How it works...
We first enabled GuardDuty. GuardDuty asked us for the permissions for ec2:DescribeInstances and ec2:DescribeImages. An actual permissions file is available with the code files for reference. For testing purposes, we then generated sample findings from the GuardDuty console; GuardDuty generated 54 sample events in my case. GuardDuty events are categorized into three severity levels, from lowest to highest, denoted by blue, yellow, and red icons, where blue is the least severe and red is the most severe. Once we click on a finding, we will get additional information about the finding.
We whitelisted and blacklisted a few IP addresses by adding them to the trusted IP lists and threat lists, respectively. GuardDuty will not ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access