0PricingLogin
AWS Security Academy · Lesson

How Detective Builds a Behavior Graph

Understand how Detective links events into an investigable graph.

From Alert to Understanding

Detection tells you something is wrong; investigation tells you what actually happened. Amazon Detective is the service built for investigation. It automatically analyzes activity and builds a visual model so you can understand the full story behind a finding, not just the alert.

What Detective Does

Detective continuously ingests and links log data to build a graph of behavior over time. Instead of manually correlating logs across services, you get a pre-built, queryable picture of how entities like accounts, instances, and IP addresses have interacted.

All lessons in this course

  1. How Detective Builds a Behavior Graph
  2. Pivoting from a GuardDuty Finding
  3. Analyzing Entities and Time Windows
  4. Spotting Anomalous Activity Patterns
← Back to AWS Security Academy