AWS launches GuardDuty’s latest AI/ML-powered threat detection capabilities for advanced cloud security

by

Azunta Gaviola

-

1 year ago

Singapore – Aiming to advance cloud security, Amazon Web Services has recently announced new updates to its Amazon GuardDuty, incorporating advanced AI/ML threat detection capabilities. This new feature allows the use of extensive cloud visibility and scale of AWS to provide improved threat detection for your applications, workloads, and data. 

According to the firm, the platform now features new AI/ML capabilities that correlate security signals to identify active attack sequences in your AWS environment. These sequences may involve multiple steps taken by an adversary, including privilege discovery, API manipulation, persistence activities, and data exfiltration. 

Moreover, it also introduces new attack sequence findings and improves actionability for existing detections in areas such as credential exfiltration, privilege escalation, and data exfiltration. 

With this enhancement, GuardDuty provides composite detections that integrate data across various sources, timelines, and resources, offering a more holistic view of complex cloud attacks within one’s account.

In addition, the new capabilities further bring attack sequence findings to GuardDuty, classified as critical severity. These findings include a natural language summary describing the threat’s nature and impact, observed activities aligned with MITRE ATT&CK tactics and techniques, and prescriptive remediation steps based on AWS best practices.

In terms of functionality, the GuardDuty includes new widgets on the summary page, such as (q) an overview widget showing the number of attack sequences; (2) a widget displaying findings broken down by severity; and (3) the ability to filter for top attack sequences.

On the other hand, types of findings under it encompass indication of potential data compromise, possibly part of a larger ransomware attack, and detection of misuse of compromised credentials in early attack stages.

These findings further provide extensive details such as specific user actions, affected accounts and resources, extended time periods of activity, multiple signals observed over time, and tactics and techniques mapped to the MITRE ATT&CK framework.

Additionally, extended capabilities include automatic activation for all accounts in a region, availability at no extra cost in all supported commercial AWS regions, and integration with existing GuardDuty workflows, such as AWS Security Hub and Amazon EventBridge.

The firm further revealed that said enhancement improves cloud security by automating the detection of sophisticated attack patterns and providing actionable insights, assisting security teams to concentrate on mitigating critical threats effectively.

Recognise the innovators redefining commerce at the Retail & E-commerce Excellence Awards Asia Pacific 2026! Taking place this December 2026, we celebrate the region’s most impactful retail strategies, standout e-commerce experiences, and forward-thinking leaders—submit your entries today!
Honour the women shaping the future of marketing and technology at the Empowered Women Awards 2026! This December 2026, we celebrate inspiring leaders, changemakers, and rising voices driving impact across the industry—submit your entries today!
Share

RECENT ARTICLES

HDBank taps London Stock Exchange to broaden global funding routes for Vietnamese firms
Paymentology enters Australian market to support evolving fintech, digital payments landscape
AEON360, Google Cloud collaborate on AI ecosystem to enhance retail experiences in Southeast Asia
Sumsub taps Go Digital Philippines to strengthen digital trust, AI governance across ASEAN
ITSEC Asia launches IntelliBron Aman Enterprise to expand mobile cybersecurity across Indonesia
Ellipse 3

RELATED ARTICLES

Comviva, AWS partnership to accelerate market time, revenue growth for businesses using AI, cloud-first solutions_11zon
Amazon Web Services announces partnership with Australian gov’t for enhanced defence, intelligence capabilities (1) (2)
Chevron, AWS reStart partnership to drive cloud computing skills amongst underprivileged individuals in PH_11zon
Ellipse 3

FEATURED ARTICLES

1_Huawei unveils smart tech strategies for secure, transparent e-commerce future 
1_Beyond the cart Shoppertainment execs on harnessing the potential of live commerce for unmatched customer experience_11zon
EW2025_(UT)Launch Article_Feature Image_11zon

Subscribe to UpTech Media Newsletter