AWSPlatform ChangesRetrospectives

Amazon Detective Goes GA (Mar 2020): Investigation Graphs for AWS Security Findings

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.

In March 2020, Amazon Detective became generally available. It helps security teams investigate findings from GuardDuty and other sources by automatically building a graph of activity across AWS accounts.

What it does

Detective ingests CloudTrail logs, VPC Flow Logs, GuardDuty findings and, later, EKS audit logs and other sources. It builds a behavior graph linking IAM users and roles, IP addresses, EC2 instances, S3 buckets and other entities over time. Investigators can then pivot from a finding to see:

  • What else that role or user did before and after the finding.
  • Which IP addresses it connected from, and whether they were new.
  • Whether activity volume or API usage changed from its normal baseline.

Why it mattered

GuardDuty told you something suspicious had happened. Answering "how bad is it?" meant writing many CloudTrail queries across accounts and regions. Detective made that investigation visual and fast, which mattered most for small teams without dedicated analysts.

How it fits

Detective is not a SIEM or detection tool; it is an investigation tool. Organizations using Microsoft Sentinel or another SIEM may run similar investigations there. For AWS-centric teams, Detective became the natural companion to GuardDuty and Security Hub, and later added generative AI summaries of finding groups.

In hindsight

Detection without fast investigation leads to two bad outcomes: real incidents dismissed as noise, or every alert escalated because nobody can tell the difference. Detective's value is in shortening the time between "alert" and "decision."

amazon detectiveAmazon Detective GA2020

More on this story