#AmazonGuardDuty
Amazon GuardDuty Malware Protection for EC2 now available in AWS GovCloud (US) Regions

Today, Amazon Web Services (AWS) announces the availability of https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection.html in AWS GovCloud (US) Regions, enab...

#AWS #AmazonGuardduty #AwsGovcloudUs
Amazon GuardDuty Malware Protection for EC2 now available in AWS GovCloud (US) Regions
Today, Amazon Web Services (AWS) announces the availability of https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection.html in AWS GovCloud (US) Regions, enabling GuardDuty customers to detect the potential presence of malware by scanning the Amazon Elastic Block Store (Amazon EBS) volumes attached to Amazon Elastic Compute Cloud (Amazon EC2) instances and container workloads running on Amazon EC2. Malware scanning in GuardDuty does not any additional security software to be deployed and is designed to have no performance impact to running workloads. When potential malware is identified, GuardDuty generates actionable security findings with information related to the resource and the detected threat. Malware Protection for EC2 supports two methods of scanning: 1/ GuardDuty-initiated scans, which automatically initiates a malware scan when GuardDuty detects https://docs.aws.amazon.com/guardduty/latest/ug/gd-findings-initiate-malware-protection-scan.html indicative of malware on the instance, and 2/ On-demand scans, where you can initiate scan by providing the Amazon Resource Name (ARN) of the Amazon EC2 instance. Tens of thousands of customers across many industries and geographies use GuardDuty. GuardDuty can identify unusual or unauthorized activity like cryptocurrency mining, access to data stored in Amazon Simple Storage Service (Amazon S3) from unusual locations, or unauthorized access to Amazon Elastic Kubernetes Service (Amazon EKS) clusters. If you’re new to GuardDuty, you can try it at no cost for 30 days on the AWS Free Tier. To learn more and https://aws.amazon.com/guardduty/getting-started/: Refer to the https://docs.aws.amazon.com/guardduty/latest/ug/malware-protection.html to learn about the new capability Get updates on new features and threat detections with the https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_sns.html
aws.amazon.com
May 13, 2025 at 10:05 PM
🆕 Amazon GuardDuty now supports malware scans for Amazon S3 continuous backups in AWS Backup, identifying clean points across your backup timeline for safe recovery. Available everywhere, start using the AWS Backup console, API, or CLI.

#AWS #AmazonGuardduty #AwsBackup
Amazon GuardDuty Malware Protection for AWS Backup supports Amazon S3 continuous backups
Amazon GuardDuty Malware Protection for AWS Backup is now available for Amazon S3 continuous backups. You can now scan your S3 continuous backups for malware and identify clean points in time across your entire backup timeline for safe recovery. You can enable full or incremental malware scans for S3 continuous backups within your backup plan, and run on-demand scans up to any restorable point in time. You can now query the malware scan status at any point in time within your continuous backup using the new GetPITRMalwareScanResults API, allowing you to verify whether a specific recovery time is clean before initiating a restore. Support for S3 continuous backups is available in all AWS Regions where Amazon GuardDuty Malware Protection for AWS Backup is supported. You can get started using the AWS Backup console, API, or CLI. To learn more, visit the AWS Backup documentation and Amazon GuardDuty Malware Protection documentation.
aws.amazon.com
May 26, 2026 at 11:10 PM
🆕 AWS announces AWS Security Incident Response for general availability

#AWS #AmazonGuardduty #AwsSecurityHub #AwsOrganizations
AWS announces AWS Security Incident Response for general availability
Today, AWS announces the general availability of AWS Security Incident Response, a new service that helps you prepare for, respond to, and recover from security events. This service offers automated monitoring and investigation of security findings to free up your resources from routine tasks, communication and collaboration features to streamline response coordination, and direct 24/7 access to the AWS Customer Incident Response Team (CIRT). Security Incident Response integrates with existing detection services, such as Amazon GuardDuty, and third-party tools through AWS Security Hub to rapidly review security alerts, escalate high-priority findings, and, with your permission, implement containment actions. It reduces the number of alerts your team needs to analyze, saving time and allowing your security personnel to focus on strategic initiatives. The service centralizes all incident-related communications, documentation, and actions, making coordinated incident response across internal and external stakeholders possible and reducing the time to coordinate from hours to minutes. You can preconfigure incident response team members, set up automatic notifications, manage case permissions, and use communication tools like video conferencing and in-console messaging during security events. By accessing the service through a single, centralized dashboard in the AWS Management Console, you can monitor active cases, review resolved security incident cases, and track key metrics, such as the number of triaged events and mean time to resolution, in real time. If you require specialized expertise, you can connect 24/7 to the AWS CIRT in only one step. For more information about AWS Regions where Security Incident Response is available, refer to the following service documentation. To get started, visit the Security Incident Response console, and explore the overview page to learn more. For configuration details, refer to the Security Incident Response User Guide.
aws.amazon.com
December 2, 2024 at 4:54 AM
Enhancing threat detection with Amazon GuardDuty new custom entity lists

