

本文為英文版的機器翻譯版本，如內容有任何歧義或不一致之處，概以英文版為準。

# GuardDuty 與 AWS 安全服務整合
<a name="guardduty_integrations"></a>

GuardDuty 可以與其他 AWS 安全服務整合。這些服務可以從 GuardDuty 擷取資料，讓您以新方式檢視調查結果。檢閱以下整合選項，進一步了解如何設定服務，以搭配 GuardDuty 使用。

## 將 GuardDuty 與 整合 AWS Security Hub CSPM
<a name="gd-securityhub"></a>

AWS Security Hub CSPM 會從 AWS 您的帳戶、服務和支援的第三方合作夥伴產品中收集安全資料，以根據產業標準和最佳實務評估環境的安全狀態。除了評估您的安全狀態之外，Security Hub CSPM 還為所有整合 AWS 服務和 AWS 合作夥伴產品建立調查結果的集中位置。使用 GuardDuty 啟用 Security Hub CSPM 會自動允許 Security Hub CSPM 擷取 GuardDuty 調查結果資料。

 如需搭配 GuardDuty 使用 Security Hub CSPM 的詳細資訊，請參閱 [與 整合 AWS Security Hub CSPM](securityhub-integration.md)。

## 將 GuardDuty 與 Amazon Detective 整合
<a name="gd-detective"></a>

Amazon Detective 使用來自您 AWS 帳戶的日誌資料，為您的資源和與您的環境互動的 IP 地址建立資料視覺化。Detective 的視覺化效果可協助您快速輕鬆地調查安全問題。啟用這兩項服務後，您可以將 GuardDuty 的調查結果詳細資訊轉換為 Detective 主控台中的資訊。

 如需有關將 Detective 與 GuardDuty 搭配使用的詳細資訊，請參閱[與 Amazon Detective 整合](detective-integration.md)。

# 與 整合 AWS Security Hub CSPM
<a name="securityhub-integration"></a>

[AWS Security Hub CSPM](https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub.html) 可讓您全方位地檢視 AWS 中的安全狀態，並可協助您檢查環境是否符合安全業界標準和最佳實務。Security Hub CSPM 會從跨 AWS 帳戶、服務和支援的第三方合作夥伴產品收集安全資料，並協助您分析安全趨勢並識別最高優先順序的安全問題。

Amazon GuardDuty 與 Security Hub CSPM 整合可讓您將問題清單從 GuardDuty 傳送至 Security Hub CSPM。然後，Security Hub CSPM 可以在分析您的安全狀態時包含這些調查結果。

**Contents**
+ [Amazon GuardDuty 如何將問題清單傳送至 AWS Security Hub CSPM](#securityhub-integration-sending-findings)
  + [GuardDuty 傳送至 Security Hub CSPM 的問題清單類型](#securityhub-integration-finding-types)
    + [傳送新問題清單的延遲](#securityhub-integration-finding-latency)
    + [無法使用 Security Hub CSPM 時重試](#securityhub-integration-retry-send)
    + [更新 Security Hub CSPM 中的現有調查結果](#securityhub-integration-finding-updates)
+ [在 中檢視 GuardDuty 調查結果 AWS Security Hub CSPM](#findings-in-securityhub)
  + [在 中解譯 GuardDuty 調查結果名稱 AWS Security Hub CSPM](#interpreting-findings-in-securityhub)
  + [GuardDuty 的典型調查結果](#securityhub-integration-finding-example)
+ [啟用與設定整合](#securityhub-integration-enable)
+ [在 Security Hub CSPM 中使用 GuardDuty 控制項](#securityhub-integration-using-guardduty-controls)
+ [停止將問題清單發佈至 Security Hub CSPM](#securityhub-integration-disable)

## Amazon GuardDuty 如何將問題清單傳送至 AWS Security Hub CSPM
<a name="securityhub-integration-sending-findings"></a>

在 中 AWS Security Hub CSPM，安全問題會追蹤為問題清單。有些問題清單來自 AWS 其他服務或第三方合作夥伴偵測到的問題。Security Hub CSPM 也有一組規則，可用來偵測安全問題並產生問題清單。

Security Hub CSPM 提供用來跨所有這些來源管理調查結果的工具。您可以檢視並篩選問題清單列表，並檢視問題清單的詳細資訊。如需詳細資訊，請參閱《*AWS Security Hub 使用者指南*》中的[檢視問題清單](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-viewing.html)。您也可以追蹤問題清單的調查狀態。如需詳細資訊，請參閱《*AWS Security Hub 使用者指南*》中的[針對問題清單採取動作](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-taking-action.html)。

Security Hub CSPM 中的所有問題清單都使用稱為 AWS 安全問題清單格式 (ASFF) 的標準 JSON 格式。ASFF 包含問題來源、受影響的資源以及問題清單目前狀態的詳細資訊。請參閱 *AWS Security Hub 使用者指南* 中的 [AWS 安全問題清單格式 (ASFF)](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-format.html)。

Amazon GuardDuty 是將問題清單傳送至 Security Hub CSPM AWS 的服務之一。

### GuardDuty 傳送至 Security Hub CSPM 的問題清單類型
<a name="securityhub-integration-finding-types"></a>

在相同帳戶中啟用 GuardDuty 和 Security Hub CSPM 後 AWS 區域，GuardDuty 會開始將所有產生的調查結果傳送至 Security Hub CSPM。這些問題清單會使用安全[AWS 問題清單格式 (ASFF) 傳送至 Security](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-format.html) Hub CSPM。在 ASFF 中，`Types` 欄位提供問題清單類型。

#### 傳送新問題清單的延遲
<a name="securityhub-integration-finding-latency"></a>

當 GuardDuty 建立新的調查結果時，通常會在五分鐘內傳送至 Security Hub CSPM。

#### 無法使用 Security Hub CSPM 時重試
<a name="securityhub-integration-retry-send"></a>

如果 Security Hub CSPM 無法使用，GuardDuty 會重試傳送問題清單，直到收到問題清單為止。

#### 更新 Security Hub CSPM 中的現有調查結果
<a name="securityhub-integration-finding-updates"></a>

將問題清單傳送至 Security Hub CSPM 後，GuardDuty 會傳送更新，以反映對 Security Hub CSPM 的問題清單活動的其他觀察。這些調查結果的新觀察結果會根據 中的[步驟 5 – 匯出問題清單的頻率](guardduty_exportfindings.md#guardduty_exportfindings-frequency)設定傳送至 Security Hub CSPM AWS 帳戶。

當您封存或取消封存問題清單時，GuardDuty 不會將該問題清單傳送至 Security Hub CSPM。任何稍後在 GuardDuty 中變為作用中的手動未封存問題清單都不會傳送至 Security Hub CSPM。

## 在 中檢視 GuardDuty 調查結果 AWS Security Hub CSPM
<a name="findings-in-securityhub"></a>

登入 AWS 管理主控台 ，並在 https：//[https://console.aws.amazon.com/securityhub/](https://console.aws.amazon.com/securityhub/) 開啟 AWS Security Hub CSPM 主控台。

