Skip to main content

Netskope Help

Validate the AWS GuardDuty Plugin

Validation from netskope CE platform

  1. Open Threat Exchange Module.

  2. Go to Threat IOCs.

  1. You’ll be able to see the page similar to what is shown below.

  1. Now create a filter for GuardDuty.

  2. Select “Source”.

  1. Select “Is equal”.

  1. Enter “GuardDuty” as string in the text box.

  1. Click on the “Apply Filter” button.

  1. Now the only IOCs shown will be those sourced from GuardDuty.

  1. Click the down carrot (“v”) button to explore matching IOC.

  1. Now you’ll see all the mapped fields that apply to each IOC, including tags that match to categories from GuardDuty, including the original source (in this example, from BitDefender and from Private).

The comments field will include other data from GuardDuty associated with each filehash. Any or all of these can be used to create a filter for a business rule. For example, you could match on “Comments” contains “any in” “eicar” and NOT share those IOC use for testing.


Validation from GuardDuty Console

  1. Validate No of Findings

    • Open the GuardDuty Console. You’ll see a screen similar to that shown below.

  • See the number of findings (“Showing 113 of 113”).

  • These findings should be able to match with the number of findings CE is retrieving.

  • Note: It may vary depending on initial sync. For that you can use filter.