guardduty

Manage Amazon GuardDuty detectors, findings, and IP lists across AWS accounts.

3|Updated Mar 16, 2026
One-click install
npx skills add https://github.com/david-2814/claw-aws --skill guardduty
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: guardduty
Source: https://github.com/david-2814/claw-aws/tree/main/skills/guardduty
Command: npx skills add https://github.com/david-2814/claw-aws --skill guardduty

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Helps security teams configure GuardDuty detectors, review findings, manage trusted IP lists and threat intel sets, and coordinate multi-account deployments via the AWS CLI.

Core Features & Use Cases

  • Enable detectors per region and manage findings across accounts.
  • Create and manage IP sets and threat intel sets to tailor detections.
  • Manage member accounts and multi-account GuardDuty configurations.
  • Suppress, archive, or investigate findings to maintain incident response efficiency.

Quick Start

Install and configure GuardDuty across regions with the AWS CLI to begin monitoring immediately.

Frequently Asked Questions about guardduty

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate Amazon GuardDuty threat detection across multiple AWS accounts?

Automate Amazon GuardDuty threat detection by applying the Skill to enable detectors and review findings across multiple regions and member accounts. It coordinates multi-account configurations via the AWS CLI to manage threat detection centrally.

What is the best way to manage GuardDuty findings and suppress false positives?

The best way to manage GuardDuty findings is to inspect them and apply suppression or archival actions. This maintains incident response efficiency by archiving items as needed after reviewing the threat detection alerts.

How do I configure trusted IP lists and threat intel sets in GuardDuty?

Configure trusted IP lists and threat intel sets in GuardDuty by creating and managing these sets to tailor detections. The Skill handles IP and threat list management to customize threat detection behavior across your accounts.

Can I manage GuardDuty member accounts across multiple regions using the AWS CLI?

Yes, you can manage GuardDuty member accounts across multiple regions using the AWS CLI. The Skill applies across regions and member accounts to coordinate multi-account deployments and manage detector lifecycles centrally.

When do I need to enable GuardDuty detectors per region?

You need to enable GuardDuty detectors per region when setting up threat detection monitoring. The Skill manages the detector lifecycle, allowing you to enable detectors region by region and immediately begin monitoring findings.

Does this GuardDuty automation tool include safety prompts for incident response?

Yes, the GuardDuty automation tool includes safety prompts for incident response. It satisfies requirements for detector lifecycle management and finding inspection while providing safety prompts during suppression or archival actions.