Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment
Security Blog
This article introduces the Amazon GuardDuty investigation agent, an AI-powered tool now in public preview that automates security threat assessment across AWS environments.
- Reduces investigation time from hours to minutes by automating correlation of security findings across multiple data sources
- Provides structured assessments including risk levels, confidence scores, MITRE ATT&CK mappings, and actionable remediation recommendations
- Accessible via AWS Management Console, CLI, APIs, SDKs, and integrated with AWS MCP server for AI-powered workflows
- Supports investigation scoping by specific finding, individual account, or entire organization
- Uses Cross-Region Inference Service to process findings while keeping data encrypted and stored in originating region
- Available in 10 AWS regions; free during public preview with limits of 10 investigations per account daily
- Can integrate into existing SIEM and automation pipelines via EventBridge and Lambda for enriched threat intelligence
The investigation agent enables security teams to shift focus from manual log correlation to validating assessments and responding to confirmed threats.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.