Amazon GuardDuty AI-powered investigations accelerate threat response (Preview)
GuardDuty now auto-investigates threats in minutes—with confidence scores, MITRE mapping, and fix recommendations—slashing manual triage time.
View original announcement →Visual Summary
What's New
AWS has announced the preview of AI-powered investigations in Amazon GuardDuty, a capability that automatically analyzes security findings to distinguish genuine threats from false positives without manual intervention. The feature examines up to 90 days of contextual activity, affected resources, and threat indicators using knowledge graphs and threat intelligence, delivering results in minutes. Each investigation produces a disposition assessment with confidence scoring, MITRE ATT&CK® technique mapping, supporting evidence, and concrete remediation or suppression recommendations.
How It Works
- Automated finding analysis: When a GuardDuty finding is submitted for investigation, the AI engine automatically pulls the finding's full context, including the triggering event, associated resource metadata, and historical activity from the past 90 days.
- Knowledge graph construction: The system builds a knowledge graph linking entities such as IAM principals, EC2 instances, S3 buckets, and network connections to surface relationships and behavioral patterns that may indicate lateral movement or compromise.
- Threat intelligence enrichment: Findings are cross-referenced against AWS threat intelligence feeds and known malicious indicators (IPs, domains, signatures) to assess external threat context.
- Disposition assessment with confidence scoring: The AI produces a verdict (e.g., true positive, likely benign, or needs review) accompanied by a confidence score, giving analysts a prioritized signal rather than raw alert data.
- MITRE ATT&CK® classification: Each investigation maps observed behaviors to specific MITRE ATT&CK® techniques and tactics, providing a standardized framework for understanding attacker intent and stage.
- Actionable recommendations: The output includes specific next steps—whether to suppress the finding, contain the affected resource, or initiate a remediation workflow—reducing the cognitive load on analysts.
- Access methods: Investigations can be triggered and retrieved via the GuardDuty console, AWS CLI, API, or the AWS MCP (Model Context Protocol) Server, enabling integration into existing SOAR and automation pipelines.
- Organizational scope: The feature can operate across individual AWS accounts or at the AWS Organizations level, allowing centralized security teams to investigate findings across an entire multi-account environment.
Why It's Important
- Combats alert fatigue: Security operations centers routinely face hundreds of GuardDuty findings daily; automated triage with confidence scoring allows analysts to focus attention on high-fidelity alerts rather than manually reviewing every event.
- Accelerates mean time to resolution (MTTR): By compressing what could be hours of manual investigation into minutes, the feature directly reduces the window of exposure during an active incident.
- Reduces analyst skill dependency: Structured MITRE ATT&CK® mappings and evidence summaries make findings accessible to analysts of varying experience levels, lowering the barrier to effective cloud threat response.
- Enables proactive containment: Actionable recommendations for containment and remediation allow teams to act immediately rather than spending time determining what to do after identifying a threat.
- Scales with cloud growth: As AWS environments expand across accounts and regions, manual investigation becomes increasingly untenable; AI-driven automation scales linearly with finding volume without proportional headcount increases.
- Improves audit and compliance posture: Documented disposition assessments with supporting evidence create a traceable investigation record useful for compliance reporting and post-incident reviews.
How It's Different
- Beyond detection to investigation: Traditional GuardDuty surfaces findings but leaves investigation entirely to the analyst; AI-powered investigations closes the loop by automating the analysis step that follows detection.
- 90-day historical context window: Unlike point-in-time alert tools, this feature correlates current findings against three months of prior activity, enabling detection of slow-moving or low-and-slow attack patterns that single-event analysis would miss.
- Knowledge graph vs. rule-based correlation: Rather than relying on static correlation rules, the system uses a dynamic knowledge graph to discover non-obvious relationships between entities, improving detection of novel attack paths.
- Native AWS integration without third-party SIEM dependency: Security teams can perform structured, evidence-backed investigations directly within GuardDuty without routing data to an external SIEM or SOAR platform first.
- MCP Server accessibility: Availability via the AWS MCP Server allows AI assistants and agentic workflows to programmatically trigger and consume investigations, enabling next-generation security automation patterns not possible with traditional APIs alone.
- Confidence-scored verdicts vs. binary alerts: Competing tools often produce binary alert/no-alert outputs; the confidence scoring here gives analysts a nuanced signal to calibrate their response effort appropriately.
When to Prefer It
- High-volume SOC environments: Teams processing large numbers of GuardDuty findings daily where manual triage is creating bottlenecks or causing genuine threats to be missed amid noise.
- Small or under-resourced security teams: Organizations without dedicated cloud security analysts who need AI assistance to interpret and act on complex GuardDuty findings effectively.
- Multi-account AWS Organizations: Enterprises managing dozens or hundreds of AWS accounts through AWS Organizations who need a scalable way to investigate findings across the entire estate from a central security account.
- Incident response under time pressure: Situations where a high-severity finding has been triggered and the team needs rapid context—affected resources, blast radius, and recommended containment—without waiting for a manual deep-dive.
- Compliance-driven environments: Organizations in regulated industries that require documented, evidence-backed investigation records for every security finding to satisfy audit requirements.
- SOAR and automation pipeline integration: Teams building automated security workflows who want to embed structured investigation outputs (disposition, confidence, MITRE mapping) as decision nodes in their automation logic via CLI or API.
- Threat hunting and posture review: Security engineers who want to proactively investigate accounts or resources for historical suspicious activity using the 90-day lookback, even outside of an active incident.
Availability
- Status: Currently in public preview as of June 23, 2026; not yet generally available (GA).
- Supported regions (10): US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Ireland), Europe (London), Europe (Frankfurt), Europe (Paris), Europe (Stockholm), and Asia Pacific (Tokyo).
- Access methods: Available through the Amazon GuardDuty console, AWS CLI, GuardDuty API, and the AWS MCP Server.
- Scope: Supports investigations at the individual AWS account level and across entire AWS Organizations.
- Pricing: Specific pricing details have not been published for the preview; costs during preview periods on AWS are often reduced or waived, but customers should consult the GuardDuty pricing page for current information.
- Limitations: As a preview feature, it may be subject to change before GA; region availability is limited to the 10 listed regions and is not yet available in GovCloud, China, or other commercial regions.
- Prerequisites: Requires Amazon GuardDuty to be enabled in the target account(s); existing GuardDuty customers can access the feature immediately through the console or API without additional setup.