Amazon GuardDuty vs. AWS CloudTrail

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Amazon GuardDuty
Score 9.9 out of 10
N/A
Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior to protect your AWS accounts and workloads.N/A
AWS CloudTrail
Score 8.6 out of 10
N/A
AWS CloudTrail is a service that enables governance, compliance, operational auditing, and risk auditing of an AWS account. With CloudTrail, users can log, continuously monitor, and retain account activity related to actions across AWS infrastructure. CloudTrail provides event history of AWS account activity, including actions taken through the AWS Management Console, AWS SDKs, command line tools, and other AWS services. This event history simplifies security analysis, resource change tracking,…N/A
Pricing
Amazon GuardDutyAWS CloudTrail
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Amazon GuardDutyAWS CloudTrail
Free Trial
NoYes
Free/Freemium Version
NoYes
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional DetailsYou can view, filter, and download the most recent 90 days of your account activity for all management events in supported AWS services free of charge. You can set up a trail that delivers a single copy of management events in each region free of charge. Once a CloudTrail trail is set up, Amazon S3 charges apply based on your usage. You will be charged for any data events or additional copies of management events recorded in that region. In addition, you can choose CloudTrail Insights by enabling Insights events in your trails. CloudTrail Insights analyzes write management events, and you are charged based on the number of events that are analyzed in that region.
More Pricing Information
Community Pulse
Amazon GuardDutyAWS CloudTrail
User Ratings
Amazon GuardDutyAWS CloudTrail
Likelihood to Recommend
10.0
(0 ratings)
8.0
(0 ratings)
User Testimonials
Amazon GuardDutyAWS CloudTrail
Likelihood to Recommend
In a multi-account/multi-tenant environment, GuardDuty often alerts us to possible malicious traffic before it becomes an issue. The ability to automatically enable GuardDuty creates baseline security which is crucial when an account is first created. It also helps greatly in environments where other users are able to create resources as often GuardDuty alerts us to insecure resources we did not know about. It can however sometimes be a little overzealous with its assessments alerting on benign activity which then requires suppression rules.
Read full review
Most probably it would be suitable for Finance industries, where security is at the head of the table. However, in our case for E-commerce, it's also quite suitable, since we have quite a significant amount of data and usage of AWS services. Especially with usage of AWS services, AWS CloudTrail comes into play as a heavy plus. For instance, troubleshooting any issues in AWS services is really nice. Therefore, it would be less appropriate with a small amount of AWS service usage and some basic web hosting.
Read full review
Pros
  • Monitors outgoing connections from AWS resources to known malicious hosts.
  • Monitors incoming connection to AWS resources from known malicious hosts.
  • Integrates with other centralized logging solutions.
Read full review
  • Logs details
  • Easy implementation
  • Great support
Read full review
Cons
  • Does not have the ability to add any custom monitors.
Read full review
  • Delay
  • User interface, must send logs elsewhere to view them
Read full review
Alternatives Considered
No answers on this topic
For this specific functionality, I am not aware of any other product that can do what [AWS] Cloudtrail does. We did not evaluate any other products.
Read full review
Return on Investment
  • GuardDuty has helped us prevent possible security incidents multiple times which could have caused substantial damage.
Read full review
  • Saved us from purchasing and managing 3rd party solutions
  • Satisfies Security/Governance requirements
  • No upkeep/maintenance
Read full review
ScreenShots

AWS CloudTrail Screenshots

Screenshot of CloudTrail Insights: Identify and respond to unusual operational activity
•Unexpected spikes in resource provisioning
•Bursts of IAM management actions
•Gaps in periodic maintenance activity
•Automatic analysis of API calls and usage patterns
•Alerts when unusual activity is detected