GD
LowerPlane

AWS GuardDuty Integration for Compliance

Automate evidence from AWS GuardDuty for threat detection, security monitoring, malware protection, and incident response. Achieve SOC 2, ISO 27001, and PCI-DSS compliance.

Supported Frameworks:SOC 2ISO 27001PCI-DSSHIPAA

What Gets Automated

Continuous evidence collection from AWS GuardDuty threat detection and security findings with zero manual exports

Threat Detection

  • Reconnaissance detection findings
  • Instance compromise indicators
  • Account compromise alerts
  • Malicious IP communications
  • Cryptocurrency mining detection
  • Data exfiltration alerts

Malware Protection

  • EBS malware scan results
  • S3 malware protection findings
  • EC2 runtime threat detections
  • Container threat findings
  • Lambda function threats
  • Malware scan configurations

Security Monitoring

  • Detector configurations
  • Finding severity trends
  • Regional coverage status
  • Integration configurations
  • Suppression rules
  • Finding statistics

Setup in 2 Minutes

Simple IAM role connection with read-only access

1
1 min

Create IAM Role

In AWS IAM, create a role with read-only GuardDuty permissions (guardduty:Get*, guardduty:List*, guardduty:Describe*). Add LowerPlane as a trusted entity.

2
30 sec

Configure Regions

Select which AWS regions to monitor for GuardDuty findings. Enable multi-region collection for comprehensive threat detection coverage.

3
30 sec

Sync & Verify

LowerPlane verifies access and begins collecting threat detection findings. Historical findings up to 90 days are imported automatically.

Security Note

LowerPlane uses read-only AWS IAM access and cannot modify GuardDuty settings, suppress findings, or change detector configurations. IAM roles are configured with least privilege and you can revoke access at any time from AWS IAM console.

Evidence Collected Automatically

Real-time threat detection and security evidence mapped directly to compliance controls

ControlEvidence TypeServiceFrequency
Threat DetectionSOC 2
Security findings & threat intelligenceGuardDuty FindingsReal-time
Malware ProtectionISO 27001
Malware scan results & detectionsMalware ProtectionReal-time
Incident DetectionPCI-DSS
Compromise indicators & alertsThreat IntelligenceReal-time
Network SecuritySOC 2
Malicious IP & DNS findingsNetwork AnalysisContinuous
Container SecurityISO 27001
EKS & container threat findingsRuntime MonitoringReal-time
Data ProtectionHIPAA
S3 protection & exfiltration alertsS3 ProtectionReal-time
Security MonitoringPCI-DSS
Detector status & configurationGuardDuty ConfigDaily
Vulnerability ManagementSOC 2
Instance vulnerability findingsEC2 FindingsContinuous

Collecting evidence from all GuardDuty protection features

View complete evidence mapping

Framework Coverage

AWS GuardDuty integration satisfies threat detection and security monitoring controls across multiple compliance frameworks

20

SOC 2 Type II Controls

GuardDuty integration covers 20 out of 64 SOC 2 controls, focusing on Security, Availability, and Monitoring criteria for threat detection and response.

Common Criteria (CC)

  • CC6.6 - Threat Detection
  • CC6.8 - Malware Protection
  • CC7.2 - Security Monitoring
  • CC7.3 - Security Analysis
  • CC7.4 - Incident Response

Security (S)

  • S1.1 - Security Monitoring
  • S1.2 - Threat Intelligence
  • S1.3 - Incident Detection

Trusted by Security & DevOps Teams

AWS GuardDuty is essential for cloud threat detection compliance

58%
Of AWS customers use GuardDuty integration
125K+
Findings analyzed monthly
99.9%
Threat detection coverage
40min
Average time saved per week

"Our auditors needed proof of continuous threat detection and malware protection. The GuardDuty integration automatically pulled all our security findings, detector configurations, and threat trends. Saved us 40+ hours during our SOC 2 audit."

MJ
Michael Johnson
Cloud Security Lead, FinTech Startup
SOC 2 Type II + PCI-DSS Certified
AWS GuardDuty Partner
GD
SOC 2
SOC 2
ISO 27001
ISO 27001
PCI-DSS
PCI-DSS
HIPAA
HIPAA

Frequently Asked Questions

Everything you need to know about AWS GuardDuty integration

Still have questions?

Contact our security team

Related Integrations

Build comprehensive AWS security and monitoring operations

Ready to automate GuardDuty compliance evidence?

Connect your AWS GuardDuty in 2 minutes and start collecting threat detection evidence automatically

No credit card required • 14-day free trial • Setup in 2 minutes