Setting the file. One moment.
AWS Guardduty · Prompt Library For Startups · aws/agent-toolkit-for-aws · Skills Docs
Deploy comprehensive threat detection and security monitoring with GuardDuty and Security Hub, including automated email notifications for critical findings via EventBridge and SNS integration.
ContentsBack to the top of the page 31
Prompt Library For Startups
81
Creating Amazon Aurora Db Cluster With Instances
104
Routing Traffic With Route53 And CloudFront
Resilience Program Design
Creating API Gateway Stage
You are an AWS security architect tasked with deploying and configuring AWS GuardDuty and AWS Security Hub to enhance the security posture of an AWS environment. Your goal is to set up comprehensive threat detection and security monitoring with automated notifications for critical findings.
AWS GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. AWS Security Hub provides a comprehensive view of security alerts and security posture across AWS accounts. Together, they form a robust security monitoring solution.
Deploy and configure the following components:
AWS GuardDuty
Enable GuardDuty in the target AWS region(s)
Configure detector settings with appropriate finding publishing frequency
Enable protection plans if related resources exist:
S3 Protection
EKS Protection (enable Runtime Protection too)
Malware Protection
Set up trusted IP lists and threat lists if applicable
AWS Security Hub
Enable Security Hub in the target AWS region(s)
Enable AWS Foundational Security Best Practices standard
Enable CIS AWS Foundations Benchmark standard
Configure GuardDuty as a findings provider
Set up custom insights for critical findings
EventBridge Rule
Create an EventBridge rule to capture critical and high severity findings
Filter for findings with severity labels “CRITICAL” or “HIGH”
Support findings from both GuardDuty and Security Hub
SNS Topic and Subscription
Create an SNS topic for security notifications
Configure email subscription(s) for security team
Set up appropriate access policies
Enable encryption at rest using AWS KMS
IAM Roles and Policies
Create necessary IAM roles with least privilege access
Configure service-linked roles for GuardDuty and Security Hub
Set up cross-service permissions for EventBridge to publish to SNS
Provide Infrastructure as Code (IaC) using one of the following:
AWS CloudFormation template (YAML or JSON)
Terraform configuration files
AWS CDK code (Python, TypeScript, or Java)
Complete deployment scripts with all required resources
Configuration parameters for customization (email addresses, regions, severity thresholds)
Documentation explaining the architecture and deployment steps
Testing procedures to verify the setup
Cost estimation for the deployed resources
When deployed, the solution should:
Automatically detect and analyze security threats across the AWS environment
Aggregate findings from multiple security services in Security Hub
Trigger notifications via email when critical or high severity findings are detected
Provide a centralized dashboard for security posture management
Enable compliance reporting against industry standards
Ensure the solution supports multi-region deployment
Include tagging strategy for resource management
Implement proper error handling and logging
Consider integration with existing SIEM or ticketing systems
Document any prerequisites (e.g., AWS Organizations, specific IAM permissions)
Include cleanup/teardown procedures
The deployment is successful when:
GuardDuty is actively monitoring and generating findings
Security Hub is aggregating findings from GuardDuty and other sources
Email notifications are received for test critical findings
All resources are properly tagged and documented
The solution follows AWS Well-Architected Framework security best practices
references/prompt-library/aws-guardduty.md