AWS::GuardDuty::Detector
- Intelligent
threat discoveryto protect your AWS account.E.g., cryptocurrency attacks - Uses
MLto detect anomaly - Events can be setup with
Cloud Watch Events Rules

- GuardDuty can be:
Disabled: delete all remaining data-
Suspended: stop the service but does not delete existing finding and configurations -
Logs to be analyzed
CloudTrail logsVPC Flow logsDNS logs
Properties
Type: AWS::GuardDuty::Detector
Properties:
DataSources:
CFNDataSourceConfigurations
Enable: Boolean
Features:
- CFNFeatureConfiguration
FindingPublishingFrequency: String
Tags:
- TagItem
DataSources
- Data stored in S3 bucket