Today, AWS announced the general availability of Amazon GuardDuty https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_upload-lists.html. This new feature enhances threat detection capabilities...

#AWS #AmazonGuardduty
Enhancing threat detection with Amazon GuardDuty new custom entity lists
Today, AWS announced the general availability of Amazon GuardDuty https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_upload-lists.html. This new feature enhances threat detection capabilities in GuardDuty by extending support to incorporate your own domain-based threat intelligence into the service beyond originally supported custom IP list. You can now detect threats in GuardDuty using malicious domains or IP addresses defined in your custom threat list. As part of this update, GuardDuty introduces a new finding type, https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-ec2.html#impact-ec2-maliciousdomainrequest-custom, which is triggered when activity related to a domain in your custom threat list is detected. Additionally, you can use entity lists to suppress alerts from trusted sources, giving you greater control over your threat detection strategy. Entity lists offer enhanced flexibility compared to the previous IP address lists. These new lists can include IP addresses, domains, or both, allowing for more comprehensive threat intelligence integration. Unlike the legacy IP list format, entity lists provides simplified permission management and avoids impacting IAM policy size limits across multiple AWS Regions, making it easier to implement and manage custom threat detection across your AWS environment. GuardDuty custom entity list is available in all https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_regions.html#gd-regional-feature-availability where GuardDuty is offered, excluding China Regions and GovCloud (US) Regions. 
aws.amazon.com
September 5, 2025 at 7:05 PM
🆕 AWS GuardDuty now supports Amazon EKS, enhancing threat detection and correlating security signals to spot multi-stage attacks, cutting first-level analysis time and minimizing business impact. Automatically enabled at no extra cost; enable GuardDuty EKS Protection for ful…

#AWS #AmazonGuardduty
Amazon GuardDuty Extended Threat Detection now supports Amazon EKS
Today, AWS announces further enhancements to Amazon GuardDuty Extended Threat Detection. This capability now includes coverage for multi-stage attacks targeting Amazon Elastic Kubernetes Service (EKS) clusters in your AWS environment. GuardDuty correlates multiple security signals across Amazon EKS audit logs, runtime behavior of processes, malware execution, and AWS API activity to detect sophisticated attack patterns that might otherwise go unnoticed.  These new attack sequence findings cover multiple resources and data sources over an extensive time period, allowing you to spend less time on first-level analysis and more time responding to critical severity threats, thereby minimizing business impact.  GuardDuty Extended Threat Detection uses artificial intelligence and machine learning algorithms trained at AWS scale to automatically correlate security signals to detect critical threats. For example, it can identify an anomalous deployment of a privileged container followed by persistence attempts, crypto mining, and reverse shell creation, representing these related events as a single, critical-severity finding. You can then take action based on a new attack sequence finding type of critical severity. Each finding includes an incident summary, detailed events timeline, mapping to MITRE ATT&CK® tactics and techniques, and remediation recommendations. This capability is automatically enabled for all GuardDuty customers at no additional cost in all Regions where GuardDuty is available. To detect attack sequences involving Amazon EKS clusters, you must enable GuardDuty EKS Protection, and GuardDuty recommends to also enable GuardDuty Runtime Monitoring for EKS for a more comprehensive security coverage. Take action on findings directly from the GuardDuty console or via integrations with AWS Security Hub and Amazon EventBridge. To get started, visit the Amazon GuardDuty product page or try GuardDuty free for 30 days on the AWS Free Tier.
aws.amazon.com
June 17, 2025 at 5:41 PM
Amazon GuardDuty Malware Protection for S3 announces price reduction

https://docs.aws.amazon.com/guardduty/latest/ug/gdu-malware-protection-s3.html provides a fully-managed offering to scan new object uploads to S3 bucket for malware. Starting February 1, 2025, we are lo...

#AWS #AmazonGuardduty
Amazon GuardDuty Malware Protection for S3 announces price reduction
https://docs.aws.amazon.com/guardduty/latest/ug/gdu-malware-protection-s3.html provides a fully-managed offering to scan new object uploads to S3 bucket for malware. Starting February 1, 2025, we are lowering the price for the data scanned dimension by 85%. Over the past few months we have made improvements to our scanning infrastructure and data processing efficiencies, enabling us to reduce the price as part of our commitment to pass savings back to customers. GuardDuty Malware Protection for S3 is priced based on two dimensions: the number of objects evaluated and the amount of data scanned. We are lowering the price for the data scanned dimension, for example in US East (N. Virginia) from $0.60 to $0.09 per GB. The price for objects evaluated remains unchanged. With this price reduction, you will be more capable of building secure and cost-effective data pipelines on Amazon S3 for applications with untrusted uploads across the enterprise. The price reduction applies automatically to all AWS Regions where GuardDuty Malware Protection for S3 is available, requiring no action from customers. For additional information visit Amazon GuardDuty https://aws.amazon.com/guardduty/pricing/ page. To receive programmatic updates on new GuardDuty features and threat detections, subscribe to the https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_sns.html.  
aws.amazon.com
February 6, 2025 at 7:05 PM
Amazon GuardDuty Malware Protection for AWS Backup supports Amazon S3 continuous backups

Amazon GuardDuty Malware Protection for AWS Backup is now available for Amazon S3 continuous backups. You can now scan your S3 continuous backups for malware and identify cl...

#AWS #AmazonGuardduty #AwsBackup
Amazon GuardDuty Malware Protection for AWS Backup supports Amazon S3 continuous backups
Amazon GuardDuty Malware Protection for AWS Backup is now available for Amazon S3 continuous backups. You can now scan your S3 continuous backups for malware and identify clean points in time across your entire backup timeline for safe recovery. You can enable full or incremental malware scans for S3 continuous backups within your backup plan, and run on-demand scans up to any restorable point in time. You can now query the malware scan status at any point in time within your continuous backup using the new GetPITRMalwareScanResults API, allowing you to verify whether a specific recovery time is clean before initiating a restore. Support for S3 continuous backups is available in all AWS Regions where Amazon GuardDuty Malware Protection for AWS Backup is supported. You can get started using the https://console.aws.amazon.com/backup/home, API, or CLI. To learn more, visit the https://docs.aws.amazon.com/aws-backup/latest/devguide/malware-protection.html and https://docs.aws.amazon.com/guardduty/latest/ug/what-is-guardduty.html.
aws.amazon.com
May 26, 2026 at 11:05 PM
🆕 Amazon GuardDuty now has Custom Detection Rules with 35 prebuilt threat detections for CloudTrail events, extending tailored coverage. Available globally, it links 26 findings to 10 MITRE ATT&CK tactics without needing log management.

#AWS #AmazonGuardduty #AwsGovcloudUs
Amazon GuardDuty adds optional threat detection rules
Amazon GuardDuty now offers Custom Detection Rules, a library of 35 prebuilt, opt-in rules for CloudTrail management events that let you extend threat detection coverage to match your environment. Custom Detection Rules produces 26 unique finding types mapped to 10 MITRE ATT&CK® tactics, without the heavy lifting of log ingestion, normalization, or storage. Some threat techniques, such as sharing an AMI externally, disabling flow logs, or signing in without MFA, could be meaningful indicators of compromise in some accounts but routine in others. Custom Detection Rules lets you enable these detections only where the activity is unexpected — expanding your TTP coverage tailored to your environment. To get started, browse Custom Detection Rules via the GuardDuty console or API, and enable rules in dry-run mode to evaluate detection efficacy before going live. Custom Detection Rules is available in all AWS commercial Regions and the AWS GovCloud (US) Regions. To learn more, see Amazon GuardDuty Custom Detection Rules. To receive programmatic updates on new Amazon GuardDuty features and threat detections, subscribe to the Amazon GuardDuty SNS topic.
aws.amazon.com
September 8, 2026 at 4:10 PM
Amazon GuardDuty adds optional threat detection rules

Amazon GuardDuty now offers Custom Detection Rules, a library of 35 prebuilt, opt-in rules for CloudTrail management events that let you extend threat detection coverage to match your environment. Custom ...

#AWS #AmazonGuardduty #AwsGovcloudUs
Amazon GuardDuty adds optional threat detection rules
Amazon GuardDuty now offers Custom Detection Rules, a library of 35 prebuilt, opt-in rules for CloudTrail management events that let you extend threat detection coverage to match your environment. Custom Detection Rules produces 26 unique finding types mapped to 10 MITRE ATT&CK® tactics, without the heavy lifting of log ingestion, normalization, or storage. Some threat techniques, such as sharing an AMI externally, disabling flow logs, or signing in without MFA, could be meaningful indicators of compromise in some accounts but routine in others. Custom Detection Rules lets you enable these detections only where the activity is unexpected — expanding your TTP coverage tailored to your environment. To get started, browse Custom Detection Rules via the GuardDuty console or API, and enable rules in dry-run mode to evaluate detection efficacy before going live. Custom Detection Rules is available in all AWS commercial Regions and the AWS GovCloud (US) Regions. To learn more, see https://docs.aws.amazon.com/guardduty/latest/ug/custom-detection-rules.html. To receive programmatic updates on new Amazon GuardDuty features and threat detections, subscribe to the https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_sns.html.
aws.amazon.com
September 8, 2026 at 4:05 PM
#うひーメモ
2023-11-29 00:08:14
[アップデート]Amazon GuardDutyがEC2のランタイム保護(プレビュー)をサポートしマルウェアの検出やプロセスツリーの確認ができるようになりました
#技術系ブログ等
#アップデート
#amazonguarddut
#amazonguardduty
[アップデート]Amazon GuardDutyがEC2のランタイム保護(プレビュー)をサポートしマルウェアの検出やプロセスツリーの確認ができるようになりました
こんにちは臼田ですみなさんGuardDuty使ってますか挨拶今回はついに待望のECのRuntimeMonitoringがプレビューとして登場したので実際に試してみましたAmazonGuardDut
dev.classmethod.jp
November 28, 2023 at 3:08 PM
#うひーメモ
2023-11-18 19:02:33
Amazon GuardDutyとCloudTrail Insightsの違い
#Program
#amazonguardduty
#amazonwebservicesaws
#cloudtrailinsights
Amazon GuardDutyとCloudTrail Insightsの違い
AmazonGuardDutyとCloudTrailInsightsの違いAmazonWebServicesAWSは高度なセキュリティ機能を提供しクラウド上の資産を保護しますその
qiita.com
November 18, 2023 at 10:02 AM
Amazon GuardDuty AI-powered investigations accelerate threat response (Preview)

AWS announces the preview of AI-powered investigations in Amazon GuardDuty, a new capability that automatically analyzes GuardDuty findings and accounts to help you quickly distinguish true thr...

#AWS #AmazonGuardduty
Amazon GuardDuty AI-powered investigations accelerate threat response (Preview)
AWS announces the preview of AI-powered investigations in Amazon GuardDuty, a new capability that automatically analyzes GuardDuty findings and accounts to help you quickly distinguish true threats from benign findings. This feature addresses the time-intensive manual investigation process that contributes to alert fatigue and slows incident response for security operations centers and cloud security analysts.  AI-powered investigations examine finding context, related activity from the last 90 days, affected resources, and threat indicators using knowledge graphs and threat intelligence, in minutes. Each investigation provides a disposition assessment with confidence scoring, MITRE ATT&CK® technique classification, supporting evidence, and actionable recommendations for suppression, containment, or remediation. This automation enables security teams to focus on genuine threats across individual AWS accounts or entire AWS Organizations and accelerate mean time to resolution. This feature is available in preview in 10 AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Ireland), Europe (London), Europe (Frankfurt), Europe (Paris), Europe (Stockholm), Asia Pacific (Tokyo). To get started, access AI-powered investigations through the Amazon GuardDuty console, CLI, API, or AWS' MCP Server.  To learn more, visit the https://docs.aws.amazon.com/guardduty/.
aws.amazon.com
June 24, 2026 at 4:05 PM
Amazon GuardDuty adds sensitive file modification threat detections

Amazon GuardDuty Runtime Monitoring now includes three new threat detections that alert security teams when sensitive files are modified on Amazon EC2 instances and contain...

#AWS #AmazonEc2 #AmazonEks #AmazonGuardduty #AmazonEcs
Amazon GuardDuty adds sensitive file modification threat detections
Amazon GuardDuty Runtime Monitoring now includes three new threat detections that alert security teams when sensitive files are modified on Amazon EC2 instances and container workloads running on Amazon EKS or Amazon ECS. These findings help identify post-compromise attacker activities by monitoring critical system files, including configuration files, authentication settings, and system logs. This capability is designed for security teams, DevSecOps professionals, and cloud security architects who need comprehensive threat visibility across their AWS compute environments. The new detections—Persistence:Runtime/SensitiveFileModified, PrivilegeEscalation:Runtime/SensitiveFileModified, and DefenseEvasion:Runtime/SensitiveFileModified—help identify attempts to maintain persistent access, escalate privileges, and evade detection after an initial system compromise. By monitoring five specific file operations (open-for-write, rename, symlink, link, and unlink) directly, these findings can detect threats even when attackers use obfuscated techniques that bypass traditional command-line monitoring. The correlation-based analysis distinguishes malicious behavior from legitimate administrative operations, helping reduce false positives while providing actionable intelligence with MITRE ATT&CK® tactics mapping and remediation recommendations. These sensitive file modification findings are now available to all customers who have enabled GuardDuty Runtime Monitoring for their Amazon EC2, Amazon EKS, or Amazon ECS workloads. A 30-day free trial is available for new users. To learn more, see https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_findings.html. To receive programmatic updates on new Amazon GuardDuty features and threat detections, please subscribe to the https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_sns.html.
aws.amazon.com
July 1, 2026 at 9:05 PM
Amazon GuardDuty Extended Threat Detection now supports Amazon EC2 and Amazon ECS

AWS announces further enhancements to Amazon GuardDuty Extended Threat Detection with new capabilities to detect multistage attacks targeting Amazon Elastic Compute Cloud (Amazon EC2) insta...

#AWS #AmazonGuardduty
Amazon GuardDuty Extended Threat Detection now supports Amazon EC2 and Amazon ECS
AWS announces further enhancements to Amazon GuardDuty Extended Threat Detection with new capabilities to detect multistage attacks targeting Amazon Elastic Compute Cloud (Amazon EC2) instances and Amazon Elastic Container Service (Amazon ECS) clusters running on AWS Fargate or Amazon EC2. GuardDuty Extended Threat Detection uses artificial intelligence and machine learning algorithms trained at AWS scale to automatically correlate security signals and detect critical threats. It analyzes multiple security signals across network activity, process runtime behavior, malware execution, and AWS API activity over extended periods to detect sophisticated attack patterns that might otherwise go unnoticed. With this launch, GuardDuty introduces two new critical-severity findings: AttackSequence:EC2/CompromisedInstanceGroup and AttackSequence:ECS/CompromisedCluster. These findings provide attack sequence information, allowing you to spend less time on initial analysis and more time responding to critical threats, minimizing business impact. For example, GuardDuty can identify suspicious processes followed by persistence attempts, crypto-mining activities, and reverse shell creation, representing these related events as a single, critical-severity finding. Each finding includes a detailed summary, events timeline, mapping to MITRE ATT&CK® tactics and techniques, and remediation recommendations. While GuardDuty Extended Threat Detection is automatically enabled for GuardDuty customers at no additional cost, its detection comprehensiveness depends on your enabled GuardDuty protection plans. To improve attack sequence coverage and threat analysis of Amazon EC2 instances, enable Runtime Monitoring for EC2. To enable detection of compromised ECS clusters, enable Runtime Monitoring for Fargate or EC2 depending on your infrastructure type. To get started, enable GuardDuty protection plans via the Console or API. New GuardDuty customers can start with a https://portal.aws.amazon.com/billing/signup?pg=guarddutyprice&cta=herobtn&redirect_url=https%3A%2F%2Faws.amazon.com%2Fregistration-confirmation, and existing customers who haven't used Runtime Monitoring can also try it free for 30 days. For additional information, visit the blog post and https://aws.amazon.com/guardduty/.
aws.amazon.com
December 2, 2025 at 6:05 PM
Amazon GuardDuty Malware Protection for AWS Backup is now available

Amazon GuardDuty Malware Protection for AWS Backup is now available, extending malware detection to your Amazon EC2, Amazon EBS, and Amazon S3 backups. This capability automates...

#AWS #AwsGovcloudUs #AmazonGuardduty #AwsBackup
Amazon GuardDuty Malware Protection for AWS Backup is now available
Amazon GuardDuty Malware Protection for AWS Backup is now available, extending malware detection to your Amazon EC2, Amazon EBS, and Amazon S3 backups. This capability automates malware detection in your backups without requiring additional security software or agents. You can identify your last known clean backup to minimize business disruption during recovery. Malware protection scans new backups automatically, runs on-demand scans of existing backups, and verifies backups are clean before restoration. You can enable this capability even if https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_data-sources.html aren't enabled in your account. You can also use incremental scanning which analyzes only changed data between backups, reducing costs compared to rescanning full backups. Amazon GuardDuty Malware Protection for AWS Backup is available in the list of https://docs.aws.amazon.com/aws-backup/latest/devguide/backup-feature-availability.html. You can get started using the https://console.aws.amazon.com/backup/home, API, or CLI. To learn more, read the https://aws.amazon.com/blogs/storage/scan-backups-for-malware-with-amazon-guardduty-malware-protection-for-aws-backup or visit the https://docs.aws.amazon.com/aws-backup/latest/devguide/whatisbackup.html and https://docs.aws.amazon.com/guardduty/latest/ug/what-is-guardduty.html.
aws.amazon.com
November 19, 2025 at 10:05 PM
Amazon GuardDuty Extended Threat Detection now supports Amazon EKS

Today, AWS announces further enhancements to Amazon GuardDuty https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-extended-threat-detection.html. This capability now includes coverage for multi-stag...

#AWS #AmazonGuardduty
Amazon GuardDuty Extended Threat Detection now supports Amazon EKS
Today, AWS announces further enhancements to Amazon GuardDuty https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-extended-threat-detection.html. This capability now includes coverage for multi-stage attacks targeting Amazon Elastic Kubernetes Service (EKS) clusters in your AWS environment. GuardDuty correlates multiple security signals across Amazon EKS audit logs, runtime behavior of processes, malware execution, and AWS API activity to detect sophisticated attack patterns that might otherwise go unnoticed.  These new attack sequence findings cover multiple resources and data sources over an extensive time period, allowing you to spend less time on first-level analysis and more time responding to critical severity threats, thereby minimizing business impact.  GuardDuty Extended Threat Detection uses artificial intelligence and machine learning algorithms trained at AWS scale to automatically correlate security signals to detect critical threats. For example, it can identify an anomalous deployment of a privileged container followed by persistence attempts, crypto mining, and reverse shell creation, representing these related events as a single, critical-severity finding. You can then take action based on a new attack sequence finding type of critical severity. Each finding includes an incident summary, detailed events timeline, mapping to MITRE ATT&CK® tactics and techniques, and remediation recommendations. This capability is automatically enabled for all GuardDuty customers at no additional cost in all Regions where GuardDuty is available. To detect attack sequences involving Amazon EKS clusters, you must enable GuardDuty EKS Protection, and GuardDuty recommends to also enable GuardDuty Runtime Monitoring for EKS for a more comprehensive security coverage. Take action on findings directly from the GuardDuty console or via integrations with AWS Security Hub and Amazon EventBridge. To get started, visit the https://aws.amazon.com/guardduty/ product page or try GuardDuty free for 30 days on the https://aws.amazon.com/guardduty/pricing/.
aws.amazon.com
June 17, 2025 at 6:05 PM
Amazon GuardDuty Extended Threat Detection now available in AWS GovCloud (US) and China Regions

Amazon GuardDuty https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-extended-threat-detection.html is now automatically available in AWS GovCloud (US) an...

#AWS #AwsGovcloudUs #AmazonGuardduty
Amazon GuardDuty Extended Threat Detection now available in AWS GovCloud (US) and China Regions
Amazon GuardDuty https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-extended-threat-detection.html is now automatically available in AWS GovCloud (US) and China Regions. This capability allows you to identify sophisticated, multi-stage attacks targeting your AWS accounts, workloads, and data. You can now use new attack sequence findings that cover multiple resources and data sources over an extensive time period, allowing you to spend less time on first-level analysis and more time responding to critical-severity threats to minimize business impact. GuardDuty Extended Threat Detection uses artificial intelligence and machine learning algorithms trained at AWS scale and automatically correlates security signals from across AWS services to detect critical threats. It identifies attack sequences, such as credential compromise followed by data exfiltration, and represents them as a single, critical-severity finding. The finding includes an incident summary, a detailed events timeline, mapping to MITRE ATT&CK® tactics and techniques, and remediation recommendations. GuardDuty Extended Threat Detection is also available in all AWS commercial Regions where GuardDuty is available. This capability is automatically enabled for all new and existing GuardDuty customers at no additional cost. You do not need to enable all GuardDuty protection plans. However, enabling additional protection plans such as GuardDuty S3 Protection will increase the breadth of security signals, allowing for more comprehensive threat analysis and coverage of attack scenarios. You can take action on findings directly from the GuardDuty console or via its integrations with AWS Security Hub and Amazon EventBridge. To get started, visit the https://aws.amazon.com/guardduty/ product page or try GuardDuty free for 30 days on the https://aws.amazon.com/guardduty/pricing/.  
aws.amazon.com
March 14, 2025 at 6:05 PM
Amazon GuardDuty Malware Protection for S3 now available in AWS GovCloud (US) Regions

Today, Amazon Web Services (AWS) announces the availability of https://docs.aws.amazon.com/guardduty/latest/ug/gdu-malware-protection-s3.html in AWS GovCloud (US) regions...

#AWS #AmazonGuardduty #AwsGovcloudUs
Amazon GuardDuty Malware Protection for S3 now available in AWS GovCloud (US) Regions
Today, Amazon Web Services (AWS) announces the availability of https://docs.aws.amazon.com/guardduty/latest/ug/gdu-malware-protection-s3.html in AWS GovCloud (US) regions. This expansion of GuardDuty Malware Protection allows you to scan newly uploaded objects to Amazon S3 buckets for potential malware, viruses, and other suspicious uploads and take action to isolate them before they are ingested into downstream processes. GuardDuty helps customers protect millions of Amazon S3 buckets and AWS accounts. GuardDuty Malware Protection for Amazon S3 is fully managed by AWS, alleviating the operational complexity and overhead that normally comes with managing a data-scanning pipeline, with compute infrastructure operated on your behalf. This feature also gives application owners more control over the security of their organization’s S3 buckets; they can enable GuardDuty Malware Protection for S3 even if core GuardDuty is not enabled in the account. Application owners are automatically notified of the scan results using Amazon EventBridge to build downstream workflows, such as isolation to a quarantine bucket, or define bucket policies using tags that prevent users or applications from accessing certain objects. GuardDuty Malware Protection for Amazon S3 is available in all https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_regions.html#gd-regional-feature-availability where GuardDuty is available, excluding China Regions.  
aws.amazon.com
March 13, 2025 at 9:05 PM
Amazon GuardDuty is now available in AWS Asia Pacific (Malaysia) Region

https://aws.amazon.com/guardduty/ is now available in the Asia Pacific (Malaysia) Region. You can now use this additional Region to continuously monitor and detect anomalous behavior, security threat...

#AWS #AmazonGuardduty
Amazon GuardDuty is now available in AWS Asia Pacific (Malaysia) Region
https://aws.amazon.com/guardduty/ is now available in the Asia Pacific (Malaysia) Region. You can now use this additional Region to continuously monitor and detect anomalous behavior, security threats, and sophisticated multi-stage attack sequences targeting your AWS accounts to help protect your AWS accounts, workloads, and data. Tens of thousands of customers across many industries and geographies use GuardDuty. GuardDuty can identify unusual or unauthorized activity like cryptocurrency mining, access to data stored in Amazon Simple Storage Service (Amazon S3) from unusual locations, or unauthorized access to Amazon Elastic Kubernetes Service (Amazon EKS) clusters. GuardDuty Malware Protection adds file scanning for workloads using Amazon Elastic Block Store (Amazon EBS) volumes or Amazon S3 to detect the presence of malware. GuardDuty continually evolves its techniques to identify indicators of compromise, such as regularly updating machine learning (ML) models, adding new anomaly detections, and growing integrated threat intelligence to identify and prioritize potential threats to your AWS resources. You can begin your https://aws.amazon.com/guardduty/pricing/ of Amazon GuardDuty with a single click in the AWS Management Console. To receive programmatic updates on new GuardDuty features and threat detections, subscribe to the https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_sns.html.  
aws.amazon.com
January 17, 2025 at 12:05 AM
AWS announces AWS Security Incident Response for general availability

Today, AWS announces the general availability of AWS Security Incident Response, a new service that helps you prepare for, respond to, and recover from security events...

#AWS #AmazonGuardduty #AwsSecurityHub #AwsOrganizations
AWS announces AWS Security Incident Response for general availability
Today, AWS announces the general availability of AWS Security Incident Response, a new service that helps you prepare for, respond to, and recover from security events. This service offers automated monitoring and investigation of security findings to free up your resources from routine tasks, communication and collaboration features to streamline response coordination, and direct 24/7 access to the AWS Customer Incident Response Team (CIRT). Security Incident Response integrates with existing detection services, such as Amazon GuardDuty, and third-party tools through AWS Security Hub to rapidly review security alerts, escalate high-priority findings, and, with your permission, implement containment actions. It reduces the number of alerts your team needs to analyze, saving time and allowing your security personnel to focus on strategic initiatives. The service centralizes all incident-related communications, documentation, and actions, making coordinated incident response across internal and external stakeholders possible and reducing the time to coordinate from hours to minutes. You can preconfigure incident response team members, set up automatic notifications, manage case permissions, and use communication tools like video conferencing and in-console messaging during security events. By accessing the service through a single, centralized dashboard in the AWS Management Console, you can monitor active cases, review resolved security incident cases, and track key metrics, such as the number of triaged events and mean time to resolution, in real time. If you require specialized expertise, you can connect 24/7 to the AWS CIRT in only one step. For more information about AWS Regions where Security Incident Response is available, refer to the following service https://docs.aws.amazon.com/security-ir/latest/userguide/supported-configs.html. To get started, visit the https://us-east-1.console.aws.amazon.com/security-ir, and explore the https://aws.amazon.com/security-incident-response/ to learn more. For configuration details, refer to the Security Incident Response User Guide.
aws.amazon.com
December 2, 2024 at 5:06 AM
Amazon GuardDuty introduces GuardDuty Extended Threat Detection

Today, Amazon Web Services (AWS) announces the general availability of Amazon GuardDuty https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-extended-threat-detection.html. This new capability allows yo...

#AWS #AmazonGuardduty
Amazon GuardDuty introduces GuardDuty Extended Threat Detection
Today, Amazon Web Services (AWS) announces the general availability of Amazon GuardDuty https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-extended-threat-detection.html. This new capability allows you to identify sophisticated, multi-stage attacks targeting your AWS accounts, workloads, and data. You can now use new attack sequence findings that cover multiple resources and data sources over an extensive time period, allowing you to spend less time on first-level analysis and more time responding to critical severity threats to minimize business impact. GuardDuty Extended Threat Detection uses artificial intelligence and machine learning algorithms trained at AWS scale and automatically correlates security signals from across AWS services to detect critical threats. This capability allows for the identification of attack sequences, such as credential compromise followed by data exfiltration, and represents them as a single, critical-severity finding. The finding includes an incident summary, a detailed events timeline, mapping to MITRE ATT&CK® tactics and techniques, and remediation recommendations. GuardDuty Extended Threat Detection is available in all AWS commercial Regions where GuardDuty is available. This new capability is automatically enabled for all new and existing GuardDuty customers at no additional cost. You do not need to enable all GuardDuty protection plans. However, enabling additional protection plans will increase the breadth of security signals, allowing for more comprehensive threat analysis and coverage of attack scenarios. You can take action on findings directly from the GuardDuty console or via its integrations with AWS Security Hub and Amazon EventBridge. To get started, visit the https://aws.amazon.com/guardduty/ product page or try GuardDuty free for 30 days on the https://aws.amazon.com/guardduty/pricing/.  
aws.amazon.com
December 2, 2024 at 5:06 AM
Introducing Amazon GuardDuty Extended Threat Detection: AI/ML attack sequence identification for enhanced cloud security

AWS extends GuardDuty with AI/ML capabilities to detect complex attack sequences across ...

#AWS #AmazonGuardduty #Announcements #Launch #News #Security #Identity #&Compliance
Introducing Amazon GuardDuty Extended Threat Detection: AI/ML attack sequence identification for enhanced cloud security
AWS extends GuardDuty with AI/ML capabilities to detect complex attack sequences across workloads, applications, and data, correlating multiple security signals over time for proactive cloud security.
aws.amazon.com
December 2, 2024 at 4:05 AM