Tools/Amazon_GuardDuty
Amazon GuardDuty
Continuous threat detection service — monitors AWS_CloudTrail, VPC Flow Logs, and DNS logs for malicious activity and unauthorized/anomalous behavior. Behavior-focused, not a config or content scanner (compare AWS_Config and Amazon_Macie). Closest open-source equivalent is Wazuh, a full SIEM/XDR covering log analysis and host-based intrusion detection across cloud and on-prem; narrower single-purpose alternatives include Falco (runtime/container threat detection) and Suricata/Zeek (network IDS).