AWS Compare High-frequency comparison

Inspector vs GuardDuty vs Macie vs Detective vs Security Hub

Inspector vs GuardDuty vs Macie vs Detective vs Security Hub

compareInspector vs GuardDuty vs Macie vs Detective vs Security HubAWS
Last organized

Vulnerability scanning, threat detection, sensitive-data discovery, investigation, and centralized aggregation cover different stages of the security workflow.

One-line conclusion

  • Amazon Inspector scans EC2, ECR images, and Lambda for software vulnerabilities.
  • Amazon GuardDuty continuously detects suspicious account, network, and workload behavior.
  • Amazon Macie discovers sensitive data such as PII in S3.
  • Amazon Detective investigates root causes, relationships, and attack paths.
  • AWS Security Hub aggregates and standardizes findings from multiple security services.

Core differences

ServicePrimary scopeTypical keywordsMain output
InspectorEC2, ECR, LambdaCVE, packages, vulnerability scanVulnerability findings and remediation
GuardDutyAccount, network, workload behaviorMalicious IP, anomalous API, threat intelligenceThreat findings
MacieAmazon S3 dataPII, sensitive data, discoverySensitive-data findings
DetectiveSecurity-event contextRoot cause, timeline, relationship graphInvestigation context and impact
Security HubFindings from multiple sourcesAggregation, normalization, complianceUnified security view and insights

Combined workflow

Inspector, GuardDuty, and Macie detect issues → Security Hub aggregates and prioritizes → Detective investigates → EventBridge triggers automated response.

Common traps

  • Inspector is not a behavioral threat-detection service.
  • GuardDuty does not patch vulnerabilities.
  • Macie focuses on sensitive data in S3.
  • Detective investigates; it is not the central findings hub.