AI SafetyAgents 🇨🇳 05.08.2026 10:01

AWS Launches GuardDuty Investigation Agent Public Preview to Let AI Trace Attack Leads for Security Teams

Amazon Web ServicesAmazon Web Services
AWS has released the public preview of Amazon GuardDuty Investigation Agent, an AI-powered security tool that evaluates findings, correlates historical activity, and maps threat telemetry across AWS accounts and organizations. The tool aims to compress security investigations from hours to minutes by integrating finding metadata, 90-day activity logs, and affected resource topology into structured analysis reports. It supports three scopes—finding, account, and organization analysis—and generates risk levels, confidence scores, MITRE ATT&CK classifications, and CLI remediation steps.
Amazon Web Services (AWS) has announced the public preview of Amazon GuardDuty Investigation Agent, an AI-driven security tool designed to evaluate security findings, correlate historical activity, and map threat telemetry across AWS accounts and organizations. The service integrates finding metadata, 90-day activity logs, and affected resource topology into structured analysis reports, aiming to reduce investigation time from hours to minutes. It was initially announced as 'AI-powered investigations' in June and detailed under the name Investigation Agent in July. The agent operates on three scopes: finding analysis for a specific 32-character GuardDuty finding ID, account analysis for a single 12-digit AWS account, and organization analysis for up to 100 member accounts in an AWS Organization. Each analysis produces a structured result set including a risk level (from Info to Critical), confidence score, MITRE ATT&CK classification, and executable CLI remediation steps. AWS Security Hero Sena Yakut noted the difference from GuardDuty's existing Extended Threat Detection, which links related findings into attack chains, while Investigation analyzes affected resources, IAM activity, and surrounding context to generate a summary report with recommendations. The tool is particularly suited for organizations without large security teams, but Yakut emphasized that AI should assist, not replace, human investigation and decision-making. Developers and SecOps teams can trigger investigations programmatically via AWS SDK, the aws guardduty create-investigation CLI command, or EventBridge rules. AWS MCP Server integration allows engineers to trigger threat investigations from Claude Desktop or custom CLI agent runners using existing IAM credentials. AWS addresses governance concerns by noting that investigation data and reports are stored in the original region, even though inference may route to other regions via the Cross-Region Inference Service (CRIS) powered by Bedrock models. The service competes with Microsoft's Security Copilot and Google's Gemini-assisted investigations. The differentiation lies in its scope, limited to GuardDuty findings and surrounding AWS telemetry, which narrows the reasoning domain and makes outputs verifiable. The public preview is available in 10 AWS commercial regions and is free during preview, with limits of 10 investigations per account per day and 100 total per account. These limits suggest a focus on manual analysis rather than automated response pipelines, aligning with Yakut's reminder that the preview is for evaluating outputs, not for autonomous response.
Abbreviations
AWS = Amazon Web Services — Amazon Web Services
IAM = Identity and Access Management — Управление доступом и идентификацией
CLI = Command Line Interface — Интерфейс командной строки
SDK = Software Development Kit — Комплект разработки программного обеспечения
MCP = Model Context Protocol — Протокол контекста модели
CRIS = Cross-Region Inference Service — Кросс-региональный сервис вывода
XTD = Extended Threat Detection — Расширенное обнаружение угроз
Source: InfoQ 中国 — original
Our earlier posts on this topic ↓
Fresh news