Automate threat triage with AI that correlates risk and context.

Amazon GuardDuty's new investigation agent, now in public preview, takes a significant step toward easing the burden of threat triage.

3 min readInfoQ
Automate threat triage with AI that correlates risk and context.

The security industry has spent years promising that artificial intelligence would finally tame the alert fatigue that plagues every cloud operations team. AWS's new GuardDuty investigation agent is the first feature that actually feels like it understands the problem, rather than just adding another dashboard to check. By correlating findings with 90-day activity logs and resource topologies, the agent produces structured reports complete with risk ratings, confidence scores, and MITRE ATT&CK classifications. That is a meaningful departure from the usual approach of generating more raw signals and calling it intelligence.

For teams drowning in alerts, the practical value here is immediate. Instead of assigning a human to manually pivot between CloudTrail logs, VPC flow logs, and IAM policies to piece together what happened, the agent does that heavy lifting and hands back a narrative. The inclusion of resource topology is particularly telling. It means the agent is not just looking at isolated events but understanding the blast radius within your actual infrastructure. This is the kind of context that separates a genuine investigation from a glorified log dump. And because it is reachable through the AWS MCP Server, you can drive these investigations from your existing agentic tooling. That is not a minor feature add; it is a structural shift in how security operations will be run.

We would tell any reader who asked us whether to pay attention: this is the first step toward the security analyst becoming a reviewer rather than a hunter. The 10-investigation-per-account-per-day preview quota is the constraint to watch. It suggests AWS is being cautious about cost and latency, but it also means you cannot yet rely on this for full-scale production triage across a large environment. For now, treat it as a powerful force multiplier for your highest-priority incidents, not a replacement for your existing playbooks. The confidence scores and risk ratings are useful, but they are only as good as the underlying model's ability to reason about your specific environment.

The open question that will define this feature's success is whether the agent's reports earn trust through accuracy or erode it through subtle hallucinations. The MITRE ATT&CK classification is a nice touch, but it only helps if the mapping is precise. We expect teams to spend the preview period testing the agent against known past incidents, and that is exactly the right approach. The concrete point to watch: when the quota lifts, does the agent scale from a triage aid to a primary investigation tool? If it does, the role of the cloud security professional changes from assembler to verifier. That is a future worth exploring, and for once, it feels like the technology is ready to lead the way there.

From InfoQ

AWS released a public preview of the GuardDuty investigation agent, which correlates findings, 90-day activity logs, and resource topologies into structured reports with risk ratings, confidence scores, and MITRE ATT&CK classification. It is reachable through the AWS MCP Server, so investigations can run from agentic tooling. Preview quotas cap usage at 10 investigations per account per day.

Read the original at InfoQ