Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
セキュリティ運用エージェントGuardDuty-Operatorを作って社内に配ってみた @ ...
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
SimSta
May 26, 2026
210
2
Share
セキュリティ運用エージェントGuardDuty-Operatorを作って社内に配ってみた @ JAWS-UG SRE支部
SimSta
May 26, 2026
More Decks by SimSta
See All by SimSta
祝日にも対応なコスト節約ツールNAT-Schedulerの紹介 @ JAWS-UG 札幌×秋田コラボ
shimagaji
1
130
AgentCore RuntimeのCDKデプロイにdeploy-time-buildを使ってみよう @ JAWS-UG Sapporo
shimagaji
2
150
AWSの2025年最新トレンドをフル活用してフルサーバーレスな司書エージェントを作ってみた @ JAWS-UG Sapporo
shimagaji
3
330
AWS Media Servicesを使ってAmazon IVSとYouTubeへの同時配信を試してみた @ JAWS-UG千葉支部 x Media-JAWS
shimagaji
1
150
AWSアップデートまとめ #しむそく をFun Done Learnで振り返る @ JAWS-UG Tokyo
shimagaji
2
330
Amazon Q DeveloperでMCP Serverを使ってKnowledge Baseを呼び出してみた @ JAWS-UG 彩の国埼玉支部#1
shimagaji
1
530
KAG社内のPlatform Engineeringをちょっとだけ紹介します @ Sapporo Engineer Base
shimagaji
0
62
日本からre:Inventを支えた活動報告&ミニre:Cap @ JAWS-UG Sapporo
shimagaji
0
140
Step FunctionsとInfrastructure Composerで挑むローコード × Platform Engineering @ JAWS-UG 青森
shimagaji
1
380
Featured
See All Featured
Self-Hosted WebAssembly Runtime for Runtime-Neutral Checkpoint/Restore in Edge–Cloud Continuum
chikuwait
0
540
Refactoring Trust on Your Teams (GOTO; Chicago 2020)
rmw
35
3.5k
Building Better People: How to give real-time feedback that sticks.
wjessup
370
20k
