Guard Duty is an automatic threat detection service which reviews data from supported services and attempts to identify any events outside of the ‘norm’ for a given AWS account or Accounts.
Guard duty is a continuous inspector.
It does this using Artificial Intelligence and Machine Learning, however, user can do certain functions such as whitelisting, etc
It learns unusual or suspicious activities by itself.
Guard duty can be a part of an autonomous threat management pipeline.
Integrates with SNS, Lambda for remidiation and further processing.
Can Manage multiple AWS Accounts from a single Location.