← Back to all announcements
★★☆☆☆ 23/06/2026

Amazon GuardDuty AI-powered investigations accelerate threat response (Preview)

GuardDuty now auto-investigates threats in minutes—with confidence scores, MITRE mapping, and fix recommendations—slashing manual triage time.

View original announcement →

Visual Summary

graph TD A{{GuardDuty AI Investigations}}:::announced B((Security Analyst)):::external C([Knowledge Graph]):::feature D([Threat Intelligence]):::feature E([Disposition Assessment]):::feature F([MITRE ATT&CK Mapping]):::feature G(AWS Organizations):::compute H(AWS MCP Server):::compute I([Remediation Actions]):::feature B ==>|"triggers"| A A -->|"builds"| C A -->|"enriches with"| D C -->|"produces"| E E -->|"classifies"| F F -->|"recommends"| I A -->|"scans across"| G H -.->|"integrates"| A classDef announced fill:#ff9900,stroke:#ec7211,color:#fff,font-weight:bold classDef compute fill:#e3f2fd,stroke:#1565c0,color:#1565c0 classDef storage fill:#e8f5e9,stroke:#2e7d32,color:#2e7d32 classDef feature fill:#fff3e0,stroke:#e65100,color:#e65100 classDef external fill:#f5f5f5,stroke:#616161,color:#616161

What's New

AWS has announced the preview of AI-powered investigations in Amazon GuardDuty, a capability that automatically analyzes security findings to distinguish genuine threats from false positives without manual intervention. The feature examines up to 90 days of contextual activity, affected resources, and threat indicators using knowledge graphs and threat intelligence, delivering results in minutes. Each investigation produces a disposition assessment with confidence scoring, MITRE ATT&CK® technique mapping, supporting evidence, and concrete remediation or suppression recommendations.

How It Works

  • Automated finding analysis: When a GuardDuty finding is submitted for investigation, the AI engine automatically pulls the finding's full context, including the triggering event, associated resource metadata, and historical activity from the past 90 days.
  • Knowledge graph construction: The system builds a knowledge graph linking entities such as IAM principals, EC2 instances, S3 buckets, and network connections to surface relationships and behavioral patterns that may indicate lateral movement or compromise.
  • Threat intelligence enrichment: Findings are cross-referenced against AWS threat intelligence feeds and known malicious indicators (IPs, domains, signatures) to assess external threat context.
  • Disposition assessment with confidence scoring: The AI produces a verdict (e.g., true positive, likely benign, or needs review) accompanied by a confidence score, giving analysts a prioritized signal rather than raw alert data.
  • MITRE ATT&CK® classification: Each investigation maps observed behaviors to specific MITRE ATT&CK® techniques and tactics, providing a standardized framework for understanding attacker intent and stage.
  • Actionable recommendations: The output includes specific next steps—whether to suppress the finding, contain the affected resource, or initiate a remediation workflow—reducing the cognitive load on analysts.
  • Access methods: Investigations can be triggered and retrieved via the GuardDuty console, AWS CLI, API, or the AWS MCP (Model Context Protocol) Server, enabling integration into existing SOAR and automation pipelines.
  • Organizational scope: The feature can operate across individual AWS accounts or at the AWS Organizations level, allowing centralized security teams to investigate findings across an entire multi-account environment.

Why It's Important

  • Combats alert fatigue: Security operations centers routinely face hundreds of GuardDuty findings daily; automated triage with confidence scoring allows analysts to focus attention on high-fidelity alerts rather than manually reviewing every event.
  • Accelerates mean time to resolution (MTTR): By compressing what could be hours of manual investigation into minutes, the feature directly reduces the window of exposure during an active incident.
  • Reduces analyst skill dependency: Structured MITRE ATT&CK® mappings and evidence summaries make findings accessible to analysts of varying experience levels, lowering the barrier to effective cloud threat response.
  • Enables proactive containment: Actionable recommendations for containment and remediation allow teams to act immediately rather than spending time determining what to do after identifying a threat.
  • Scales with cloud growth: As AWS environments expand across accounts and regions, manual investigation becomes increasingly untenable; AI-driven automation scales linearly with finding volume without proportional headcount increases.
  • Improves audit and compliance posture: Documented disposition assessments with supporting evidence create a traceable investigation record useful for compliance reporting and post-incident reviews.

How It's Different

  • Beyond detection to investigation: Traditional GuardDuty surfaces findings but leaves investigation entirely to the analyst; AI-powered investigations closes the loop by automating the analysis step that follows detection.
  • 90-day historical context window: Unlike point-in-time alert tools, this feature correlates current findings against three months of prior activity, enabling detection of slow-moving or low-and-slow attack patterns that single-event analysis would miss.
  • Knowledge graph vs. rule-based correlation: Rather than relying on static correlation rules, the system uses a dynamic knowledge graph to discover non-obvious relationships between entities, improving detection of novel attack paths.
  • Native AWS integration without third-party SIEM dependency: Security teams can perform structured, evidence-backed investigations directly within GuardDuty without routing data to an external SIEM or SOAR platform first.
  • MCP Server accessibility: Availability via the AWS MCP Server allows AI assistants and agentic workflows to programmatically trigger and consume investigations, enabling next-generation security automation patterns not possible with traditional APIs alone.
  • Confidence-scored verdicts vs. binary alerts: Competing tools often produce binary alert/no-alert outputs; the confidence scoring here gives analysts a nuanced signal to calibrate their response effort appropriately.

