OrchestrAI Live

AWS · Cloud service

Amazon GuardDuty with OrchestrAI

Catalog exported 2026-09-02

Enable Amazon GuardDuty and review threat findings from chat, with feature toggles for S3 and EKS protection.

OrchestrAI exposes 7 GuardDuty operations: 5 are low-risk (read-only or low-impact), and 2 create or modify resources and run only after you confirm the plan. 2 of them also carry a step-level approval gate.

7operations
5low risk
2create or modify
0destructive
2step-level approval

What teams use it for

Security teams use OrchestrAI to enable GuardDuty in each region, switch on detection features such as S3 or EKS protection, list detectors across the account, and pull the current findings sorted by severity during a review. Listing detectors and reading findings are low risk; updating features waits for your confirmation. There is no operation to archive findings, create suppression rules, or disable a detector, so triage state is managed in the GuardDuty console.

Every GuardDuty operation, with its risk level

Amazon GuardDuty operations available through OrchestrAI
Operation What it does Risk Step-level approval
Configure GuardDuty Feature Configure a GuardDuty detector feature Low risk No
Create GuardDuty Detector Enable Amazon GuardDuty threat detection in a region Low risk No
Create GuardDuty Detector Enable GuardDuty threat detection Low risk No
Get GuardDuty Findings Get GuardDuty threat findings Low risk No
List GuardDuty Detectors List GuardDuty detectors Low risk No
Enable GuardDuty Enable GuardDuty detector Creates resources Yes
Update GuardDuty Features Enable or disable specific GuardDuty detection features Creates resources Yes

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

Prompts that work

  • Enable GuardDuty in eu-west-1
  • List GuardDuty detectors and show me all high severity findings from the last 7 days
  • Turn on S3 protection and EKS audit log monitoring for the detector in us-east-1

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI archive GuardDuty findings?
No, it retrieves findings, but archiving and suppression rules are not covered.
Is enabling a GuardDuty feature reversible in OrchestrAI?
Yes, the update features operation can enable or disable individual features, is medium risk, and waits for confirmation.
Which GuardDuty operations need an extra approval step?
2 operations carry a step-level approval gate on top of plan confirmation: Update GuardDuty Features, Enable GuardDuty. None of them is classed destructive.

Other AWS services

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.