Amazon GuardDuty
Connect Amazon GuardDuty to Iru Compliance Automation to collect detector configuration, finding metadata, and threat-intel settings.
Detectors either catch something or they don't, and Iru connects to AWS GuardDuty to show which is true — reading detector configuration, findings, and telemetry coverage directly.
Key Capabilities
- Verify threat detection is enabled across accounts
- Confirm findings are triaged rather than accumulated
- Track alerts into your incident response process
Evidence Collected
- Detector configuration and enabled data sources
- Findings with severity and triage outcomes
- Coverage across CloudTrail, VPC Flow Logs, and DNS telemetry
- Optional Kubernetes audit, S3 data plane, and malware protection signals