AWS Config is a fully-managed service that provides you with an AWS resource inventory,
configuration history, and configuration change notifications to enable security and regulatory
compliance.
CloudTrail tracks API activity. This means it is used to monitor who does what on Amazon. It does
not provide a resource inventory or configuration history.
Amazon GuardDuty offers threat detection and continuous security monitoring for malicious or
unauthorized behavior to help you protect your AWS accounts and workloads.
AWS Artifact is used for obtaining on-demand security and compliance reports and select online
agreements. This service provides access to AWS security and compliance reports such as SOC and
PCI. You don’t use Artifact to track your own resource inventory and configuration history.