AWS
GuardDuty and Inspector
Amazon's two security scanners — what each one finds, and what to do about it.
Two AWS services, two different questions, two screens here.
- GuardDuty — is something suspicious happening right now? It watches behaviour: unusual API calls, connections to known-bad addresses, credentials suddenly used from another country.
- Inspector — is anything I run vulnerable? It scans EC2 instances and container images for known security holes in the software they run.
Both screens gather findings across regions and list them by severity.
GuardDuty
Findings are rated High, Medium and Low.
Common ones and what they usually mean:
| Finding | Usually means |
|---|---|
UnauthorizedAccess:EC2/SSHBruteForce | Someone is guessing SSH passwords. Extremely common on any public server — see below |
CryptoCurrencyMining | Take seriously. A machine has been compromised and is mining for someone else |
UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration | Urgent. Credentials from an instance are being used elsewhere |
Recon:EC2/PortProbeUnprotectedPort | Someone is scanning your open ports. Background noise, but check what is open |
Policy:IAMUser/RootCredentialUsage | Someone used the root account. It should be locked away |
SSH brute force is constant on any server with port 22 open to the internet. It is not a breach, and you do not need to panic about it — but it is a good argument for turning off password authentication and using keys only.
If GuardDuty is not enabled, the Dashboard says so. Enabling it takes one click in the AWS console and the free tier covers most small accounts.
Inspector
Findings are vulnerabilities in installed software, with a severity and a CVE number.
The practical response to most of them is the same: install updates. Open the server's Packages tab, or run the guided task Install security updates — see Guided tasks.
Do not try to fix them one CVE at a time. Patch, then re-scan.
How to work through findings
- Sort by severity. Critical and High first.
- Understand before acting. Ask the assistant — "explain this GuardDuty finding and tell me if I should worry" — it reads the finding and answers in plain English.
- Fix the cause, not the alert. Suppressing a finding does not remove the problem.
- Re-check. Both services re-scan; findings disappear once resolved.
If a machine is actually compromised
Signs: crypto-mining findings, credential exfiltration, processes you cannot account for in Monitor, unexplained root cron jobs in Scheduled.
Do not clean it up and carry on. Rotate every credential that machine could reach, rebuild it from a known-good image, and get a person involved. An assistant is not the right tool for a compromise.
Permissions
Needs guardduty:* list/get and inspector2:ListFindings on the key. See
AWS permissions.
