Amazon GuardDuty adds sensitive file modification threat detections
News
Amazon GuardDuty Runtime Monitoring now includes three new threat detections that alert security teams when sensitive files are modified on EC2 instances and container workloads.
- Detects Persistence, PrivilegeEscalation, and DefenseEvasion tactics through sensitive file modifications
- Monitors five file operations: open-for-write, rename, symlink, link, and unlink
- Works on EC2, Amazon EKS, and Amazon ECS workloads
- Bypasses obfuscated techniques that evade command-line monitoring
- Includes MITRE ATT&CK mapping and remediation recommendations
- 30-day free trial available for new users
These findings help security teams identify post-compromise attacker activities and reduce false positives through correlation-based analysis.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Sep 8
2026
2026
Amazon GuardDuty adds optional threat detection rules
Dec 2
2024
2024
Amazon GuardDuty introduces GuardDuty Extended Threat Detection
Dec 2
2025
2025
Amazon GuardDuty adds Extended Threat Detection for Amazon EC2 and Amazon ECS
Jun 24
2026
2026
Amazon GuardDuty AI-powered investigations accelerate threat response (Preview)
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.