Amazon GuardDuty Investigation Agent: Accelerate Threat Investigations with AI-Powered Security Assessments
News | 21.07.2026
Security operations teams are under constant pressure to investigate an ever-growing number of alerts while reducing response times and minimizing business risk. Correlating data across multiple AWS services and security tools often requires hours of manual analysis before security analysts can determine whether an alert represents a real threat.
To simplify this process, Amazon GuardDuty now introduces the GuardDuty Investigation Agent (currently available in public preview)—an AI-powered capability that automatically investigates security findings across your AWS environment and delivers structured, actionable threat assessments within minutes.
As an official Amazon Web Services (AWS) partner, Softprom helps organizations strengthen their cloud security posture by implementing AWS-native security services and best practices. The new GuardDuty Investigation Agent provides another powerful tool for improving incident response while reducing operational overhead.
What Is the Amazon GuardDuty Investigation Agent?
Amazon GuardDuty is AWS's intelligent threat detection service that continuously monitors AWS accounts, workloads, and resources for suspicious activities, malicious behavior, compromised credentials, and unauthorized access attempts.
The new Investigation Agent builds on these capabilities by automatically analyzing GuardDuty findings and producing comprehensive investigation reports that include:
- Overall risk level
- Confidence score
- Executive investigation summary
- Detailed threat analysis
- MITRE ATT&CK® technique mapping
- Affected AWS resources
- Prioritized remediation recommendations
- AWS CLI commands for remediation
Instead of manually gathering evidence from multiple AWS services, security teams receive a complete investigation report generated automatically.
From Hours of Investigation to Minutes
Investigating cloud security incidents typically involves collecting information from multiple sources, including:
- Amazon GuardDuty findings
- AWS CloudTrail logs
- Identity activity
- Network events
- Runtime behavior
- Resource configurations
The GuardDuty Investigation Agent automates this correlation process and presents findings in a structured format that helps analysts quickly determine:
- What happened
- Which resources are affected
- How severe the incident is
- Which attack techniques were used
- What actions should be taken next
As a result, investigation time can be reduced from several hours to just a few minutes.
Flexible Investigation Scopes
Organizations can launch investigations directly from the AWS Management Console, AWS CLI, AWS APIs, or AWS SDKs.
The Investigation Agent supports multiple investigation scopes, including:
Individual Security Findings
Analyze a specific GuardDuty finding in depth to understand its root cause and impact.
AWS Account Assessment
Evaluate the overall security posture of a single AWS account by correlating related findings.
Organization-Wide Analysis
Security administrators can investigate findings across all accounts within an AWS Organization to identify lateral movement, coordinated attacks, or widespread security risks. The service also supports natural language investigation prompts through the API, allowing teams to describe what they want to investigate without relying on predefined filters.
AI-Powered Threat Assessment
Every completed investigation generates a standardized security assessment containing:
Risk Level
Threat severity is categorized as:
- Informational
- Low
- Medium
- High
- Critical
Confidence Score
The agent indicates how confident it is in the assessment, helping analysts prioritize incidents that require immediate attention.
MITRE ATT&CK Mapping
Each investigation maps detected behaviors to the MITRE ATT&CK framework, making it easier for SOC teams to understand attacker tactics and techniques.
Recommended Actions
Rather than simply identifying a threat, the Investigation Agent provides concrete remediation guidance, including AWS CLI commands where appropriate. This significantly shortens the time between detection and remediation.
AI Built for AWS Security Operations
Unlike general-purpose AI assistants, the GuardDuty Investigation Agent is purpose-built for AWS cloud security. The service automatically correlates information across AWS security telemetry and produces consistent, structured investigations without requiring customers to manage AI models or complex workflows. The agent uses AWS cross-Region inference capabilities to process investigations efficiently while maintaining secure encrypted data transfer. Customer data remains stored in the AWS Region where the investigation originated, although inference processing may occur within the same geographic area.
Integrating Security Investigations into Existing Workflows
One of the Investigation Agent's major advantages is its API-first design. Organizations can integrate automated investigations into existing security operations workflows, including:
- Security Information and Event Management (SIEM) platforms
- Security orchestration and automation (SOAR) solutions
- AWS Lambda automation
- Amazon EventBridge event pipelines
- Ticketing platforms
- Internal security dashboards
For example, when GuardDuty generates a new finding, an EventBridge rule can automatically trigger an investigation. The completed assessment can then be forwarded to a SIEM together with:
- Risk level
- Confidence score
- MITRE ATT&CK mapping
- Recommended remediation steps
This allows security analysts to focus on validated threats instead of manually correlating raw alerts.
AI Security Operations with Model Context Protocol (MCP)
The Investigation Agent also integrates with the AWS Model Context Protocol (MCP) Server, enabling AI assistants such as Claude, Kiro, and other MCP-compatible clients to initiate investigations using natural language.
Examples include:
- "Investigate the latest high-severity finding in my production account."
- "Summarize what happened in finding ID XYZ."
- "List investigations from the last 24 hours that require human review."
This capability enables organizations to build AI-assisted Security Operations Centers (SOC) while maintaining secure access to AWS resources.
Security Governance and Access Control
The Investigation Agent follows the existing GuardDuty authorization model. Administrator accounts can:
- Create investigations
- Retrieve investigation results
- Review investigations across member accounts
Member accounts can only view investigations related to their own AWS account.
Three new IAM permissions are required:
- guardduty:CreateInvestigation
- guardduty:GetInvestigation
- guardduty:ListInvestigations
This allows organizations to integrate the feature into existing IAM governance models.
How Softprom Helps
Implementing cloud-native security requires more than enabling services—it requires designing an effective detection, investigation, and response strategy. As an official AWS partner, Softprom helps organizations:
- Deploy and configure Amazon GuardDuty
- Build cloud-native threat detection strategies
- Integrate AWS security services with existing SOC platforms
- Automate incident response workflows
- Strengthen AWS security governance and compliance
- Accelerate cloud security modernization using AWS-native services
Our AWS experts help organizations improve visibility, reduce investigation time, and build scalable security operations powered by artificial intelligence.
Conclusion
The new Amazon GuardDuty Investigation Agent represents an important step forward in AI-assisted cloud security operations. By automatically correlating security findings, generating structured threat assessments, and providing actionable remediation guidance, it enables security teams to investigate incidents dramatically faster while improving decision-making. Combined with existing AWS security services, the Investigation Agent helps organizations shift their focus from manual investigation toward proactive threat response—making cloud security operations faster, smarter, and more efficient.