Detective
Amazon Detective helps analyze and investigate security findings and suspicious activity.
Automatically collects log data from AWS services like CloudTrail, VPC Flow Logs, and GuardDuty.
Builds visualizations of user and resource behavior over time.
Provides graph-based investigations to identify the root cause of incidents.
Fully automated data ingestion and correlation—no manual setup needed.
Supports deep dive into API activity, login attempts, and network traffic.
Retains data for up to 1 year for historical analysis.
Integrated natively with Amazon GuardDuty and AWS Security Hub.
Does not generate findings, but helps analyze and contextualize existing ones.
Automatically groups related events and entities into profiles.
No agent installation required—data is sourced from AWS service logs.
Supports investigation of IAM roles, EC2 instances, IP addresses, and accounts.
Useful for forensics, incident response, and threat hunting.
Supports multi-account investigations using AWS Organizations.
Visual UI in the console helps security teams trace actions and dependencies.
Last updated