Amazon GuardDuty
Amazon GuardDuty is a managed threat detection service that continuously analyzes CloudTrail, VPC Flow Logs, DNS logs, and more with machine learning and threat intelligence to automatically detect threats to accounts and workloads. For example, it detects suspicious API calls, access from unexpected regions, and use of possibly compromised credentials, and notifies you as findings with severity.
It only detects threats and alerts you, and is not a feature that defines and controls access in advance, so it is incorrect (defining access permissions is IAM's role).