Activate Amazon GuardDuty

Enable GuardDuty button.
Prepare resources with AWS CloudFormation
Create Stack button.Create Stack page,Upload a template file and using the Choose file button to choose the downloaded template.

Specify Stack Details page, under Provide a stack name and Parameters, we will enter some required information as follows:GuardDuty-Lab98-WorkshopEmailAddress: Personal Email account to receive notifications.
Configure stack options page, under Capabilities, proceed to accept (Acknowledge) to allow the Template to create IAM roles, and select the Next button.

Review and create page, select the Submit button to create the resources.

The above process will take 5-10 minutes until we see the status of the Stack as CREATE_COMPLETE. We will receive an email notification with the same subject as AWS Notification - Subscription Confirmation.


Initial results will start showing 10 minutes after the CloudFormation Stack setup is completed.
CloudFormation Template will prepare us with the following resources:
Compromised Instance.Malicious Instance.