The Mindset for Success: Future Career Progression
greggifford
PRO
0
340
Faster Mobile Websites
deanohume
310
31k
Test your architecture with Archunit
thirion
1
2.2k
Building a Modern Day E-commerce SEO Strategy
aleyda
45
9k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
5.9k
New Earth Scene 8
popppiees
3
2.3k
HU Berlin: Industrial-Strength Natural Language Processing with spaCy and Prodigy
inesmontani
PRO
0
390
Typedesign – Prime Four
hannesfritz
42
3k
WENDY [Excerpt]
tessaabrams
10
37k
Transcript
ηΩϡϦςΟӡ༻ΤʔδΣϯτ (VBSE%VUZ0QFSBUPSΛ ࡞ͬͯࣾʹͬͯΈͨ 4JN4UB !TIJNBHBKJ +"846(43& ू·ΕʂԶͨͪͷ࡞ͬͨ࠷ڧͷӡ༻"HFOUେ-5େձ KBXTVH@TSF
ࣗݾհ +BQBO"845PQ&OHJOFFS +BQBO"MM"84$FSUJGJDBUJPOT&OHJOFFS "84$PNNVOJUZ#VJMEFS ࡛ۄˠࡳຈˠਆಸˠࡳຈ 4JN4UBʢΦϯϥΠϯͷ͕ͨ͢ʣ ,%%*ΞδϟΠϧ։ൃηϯλʔגࣜձࣾʢ,"(ʣ ϓϥοτϑΥʔϜΤϯδχΞϦϯά෦ ઓུاը෦ 4FSWFSMFTT
ΧάΧά !TIJNBHBKJ 5XJUUFS
ۙͷొஃ༧ఆ ίετݮπʔϧ/"54DIFEVMFSͷ ηΩϡϦςΟӡ༻ΤʔδΣϯτ (VBSE%VUZ0QFSBUPSͷ ʢԾʣ৴தʹۓٸใΛड৴ͨ͠Βʜͳ
"HFOEB • (VBSE%VUZʹؔ͢ΔΈ • ,"(ͷ1MBUGPSN&OHJOFFSJOHͱLBHUPPMT • (VBSE%VUZ4VNNBSJ[FSͷհ • #FESPDL"HFOU$PSFͷొ •
(VBSE%VUZ0QFSBUPSͷհ • ࡞͔ͬͯͬͯͬͨ՝ • ·ͱΊ
(VBSE%VUZ ͪΌΜͱӡ༻Ͱ͖ͯ·͔͢ʁ
(VBSE%VUZͱͦͷ௨ • $MPVE5SBJMͳͲͷΞΫςΟϏςΟͳͲΛݩʹҟৗΛࢹ͠ɺ "84ΞΧϯτʹ࣮ࡍʹى͖͍ͯΔڴҖΛݕग़ͯ͠௨ • 4FDVSJUZ)VCͱ͍ͬͨʮΞΧϯτͷηΩϡϦςΟෆඋʯͰͳ͘ ʮΞΧϯτʹൃੜͨ͠ڴҖͦͷͷʯ͕ಧ͘ͷͰɺ ௨͞ΕͨΒ͙͢ʹରԠ͠ͳ͚ΕͳΒͳ͍ ˠͰ(VBSE%VUZ͔Βͷ௨ͲΜͳײ͡Ͱಧ͘ʁ
ʮ&$ͷϩʔϧೝূใ͕"84֎͔Βར༻͞Εͨʯ ͱ͍͏ڴҖͷ௨ ΠϕϯτΛͦͷ··௨͢Δͱ ˡͷΑ͏ͳ͍͍+40/͕ಧ͘ &WFOU#SJEHF -BNCEBͳͲͰܗͰ͖Δ͕ ։ൃऀʹͱͬͯೝෛՙ͕ߴ͘ ʮԿ͕ى͖͍ͯͯɺͲ͏͢Ε͍͍ʁʯΛ அɾ࣮ߦͰ͖Δਓগͳ͍ ˣ
