I mainly use GuardDuty to check user responses, collect logs, and collect data on who logs in and out and their permission and authorization.
Information Security Manager at Tata Consultancy Services
Highly stable and scalable solution that streamlines data collection
Pros and Cons
- "The most valuable features are the single system for data collection and the alert mechanisms."
- "GuardDuty is really scalable, which is helping us to upscale our environment to the cloud, and I really appreciate the scalability measures that Amazon is providing to all its customers."
- "An improvement would be to have a mobile version where remote workers can log in and monitor and fix issues."
What is our primary use case?
How has it helped my organization?
Prior to using GuardDuty, we had multiple systems to collect data and put it in a centralized location so we could look into it. Now we don't need to do that anymore as GuardDuty does it for us.
What is most valuable?
The most valuable features are the single system for data collection and the alert mechanisms.
What needs improvement?
An improvement would be to have a mobile version where remote workers can log in and monitor and fix issues. In the next release, I'd like Amazon to add a pane to visualize all seven layers of security.
Buyer's Guide
AWS GuardDuty
June 2026
Learn what your peers think about AWS GuardDuty. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
For how long have I used the solution?
I've been using GuardDuty for two to three years.
What do I think about the stability of the solution?
GuardDuty's stability is really good - we never see outages or falls in networking or BPC connections.
What do I think about the scalability of the solution?
GuardDuty is really scalable, which is helping us to upscale our environment to the cloud. I really appreciate the scalability measures that Amazon is providing to all its customers.
How are customer service and support?
We've had enormous support from the Amazon support team.
Which solution did I use previously and why did I switch?
Previously, I used GCT.
How was the initial setup?
GuardDuty is set up through a one-touch system, so the process was simple.
What about the implementation team?
We used the AWS team to do our workload, publishing, and so on, so it took about a quarter of the time it would have otherwise.
What's my experience with pricing, setup cost, and licensing?
We use a pay-as-you-use license, which is competitively priced in the market.
What other advice do I have?
I'd rate GuardDuty as nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Developer at a sports company with 501-1,000 employees
Very intuitive, simple to use, and offers great pricing
Pros and Cons
- "With anomaly detection, active threat monitoring, and set correlation, GuardDuty alerts me to any unusual user behavior or traffic patterns right away, which is great for staying on top of potential security risks."
- "One improvement I would suggest for AWS GuardDuty is the ability to assign findings to specific users or groups, facilitating better communication and follow-up actions."
What is our primary use case?
I use AWS GuardDuty to monitor my AWS environment for potential security threats. It analyzes data from various sources like CloudTrail logs and VPC Flow Logs to detect malicious activity. GuardDuty provides insights into potential threats, categorizing them by severity levels, helping me prioritize and respond effectively.
What is most valuable?
As I explore AWS GuardDuty, I find its features helpful for spotting threats in my AWS setup. With anomaly detection, active threat monitoring, and set correlation, GuardDuty alerts me to any unusual user behavior or traffic patterns right away, which is great for staying on top of potential security risks. While I'm still new to using it and haven't faced many threats yet, I see how GuardDuty is crucial for beefing up my AWS security by catching and dealing with vulnerabilities early on.
What needs improvement?
One improvement I would suggest for AWS GuardDuty is the ability to assign findings to specific users or groups, facilitating better communication and follow-up actions. It would be beneficial to have a knowledge bank where past findings and actions taken are stored, aiding in handling repeat incidents and providing historical precedence for new team members.
For how long have I used the solution?
I have been using AWS GuardDuty for a year.
What do I think about the stability of the solution?
AWS GuardDuty is stable and responsive. I haven't encountered any glitches or stability issues, and the analytics are quick and reliable.
What do I think about the scalability of the solution?
As a very small business in its initial stage, I find AWS GuardDuty to be scalable for our needs.
How are customer service and support?
