How it works
Runtime Monitoring uses a lightweight security agent to observe the runtime behavior of your Amazon EC2, Amazon EKS, and Amazon ECS on Fargate workloads and detect threats. It works end to end as follows:
-
The agent is deployed to your resources. GuardDuty can deploy and update the agent for you (automated agent configuration), or you can deploy and manage it yourself (manual agent configuration). The steps depend on the resource type.
-
The agent collects runtime events. On each monitored resource, the agent observes operating system-level activity, such as process execution, file access, and network connections.
-
The agent sends events to GuardDuty. The agent delivers the events to the GuardDuty backend. The data remains within the AWS network, and GuardDuty doesn't charge for the events transmitted from your compute resources to GuardDuty. For details, see How the security agent connects to GuardDuty.
-
GuardDuty analyzes the events and generates findings. When it detects suspicious behavior, such as privilege escalation or communication with a known malicious host, GuardDuty generates a finding. To see the up-to-date list of findings that GuardDuty generates, see GuardDuty Runtime Monitoring finding types.
The agent runs within defined CPU and memory limits, so its resource consumption stays predictable and doesn't degrade the performance or availability of the workloads running on the same host. For these limits, see Prerequisites to enabling Runtime Monitoring.