Detection and Response on AWS

Continuously detect, prioritize, and respond to security risks to help protect your workloads, at scale

What is Detection and Response on AWS?

AWS detection and response services help protect your cloud environment with integrated security capabilities in a unified security solution. These services help you continuously detect and prioritize critical issues by correlating and enriching security signals, such as threats and vulnerabilities, enabling you to surface and prioritize active security risks and streamline response at scale to protect your cloud environment.

What is Detection and Response on AWS?

Overview

Continuously detect and prioritize critical issues through automated correlation and enriching of security signals, such as threats and vulnerabilities,to help your organization operate more securely on AWS.

Gaind broader security visibility across your cloud environment through centralized management in a unified security solution, aggregating security data from AWS services and partner products across your accounts and Regions.

Surface and prioritize active risks through actionable insights and automated workflows, enabling streamlined response at scale.

Normalize and combine security data from cloud and on-premises sources, gain a holistic view of your security, and leverage your preferred analytics tools to investigate and respond to events, all while retaining control and ownership of your data.

Use cases

Surface active risks through unified signals across multiple security services, centralized management, and standardizing controls to reduce operational complexity.

Automatically discover and quickly route vulnerability findings in near real time to the appropriate teams, so they can take immediate action.

Continuously detect and remediate cloud resource misconfigurations and compliance risks to ensure your environment is operating according to security best practices.

Defend your accounts and workloads from potential threats, streamline threat response with automation, and minimize business impact through faster remediation and recovery time.

Discover and protect sensitive data and workloads to increase visibility and automate remediation of your data security risks.

  • Expedia

    Expedia needs to stay up to date with global and local compliance requirements and the ability to process, analyze, and control the vast amounts of data we generate. The AWS solution we built around Amazon Macie has helped us automate data scanning, tagging, sampling, and identification and implement rule configuration, generation of metrics, and scaling security controls. With Macie at the solution's core, we can reduce the footprint on our sensitive data. By reducing PII data, we can open up data access to our analysts while reducing exposure and, at the same time, resulting in an empowering and enriching experience for our customers.

    Aaron Miller, Principal Engineer, Expedia Group
    Learn how Expedia uses Macie for data protection at petabyte scale »

Learn about the new security hub

Learn more

AWS Security Hub Detect and respond to critical security issues

AWS Security Hub Demp

AWS Security Hub Exposure Findings

GuardDuty Malware Protection

GuardDuty Extended Threat Detection - Identify multi stage attacks

Multi-stage threat detection using Amazon GuardDuty and MITRE

Explore this infographic for an overview of detection and response services.

Learn more

Read this eBook for an overview of detection and response on AWS. 

Learn more

Enhanced threat detection for Amazon EKS with Amazon GuardDuty (59:33)
Build your security data lake with Amazon Security Lake, featuring IPG (53:52)
Vulnerability management at scale drives enterprise transformation (59:34)
Continuous innovation in AWS detection and response services (56:21)
AWS security services for container threat detection (54:53)

Blogs

1