Amazon GuardDuty adds optional threat detection rules
Amazon GuardDuty now offers custom detection rules with 35 prebuilt options for CloudTrail management events, expanding threat detection coverage without log ingestion or storage
Amazon GuardDuty now offers custom detection rules, providing 35 pre-built rules for CloudTrail management events to extend threat detection for your environment. These rules generate 26 unique detection types mapped to 10 MITRE ATT&CK tactics without requiring log collection, normalization, or storage. Because certain threat techniques like external AMI sharing or disabling flow logs may be routine in some accounts but problematic in others, custom rules can be enabled only for unexpected activity. Accessible via the GuardDuty console or API, they can be tested in dry-run mode before live deployment and are available in all AWS commercial and AWS GovCloud (US) regions.
Why it matters
Amazon GuardDuty is a security service that detects malicious and unauthorized behavior, and this update allows organizations to customize their detection scope