您現在可以使用下列其中一種方式，在 Security Hub CSPM 主控台中檢視 GuardDuty 調查結果：

**選項 1：在 Security Hub CSPM 中使用*整合* **  

1. 在左側導覽窗格中，選擇**整合**。

1. 在**整合**頁面上，檢查 Amazon **的狀態**：GuardDuty。 ** GuardDuty** 
   + 如果**狀態**為**接受問題**清單，請選擇接受**問題清單旁的查看****問題清單**。
   + 如果沒有，則如需**整合如何**運作的詳細資訊，請參閱*AWS Security Hub 《 使用者指南*》中的 [Security Hub CSPM 整合](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-providers.html)。

**選項 2：在 Security Hub CSPM 中使用*問題清單* **  

1. 在左側導覽窗格中，選擇**問題清單**。

1. 在**問題清單**頁面上，新增篩選條件**產品名稱**，然後輸入 **GuardDuty** 以僅檢視 GuardDuty 問題清單。

### 在 中解譯 GuardDuty 調查結果名稱 AWS Security Hub CSPM
<a name="interpreting-findings-in-securityhub"></a>

GuardDuty 會使用安全調查結果[AWS 格式 (ASFF) 將調查結果傳送至 Security](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-format.html) Hub CSPM。在 ASFF 中，`Types` 欄位提供問題清單類型。ASFF 類型使用的命名方案與 GuardDuty 類型不同。下表詳細說明所有 GuardDuty 調查結果類型及其 ASFF 對應項目，如 Security Hub CSPM 所示。

**注意**  
對於某些 GuardDuty 調查結果類型，Security Hub CSPM 會根據調查結果詳細資訊**的資源角色**為 **ACTOR** 或 **TARGET**，指派不同的 ASFF 調查結果名稱。如需更多資訊，請參閱[調查結果詳細資訊](guardduty_findings-summary.md)。


