0Pricing
AWS Security Academy · Lesson

Pivoting from a GuardDuty Finding

Trace a single alert into the full story of what happened.

Pivoting from a GuardDuty Finding is a free AWS Security Academy lesson on CoddyKit — lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the AWS Security Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Starting from a Finding

Investigations usually begin with an alert. Detective integrates tightly with GuardDuty so you can pivot directly from a finding into the behavior graph. One click takes you from "something is wrong" to a rich, contextual view of everything related to that finding.

The Investigate Link

In GuardDuty and Security Hub, findings carry an Investigate in Detective action. Choosing it opens Detective focused on the entities in that finding, such as the affected instance, the IAM role, or the remote IP. The context comes preloaded, saving setup time.

Landing on an Entity Profile

Pivoting drops you onto an entity profile, a page summarizing one entity's activity: its typical behavior, recent changes, and connections. From the finding's instance, for example, you immediately see its API call volume, network activity, and any anomalies.

Following the Trail

From one entity you pivot to related entities: the IP that contacted the instance, the role whose credentials were used, or other resources the actor touched. Each pivot expands the picture, letting you trace an attacker's path through the environment step by step.

Scoping the Blast Radius

A core goal is determining blast radius: what else did the actor touch? Detective's linked graph shows whether a single instance was affected or whether credentials spread to other resources. This scoping decides how broad your containment must be.

Confirming or Dismissing

Pivoting also helps you decide if a finding is a true positive. If the related activity matches a known, benign pattern, you can dismiss it confidently. If it reveals more suspicious behavior, you escalate. Either way you act on evidence, not guesses.

Time-Aware Context

When you pivot, Detective shows activity around the finding's time window, comparing it to the entity's historical baseline. Seeing that a spike began exactly when the finding fired strengthens the case that the finding marks a real intrusion.

Cross-Account Pivots

With organization integration, a pivot can follow activity across accounts. If a compromised credential was used in a second account, Detective can show it in the same graph. This is vital because attackers often move laterally between accounts.

Speeding Up Response

By eliminating manual log correlation, pivoting compresses investigation from hours to minutes. Faster understanding means faster containment, which directly limits damage. The exam frames Detective as the accelerator between a GuardDuty alert and an effective response.

Pivoting Into Investigation From Security Hub

The Investigate in Detective action is not limited to GuardDuty. Security Hub findings that come from GuardDuty also offer the pivot, so an analyst triaging the aggregated dashboard can jump straight into the behavior graph. This means the central console and the investigation tool connect directly, keeping the detect-aggregate-investigate flow seamless.

Finding Groups

Detective can cluster related findings into finding groups, automatically connecting findings, entities, and the activity that links them into one investigable unit. Instead of pivoting from a single finding, you start from a group that already tells a coordinated story. This speeds investigation by surfacing the whole incident rather than one alert at a time.

Quick Check

Trace the investigation workflow.

Recap

Detective integrates with GuardDuty via the Investigate in Detective action. Pivoting opens an entity profile, lets you follow related entities to scope the blast radius, compares activity to a time-aware baseline, and can follow lateral movement across accounts. This turns a finding into fast, evidence-based investigation and response.

Frequently asked questions

Is the “Pivoting from a GuardDuty Finding” lesson free?

Yes — the full text of “Pivoting from a GuardDuty Finding” is free to read here on the web, and the AWS Security Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the AWS Security Academy course, upgrade to CoddyKit PRO.

What will I learn in “Pivoting from a GuardDuty Finding”?

Trace a single alert into the full story of what happened. You practise AWS Security Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start AWS Security Academy?

No prior experience is required. AWS Security Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “Pivoting from a GuardDuty Finding” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this AWS Security Academy lesson?

Yes. Every AWS Security Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. How Detective Builds a Behavior Graph
  2. Pivoting from a GuardDuty Finding
  3. Analyzing Entities and Time Windows
  4. Spotting Anomalous Activity Patterns
← Back to AWS Security Academy