AWS Security Hub Adds GuardDuty Runtime Monitoring
🔔 AWS has integrated Amazon GuardDuty Runtime Monitoring into the AWS Security Hub Threat Analytics plan. This runtime capability inspects OS, network, and file activity to detect threats like container escapes, privilege escalation, and cryptomining across Amazon EC2, Amazon EKS, and Amazon ECS on AWS Fargate. Billing for Runtime Monitoring is now consolidated under Security Hub as a single usage type, eliminating separate GuardDuty Runtime Monitoring charges for accounts and regions with Security Hub enabled. Detection behavior, finding types, and GuardDuty agents remain unchanged, and no reconfiguration is required; free-trial terms for Threat Analytics and Security Hub Essentials remain separate.
