It quickly raises an alert shortly after it detects an incident. While almost all warnings, when investigated, result from innocuous activities, the actions triggering them are precisely the sort that an attacker would be taking. The number of alerts is also low, so exploring false positives does not take long. When Guarduty is in the same AWS account as the entity that is the alert source, the alert can be clicked on to go directly to the entity, which results in a time-saving. Review collected by and hosted on G2.com.
Having to log in to GuardDuty to see the alerts will likely result in missed warnings. To get the most out of GuardDuty, integrate it with a monitored platform so that the alerts can be seen and acted upon. Review collected by and hosted on G2.com.
At G2, we prefer fresh reviews and we like to follow up with reviewers. They may not have updated their review text, but have updated their review.
The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.
Validated through a business email account
This reviewer was offered a nominal gift card as thank you for completing this review.
Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.