AWS has released a public preview of the Amazon GuardDuty investigation agent, an AI-powered security tool for triaging suspicious activity across AWS environments. InfoQ reports that the agent evaluates GuardDuty findings, historical activity, and resource topology to produce structured investigation reports.
The tool is designed to reduce threat investigation work from hours to minutes by correlating signals that security teams would otherwise inspect manually across accounts, logs, and affected resources. Reports can include risk ratings, confidence scores, and MITRE ATT&CK classification. The agent is also reachable through the AWS MCP Server, allowing investigations to run from agentic tooling.
The useful framing is that many security teams do not lack alerts; they lack time to investigate them. GuardDuty’s agent may help with that bottleneck, but preview limits matter. InfoQ notes a quota of 10 investigations per account per day, so teams should treat it as a triage accelerator rather than a full replacement for security analysts.