Amazon has introduced the Amazon GuardDuty investigation agent in public preview, adding an AI-powered capability that automates the first stages of investigating GuardDuty findings across AWS environments. The service correlates evidence and returns structured assessments with risk levels, confidence scores, MITRE ATT&CK mappings, affected resource details, and recommended remediation actions, aiming to cut investigation time from hours to minutes. It can scope investigations to a single finding, an AWS account, or an entire organization.
The new capability is available through the AWS Management Console, AWS CLI, APIs, SDKs, and the official AWS MCP server, and it supports asynchronous investigations, natural-language prompts in the CLI, and integration with Amazon EventBridge and MCP-compatible AI assistants. AWS said the preview is offered at no additional cost in 10 Regions, with limits of 10 investigations per account per day and 100 total per account during the preview period. The company also introduced new IAM permissions for creating and retrieving investigations, and said processing uses cross-Region inference within the same geographic area while keeping stored data in the originating Region and encrypting data in transit.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
AWS announced the Amazon GuardDuty investigation agent in public preview as an AI-powered capability for investigating GuardDuty findings across AWS environments. AWS said the feature automates correlation and analysis and is available through the console, CLI, APIs, SDKs, and the AWS MCP server, with preview availability in 10 Regions at no additional charge.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.