Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
5min GuardDuty Extended Threat Detection EKS
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
takakuni
June 30, 2025
Technology
390
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
5min GuardDuty Extended Threat Detection EKS
takakuni
June 30, 2025
More Decks by takakuni
See All by takakuni
ECS Express Mode
takakuni
0
37
AWS WAF Anti-DDoS Protection in 5 Minutes!
takakuni
0
640
AWS Backup Air-Gapped Vaults with Multi-Party Approval Explained in 5 Minutes!
takakuni
0
320
OpenAI models overview 202505
takakuni
0
460
[Sample] Validate hyperlink for Amazon Bedrock Data Automation
takakuni
0
320
Classmethod AI Talks #13
takakuni
0
440
About Extended Threat Detection in Amazon GuardDuty
takakuni
0
430
SageMaker Hyperpod 101 #regrowth_sapporo
takakuni
1
440
What is Amazon Bedrock knowledge base with an Amazon Kendra GenAI index?
takakuni
0
800
Other Decks in Technology
See All in Technology
『AIに負けない』より『AIと遊ぶ』」〜ワクワクが最強のテスト・QA学習戦略_公開用
odan611
1
370
Kotlin 開発のツラミを爆破した話! / Explode the difficulty of Kotlin dev!
eller86
0
140
金融の未来を考える / Thinking About the Future of Finance
ks91
PRO
0
150
End-to-Endで考える信頼性 —LINEアプリにおけるクライアント開発×SRE連携の実践
maruloop
0
190
Amazon EVS で VCF 9.0 / 9.1 のサポート開始まとめ
mtoyoda
0
190
「ちゃんとやっている」は独りよがりだった ― 不安に寄り添うインシデント対応へ / Towards incident response that addresses anxieties
chmikata
1
370
次世代ランサムウェア対策の考察 / 20260704 Mitsutoshi Matsuo
shift_evolve
PRO
5
1.7k
cccccc
moznion
0
1.7k
組織における AI-DLC 実践
askul
0
300
きのこカンファレンス2026_肩書きを外したとき私は誰か
yamasatimi
1
130
Tech-Verse 2026_Keynote
lycorptech_jp
PRO
0
130
Text-to-SQLをAgentCoreで実現し、生成されるSQLの精度を定量的に評価する
yakumo
2
520
Featured
See All Featured
How to Build an AI Search Optimization Roadmap - Criteria and Steps to Take #SEOIRL
aleyda
1
2.1k
How STYLIGHT went responsive
nonsquared
100
6.2k
Why Our Code Smells
bkeepers
PRO
340
58k
Measuring & Analyzing Core Web Vitals
bluesmoon
9
880
KATA
mclloyd
PRO
35
15k
Mozcon NYC 2025: Stop Losing SEO Traffic
samtorres
1
270
GraphQLとの向き合い方2022年版
quramy
50
15k
The Language of Interfaces
destraynor
162
27k
Building an army of robots
kneath
306
46k
Practical Tips for Bootstrapping Information Extraction Pipelines
honnibal
25
2k
What's in a price? How to price your products and services
michaelherold
247
13k
Highjacked: Video Game Concept Design
rkendrick25
PRO
1
400
Transcript
5分でわかる!GuardDuty 拡張脅威検出 EKS 編
2 • 部署 ◦ クラウド事業本部コンサルティング部 • 名前(ニックネーム) ◦ たかくに •
ロール ◦ ソリューションアーキテクト ⾃⼰紹介
re:Inforce 2025 どうでしたか?
GuardDuty でしたね。
Extended Threat Detection の話をします。
Extended Threat Detection とは
拡張脅威検出 です!
拡張脅威検出とは
拡張された脅威を検出する機能!
10 今までの GuardDuty Threat Detection 1. EC2 finding types 2.
IAM finding types 3. S3 Protection finding types 4. EKS Protection finding types 5. GuardDuty Runtime Monitoring finding types 6. Malware Protection for EC2 finding types 7. Malware Protection for S3 finding type 8. RDS Protection finding types 9. Lambda Protection finding types
11 これからの GuardDuty Threat Detection 1. EC2 finding types 2.
IAM finding types 3. S3 Protection finding types 4. EKS Protection finding types 5. GuardDuty Runtime Monitoring finding types 6. Malware Protection for EC2 finding types 7. Malware Protection for S3 finding type 8. RDS Protection finding types 9. Lambda Protection finding types 10. GuardDuty attack sequence finding types(NEW !)
• 複数の脅威が連なった状態を検出 • 普段の検出タイプに加え、弱いシグナルも評価対象 ◦ 弱いシグナル:普段の検出タイプでは表⽰されな い API アクティビティ •
MITRE ATT&CK のステップ別に重要度を表⽰ 12 GuardDuty attack sequence finding types
• Attack sequence ◦ 複数のイベント(シグナル)の相関関係 • Findings ◦ GuardDuty が発⾒した脅威(≒シグナル)
• Signals ◦ GuardDuty が観察した API アクティビティ 13 単語のおさらい
14 図にすると
ここからアップデートの紹介です
• AttackSequence:IAM/CompromisedCredentials ◦ IAM が侵害されている可能性が⾼い場合に検出 • AttackSequence:S3/CompromisedData ◦ S3 が漏洩している可能性が⾼い場合に検出
• AttackSequence:EKS/CompromisedCluster(NEW) ◦ Amazon EKS クラスター内で⼀連の疑わしいアクショ ンがあった場合に検出される 16 GuardDuty attack sequence finding types
17 複数の脅威が連なった状態を検出
18 MITRE ATT&CK のステップ別に重要度を表⽰
• EKS audit log events • AWS CloudTrail data events
for S3 • AWS CloudTrail management events • VPC Flow Logs • Route53 Resolver DNS query logs • Amazon EKS malware detection for Amazon EC2 • Runtime Monitoring for Amazon EKS 19 参照するソース
20 ログを有効化しておく必要があるのか...? https://aws.amazon.com/jp/guardduty/faqs/
以下のどちらかを有効にしておくこと • EKS Protection • EKS Runtime Monitoring 最⼤限活⽤したい場合は、どちらも有効が推奨 21
前提条件
• 拡張脅威検出は⼀連の脅威を連なった形で検出する脅威タイプ ◦ 今回新たに EKS クラスターの脅威タイプが加わった • 複数のデータソースから脅威を検出 ◦ ⼀部のデータソースはユーザー側の設定がなくとも、
GuardDuty 側で独⽴して収集してくれる • EKS Protection または Runtime Monitoring for Amazon EKS のど ちらも有効化して最⼤限機能を活かしましょう! 22 まとめ
None