> For the complete documentation index, see [llms.txt](https://karansingh.gitbook.io/tutorialsdojo-wrong-answers-aws-sec-spec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://karansingh.gitbook.io/tutorialsdojo-wrong-answers-aws-sec-spec/incident-response-57/amazon-guardduty.md).

# GuardDuty

* GuardDuty **analyses tens of billions of events across multiple AWS data sources, such as CloudTrail, VPC Flow Logs, and DNS logs**.<br>

* Through the **multi-account feature, all member accounts findings can be aggregated with a GuardDuty administrator account**.

* It can **inform you that an EC2 instance in your AWS environment was involved in a brute force attack**.
  * This can **protect your AWS resources from attacks that are aimed at obtaining passwords to SSH services on Linux-based systems**.
