AWS::GuardDuty::Detector
- Intelligent
threat discoveryto protect your AWS account.E.g., cryptocurrency attacks - Uses
MLto detect anomaly - Events can be setup with
Cloud Watch Events Rules

- GuardDuty can be:
Disabled: delete all remaining data-
Suspended: stop the service but does not delete existing finding and configurations -
Logs to be analyzed
CloudTrail logsVPC Flow logsDNS logs
Properties
DataSources
- Data stored in S3 bucket