ೝෛՙΛԼ͛ͯ ୭ͰཧղɾରԠͰ͖ΔΑ͏ʹ͍ͨ͠ʂ ͜Μͳײ͡
,"(ͷ 1MBUGPSN&OHJOFFSJOHͱ LBHUPPMT
,"(ͷ1MBUGPSN&OHJOFFSJOHͱLBHUPPMT • ։ൃνʔϜͷೝෛՙΛܰݮ͢ΔηϧϑαʔϏεπʔϧΛ LBHUPPMTͱͯࣾ͠Ͱల։ • (JU)VC&OUFSQSJTFͷϦϙδτϦʹͯΠϯφʔιʔεͱͯ͠ఏڙ • ୭ͰίϯτϦϏϡʔτ0, • ηΩϡϦςΟɺΨόφϯεɺίετݮɺ։ൃڥͳͲ͍Ζ͍Ζ
• ίετݮܥπʔϧͷͭ/"54DIFEVMFSʹ͍ͭͯ Ұࡢʢ݄ʣͷ+"846(ࡳຈºळాࢧ෦ίϥϘʹ͓ͯ͠·ͨ͠ • ຊհͷ(VBSE%VUZ4VNNBSJ[FS0QFSBUPSηΩϡϦςΟܥͷπʔϧ
(VBSE%VUZ0QFSBUPSͷલ (VBSE%VUZ4VNNBSJ[FSͷհ
(VBSE%VUZ4VNNBSJ[FSͷ֓ཁ • (VBSE%VUZͷݕ༰Λ#FESPDLʢ$MBVEF4POOFUʣʹͯ͠ ཁ͔ͤͯ͞ΒϢʔβʔʹ௨͢Δπʔϧ • มΛೖΕͯγΣϧεΫϦϓτΛ࣮ߦ͢Δ͚ͩͰ୭Ͱ؆୯ʹσϓϩΠ • 4UFQ'VODUJPOTͰ݁ɺ-BNCEBϨεͰϝϯςφϯεָ͕ • 4FDVSJUZ)VCͰϚϧνΞΧϯτͷ(VBSE%VUZΛू͍ͯ͠Ε
୯ҰͷཧΞΧϯτʹσϓϩΠ͢Δ͚ͩͰ0, • #FESPDLͷϞσϧ୯७ʹݺͼग़͚ͩ͢ͳͷͰɺϞσϧͷࣝʹґଘ ʢ3"("84υΩϡϝϯτͷࢀর͠ͳ͍ʣ
AWS Cloud GuardDuty Step Functions Bedrock SNS Invoke Execute EventBridge
User Threats E-Mail Publish Slack Security Hub ᶃ(VBSE%VUZͷΠϕϯτΛर͏ ᶄ4FDVSJUZ)VCʹू͞ΕͨΠϕϯτΛर͏ ͷͲͪΒ͔Λબͯ͠σϓϩΠՄೳ (VBSE%VUZ4VNNBSJ[FSͷߏ (VBSE%VUZͷݕ༰Λཁͯ͠4MBDLʹ௨
#FESPDL"HFOU$PSFͷొ
#FESPDL"HFOU$PSF ࡞ͨ͠ੜ"*ΤʔδΣϯτΛσϓϩΠ͢ΔͨΊͷϓϥοτϑΥʔϜ 4USBOETͳͲΛ ίϯςφԽ ձͷهԱ Մ؍ଌੑ˕ ଟ࠼ͳπʔϧͱ ҆શͳར༻ IUUQTHJUIVCDPNBXTMBCTBNB[POCFESPDLBHFOUDPSFTBNQMFTCMPCNBJOUVUPSJBMTJNBHFTBHFOUDPSF@PWFSWJFXQOH
#FESPDL"HFOU$PSFͷొʹΑΔϞνϕʔγϣϯ • (VBSE%VUZʹΑΔݕͷ୯७ͳཁ͚ͩͰͳ͘ɺʮࠓͲΜͳঢ়ଶʁʯ ʮͲ͏ରॲ͢Ε͍͍ͷʁʯ·Ͱ"*͕౿ΈࠐΊΔΑ͏ʹͳΓͦ͏ • 4USBOET"HFOUT #FESPDL"HFOU$PSFͷΈ߹Θ͕ͤ ࠓޙελϯμʔυʹͳΔ͜ͱΛݟӽ͠ɺ൚༻తʹ࠶ར༻Ͱ͖Δ "*ΤʔδΣϯτͷςϯϓϨʔτΛ࡞͓͖͍ͬͯͨ •