|  GuardDuty 調查結果類型  |  ASFF 問題清單類型  | 
| --- | --- | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-attack-sequence-finding-types.html#attack-sequence-iam-compromised-credentials](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-attack-sequence-finding-types.html#attack-sequence-iam-compromised-credentials)  |  TTPs/AttackSequence:IAM/CompromisedCredentials   | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-attack-sequence-finding-types.html#attack-sequence-s3-compromised-data](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-attack-sequence-finding-types.html#attack-sequence-s3-compromised-data)  |  TTPs/AttackSequence:S3/CompromisedData   | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-ccactivityb](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-ccactivityb)  |  TTPs/Command and Control/Backdoor:EC2-C&CActivity.B  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-ccactivitybdns](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-ccactivitybdns)  |  TTPs/Command and Control/Backdoor:EC2-C&CActivity.B\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofservicedns](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofservicedns)  |  TTPs/Command and Control/Backdoor:EC2-DenialOfService.Dns  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofservicetcp](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofservicetcp)  |  TTPs/Command and Control/Backdoor:EC2-DenialOfService.Tcp  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofserviceudp](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofserviceudp)  |  TTPs/Command and Control/Backdoor:EC2-DenialOfService.Udp  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofserviceudpontcpports](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofserviceudpontcpports)  |  TTPs/Command and Control/Backdoor:EC2-DenialOfService.UdpOnTcpPorts  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofserviceunusualprotocol](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-denialofserviceunusualprotocol)  |  TTPs/Command and Control/Backdoor:EC2-DenialOfService.UnusualProtocol  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-spambot](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#backdoor-ec2-spambot)  |  TTPs/Command and Control/Backdoor:EC2-Spambot  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#behavior-ec2-networkportunusual](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#behavior-ec2-networkportunusual)  |  Unusual Behaviors/VM/Behavior:EC2-NetworkPortUnusual  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#behavior-ec2-trafficvolumeunusual](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#behavior-ec2-trafficvolumeunusual)  |  Unusual Behaviors/VM/Behavior:EC2-TrafficVolumeUnusual  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#backdoor-lambda-ccactivity-b](https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#backdoor-lambda-ccactivity-b)  |  TTPs/Command and Control/Backdoor:Lambda-C&CActivity.B  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#backdoor-runtime-ccactivityb](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#backdoor-runtime-ccactivityb)  |  TTPs/Command and Control/Backdoor:Runtime-C&CActivity.B  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#backdoor-runtime-ccactivitybdns](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#backdoor-runtime-ccactivitybdns)  |  TTPs/Command and Control/Backdoor:Runtime-C&CActivity.B\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#credentialaccess-iam-anomalousbehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#credentialaccess-iam-anomalousbehavior)  |  TTPs/Credential Access/IAMUser-AnomalousBehavior  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credaccess-kubernetes-anomalousbehavior-secretsaccessed](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credaccess-kubernetes-anomalousbehavior-secretsaccessed)  |  TTPs/AnomalousBehavior/CredentialAccess:Kubernetes-SecretsAccessed  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credentialaccess-kubernetes-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credentialaccess-kubernetes-maliciousipcaller)  |  TTPs/CredentialAccess/CredentialAccess:Kubernetes-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credentialaccess-kubernetes-maliciousipcallercustom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credentialaccess-kubernetes-maliciousipcallercustom)  |  TTPs/CredentialAccess/CredentialAccess:Kubernetes-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credentialaccess-kubernetes-successfulanonymousaccess](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credentialaccess-kubernetes-successfulanonymousaccess)  |  TTPs/CredentialAccess/CredentialAccess:Kubernetes-SuccessfulAnonymousAccess  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credentialaccess-kubernetes-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#credentialaccess-kubernetes-toripcaller)  |  TTPs/CredentialAccess/CredentialAccess:Kubernetes-TorIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-anombehavior-failedlogin](https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-anombehavior-failedlogin)  |  TTPs/Credential Access/CredentialAccess:RDS-AnomalousBehavior.FailedLogin  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-anombehavior-successfulbruteforce](https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-anombehavior-successfulbruteforce)  |  TTPs/Credential Access/CredentialAccess:RDS-AnomalousBehavior.SuccessfulBruteForce  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-anombehavior-successlogin](https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-anombehavior-successlogin)  |  TTPs/Credential Access/CredentialAccess:RDS-AnomalousBehavior.SuccessfulLogin  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-maliciousipcaller-failedlogin](https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-maliciousipcaller-failedlogin)  |  TTPs/Credential Access/CredentialAccess:RDS-MaliciousIPCaller.FailedLogin  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-maliciousipcaller-successfullogin](https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-maliciousipcaller-successfullogin)  |  TTPs/Credential Access/CredentialAccess:RDS-MaliciousIPCaller.SuccessfulLogin  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-toripcaller-failedlogin](https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-toripcaller-failedlogin)  |  TTPs/Credential Access/CredentialAccess:RDS-TorIPCaller.FailedLogin  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-toripcaller-successfullogin](https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#credaccess-rds-toripcaller-successfullogin)  |  TTPs/Credential Access/CredentialAccess:RDS-TorIPCaller.SuccessfulLogin  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#cryptocurrency-ec2-bitcointoolb](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#cryptocurrency-ec2-bitcointoolb)  |  TTPs/Command and Control/CryptoCurrency:EC2-BitcoinTool.B  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#cryptocurrency-ec2-bitcointoolbdns](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#cryptocurrency-ec2-bitcointoolbdns)  |  TTPs/Command and Control/CryptoCurrency:EC2-BitcoinTool.B\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#cryptocurrency-lambda-bitcointool-b](https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#cryptocurrency-lambda-bitcointool-b)  |  TTPs/Command and Control/CryptoCurrency:Lambda-BitcoinTool.B Effects/Resource Consumption/CryptoCurrency:Lambda-BitcoinTool.B  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#cryptocurrency-runtime-bitcointoolb](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#cryptocurrency-runtime-bitcointoolb)  |  TTPs/Command and Control/CryptoCurrency:Runtime-BitcoinTool.B  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#cryptocurrency-runtime-bitcointoolbdns](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#cryptocurrency-runtime-bitcointoolbdns)  |  TTPs/Command and Control/CryptoCurrency:Runtime-BitcoinTool.B\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#defenseevasion-ec2-unusualdnsresolver](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#defenseevasion-ec2-unusualdnsresolver)  |  TTPs/DefenseEvasion/EC2:Unusual-DNS-Resolver  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#defenseevasion-ec2-unsualdohactivity](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#defenseevasion-ec2-unsualdohactivity)  |  TTPs/DefenseEvasion/EC2:Unusual-DoH-Activity  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#defenseevasion-ec2-unusualdotactivity](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#defenseevasion-ec2-unusualdotactivity)  |  TTPs/DefenseEvasion/EC2:Unusual-DoT-Activity  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#defenseevasion-iam-anomalousbehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#defenseevasion-iam-anomalousbehavior)  |  TTPs/Defense Evasion/IAMUser-AnomalousBehavior  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#defenseevasion-iam-bedrockloggingdisabled](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#defenseevasion-iam-bedrockloggingdisabled)  |  TTPs/Defense Evasion/DefenseEvasion:IAMUser-BedrockLoggingDisabled  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#defenseevasion-kubernetes-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#defenseevasion-kubernetes-maliciousipcaller)  |  TTPs/DefenseEvasion/DefenseEvasion:Kubernetes-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#defenseevasion-kubernetes-maliciousipcallercustom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#defenseevasion-kubernetes-maliciousipcallercustom)  |  TTPs/DefenseEvasion/DefenseEvasion:Kubernetes-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#defenseevasion-kubernetes-successfulanonymousaccess](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#defenseevasion-kubernetes-successfulanonymousaccess)  |  TTPs/DefenseEvasion/DefenseEvasion:Kubernetes-SuccessfulAnonymousAccess  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#defenseevasion-kubernetes-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#defenseevasion-kubernetes-toripcaller)  |  TTPs/DefenseEvasion/DefenseEvasion:Kubernetes-TorIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseeva-runtime-filelessexecution](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseeva-runtime-filelessexecution)  |  TTPs/Defense Evasion/DefenseEvasion:Runtime-FilelessExecution  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseevasion-runtime-kernelmoduleloaded](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseevasion-runtime-kernelmoduleloaded)  |  TTPs/Defense Evasion/DefenseEvasion:Runtime-KernelModuleLoaded  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseeva-runtime-processinjectionproc](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseeva-runtime-processinjectionproc)  |  TTPs/Defense Evasion/DefenseEvasion:Runtime-ProcessInjection.Proc  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseeva-runtime-processinjectionptrace](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseeva-runtime-processinjectionptrace)  |  TTPs/Defense Evasion/DefenseEvasion:Runtime-ProcessInjection.Ptrace  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseeva-runtime-processinjectionvirtualmemw](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseeva-runtime-processinjectionvirtualmemw)  |  TTPs/Defense Evasion/DefenseEvasion:Runtime-ProcessInjection.VirtualMemoryWrite  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseevasion-runtime-ptrace-anti-debug](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseevasion-runtime-ptrace-anti-debug)  |  TTPs/DefenseEvasion/DefenseEvasion:Runtime-PtraceAntiDebugging  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseevasion-runtime-suspicious-command](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#defenseevasion-runtime-suspicious-command)  |  TTPs/DefenseEvasion/DefenseEvasion:Runtime-SuspiciousCommand  | 
