AWS launched the GuardDuty investigation agent in preview. It uses AI to investigate security findings across AWS environments. The agent reduces investigation time from hours to minutes by correlating data and providing structured assessments with risk levels, confidence scores, and recommendations. Security teams can scope investigations to specific findings, accounts, or organizations. It is accessible via console, CLI, APIs, or AWS MCP server. The agent uses cross-Region inference while keeping data in the originating Region. It maps to MITRE ATT&CK techniques and suggests remediation steps. This helps address alert fatigue and speeds response. GuardDuty continues monitoring for malicious activity. The new capability builds on existing threat detection.
AWS launched the GuardDuty investigation agent in preview. It uses AI to investigate security findings across AWS environments. The agent reduces investigation time from hours to minutes by correlating data and providing structured assessments with risk levels, confidence scores, and recommendations. Security teams can scope investigations to specific findings, accounts, or organizations. It is accessible via console, CLI, APIs, or AWS MCP server. The agent uses cross-Region inference while keeping data in the originating Region. It maps to MITRE ATT&CK techniques and suggests remediation steps. This helps address alert fatigue and speeds response. GuardDuty continues monitoring for malicious activity. The new capability builds on existing threat detection.