AWS

GuardDuty and Inspector

Amazon's two security scanners — what each one finds, and what to do about it.

Two AWS services, two different questions, two screens here.

  • GuardDuty — is something suspicious happening right now? It watches behaviour: unusual API calls, connections to known-bad addresses, credentials suddenly used from another country.
  • Inspector — is anything I run vulnerable? It scans EC2 instances and container images for known security holes in the software they run.

Both screens gather findings across regions and list them by severity.

GuardDuty

Findings are rated High, Medium and Low.

Common ones and what they usually mean:

FindingUsually means
UnauthorizedAccess:EC2/SSHBruteForceSomeone is guessing SSH passwords. Extremely common on any public server — see below
CryptoCurrencyMiningTake seriously. A machine has been compromised and is mining for someone else
UnauthorizedAccess:IAMUser/InstanceCredentialExfiltrationUrgent. Credentials from an instance are being used elsewhere
Recon:EC2/PortProbeUnprotectedPortSomeone is scanning your open ports. Background noise, but check what is open
Policy:IAMUser/RootCredentialUsageSomeone used the root account. It should be locked away

SSH brute force is constant on any server with port 22 open to the internet. It is not a breach, and you do not need to panic about it — but it is a good argument for turning off password authentication and using keys only.

If GuardDuty is not enabled, the Dashboard says so. Enabling it takes one click in the AWS console and the free tier covers most small accounts.

Inspector

Findings are vulnerabilities in installed software, with a severity and a CVE number.

The practical response to most of them is the same: install updates. Open the server's Packages tab, or run the guided task Install security updates — see Guided tasks.

Do not try to fix them one CVE at a time. Patch, then re-scan.

How to work through findings

  1. Sort by severity. Critical and High first.
  2. Understand before acting. Ask the assistant — "explain this GuardDuty finding and tell me if I should worry" — it reads the finding and answers in plain English.
  3. Fix the cause, not the alert. Suppressing a finding does not remove the problem.
  4. Re-check. Both services re-scan; findings disappear once resolved.

If a machine is actually compromised

Signs: crypto-mining findings, credential exfiltration, processes you cannot account for in Monitor, unexplained root cron jobs in Scheduled.

Do not clean it up and carry on. Rotate every credential that machine could reach, rebuild it from a known-good image, and get a person involved. An assistant is not the right tool for a compromise.

Permissions

Needs guardduty:* list/get and inspector2:ListFindings on the key. See AWS permissions.