Amazon GuardDuty
You can integrate Amazon GuardDuty with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Amazon GuardDuty product overview
Amazon GuardDuty is AWS's threat detection service. It continuously monitors your AWS accounts and workloads for malicious activity, analyzing data sources such as AWS CloudTrail events, VPC Flow Logs, and DNS logs with threat intelligence feeds and machine learning, and delivers detailed security findings for visibility and remediation.
What we ingest
Sophos XDR collects GuardDuty findings through the Sophos XDR AWS collector, using a read-only AWS Identity and Access Management (IAM) role that you grant. The following log categories are collected:
- Findings: GuardDuty security findings for potentially malicious or unauthorized activity detected in your AWS environment.
Event and data types
We ingest the following event and data types from GuardDuty:
- Findings: GuardDuty security findings, including the finding type, severity, affected resource, and the actor or activity that triggered the detection. Normalized to third-party security alert telemetry.
Data provided by this integration
Data provided by GuardDuty gets normalized to the following schemas:
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.