Home icon

Amazon GuardDuty adds sensitive file modification threat detections

News



Amazon GuardDuty Runtime Monitoring now includes three new threat detections that alert security teams when sensitive files are modified on EC2 instances and container workloads.

  • Detects Persistence, PrivilegeEscalation, and DefenseEvasion tactics through sensitive file modifications
  • Monitors five file operations: open-for-write, rename, symlink, link, and unlink
  • Works on EC2, Amazon EKS, and Amazon ECS workloads
  • Bypasses obfuscated techniques that evade command-line monitoring
  • Includes MITRE ATT&CK mapping and remediation recommendations
  • 30-day free trial available for new users

These findings help security teams identify post-compromise attacker activities and reduce false positives through correlation-based analysis.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Sep 8
2026
Amazon GuardDuty adds optional threat detection rules
Dec 2
2024
Amazon GuardDuty introduces GuardDuty Extended Threat Detection
Dec 2
2025
Amazon GuardDuty adds Extended Threat Detection for Amazon EC2 and Amazon ECS
Jun 24
2026
Amazon GuardDuty AI-powered investigations accelerate threat response (Preview)

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.