When to Prefer It

  • High-volume SOC environments: Teams processing large numbers of GuardDuty findings daily where manual triage is creating bottlenecks or causing genuine threats to be missed amid noise.
  • Small or under-resourced security teams: Organizations without dedicated cloud security analysts who need AI assistance to interpret and act on complex GuardDuty findings effectively.
  • Multi-account AWS Organizations: Enterprises managing dozens or hundreds of AWS accounts through AWS Organizations who need a scalable way to investigate findings across the entire estate from a central security account.
  • Incident response under time pressure: Situations where a high-severity finding has been triggered and the team needs rapid context—affected resources, blast radius, and recommended containment—without waiting for a manual deep-dive.
  • Compliance-driven environments: Organizations in regulated industries that require documented, evidence-backed investigation records for every security finding to satisfy audit requirements.
  • SOAR and automation pipeline integration: Teams building automated security workflows who want to embed structured investigation outputs (disposition, confidence, MITRE mapping) as decision nodes in their automation logic via CLI or API.
  • Threat hunting and posture review: Security engineers who want to proactively investigate accounts or resources for historical suspicious activity using the 90-day lookback, even outside of an active incident.

Availability

  • Status: Currently in public preview as of June 23, 2026; not yet generally available (GA).
  • Supported regions (10): US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Ireland), Europe (London), Europe (Frankfurt), Europe (Paris), Europe (Stockholm), and Asia Pacific (Tokyo).
  • Access methods: Available through the Amazon GuardDuty console, AWS CLI, GuardDuty API, and the AWS MCP Server.
  • Scope: Supports investigations at the individual AWS account level and across entire AWS Organizations.
  • Pricing: Specific pricing details have not been published for the preview; costs during preview periods on AWS are often reduced or waived, but customers should consult the GuardDuty pricing page for current information.
  • Limitations: As a preview feature, it may be subject to change before GA; region availability is limited to the 10 listed regions and is not yet available in GovCloud, China, or other commercial regions.
  • Prerequisites: Requires Amazon GuardDuty to be enabled in the target account(s); existing GuardDuty customers can access the feature immediately through the console or API without additional setup.

Tags

Servicesother-aws
Typepreview-launchnew-feature
Conceptsagentic-aigenairesponsible-ai
Use Casesobservabilityenterprise
GeographyAMERICASAPJEMEA

Related Resources

AI Radar AWS

AWS AI/ML news — curated, researched, explained

An automated intelligence platform that curates, researches, and analyzes AWS AI/ML/GenAI announcements daily. Every report is backed by real research — the system reads linked blog posts and documentation to provide accurate, in-depth analysis.

How Each Report Is Generated

  1. Collection — Daily monitoring of the AWS "What's New" RSS feed
  2. Filtering — AI-powered relevance detection for AI/ML/GenAI topics
  3. Taxonomy Tagging — LLM-based classification across 6 dimensions
  4. Importance Scoring — Point-based system with tag bonuses (1-5 stars)
  5. Research Phase — Follows links to blog posts and documentation
  6. Report Generation — Claude Sonnet produces structured 6-section analysis
  7. Visual Summary — Claude Opus generates Mermaid diagrams for key items
  8. Publishing — Static website rebuilt and deployed via CloudFront

Features

  • Faceted filtering by service, type, concept, and more
  • Multi-dimensional taxonomy with 80+ tags across 6 dimensions
  • Geographic availability badges (Global, APJ, EMEA, AMER) with filtering
  • Timeline visualization of announcement volume
  • PDF export for offline reading
  • Mermaid visual summaries for key announcements
  • Daily automated updates — no manual curation
What makes this different: Each report involves a dedicated research phase where the system reads linked blog posts and AWS documentation pages. This produces analysis that goes beyond the original announcement text.

Technology

Built with Python, AWS Lambda, Amazon Bedrock (Claude Sonnet 4.6, Opus 4.6, Haiku 4.5), S3, CloudFront, WAF, EventBridge, and CDK.

Open Source

This project is open source. Fork it, customize it for your needs, and deploy your own instance.
📦 github.com/bbonik/ai-radar-aws

How Importance Scoring Works

Each announcement receives a point score based on multiple factors. The total score maps to a 1-5 star rating:

1★ < 2 pts 2★ ≥ 2 pts 3★ ≥ 3.5 pts 4★ ≥ 5 pts 5★ ≥ 6.5 pts

Point Breakdown

FactorPointsWhen
Core AI service (Bedrock, AgentCore, SageMaker AI)+4Service named in title
Key AI service (SageMaker, Kiro, QuickSight)+2Service named in title
Other AI-related service+1Default
Blog post link+3Link to aws.amazon.com/blogs/
GitHub samples link+2Link to github.com/aws*
Documentation link+1Link to docs.aws.amazon.com/
New model+1.5Tagged as "new-model"
New service+1Tagged as "new-service"
New feature+0.5Tagged as "new-feature"
Anthropic / OpenAI provider+2Provider explicitly mentioned
Instance / notebook announcement-2Hardware/capacity, not feature
Performance / pricing / security-0.5Incremental updates
Region expansion to APJ+1Expands to Asia Pacific
Region expansion (non-APJ only)-1.5Only expands to other regions

Geographic Relevance Badges

Each announcement card shows a small badge indicating whether the feature is available in your region:

🌐 Global Available in all regions
🌏 APJ Asia Pacific
🌍 EMEA Europe / Middle East / Africa
🌎 AMER Americas (US, Canada, South America)
No badge Geography unknown
How geography is detected: The system detects ALL geographies mentioned in each announcement. If the text mentions specific regions (Tokyo, Frankfurt, Oregon, etc.), the corresponding geography badges are shown. If it says "all regions" or is a new feature with no region specified, it gets the Global badge. Geography is also filterable — click a geo chip to see only announcements available in that region.