|  [Discovery:IAMUser/AnomalousBehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#discovery-iam-anomalousbehavior)  |  TTPs/Discovery/IAMUser-AnomalousBehavior  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-anomalousbehavrior-permissionchecked](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-anomalousbehavrior-permissionchecked)  |  TTPs/AnomalousBehavior/Discovery:Kubernetes-PermissionChecked  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-maliciousipcaller)  |  TTPs/Discovery/Discovery:Kubernetes-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-maliciousipcallercustom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-maliciousipcallercustom)  |  TTPs/Discovery/Discovery:Kubernetes-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-successfulanonymousaccess](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-successfulanonymousaccess)  |  TTPs/Discovery/Discovery:Kubernetes-SuccessfulAnonymousAccess  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#discovery-kubernetes-toripcaller)  |  TTPs/Discovery/Discovery:Kubernetes-TorIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#discovery-rds-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#discovery-rds-maliciousipcaller)  |  TTPs/Discovery/RDS-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#discovery-rds-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/findings-rds-protection.html#discovery-rds-toripcaller)  |  TTPs/Discovery/RDS-TorIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#discovery-runtime-suspicious-command](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#discovery-runtime-suspicious-command)  |  TTPs/Discovery/Discovery:Runtime-SuspiciousCommand  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#discovery-s3-anomalousbehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#discovery-s3-anomalousbehavior)  |  TTPs/Discovery:S3-AnomalousBehavior  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#discovery-s3-bucketenumerationunusual](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#discovery-s3-bucketenumerationunusual)  |  TTPs/Discovery:S3-BucketEnumeration.Unusual  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#discovery-s3-maliciousipcallercustom.title](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#discovery-s3-maliciousipcallercustom.title)  |  TTPs/Discovery:S3-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#discovery-s3-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#discovery-s3-toripcaller)  |  TTPs/Discovery:S3-TorIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#discovery-s3-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#discovery-s3-maliciousipcaller)  |  TTPs/Discovery:S3-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#exfiltration-iam-anomalousbehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#exfiltration-iam-anomalousbehavior)  |  TTPs/Exfiltration/IAMUser-AnomalousBehavior  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#execution-kubernetes-execinkubesystempod](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#execution-kubernetes-execinkubesystempod)  |  TTPs/Execution/Execution:Kubernetes-ExecInKubeSystemPod  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#execution-kubernetes-anomalousbehvaior-execinprod](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#execution-kubernetes-anomalousbehvaior-execinprod)  |  TTPs/AnomalousBehavior/Execution:Kubernetes-ExecInPod  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#exec-kubernetes-anomalousbehavior-workloaddeployed](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#exec-kubernetes-anomalousbehavior-workloaddeployed)  |  TTPs/AnomalousBehavior/Execution:Kubernetes-WorkloadDeployed  | 
|   [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-maliciousdomainrequest-custom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-maliciousdomainrequest-custom)   |  TTPs/Impact/Impact:EC2-MaliciousDomainRequest.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#impact-kubernetes-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#impact-kubernetes-maliciousipcaller)  |  TTPs/Impact/Impact:Kubernetes-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#impact-kubernetes-maliciousipcallercustom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#impact-kubernetes-maliciousipcallercustom)  |  TTPs/Impact/Impact:Kubernetes-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#impact-kubernetes-successfulanonymousaccess](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#impact-kubernetes-successfulanonymousaccess)  |  TTPs/Impact/Impact:Kubernetes-SuccessfulAnonymousAccess  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#impact-kubernetes-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#impact-kubernetes-toripcaller)  |  TTPs/Impact/Impact:Kubernetes-TorIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-containerwithsensitivemount](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-containerwithsensitivemount)  | TTPs/Persistence/Persistence:Kubernetes-ContainerWithSensitiveMount | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privesc-kubernetes-anomalousbehavior-workloaddeployed-containerwithsensitivemount](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privesc-kubernetes-anomalousbehavior-workloaddeployed-containerwithsensitivemount)  | TTPs/AnomalousBehavior/Persistence:Kubernetes-WorkloadDeployed\$1ContainerWithSensitiveMount | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privesc-kubernetes-anomalousbehavior-workloaddeployed-privcontainer](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privesc-kubernetes-anomalousbehavior-workloaddeployed-privcontainer)  |  TTPs/AnomalousBehavior/PrivilegeEscalation:Kubernetes-WorkloadDeployed\$1PrivilegedContainer  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-maliciousipcaller)  |  TTPs/Persistence/Persistence:Kubernetes-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-maliciousipcallercustom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-maliciousipcallercustom)  |  TTPs/Persistence/Persistence:Kubernetes-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-successfulanonymousaccess](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-successfulanonymousaccess)  |  TTPs/Persistence/Persistence:Kubernetes-SuccessfulAnonymousAccess  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#persistence-kubernetes-toripcaller)  |  TTPs/Persistence/Persistence:Kubernetes-TorIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-ec2-maliciousfile](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-ec2-maliciousfile)  |  TTPs/Execution/Execution:EC2-MaliciousFile  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-ecs-maliciousfile](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-ecs-maliciousfile)  |  TTPs/Execution/Execution:ECS-MaliciousFile  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-kubernetes-maliciousfile](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-kubernetes-maliciousfile)  |  TTPs/Execution/Execution:Kubernetes-MaliciousFile  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-container-maliciousfile](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-container-maliciousfile)  |  TTPs/Execution/Execution:Container-MaliciousFile  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-ec2-suspiciousfile](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-ec2-suspiciousfile)  |  TTPs/Execution/Execution:EC2-SuspiciousFile  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-ecs-suspiciousfile](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-ecs-suspiciousfile)  |  TTPs/Execution/Execution:ECS-SuspiciousFile  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-kubernetes-suspiciousfile](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-kubernetes-suspiciousfile)  |  TTPs/Execution/Execution:Kubernetes-SuspiciousFile  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-container-suspiciousfile](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-malware-container-suspiciousfile)  |  TTPs/Execution/Execution:Container-SuspiciousFile  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection-backup.html#execution-malware-ec2-maliciousfile-snapshot](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection-backup.html#execution-malware-ec2-maliciousfile-snapshot)  |  TTPs/Execution/Execution:EC2-MaliciousFile\$1Snapshot  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection-backup.html#execution-malware-ec2-maliciousfile-ami](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection-backup.html#execution-malware-ec2-maliciousfile-ami)  |  TTPs/Execution/Execution:EC2-MaliciousFile\$1AMI  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection-backup.html#execution-malware-ec2-maliciousfile-recoverypoint](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection-backup.html#execution-malware-ec2-maliciousfile-recoverypoint)  |  TTPs/Execution/Execution:EC2-MaliciousFile\$1RecoveryPoint  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection-backup.html#execution-malware-s3-maliciousfile-recoverypoint](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection-backup.html#execution-malware-s3-maliciousfile-recoverypoint)  |  TTPs/Execution/Execution:S3-MaliciousFile\$1RecoveryPoint  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-runtime-malicious-file-executed](https://docs.aws.amazon.com/guardduty/latest/ug/findings-malware-protection.html#execution-runtime-malicious-file-executed)  |  TTPs/Execution/Execution:Runtime-MaliciousFileExecuted  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-newbinaryexecuted](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-newbinaryexecuted)  |  TTPs/Execution/Execution:Runtime-NewBinaryExecuted  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-newlibraryloaded](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-newlibraryloaded)  |  TTPs/Execution/Execution:Runtime-NewLibraryLoaded  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-reverseshell](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-reverseshell)  |  TTPs/Execution/Execution:Runtime-ReverseShell  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-suspiciouscommand](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-suspiciouscommand)  |  TTPs/Execution/Execution:Runtime-SuspiciousCommand  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-suspicious-shell-created](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-suspicious-shell-created)  |  TTPs/Execution/Execution:Runtime-SuspiciousShellCreated  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-suspicioustool](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#execution-runtime-suspicioustool)  |  TTPs/Execution/Execution:Runtime-SuspiciousTool  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#exfiltration-s3-anomalousbehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#exfiltration-s3-anomalousbehavior)  |  TTPs/Exfiltration:S3-AnomalousBehavior  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#exfiltration-s3-objectreadunusual](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#exfiltration-s3-objectreadunusual)  |  TTPs/Exfiltration:S3-ObjectRead.Unusual  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#exfiltration-s3-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#exfiltration-s3-maliciousipcaller)  |  TTPs/Exfiltration:S3-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-abuseddomainrequestreputation](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-abuseddomainrequestreputation)  |  TTPs/Impact:EC2-AbusedDomainRequest.Reputation  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-bitcoindomainrequestreputation](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-bitcoindomainrequestreputation)  |  TTPs/Impact:EC2-BitcoinDomainRequest.Reputation  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-maliciousdomainrequestreputation](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-maliciousdomainrequestreputation)  |  TTPs/Impact:EC2-MaliciousDomainRequest.Reputation  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-portsweep](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-portsweep)  |  TTPs/Impact/Impact:EC2-PortSweep  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-suspiciousdomainrequestreputation](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-suspiciousdomainrequestreputation)  |  TTPs/Impact:EC2-SuspiciousDomainRequest.Reputation  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-winrmbruteforce](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-winrmbruteforce)  |  TTPs/Impact/Impact:EC2-WinRMBruteForce  | 
