Concept and mechanism
Start detection strategy with events you need to observe and decisions depending on them. A finding is an analytical result, not necessarily a complete archive of original data. GuardDuty uses independent streams of foundational sources for detection; this does not provide a raw history managed by the team. If you need to query Flow Logs during a future investigation, configure your own collection, access, and retention. The DNS path also matters: the described GuardDuty source uses AWS resolvers, so a fleet with an external resolver can have a gap in that source. Do not present silence as proof of no activity.
Guided application
For CloudTrail, enabling integrity produces digests supporting checks for changes after delivery. Validation must be executed and its result retained; this feature does not itself prevent object writes. Keep preventive access and retention controls. Security Lake can centralize configured sources and normalize events into OCSF, with Parquet storage and bounded subscriber access. Define each consumer’s sources and Regions instead of treating normalization as global authorization. In a committee, distinguish integrated accounts from accounts still lacking collection. An acquisition is not covered merely by appearing in inventory. Record an owner, deadline, and alternative evidence for the gap while integration is prepared.
GuardDuty detected activity, but nobody retained the Flow Logs requested for the last 90 days. Explain the gap and use only actually available evidence.
Common pitfalls
Finding as archive; digest as executed validation; central as complete; absence as health.
Related topics: Response, containment, and preservation · Networking and administrative access
Describe origin, period, integrity, and limits of the evidence used.
Reference: SCS-C03 domain 1 · SCS-C03