GuardDuty Findings Calculator

GuardDuty Findings Calculator MCP Connector for Claude

A+

Project AWS GuardDuty finding volumes, detection source requirements, and resource overhead.

3 tools Official Updated Oct 1, 2026 Official Vinkius Partner

This MCP server provides deterministic calculations for AWS GuardDuty operations. Use calculate_finding_projections to estimate daily finding volumes and severity distributions based on event throughput. Use calculate_infrastructure_requirements to determine the breakdown of detection sources like CloudTrail and VPC Flow Logs, as well as resource overhead for EKS and ECS Fargate runtime monitoring. Finally, use calculate_governance_recommendations to get administrative guidelines for suppression rules, archive periods, and the number of administrators required for your account scale.

guarddutyaws-securitycloud-governanceinfrastructurethreat-detection

3 tools expose this connector's capabilities to your AI agent.

calculate_finding_projections

Estimates the total number of findings and their severity distribution based on event throughput

calculate_governance_recommendations

Provides administrative guidelines for account management and finding lifecycle

calculate_infrastructure_requirements

Determines the detection source breakdown and specific resource overhead for runtime monitoring

See how to talk to your AI agent using GuardDuty Findings Calculator.

Estimate findings for 5 accounts with 500 events per second and S3/EKS enabled.

The projected daily findings are 43,200, with a distribution of Info, Low, Medium, and High severities based on your enabled sources.

What are the infrastructure requirements for 10 EKS nodes with Runtime monitoring enabled?

The EKS agent will require 1000 MB of total memory (100 MB per node) for runtime monitoring.

How many administrators do I need for 2500 AWS accounts?

You will need 3 administrators to manage 2500 accounts based on the recommended threshold.

You can use the `calculate_finding_projections` tool. Provide the total number of AWS accounts and the estimated average number of raw log events processed per second.

Related Connectors