯτʣπʔϧܦ༝ͰཧղͰ͖Δܗࣜʹͯ͠௨ • (VBSE%VUZ4VNNBSJ[FS0QFSBUPS͍ͣΕɺ؆୯ʹσϓϩΠՄೳͳ ηϧϑαʔϏεπʔϧͱͯࣾ͠ఏڙ • ͔͠͠ɺ࡞ͬͯఏڙ͚ͨͩ͠ͰΘΕͣɺվળ͞Εͳ͍ •
πʔϧΛͬͯΒ͏ͨΊͷʮΒͤΔରʯʮฉ͖ʹ͍͘ରʯ͕ 1MBUGPSN&OHJOFFSJOHͰ͍ͩ͡ʂ
5IBOLZPVʂ