AWS Unveils AI-Powered Investigation Agent for GuardDuty Threat Detection

·
By Raisink Team

A new feature in Amazon’s threat detection service, AWS GuardDuty, aims to streamline the initial stages of security investigations. The investigation agent is now available in public preview and promises to reduce time spent on these tasks by leveraging artificial intelligence (AI) capabilities.

The AI-powered tool provides structured assessments with risk levels, confidence scores, and actionable recommendations for investigating suspicious findings or assessing an organization’s overall security posture. This feature is designed to help security teams make informed decisions about potential threats more efficiently.

Amazon GuardDuty continuously monitors AWS accounts, workloads, and data for malicious activity, delivering security findings that require investigation and remediation. The new investigation agent can be used in conjunction with these existing capabilities to enhance threat detection and response efforts.

To use the investigation agent, Amazon GuardDuty must first be enabled within an organization’s AWS account settings. Three specific permissions are required: one for creating investigations, another for retrieving results, and a third for listing investigations related to a detector. These permissions allow administrators to manage access control and ensure that only authorized personnel can initiate or view investigations.

Once the investigation agent is set up, users can start an investigation from within the GuardDuty console using various triggers such as specific findings, AWS accounts, or entire organizations. The completed investigation will include a summary of key findings, MITRE ATT&CK technique mappings, affected resources, risk and confidence assessments, and recommended remediation steps.

The feature is also accessible through the AWS Command Line Interface (CLI) and Software Development Kit (SDK), enabling users to integrate automated investigations into existing security workflows. The API-first design allows organizations to leverage this capability in conjunction with their current tools and processes for enhanced threat detection and response capabilities.

Furthermore, the investigation agent integrates seamlessly with Amazon EventBridge, allowing enriched GuardDuty findings to be sent to Security Information and Event Management (SIEM) platforms, ticketing systems, or automation tools. This integration enables organizations to streamline incident response efforts by automating tasks such as alert creation and remediation steps.

The Model Context Protocol (MCP), an open standard for secure AI assistant connections, is also supported through the official AWS MCP server. Organizations can integrate GuardDuty investigations into their existing workflows using clients like Kiro or Anthropic’s Claude that are compatible with MCP.

When initiating an investigation, the agent uses cross-Region inference capabilities to analyze findings and generate a structured assessment. This process ensures data remains encrypted in transit while being processed across different Regions within the same geographic area. Each completed investigation returns a risk level, confidence score, summary of key findings, and recommended actions based on the selected scope.

The public preview for this feature is currently available at no additional cost in 10 AWS Regions, with usage limited to 10 investigations per account per day and a cumulative limit of 100 investigations per account during the preview period. Failed investigations do not count towards these quotas.

Related news