ಛʹΠϕϯτۦಈΤʔδΣϯτʢ"NCJFOU"HFOUʣ͕ྲྀߦͬͯͨͷͰ ϊϋͷशಘͱࣾͷڞ༗Λ͍ͨ͠ ˠηΩϡϦςΟӡ༻ΤʔδΣϯτ(VBSE%VUZ0QFSBUPSΛ։ൃɾࣾల։
(VBSE%VUZ0QFSBUPSͷհ
(VBSE%VUZ0QFSBUPSͷ֓ཁ • (VBSE%VUZͷݕ༰Λ#FESPDL"HFOU$PSFʢ4USBOETʣʹͯ͠ ௐࠪ͠ɺৄࡉਪ͞ΕΔίϚϯυΛؚΊͯϢʔβʔʹ௨͢Δπʔϧ • ϩʔΧϧ·ͨ$MPVE4IFMMͰ$%,Λͬͯ୭Ͱ؆୯ʹσϓϩΠ ˠEFQMPZUJNFCVJMEࡌͰίϯςφΠϝʔδͷϏϧυΛΦϑϩʔυ • 4FDVSJUZ)VCͰϚϧνΞΧϯτͷ(VBSE%VUZΛू͍ͯ͠Ε ୯ҰͷཧΞΧϯτʹσϓϩΠ͢Δ͚ͩͰ0,
• ݱࡏͷϦιʔεͷঢ়گ࠷৽ͷ"84υΩϡϝϯτΛࢀর͠ɺ ΑΓৄࡉͰ࣮֬ͳใΛ௨͢Δ͜ͱ͕Ͱ͖Δ
(VBSE%VUZ0QFSBUPSͷߏ AWS Cloud ECR AgentCore Runtime AWS API MCP Slack
Lambda AWS Knowledge MCP SNS Strands Agents GuardDuty EventBridge (VBSE%VUZͷݕ༰Λৄࡉௐࠪͯ͠4MBDLʹ௨ SNS Security Hub ᶃ(VBSE%VUZͷΠϕϯτΛर͏ ᶄ4FDVSJUZ)VCʹू͞ΕͨΠϕϯτΛर͏ ͷͲͪΒ͔Λબͯ͠σϓϩΠՄೳ
(VBSE%VUZͷݕ༰Λৄࡉௐࠪͯ͠4MBDLʹ௨ %FW0QT"HFOUͷΑ͏ʹਪ$-*ίϚϯυͳͲΛग़ྗ (VBSE%VUZ0QFSBUPSͷߏ
࡞ͬͨ"*ΤʔδΣϯτΛ ࣾͰͬͯΈͨ
ηϧϑαʔϏεπʔϧͱͯ͠εΫϥϜνʔϜʹల։ Platform Team User User User GitHub Enterprise (JU)VC&OUFSQSJTFͰ$%,ςϯϓϨʔτΛ ཧ
ηϧϑαʔϏεπʔϧͱͯ͠εΫϥϜνʔϜʹల։ Platform Team User User User GitHub Enterprise (JU)VC&OUFSQSJTFͰ$%,ςϯϓϨʔτΛ ݱ࣮
ͬͯ͘ΕΔνʔϜ͕ ͍ͳ͍ʜ ʢ࣌ʣ
࡞͔ͬͯͬͯͬͨ՝ • πʔϧ࡞ͬͯͬͨΒऴΘΓͰͳ͘ɺΘΕͳ͍ͱՁ͕ͳ͍ • (VBSE%VUZͷݕػձͷগͳ͞ˍϑΟʔυόοΫͷෆͰ վળϧʔϓ͕ճΒͳ͘ͳͬͯ͠·͏ • ΒͤΔରʢʹࣾϚʔέςΟϯάʣ͍ͩ͡ • ฉ͖ʹ͍͘ରʢʹ֤νʔϜͱʮ՝ײʯʮຊʹඞཁͳͷʯ
ʮηΩϡϦςΟ؍ʯΛ͢Γ߹ΘͤΔ͜ͱʣ͍ͩ͡ • ηϧϑαʔϏεͷ"*ΤʔδΣϯτπʔϧΛల։͢Δࡍ ʮ࠷ॳͷҰาΛ౿Έग़ͤ͞ΔͨΊͷಋઢʯͷઃܭ͕ॏཁ
·ͱΊ
·ͱΊ • ηΩϡϦςΟ໘Ͱॏཁ͕ͩೝෛՙͷߴ͍(VBSE%VUZͷݕ༰Λ "*ʢΤʔδΣϯτʣπʔϧܦ༝ͰཧղͰ͖Δܗࣜʹͯ͠௨ • (VBSE%VUZ4VNNBSJ[FS0QFSBUPS͍ͣΕɺ؆୯ʹσϓϩΠՄೳͳ ηϧϑαʔϏεπʔϧͱͯࣾ͠ఏڙ • ͔͠͠ɺ࡞ͬͯఏڙ͚ͨͩ͠ͰΘΕͣɺվળ͞Εͳ͍ •
πʔϧΛͬͯΒ͏ͨΊͷʮΒͤΔରʯʮฉ͖ʹ͍͘ରʯ͕ 1MBUGPSN&OHJOFFSJOHͰ͍ͩ͡ʂ
5IBOLZPVʂ