The tech support for AWS GuardDuty is good. The documentation and support resources available are clear and comprehensive, making it easy to set up and configure. I would rate it around nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
GuardDuty is intuitive to use and the setup process is simple. There is not much complex configuration involved, which makes it easy to get started. Deploying AWS GuardDuty is straightforward with just a few steps, and it is all done within your AWS cloud account. As for maintenance, it is easy and there haven't been any issues or challenges.
What's my experience with pricing, setup cost, and licensing?
The pricing and licensing for AWS GuardDuty are transparent and predictable, which I appreciate. While some may find it expensive at larger scales, for our small business, it is manageable and in line with expectations. AWS's pay-as-you-go model ensures we only pay for what we use, which is beneficial for budgeting.
What other advice do I have?
GuardDuty helps by flagging unexpected or potentially unauthorized activity in my AWS environment. For instance, it alerts me when there is an API call from an unfamiliar IP address, which might indicate a security threat. However, in some cases, these alerts might be triggered by legitimate actions, such as employees working remotely from different locations using VPNs.
I find the anomaly detection and continuous monitoring features of AWS GuardDuty very effective. They give me peace of mind knowing that AWS is actively looking out for any abnormal behavior or traffic in my environment. In the past, for on-premises setups, I relied on different network tools for this, but in the cloud, GuardDuty takes care of it, sparing me from manual tasks like checking VPC logs.
Integrating AWS GuardDuty with third-party tools seems straightforward, although I haven't done it yet myself. From what I have seen, getting GuardDuty data into AWS Security Hub appears to be a simple process, allowing for centralized security monitoring across multiple accounts. I'm considering enabling it and trying it out, especially since AWS offers a 30-day trial for Security Hub.
Overall, I would rate AWS GuardDuty as a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
AWS GuardDuty
June 2026
Learn what your peers think about AWS GuardDuty. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
security analyst at a tech vendor with 201-500 employees
Provides reliable security alerts and strong technical support while offering room for UI improvements
Pros and Cons
- "AWS GuardDuty integrates seamlessly with third-party tools in our existing ecosystem, and we did not experience any challenges with integration."
- "In future updates of AWS GuardDuty, I would suggest implementing better UI features."
What is our primary use case?
We have been using AWS, and since we used a couple of tools, we decided to implement AWS GuardDuty for security purposes.
We are currently leveraging AWS GuardDuty quite often for security monitoring within our infrastructure.
What is most valuable?
I can discuss specific instances where AWS GuardDuty's automated response feature was very helpful for our security. It provides abrupt alerts, which has been a good feature.
AWS GuardDuty integrates seamlessly with third-party tools in our existing ecosystem, and we did not experience any challenges with integration.
What needs improvement?
AWS GuardDuty is currently meeting our needs concerning what could be improved.
In future updates of AWS GuardDuty, I would suggest implementing better UI features.
For how long have I used the solution?
We have recently learned AWS GuardDuty, and we are trying to integrate it right now, as it has only been a few months.
What was my experience with deployment of the solution?
When we deployed AWS GuardDuty, it proceeded smoothly without any difficulties or complexities.
What do I think about the stability of the solution?
On a scale from one to ten, I find AWS GuardDuty very stable, rating it approximately nine.
What do I think about the scalability of the solution?
For scalability, AWS GuardDuty rates around eight on the same scale.
How are customer service and support?
I have communicated with the technical support of AWS, and they are helpful and responsive.
On a scale from one to ten, I rate the technical support ten. They provided workshops and all services on time, which demonstrates their excellence.
How would you rate customer service and support?
Positive
How was the initial setup?
The deployment of AWS GuardDuty required just a few hours to complete.
What was our ROI?
AWS GuardDuty has impacted our security operational costs, but we are still in the process and experimenting with it, so I'm not fully aware of the financial implications.
Which other solutions did I evaluate?
My team was experimenting with some tools and found AWS GuardDuty to be relatively better.
What other advice do I have?
The solution can be utilized in public or private cloud environments, though I'm not fully aware of those details as my team manages the implementation.