|  [Impact:IAMUser/AnomalousBehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#impact-iam-anomalousbehavior)  |  TTPs/Impact/IAMUser-AnomalousBehavior  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-abuseddomainrequestreputation](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-abuseddomainrequestreputation)  |  TTPs/Impact/Impact:Runtime-AbusedDomainRequest.Reputation  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-bitcoindomainrequestreputation](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-bitcoindomainrequestreputation)  |  TTPs/Impact/Impact:Runtime-BitcoinDomainRequest.Reputation  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-cryptominerexecuted](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-cryptominerexecuted)  |  TTPs/Impact/Impact:Runtime-CryptoMinerExecuted  | 
| [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-maliciousdomainrequestreputation](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-maliciousdomainrequestreputation)  |  TTPs/Impact/Impact:Runtime-MaliciousDomainRequest.Reputation  | 
| [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-suspiciousdomainrequestreputation](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#impact-runtime-suspiciousdomainrequestreputation)  |  TTPs/Impact/Impact:Runtime-SuspiciousDomainRequest.Reputatio  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#impact-s3-anomalousbehavior-delete](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#impact-s3-anomalousbehavior-delete)  |  TTPs/Impact:S3-AnomalousBehavior.Delete  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#impact-s3-anomalousbehavior-permission](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#impact-s3-anomalousbehavior-permission)  |  TTPs/Impact:S3-AnomalousBehavior.Permission  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#impact-s3-anomalousbehavior-write](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#impact-s3-anomalousbehavior-write)  |  TTPs/Impact:S3-AnomalousBehavior.Write  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#impact-s3-objectdeleteunusual](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#impact-s3-objectdeleteunusual)  |  TTPs/Impact:S3-ObjectDelete.Unusual  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#impact-s3-permissionsmodificationunusual](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#impact-s3-permissionsmodificationunusual)  |  TTPs/Impact:S3-PermissionsModification.Unusual  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#impact-s3-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#impact-s3-maliciousipcaller)  |  TTPs/Impact:S3-MaliciousIPCaller  | 
|  [InitialAccess:IAMUser/AnomalousBehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#initialaccess-iam-anomalousbehavior)  |  TTPs/Initial Access/IAMUser-AnomalousBehavior  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/gdu-malware-protection-s3-finding-types.html#s3-object-s3-malicious-file](https://docs.aws.amazon.com/guardduty/latest/ug/gdu-malware-protection-s3-finding-types.html#s3-object-s3-malicious-file)  |  TTPs/Object/Object:S3-MaliciousFile  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#pentest-iam-kalilinux](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#pentest-iam-kalilinux)  |  TTPs/PenTest:IAMUser/KaliLinux  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#pentest-iam-parrotlinux](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#pentest-iam-parrotlinux)  |  TTPs/PenTest:IAMUser/ParrotLinux  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#pentest-iam-pentoolinux](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#pentest-iam-pentoolinux)  |  TTPs/PenTest:IAMUser/PentooLinux  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#pentest-iam-kalilinux](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#pentest-iam-kalilinux)  |  TTPs/PenTest:S3-KaliLinux  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#pentest-s3-parrotlinux](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#pentest-s3-parrotlinux)  |  TTPs/PenTest:S3-ParrotLinux  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#pentest-s3-pentoolinux](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#pentest-s3-pentoolinux)  |  TTPs/PenTest:S3-PentooLinux  | 
|   [Persistence:IAMUser/AnomalousBehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#persistence-iam-anomalousbehavior)   | TTPs/Persistence/IAMUser-AnomalousBehavior | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#persistence-iam-networkpermissions](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#persistence-iam-networkpermissions)  |  TTPs/Persistence/Persistence:IAMUser-NetworkPermissions  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#persistence-iam-resourcepermissions](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#persistence-iam-resourcepermissions)  |  TTPs/Persistence/Persistence:IAMUser-ResourcePermissions  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#persistence-iam-userpermissions](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#persistence-iam-userpermissions)  |  TTPs/Persistence/Persistence:IAMUser-UserPermissions  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#persistence-runtime-suspicious-command](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#persistence-runtime-suspicious-command)  |  TTPs/Persistence/Persistence:Runtime-SuspiciousCommand  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#policy-iam-rootcredentialusage](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#policy-iam-rootcredentialusage)  |  TTPs/Policy:IAMUser-RootCredentialUsage  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#policy-iam-user-short-term-root-credential-usage](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#policy-iam-user-short-term-root-credential-usage)  |  TTPs/Policy:IAMUser-ShortTermRootCredentialUsage  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#policy-kubernetes-adminaccesstodefaultserviceaccount](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#policy-kubernetes-adminaccesstodefaultserviceaccount)  |  Software and Configuration Checks/AWS Security Best Practices/Policy:Kubernetes-AdminAccessToDefaultServiceAccount  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#policy-kubernetes-anonymousaccessgranted](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#policy-kubernetes-anonymousaccessgranted)  |  Software and Configuration Checks/AWS Security Best Practices/Policy:Kubernetes-AnonymousAccessGranted  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#policy-kubernetes-exposeddashboard](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#policy-kubernetes-exposeddashboard)  |  Software and Configuration Checks/AWS Security Best Practices/Policy:Kubernetes-ExposedDashboard  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#policy-kubernetes-kubeflowdashboardexposed](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#policy-kubernetes-kubeflowdashboardexposed)  |  Software and Configuration Checks/AWS Security Best Practices/Policy:Kubernetes-KubeflowDashboardExposed  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#policy-s3-accountblockpublicaccessdisabled](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#policy-s3-accountblockpublicaccessdisabled)  |  TTPs/Policy:S3-AccountBlockPublicAccessDisabled  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#policy-s3-bucketanonymousaccessgranted](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#policy-s3-bucketanonymousaccessgranted)  |  TTPs/Policy:S3-BucketAnonymousAccessGranted  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#policy-s3-bucketblockpublicaccessdisabled](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#policy-s3-bucketblockpublicaccessdisabled)  |  Effects/Data Exposure/Policy:S3-BucketBlockPublicAccessDisabled  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#policy-s3-bucketpublicaccessgranted](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#policy-s3-bucketpublicaccessgranted)  |  TTPs/Policy:S3-BucketPublicAccessGranted  | 
|   [PrivilegeEscalation:IAMUser/AnomalousBehavior](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#privilegeescalation-iam-anomalousbehavior)   |  TTPs/Privilege Escalation/IAMUser-AnomalousBehavior  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeescalation-iam-administrativepermissions](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeescalation-iam-administrativepermissions)  |  TTPs/Privilege Escalation/PrivilegeEscalation:IAMUser-AdministrativePermissions  | 
| [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privesc-kubernetes-anomalousbehavior-rolebindingcreated](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privesc-kubernetes-anomalousbehavior-rolebindingcreated) |  TTPs/AnomalousBehavior/PrivilegeEscalation:Kubernetes-RoleBindingCreated  | 
| [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privesc-kubernetes-anomalousbehavior-rolecreated](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privesc-kubernetes-anomalousbehavior-rolecreated) |  TTPs/AnomalousBehavior/PrivilegeEscalation:Kubernetes-RoleCreated  | 
| [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privilegeescalation-kubernetes-privilegedcontainer](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-finding-types-eks-audit-logs.html#privilegeescalation-kubernetes-privilegedcontainer) |  TTPs/PrivilegeEscalation/PrivilegeEscalation:Kubernetes-PrivilegedContainer  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-containermountshostdirectory](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-containermountshostdirectory)  |  TTPs/Privilege Escalation/PrivilegeEscalation:Runtime-ContainerMountsHostDirectory  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-cgroupsreleaseagentmodified](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-cgroupsreleaseagentmodified)  |  TTPs/Privilege Escalation/PrivilegeEscalation:Runtime-CGroupsReleaseAgentModified  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-dockersocketaccessed](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-dockersocketaccessed)  |  TTPs/Privilege Escalation/PrivilegeEscalation:Runtime-DockerSocketAccessed  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-elevation-to-root](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-elevation-to-root)  |  TTPs/Privilege Escalation/PrivilegeEscalation:Runtime-ElevationToRoot  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-runccontainerescape](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-runccontainerescape)  |  TTPs/Privilege Escalation/PrivilegeEscalation:Runtime-RuncContainerEscape  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#privilege-escalation-runtime-suspicious-command](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#privilege-escalation-runtime-suspicious-command)  |  Software and Configuration Checks/PrivilegeEscalation:Runtime-SuspiciousCommand  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-userfaultfdusage](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#privilegeesc-runtime-userfaultfdusage)  |  TTPs/Privilege Escalation/PrivilegeEscalation:Runtime-UserfaultfdUsage  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#recon-ec2-portprobeemrunprotectedport](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#recon-ec2-portprobeemrunprotectedport)  |  TTPs/Discovery/Recon:EC2-PortProbeEMRUnprotectedPort  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#recon-ec2-portprobeunprotectedport](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#recon-ec2-portprobeunprotectedport)  |  TTPs/Discovery/Recon:EC2-PortProbeUnprotectedPort  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#recon-ec2-portscan](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#recon-ec2-portscan)  |  TTPs/Discovery/Recon:EC2-Portscan  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#recon-iam-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#recon-iam-maliciousipcaller)  |  TTPs/Discovery/Recon:IAMUser-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#recon-iam-maliciousipcallercustom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#recon-iam-maliciousipcallercustom)  |  TTPs/Discovery/Recon:IAMUser-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#recon-iam-networkpermissions](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#recon-iam-networkpermissions)  |  TTPs/Discovery/Recon:IAMUser-NetworkPermissions  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#recon-iam-resourcepermissions](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#recon-iam-resourcepermissions)  |  TTPs/Discovery/Recon:IAMUser-ResourcePermissions  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#recon-iam-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#recon-iam-toripcaller)  |  TTPs/Discovery/Recon:IAMUser-TorIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#recon-iam-userpermissions](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#recon-iam-userpermissions)  |  TTPs/Discovery/Recon:IAMUser-UserPermissions  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#resourceconsumption-iam-computeresources](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#resourceconsumption-iam-computeresources)  |  Unusual Behaviors/User/ResourceConsumption:IAMUser-ComputeResources  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#stealth-iam-cloudtrailloggingdisabled](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#stealth-iam-cloudtrailloggingdisabled)  |  TTPs/Defense Evasion/Stealth:IAMUser-CloudTrailLoggingDisabled  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#stealth-iam-loggingconfigurationmodified](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#stealth-iam-loggingconfigurationmodified)  |  TTPs/Defense Evasion/Stealth:IAMUser-LoggingConfigurationModified  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#stealth-iam-passwordpolicychange](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#stealth-iam-passwordpolicychange)  |  TTPs/Defense Evasion/Stealth:IAMUser-PasswordPolicyChange  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#stealth-s3-serveraccessloggingdisabled](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#stealth-s3-serveraccessloggingdisabled)  |  TTPs/Defense Evasion/Stealth:S3-ServerAccessLoggingDisabled  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-blackholetraffic](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-blackholetraffic)  |  TTPs/Command and Control/Trojan:EC2-BlackholeTraffic  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-blackholetrafficdns](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-blackholetrafficdns)  |  TTPs/Command and Control/Trojan:EC2-BlackholeTraffic\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-dgadomainrequestb](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-dgadomainrequestb)  |  TTPs/Command and Control/Trojan:EC2-DGADomainRequest.B  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-dgadomainrequestcdns](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-dgadomainrequestcdns)  |  TTPs/Command and Control/Trojan:EC2-DGADomainRequest.C\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-dnsdataexfiltration](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-dnsdataexfiltration)  |  TTPs/Command and Control/Trojan:EC2-DNSDataExfiltration  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-drivebysourcetrafficdns](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-drivebysourcetrafficdns)  |  TTPs/Initial Access/Trojan:EC2-DriveBySourceTraffic\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-droppoint](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-droppoint)  |  Effects/Data Exfiltration/Trojan:EC2-DropPoint  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-droppointdns](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-droppointdns)  |  Effects/Data Exfiltration/Trojan:EC2-DropPoint\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-phishingdomainrequestdns](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#trojan-ec2-phishingdomainrequestdns)  |  TTPs/Command and Control/Trojan:EC2-PhishingDomainRequest\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#trojan-lambda-blackhole-traffic](https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#trojan-lambda-blackhole-traffic)  |  TTPs/Command and Control/Trojan:Lambda-BlackholeTraffic  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#trojan-lambda-drop-point](https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#trojan-lambda-drop-point)  |  Effects/Data Exfiltration/Trojan:Lambda-DropPoint  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-blackholetraffic](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-blackholetraffic)  |  TTPs/Command and Control/Trojan:Runtime-BlackholeTraffic  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-blackholetrafficdns](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-blackholetrafficdns)  |  TTPs/Command and Control/Trojan:Runtime-BlackholeTraffic\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-dgadomainrequestcdns](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-dgadomainrequestcdns)  |  TTPs/Command and Control/Trojan:Runtime-DGADomainRequest.C\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-drivebysourcetrafficdns](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-drivebysourcetrafficdns)  |  TTPs/Initial Access/Trojan:Runtime-DriveBySourceTraffic\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-droppoint](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-droppoint)  |  Effects/Data Exfiltration/Trojan:Runtime-DropPoint  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-droppointdns](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-droppointdns)  |  Effects/Data Exfiltration/Trojan:Runtime-DropPoint\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-phishingdomainrequestdns](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#trojan-runtime-phishingdomainrequestdns)  |  TTPs/Command and Control/Trojan:Runtime-PhishingDomainRequest\$1DNS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-maliciousipcallercustom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-maliciousipcallercustom)  |  TTPs/Command and Control/UnauthorizedAccess:EC2-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-metadatadnsrebind](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-metadatadnsrebind)  |  TTPs/UnauthorizedAccess:EC2-MetadataDNSRebind  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-rdpbruteforce](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-rdpbruteforce)  |  TTPs/Initial Access/UnauthorizedAccess:EC2-RDPBruteForce  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-sshbruteforce](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-sshbruteforce)  |  TTPs/Initial Access/UnauthorizedAccess:EC2-SSHBruteForce  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-torclient](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-torclient)  |  Effects/Resource Consumption/UnauthorizedAccess:EC2-TorClient  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-torrelay](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#unauthorizedaccess-ec2-torrelay)  |  Effects/Resource Consumption/UnauthorizedAccess:EC2-TorRelay  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#unauthorizedaccess-iam-consolelogin](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-retired.html#unauthorizedaccess-iam-consolelogin)  |  Unusual Behaviors/User/UnauthorizedAccess:IAMUser-ConsoleLogin  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-consoleloginsuccessb](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-consoleloginsuccessb)  |  TTPs/UnauthorizedAccess:IAMUser-ConsoleLoginSuccess.B  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-instancecredentialexfiltrationinsideaws](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-instancecredentialexfiltrationinsideaws)  |  Effects/Data Exfiltration/UnauthorizedAccess:IAMUser-InstanceCredentialExfiltration.InsideAWS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-instancecredentialexfiltrationoutsideaws](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-instancecredentialexfiltrationoutsideaws)  |  Effects/Data Exfiltration/UnauthorizedAccess:IAMUser-InstanceCredentialExfiltration.OutsideAWS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-maliciousipcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-maliciousipcaller)  |  TTPs/UnauthorizedAccess:IAMUser-MaliciousIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-maliciousipcallercustom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-maliciousipcallercustom)  |  TTPs/UnauthorizedAccess:IAMUser-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-resourcecredentialexfiltrationoutsideaws](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-resourcecredentialexfiltrationoutsideaws)  |  Effects/Data Exfiltration/UnauthorizedAccess:IAMUser-ResourceCredentialExfiltration.OutsideAWS  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-iam.html#unauthorizedaccess-iam-toripcaller)  |  TTPs/Command and Control/UnauthorizedAccess:IAMUser-TorIPCaller  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#unauthorized-access-lambda-maliciousIPcaller-custom](https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#unauthorized-access-lambda-maliciousIPcaller-custom)  |  TTPs/Command and Control/UnauthorizedAccess:Lambda-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#unauthorized-access-lambda-tor-client](https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#unauthorized-access-lambda-tor-client)  |  Effects/Resource Consumption/UnauthorizedAccess:Lambda-TorClient  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#unauthorized-access-lambda-tor-relay](https://docs.aws.amazon.com/guardduty/latest/ug/lambda-protection-finding-types.html#unauthorized-access-lambda-tor-relay)  |  Effects/Resource Consumption/UnauthorizedAccess:Lambda-TorRelay  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#unauthorizedaccess-runtime-metadatadnsrebind](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#unauthorizedaccess-runtime-metadatadnsrebind)  |  TTPs/UnauthorizedAccess:Runtime-MetadataDNSRebind  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#unauthorizedaccess-runtime-torrelay](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#unauthorizedaccess-runtime-torrelay)  |  Effects/Resource Consumption/UnauthorizedAccess:Runtime-TorRelay  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#unauthorizedaccess-runtime-torclient](https://docs.aws.amazon.com/guardduty/latest/ug/findings-runtime-monitoring.html#unauthorizedaccess-runtime-torclient)  |  Effects/Resource Consumption/UnauthorizedAccess:Runtime-TorClient  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#unauthorizedaccess-s3-maliciousipcallercustom](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#unauthorizedaccess-s3-maliciousipcallercustom)  |  TTPs/UnauthorizedAccess:S3-MaliciousIPCaller.Custom  | 
|  [https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#unauthorizedaccess-s3-toripcaller](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-s3.html#unauthorizedaccess-s3-toripcaller)  |  TTPs/UnauthorizedAccess:S3-TorIPCaller  | 

