1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
|
// Code generated by smithy-go-codegen DO NOT EDIT.
// Package guardduty provides the API client, operations, and parameter types for
// Amazon GuardDuty.
//
// Amazon GuardDuty is a continuous security monitoring service that analyzes and
// processes the following data sources: VPC flow logs, Amazon Web Services
// CloudTrail management event logs, CloudTrail S3 data event logs, EKS audit logs,
// and DNS logs. It uses threat intelligence feeds (such as lists of malicious IPs
// and domains) and machine learning to identify unexpected, potentially
// unauthorized, and malicious activity within your Amazon Web Services
// environment. This can include issues like escalations of privileges, uses of
// exposed credentials, or communication with malicious IPs, URLs, or domains. For
// example, GuardDuty can detect compromised EC2 instances that serve malware or
// mine bitcoin. GuardDuty also monitors Amazon Web Services account access
// behavior for signs of compromise. Some examples of this are unauthorized
// infrastructure deployments such as EC2 instances deployed in a Region that has
// never been used, or unusual API calls like a password policy change to reduce
// password strength. GuardDuty informs you of the status of your Amazon Web
// Services environment by producing security findings that you can view in the
// GuardDuty console or through Amazon CloudWatch events. For more information, see
// the Amazon GuardDuty User Guide
// (https://docs.aws.amazon.com/guardduty/latest/ug/what-is-guardduty.html) .
package guardduty
|