We are not currently utilizing artificial intelligence in AWS GuardDuty to enhance its threat detection capabilities.
I would recommend AWS GuardDuty to other companies and businesses.
I rate AWS GuardDuty a nine out of ten.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer at a tech services company with 201-500 employees
Used to monitor the activity of over 1,000 employees
Pros and Cons
- "We have over 1,000 employees, and we monitor their activity through AWS GuardDuty."
- "The solution's user interface could be improved because it will help users to understand multiple options."
What is most valuable?
We have over 1,000 employees, and we monitor their activity through AWS GuardDuty.
What needs improvement?
The solution's user interface could be improved because it will help users to understand multiple options. Currently, we have multiple options on AWS GuardDuty, which may confuse new users.
For how long have I used the solution?
I have been using AWS GuardDuty for two years.
What do I think about the stability of the solution?
We faced some issues with AWS GuardDuty because sometimes we don't get proper loss from the solution.
I rate the solution an eight out of ten for stability.
What do I think about the scalability of the solution?
I rate the solution ten out of ten for scalability.
How was the initial setup?
The solution’s initial setup is not very difficult.
What other advice do I have?
We have a whole bunch of information on various things in AWS GuardDuty.
Overall, I rate the solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Controller at a outsourcing company with 11-50 employees
An easy-to-use and easy-to-configure solution that helps monitor threats or vulnerabilities
Pros and Cons
- "The solution will detect abnormalities in the AWS workload and alert us so that we can monitor and take action."
- "I work in a bank, and it would be good if AWS GuardDuty could be integrated with other monitoring and detection tools we use."
What is our primary use case?
My company uses AWS GuardDuty to develop the software and provide services to clients. I use the solution to monitor the service on the AWS workload or AWS instance and monitor threats or vulnerabilities.
What is most valuable?
AWS GuardDuty is easy to use and configure. I use AWS GuardDuty to check whether we are under attack or not. The solution will detect abnormalities in the AWS workload and alert us so that we can monitor and take action.
What needs improvement?
I work in a bank, and it would be good if AWS GuardDuty could be integrated with other monitoring and detection tools we use. The operation team can use a single desktop to monitor.
For how long have I used the solution?
I have been using AWS GuardDuty for less than one month.
What do I think about the scalability of the solution?
In my department, around seven to eight users are using AWS GuardDuty.
Which solution did I use previously and why did I switch?
I previously used Google Cloud for three to four years. AWS GuardDuty has more features and can be customized more than Google Cloud.
What's my experience with pricing, setup cost, and licensing?
I have heard that the solution's price is quite high. Sometimes, they need to fine-tune the service on AWS. For example, Amazon Simple Storage Service (S3) is used for static content because it is cheaper.
What other advice do I have?
Overall, I rate AWS GuardDuty an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free AWS GuardDuty Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Cloud Workload Protection Platforms (CWPP)Popular Comparisons
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
TrendAI Vision One – Cloud Security
Orca Security
CrowdStrike Falcon Cloud Security
Check Point Email Security (formerly Harmony Email & Collaboration)
Qualys TotalCloud
Illumio Segmentation
Check Point CloudGuard CNAPP
FortiCNAPP
Akamai Guardicore Segmentation
Aqua Cloud Security Platform
Cortex Cloud by Palo Alto Networks
Cisco Secure Workload
Buyer's Guide
Download our free AWS GuardDuty Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What tools provide the best container environment security?
- When evaluating Cloud Workload Security, what aspect do you think is the most important to look for?
- Can we customize the dashboard in Threat Stack Cloud Security Platform? Any recommendations for an alternative solution supporting dashboards?
- What are the best cloud workload security software solutions?
- Why use cloud workload security software?
- Why are Cloud Workload Protection Platforms (CWPP) important for companies?
- Why is CWPP (Cloud Workload Protection Platforms) important for companies?

