### GuardDuty 的典型調查結果
<a name="securityhub-integration-finding-example"></a>

GuardDuty 會使用安全調查結果[AWS 格式 (ASFF) 將調查結果傳送至 Security](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-findings-format.html) Hub CSPM。

這是 GuardDuty 的一般調查結果範例。

```
  {
  "SchemaVersion": "2018-10-08",
  "Id": "arn:aws:guardduty:us-east-1:193043430472:detector/d4b040365221be2b54a6264dc9a4bc64/finding/46ba0ac2845071e23ccdeb2ae03bfdea",
  "ProductArn": "arn:aws:securityhub:us-east-1:product/aws/guardduty",
  "GeneratorId": "arn:aws:guardduty:us-east-1:193043430472:detector/d4b040365221be2b54a6264dc9a4bc64",
  "AwsAccountId": "193043430472",
  "Types": [
    "TTPs/Initial Access/UnauthorizedAccess:EC2-SSHBruteForce"
  ],
  "FirstObservedAt": "2020-08-22T09:15:57Z",
  "LastObservedAt": "2020-09-30T11:56:49Z",
  "CreatedAt": "2020-08-22T09:34:34.146Z",
  "UpdatedAt": "2020-09-30T12:14:00.206Z",
  "Severity": {
    "Product": 2,
    "Label": "MEDIUM",
    "Normalized": 40
  },
  "Title": "199.241.229.197 is performing SSH brute force attacks against i-0c10c2c7863d1a356.",
  "Description": "199.241.229.197 is performing SSH brute force attacks against i-0c10c2c7863d1a356. Brute force attacks are used to gain unauthorized access to your instance by guessing the SSH password.",
  "SourceUrl": "https://us-east-1.console.aws.amazon.com/guardduty/home?region=us-east-1#/findings?macros=current&fId=46ba0ac2845071e23ccdeb2ae03bfdea",
  "ProductFields": {
    "aws/guardduty/service/action/networkConnectionAction/remotePortDetails/portName": "Unknown",
    "aws/guardduty/service/archived": "false",
    "aws/guardduty/service/action/networkConnectionAction/remoteIpDetails/organization/asnOrg": "CENTURYLINK-US-LEGACY-QWEST",
    "aws/guardduty/service/action/networkConnectionAction/remoteIpDetails/geoLocation/lat": "42.5122",
    "aws/guardduty/service/action/networkConnectionAction/remoteIpDetails/ipAddressV4": "199.241.229.197",
    "aws/guardduty/service/action/networkConnectionAction/remoteIpDetails/geoLocation/lon": "-90.7384",
    "aws/guardduty/service/action/networkConnectionAction/blocked": "false",
    "aws/guardduty/service/action/networkConnectionAction/remotePortDetails/port": "46717",
    "aws/guardduty/service/action/networkConnectionAction/remoteIpDetails/country/countryName": "United States",
    "aws/guardduty/service/serviceName": "guardduty",
    "aws/guardduty/service/evidence": "",
    "aws/guardduty/service/action/networkConnectionAction/localIpDetails/ipAddressV4": "172.31.43.6",
    "aws/guardduty/service/detectorId": "d4b040365221be2b54a6264dc9a4bc64",
    "aws/guardduty/service/action/networkConnectionAction/remoteIpDetails/organization/org": "CenturyLink",
    "aws/guardduty/service/action/networkConnectionAction/connectionDirection": "INBOUND",
    "aws/guardduty/service/eventFirstSeen": "2020-08-22T09:15:57Z",
    "aws/guardduty/service/eventLastSeen": "2020-09-30T11:56:49Z",
    "aws/guardduty/service/action/networkConnectionAction/localPortDetails/portName": "SSH",
    "aws/guardduty/service/action/actionType": "NETWORK_CONNECTION",
    "aws/guardduty/service/action/networkConnectionAction/remoteIpDetails/city/cityName": "Dubuque",
    "aws/guardduty/service/additionalInfo": "",
    "aws/guardduty/service/resourceRole": "TARGET",
    "aws/guardduty/service/action/networkConnectionAction/localPortDetails/port": "22",
    "aws/guardduty/service/action/networkConnectionAction/protocol": "TCP",
    "aws/guardduty/service/count": "74",
    "aws/guardduty/service/action/networkConnectionAction/remoteIpDetails/organization/asn": "209",
    "aws/guardduty/service/action/networkConnectionAction/remoteIpDetails/organization/isp": "CenturyLink",
    "aws/securityhub/FindingId": "arn:aws:securityhub:us-east-1::product/aws/guardduty/arn:aws:guardduty:us-east-1:193043430472:detector/d4b040365221be2b54a6264dc9a4bc64/finding/46ba0ac2845071e23ccdeb2ae03bfdea",
    "aws/securityhub/ProductName": "GuardDuty",
    "aws/securityhub/CompanyName": "Amazon"
  },
  "Resources": [
    {
      "Type": "AwsEc2Instance",
      "Id": "arn:aws:ec2:us-east-1:193043430472:instance/i-0c10c2c7863d1a356",
      "Partition": "aws",
      "Region": "us-east-1",
      "Tags": {
        "Name": "kubectl"
      },
      "Details": {
        "AwsEc2Instance": {
          "Type": "t2.micro",
          "ImageId": "ami-02354e95b39ca8dec",
          "IpV4Addresses": [
            "18.234.130.16",
            "172.31.43.6"
          ],
          "VpcId": "vpc-a0c2d7c7",
          "SubnetId": "subnet-4975b475",
          "LaunchedAt": "2020-08-03T23:21:57Z"
        }
      }
    }
  ],
  "WorkflowState": "NEW",
  "Workflow": {
    "Status": "NEW"
  },
  "RecordState": "ACTIVE"
}
```

