The Amazon GuardDuty Playbook enables the ingestion and processing of findings from Amazon GuardDuty into Dataminr Agentic Threat Intelligence Platform. The Playbook is triggered each time a new Finding is generated by a GuardDuty Detector. The Finding details and context are saved as a Case and the relevant Indicators are parsed and saved as Artifacts. The Amazon GuardDuty Service App is required to be installed and configured prior to activating this Playbook.
Using this App, analysts can manipulate Threat Intel Sets and Trusted IP Sets to their requirements. Threat Intel Sets consist of known malicious IP/CIDR addresses. GuardDuty generates findings based on Threat Intel Sets.
The following actions are supported:
- Create Intel Set – This action creates a new Intel Set (Threat Intel Set or Trusted IP Set.)
- Update Intel Set – Updates the Intel Set specified by the its Intel Set ID.
- Delete Intel Set – This action deletes a Threat Intel Set.
- List Findings – List Amazon GuardDuty findings for a detector ID.
- Get Finding – Describe Amazon GuardDuty findings specified by finding IDs.
- Update Finding Feedback – Mark the specified GuardDuty findings as useful or not useful and optionally add comments.
- Archive Finding – Archive a finding by its Threat Intel Set ID.
This Playbook can be found in the Dataminr App Catalog under the name: Amazon GuardDuty (Playbook)

