This control plane turns raw GuardDuty exports into one buyer-readable threat-operations surface: detector coverage, credential abuse, runtime compromise, exfiltration signals, stale findings, and the response packets needed before incidents, audits, or release windows drift.
/, /detector-lane, /finding-risks, /response-posture, /verification, /docs
/api/dashboard/summary, /api/detector-lane, /api/finding-risks, /api/response-posture, /api/verification, /api/sample
npx aws-guardduty-triage fixtures/guardduty-clean.json --format summary renders the same response posture the dashboard exposes.