Skip to content

GuardDuty Setup

GuardDuty Setup and Configuration

Configuring AWS GuardDuty is the foundational step to enabling threat detection across your AWS environment. This section guides you through enabling GuardDuty, integrating it with AWS Security Hub for centralized findings management, and setting up member accounts for multi-account architectures.


1. Enabling GuardDuty

GuardDuty must be explicitly enabled in your AWS account. By default, it is not active, and you must configure it to monitor your AWS resources.

Step-by-Step Configuration

  1. Console Setup:
    Navigate to the GuardDuty console. Select the AWS account and region, then click Enable.

    # AWS CLI command to enable GuardDuty (requires AWS CLI v2)
    aws guardduty update-detector --detector-id <detector-id> --threatintelligence-configuration '{"Enabled": true}'
    
    Note: Replace <detector-id> with the ID of your detector (e.g., d-1234567890abcdef).

  2. Customizing Detection Settings:
    Adjust sensitivity thresholds for different threat types (e.g., UNRECOGNIZED for low, HIGH for critical).

    aws guardduty update-detector --detector-id <detector-id> --finding-publishing-configuration '{"PublishingFrequency": "ONE_HOUR"}'
    
    This example sets findings to be published hourly.

  3. Region-Specific Configuration:
    Ensure GuardDuty is enabled in all regions where your workloads reside. Each region requires a separate detector.


2. Integrating with AWS Security Hub

Integrating GuardDuty with Security Hub centralizes threat detection findings, enabling unified analysis and remediation.

Enabling Integration

  1. Security Hub Setup:
    Ensure Security Hub is enabled in your master account. Navigate to the Security Hub console and verify the Standards section includes the GuardDuty Standard.

  2. Enable GuardDuty Integration:
    Use the AWS CLI to activate the integration:

    aws securityhub update-security-hub-configuration --configuration '{"GuardDuty": {"Enabled": true}}'
    
    This ensures findings are automatically published to Security Hub.

  3. Region Alignment:
    GuardDuty and Security Hub must operate in the same region for seamless integration. If using a central Security Hub account, ensure the master account is configured to receive findings from all member accounts.


3. Setting Up Member Accounts for Multi-Account Architectures

In a multi-account environment, GuardDuty must be enabled in each member account and linked to a central master account for centralized management.

Step-by-Step Configuration

  1. Enable GuardDuty in Member Accounts:
    For each member account, use the AWS CLI to activate GuardDuty:

    aws guardduty create-detector --region <region> --tags "Key=Environment,Value=Production"
    
    Replace <region> with the AWS region (e.g., us-east-1).

  2. Link Member Accounts to Master Account:
    In the master account, associate member accounts using AWS Organizations:

    aws organizations associate-organization-id --organization-id <org-id> --service-principal "guardduty.amazonaws.com"
    
    This grants the master account access to GuardDuty findings from member accounts.

  3. IAM Permissions:
    Ensure the master account has the AWSGuardDutyAdminAccess policy attached to its IAM role for cross-account access.


4. Configuring Detection Criteria

Fine-tune GuardDuty’s behavior to align with your security policies:

  • Adjust Sensitivity:
    Modify the sensitivity level for specific threat types (e.g., UNRECOGNIZED, LOW, MEDIUM, HIGH).

    aws guardduty update-detector --detector-id <detector-id> --threatintelligence-configuration '{"Enabled": true, "Sensitivity": "MEDIUM"}'
    

  • Exclude Specific Resources:
    Use the exclude parameter to avoid scanning certain resources (e.g., internal VPCs).

    aws guardduty update-detector --detector-id <detector-id> --finding-publishing-configuration '{"ExcludeByResourceIds": ["vpc-1234567890abcdef0"]}'
    


Key takeaways

  • Enable GuardDuty in all relevant AWS accounts and regions to start threat detection.
  • Integrate with Security Hub for centralized findings management and automated analysis.
  • Configure member accounts in a multi-account architecture to centralize threat visibility.
  • Customize detection criteria to align with your organization’s security policies and operational needs.