Home icon
Improve your security investigations with Detective finding groups visualizations

Blog



This article explains how Amazon Detective's finding groups visualizations help security teams consolidate and prioritize multiple security findings across AWS services.

  • Detective automatically consolidates findings from GuardDuty, Inspector, and Security Hub into single security events
  • Finding groups visualizations reduce alert fatigue by connecting related findings and entities
  • Enable GuardDuty protections: EKS Runtime Monitoring, RDS Protection, and Lambda Protection
  • Detective builds a behavior graph using CloudTrail, VPC flow logs, and security findings data
  • Enhanced visualizations include dynamic legends, aggregated icons, descriptive panels, and toggleable labels
  • Finding groups use machine learning to identify related findings and highlight root causes
  • All services offer 30-day free trials and support AWS Organizations for multi-account management

Detective's finding groups help security teams quickly identify compromised resources and real security risks by automatically visualizing connections between findings and entities.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.