Home icon

Enhancing threat detection with Amazon GuardDuty new custom entity lists

News



AWS has announced the general availability of Amazon GuardDuty custom entity lists for enhanced threat detection.

  • Allows users to incorporate custom domain-based threat intelligence
  • Introduces new finding type *Impact:EC2/MaliciousDomainRequest.Custom*
  • Enables detection of threats using custom lists of malicious domains or IP addresses
  • Provides ability to suppress alerts from trusted sources
  • Offers more flexible entity lists that can include IP addresses, domains, or both
  • Simplifies permission management across AWS Regions

Available in most AWS Regions, excluding China and GovCloud (US) Regions, this feature gives users greater control over threat detection strategies.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Sep 15
2025
Navigating Amazon GuardDuty protection plans and Extended Threat Detection
Dec 2
2024
Amazon GuardDuty introduces GuardDuty Extended Threat Detection
Dec 2
2025
Amazon GuardDuty adds Extended Threat Detection for Amazon EC2 and Amazon ECS
Jun 17
2025
Amazon GuardDuty Extended Threat Detection now supports Amazon EKS

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.