## 啟用與設定整合
<a name="securityhub-integration-enable"></a>

若要使用 整合 AWS Security Hub CSPM，您必須啟用 Security Hub CSPM。如需如何啟用 Security Hub CSPM 的資訊，請參閱*AWS Security Hub 《 使用者指南*》中的[設定 Security Hub](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-settingup.html)。

當您同時啟用 GuardDuty 和 Security Hub CSPM 時，會自動啟用整合。GuardDuty 會立即開始將問題清單傳送至 Security Hub CSPM。

## 在 Security Hub CSPM 中使用 GuardDuty 控制項
<a name="securityhub-integration-using-guardduty-controls"></a>

AWS Security Hub CSPM 使用安全控制來評估您的 AWS 資源，並根據安全產業標準和最佳實務檢查合規性。您可以使用與 GuardDuty 資源和所選保護計畫相關的控制項。如需詳細資訊，請參閱[《 使用者指南》中的 Amazon GuardDuty 控制項](https://docs.aws.amazon.com/securityhub/latest/userguide/guardduty-controls.html)。 *AWS Security Hub *

如需跨 AWS 服務和資源的所有控制項清單，請參閱*AWS Security Hub 《 使用者指南*》中的 [Security Hub CSPM 控制項參考](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-controls-reference.html)。

## 停止將問題清單發佈至 Security Hub CSPM
<a name="securityhub-integration-disable"></a>

若要停止將調查結果傳送至 Security Hub CSPM，您可以使用 Security Hub CSPM 主控台或 API。

請參閱*AWS Security Hub 《 使用者指南*》中的[停用和啟用來自整合的問題清單流程 （主控台）](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-integrations-managing.html#securityhub-integration-findings-flow-console) 或[停用來自整合的問題清單流程 (Security Hub API， AWS CLI)](https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-integrations-managing.html#securityhub-integration-findings-flow-disable-api)。

# 與 Amazon Detective 整合
<a name="detective-integration"></a>

[Amazon Detective](https://docs.aws.amazon.com/detective/latest/userguide/what-is-detective.html) 透過產生資料視覺化來代表資源隨時間的行為和互動方式，協助您快速分析和調查一或多個 AWS 帳戶的安全事件。Detective 將 GuardDuty 的調查結果建立視覺化效果。

Detective 會擷取所有調查結果類型的調查結果詳細資訊，並提供實體設定檔的存取權，以調查與調查結果有關的不同實體。實體可以是 AWS 帳戶、 帳戶中 AWS 的資源，或已與您的資源互動的外部 IP 地址。GuardDuty 主控台支援從下列實體樞紐至 Amazon Detective，取決於調查結果類型：IAM AWS 帳戶角色、使用者或角色工作階段、使用者代理程式、聯合身分使用者、Amazon EC2 執行個體或 IP 地址。

**Contents**
+ [啟用整合](#detective-integration-enable)
+ [從 GuardDuty 調查結果樞紐至 Amazon Detective](#pivot-to-detective)
+ [使用與 GuardDuty 多帳戶環境的整合](#detective-integration-multiaccount)

## 啟用整合
<a name="detective-integration-enable"></a>

若要將 Amazon Detective 與 GuardDuty 一起使用，您必須首先啟用 Amazon Detective。如需如何啟用 Detective 的資訊，請參閱《[Amazon Detective 使用者指南](https://docs.aws.amazon.com/detective/latest/userguide/detective-setup.html)*》中的開始使用 Amazon Detective*。

當您同時啟用 GuardDuty 和 Detective 時，會自動啟用整合。啟用後，Detective 將立即擷取 GuardDuty 調查結果資料。

**注意**  
GuardDuty 會根據 GuardDuty 調查結果的匯出頻率，將調查結果傳送給 Detective。根據預設，現有調查結果更新的匯出頻率為 6 小時。為了確保 Detective 能夠收到您調查結果的最新更新，建議您在 Detective 與 GuardDuty 一起使用的每個區域中將匯出頻率變更為 15 分鐘。如需詳細資訊，請參閱[步驟 5 – 設定匯出更新之作用中問題清單的頻率](guardduty_exportfindings.md#guardduty_exportfindings-frequency)。

## 從 GuardDuty 調查結果樞紐至 Amazon Detective
<a name="pivot-to-detective"></a>

1. 登入主控台，網址為 [https://console.aws.amazon.com/guardduty/](https://console.aws.amazon.com/guardduty/)。

1. 從調查結果表中選擇單個調查結果。

1. 從調查結果詳細資訊窗格中選擇**使用 Detective 來調查**。

1. 選擇調查結果的一個方面，以使用 Amazon Detective 來調查。這會針對該調查結果或實體開啟 Detective 主控台。

如果樞紐未如預期般運作，請參閱 *Amazon Detective User Guide* 中的 [Troubleshooting the pivot](https://docs.aws.amazon.com/detective/latest/userguide/profile-pivot-from-service.html#profile-pivot-troubleshooting)。

**注意**  
如果您在 Detective 主控台中封存 GuardDuty 調查結果，該調查結果也會封存在 GuardDuty 主控台中。

## 使用與 GuardDuty 多帳戶環境的整合
<a name="detective-integration-multiaccount"></a>

如果您要在 GuardDuty 中管理多帳戶環境，則必須將成員帳戶新增至 Amazon Detective，以檢視這些帳戶中調查結果和實體的 Detective 資料視覺化。

建議您使用與 Detective 的管理員帳戶相同的 GuardDuty 管理員帳戶。如需在 Detective 中新增成員帳戶的詳細資訊，請參閱《*Amazon Detective 使用者指南*》中的[管理帳戶](https://docs.aws.amazon.com/detective/latest/userguide/accounts.html)。

**注意**  
Detective 是一項區域性服務，這意味著您必須啟用 Detective，並在要使用整合的每個區域中新增成員帳戶。