Skip to content

Amazon GuardDuty

You can integrate Amazon GuardDuty with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Amazon GuardDuty product overview

Amazon GuardDuty is AWS's threat detection service. It continuously monitors your AWS accounts and workloads for malicious activity, analyzing data sources such as AWS CloudTrail events, VPC Flow Logs, and DNS logs with threat intelligence feeds and machine learning, and delivers detailed security findings for visibility and remediation.

What we ingest

Sophos XDR collects GuardDuty findings through the Sophos XDR AWS collector, using a read-only AWS Identity and Access Management (IAM) role that you grant. The following log categories are collected:

  • Findings: GuardDuty security findings for potentially malicious or unauthorized activity detected in your AWS environment.

Event and data types

We ingest the following event and data types from GuardDuty:

  • Findings: GuardDuty security findings, including the finding type, severity, affected resource, and the actor or activity that triggered the detection. Normalized to third-party security alert telemetry.

Data provided by this integration

Data provided by GuardDuty gets normalized to the following schemas:

  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation