< ciso
brief />
Tag Banner

All news with #aws guardduty tag

34 articles

AWS Security Hub Adds GuardDuty Runtime Monitoring

🔔 AWS has integrated Amazon GuardDuty Runtime Monitoring into the AWS Security Hub Threat Analytics plan. This runtime capability inspects OS, network, and file activity to detect threats like container escapes, privilege escalation, and cryptomining across Amazon EC2, Amazon EKS, and Amazon ECS on AWS Fargate. Billing for Runtime Monitoring is now consolidated under Security Hub as a single usage type, eliminating separate GuardDuty Runtime Monitoring charges for accounts and regions with Security Hub enabled. Detection behavior, finding types, and GuardDuty agents remain unchanged, and no reconfiguration is required; free-trial terms for Threat Analytics and Security Hub Essentials remain separate.
read more →

GuardDuty organization enablement policies now available

🔒 Amazon GuardDuty now supports AWS Organizations declarative policies to centrally enable threat detection across all accounts and Regions. Using a centrally managed organization policy, you can apply a consistent GuardDuty enablement configuration that automatically extends to existing accounts and to new accounts as they join. The policy allows a default baseline across all Regions where GuardDuty is available, with optional per-Region overrides, and prevents overrides through the GuardDuty console or API. This feature is available in all AWS commercial Regions and AWS GovCloud (US) Regions.
read more →

Amazon GuardDuty adds opt‑in detection rules

🛡️ Amazon GuardDuty now provides Custom Detection Rules, a library of 35 prebuilt, opt‑in rules for CloudTrail management events that produce 26 unique finding types mapped to 10 MITRE ATT&CK® tactics. These rules extend threat coverage without requiring additional log ingestion, normalization, or storage. Administrators can enable rules selectively where activity is unexpected and test in dry‑run mode via the GuardDuty console or API. The feature is available in all AWS commercial Regions and AWS GovCloud (US).
read more →

Agentic Security: Detection and Response at Machine Speed

🔒 AWS outlines how the rise of autonomous AI agents demands a shift in security posture from event-driven to continuous, machine-speed detection and response. The post summarizes a collaborative chapter with the SANS Institute in the 2026 Cloud Security Exchange eBook, emphasizing that existing security principles—identity governance, least privilege, and defense in depth—must be adapted for probabilistic, autonomous workloads. AWS highlights built-in platform services like Amazon GuardDuty, Amazon Inspector, and AWS Security Hub as components to extend trusted controls for agentic AI adoption.
read more →

AWS adds AI toolkit and expanded Automated Security Response

🔒 Today AWS announced four new capabilities for Automated Security Response on AWS (ASR). Customers can use an AI-driven Toolkit to generate custom remediations with built-in safety guardrails. ASR now supports automatic remediation of findings from Amazon Inspector, Amazon GuardDuty, and Amazon Macie, and offers an enhanced web console to centrally configure remediations. New multi-channel notification adapters for Email, Slack, Jira, and ServiceNow include severity filtering and deadline enforcement.
read more →

Detecting Multi‑Stage Attacks on AWS with Correlation

🔍 This post explains how correlating signals across AWS services and your business context reveals multi-stage attacks that single alerts miss. It outlines five attack phases and the three primary log sources—CloudTrail, VPC Flow Logs, and Route 53 Resolver logs—used to surface each phase. The guide emphasizes enabling and tuning AWS detection services such as Amazon GuardDuty, then layering custom queries that encode your environment-specific knowledge. It includes CloudWatch Logs Insights queries and operational guidance for thresholds, multi-account setups, and automating detection pipelines.
read more →

Amazon GuardDuty Investigation Agent Public Preview

🔍 The Amazon GuardDuty investigation agent, now in public preview, delivers on-demand, AI-assisted assessments of GuardDuty findings across AWS accounts and Regions. It returns structured outputs including risk level, confidence scores, MITRE ATT&CK mapping, resource context, and prioritized remediation actions. Accessible via AWS Console, CLI, APIs, SDKs, and the AWS MCP server, it supports natural-language triggers and integrates into existing security pipelines to reduce investigation time from hours to minutes.
read more →

Amazon GuardDuty adds AI Protection for AWS AI

🛡️ Amazon GuardDuty introduces AI Protection to extend threat detection to AWS AI services such as Amazon Bedrock and Amazon SageMaker. The feature continuously monitors AI workloads for threats like anomalous invocations, cost harvesting attacks, and prompt injection, using CloudTrail management and data events to surface suspicious activity. Findings integrate with AWS Security Hub for centralized triage and can be enabled per account or centrally via AWS Organizations, with a 30-day trial available for GuardDuty customers.
read more →

GuardDuty Runtime adds sensitive file modification detection

🛡️ Amazon GuardDuty Runtime Monitoring now includes three new threat detections to alert teams when sensitive files are modified on Amazon EC2 instances and container workloads on Amazon EKS and Amazon ECS. These findings monitor critical system files such as configuration files, authentication settings, and system logs to surface post-compromise activity. The detections map to MITRE ATT&CK® tactics and provide remediation guidance while using correlation analysis to reduce false positives. The capability is available to customers with GuardDuty Runtime Monitoring enabled, with a 30-day trial for new users.
read more →

AI-powered investigations preview for Amazon GuardDuty

🛡️ AWS previewed AI-powered investigations in Amazon GuardDuty to automate analysis of findings and reduce manual investigation time. The capability uses knowledge graphs and threat intelligence to examine 90 days of related activity, affected resources, and indicators, delivering disposition assessments with confidence scores, MITRE ATT&CK classifications, evidence, and remediation recommendations. Available in preview in 10 regions and accessible via the GuardDuty console, CLI, API, or AWS' MCP Server.
read more →

Accelerating AWS security investigations with Kiro CLI

🔐 This post shows how Kiro CLI, an AI-powered command line assistant, speeds AWS security investigations by proposing, explaining, and optionally executing AWS CLI commands while documenting each step. It demonstrates a GuardDuty-driven investigation following the AWS Security Incident Response Guide: triage, EC2 and IAM assessment, CloudTrail analysis, containment, and remediation. The walkthrough highlights benefits like faster triage, automated CloudTrail queries, and guided remediation, while advising human validation and forensic preservation.
read more →

Operationalizing AWS security: a maturity roadmap

🔒 This post outlines a practical, phased maturity roadmap for organizations that have enabled AWS Security Hub and Amazon GuardDuty. It emphasizes moving from enabled tooling to operational security practices by assessing current state, tuning signal quality, routing findings, automating safe remediations, and establishing a recurring operational cadence. Each phase includes goals, timelines, deliverables, and decision criteria to measure progress and reduce alert fatigue.
read more →

Introducing the AWS Customer Incident Response Team

🔒 The AWS Customer Incident Response Team (CIRT) is a 24/7 global team that helps customers during active security events affecting the customer side of the Shared Responsibility Model. The team analyzes AWS service logs and the control plane using sources like AWS CloudTrail, VPC Flow Logs, and GuardDuty, provides triage and containment guidance, and recommends follow-up actions. AWS also publishes tools, workshops, and the Threat Technique Catalog for AWS (TTC) to help customers prepare and detect recurring tactics and techniques.
read more →

GuardDuty malware scanning for S3 continuous backups

🛡️ Amazon GuardDuty Malware Protection for AWS Backup now supports Amazon S3 continuous backups, enabling malware scanning across your continuous backup timeline. You can enable full or incremental scans within your backup plan and run on-demand scans up to any restorable point in time. The new GetPITRMalwareScanResults API lets you query scan status at a specific point in time to confirm a clean recovery point. Support is available in all Regions where GuardDuty Malware Protection for AWS Backup is offered, and you can enable it via the AWS Backup console, API, or CLI.
read more →

Automating identity lifecycle with AWS Directory APIs

🔒 AWS Managed Microsoft AD now supports CRUD operations on users and groups through the Directory Service Data APIs, accessible via the AWS CLI, APIs, and Management Console. This enables automation of identity lifecycle management and tighter security controls by integrating with services like Amazon GuardDuty, AWS Step Functions, and Amazon EventBridge. The blog demonstrates a practical workflow that detects unusual AD user behavior and triggers automated remediation such as disabling accounts and notifying stakeholders.
read more →

Preventing Unauthorized AWS Organizations Account Removal

🔒 The AWS Customer Incident Response Team describes a tactic where attackers use credentials with the organizations:LeaveOrganization permission to remove a member account from an AWS Organization, bypassing inherited safeguards such as Service Control Policies and centralized management. After removal, the account is disentangled from consolidated billing, organization-wide CloudTrail trails, and delegated GuardDuty findings, reducing visibility. The post urges deploying the DenyLeaveOrganizationSCP, enforcing least privilege, securing root users with MFA and centralized root management, and updating detection and response workflows to monitor related CloudTrail events.
read more →

Detecting and Preventing Crypto Mining in AWS Environments

🔎 Amazon GuardDuty provides specialized detections and runtime monitoring to identify and mitigate cryptocurrency mining in AWS. It analyzes VPC Flow Logs, DNS queries, CloudTrail events, and workload telemetry to surface findings such as CryptoCurrency:Runtime/BitcoinTool.B and Impact:Runtime/CryptoMinerExecuted. Enable GuardDuty across accounts and Regions and combine it with patching, least-privilege access, and preventive controls to reduce risk.
read more →

AWS Security Hub Now Available in GovCloud US Regions

🔒 AWS Security Hub is now available in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions. Security Hub offers a unified cloud security posture by correlating and enriching signals from Amazon GuardDuty, Amazon Inspector, and Security Hub CSPM to prioritize active risks. The service delivers near‑real‑time risk analytics, exposure findings, automated response workflows, attack path visualization, and centralized organization-wide deployment with streamlined pricing for improved cost predictability.
read more →

Getting Started with Security Response Automation on AWS

🛡️ AWS outlines core concepts and a hands-on walkthrough for implementing security response automation to detect and remediate threats across AWS environments. The post maps automation to the NIST Cybersecurity Framework and demonstrates a CloudFormation deployment using EventBridge, Lambda, GuardDuty, and Security Hub to automatically restart CloudTrail and notify operators. It also highlights the Automated Security Response library, testing guidance, and cost and cleanup considerations.
read more →

Real-Time Malware Defense with AWS Network Firewall

🛡️AWS describes an automated active threat defense that translates MadPot honeypot intelligence into AWS Network Firewall protections within 30 minutes. The offering integrates with Amazon GuardDuty to surface detections while Network Firewall enforces multi-layered blocks across DNS, HTTP host headers, TLS SNI, and direct IP connections. Using a Swiss cheese model, it stacks inspection points so that if one layer is bypassed, others still interrupt reconnaissance, malware downloads, and C2 communications.
read more →