Amazon GuardDuty adds optional threat detection rules
News
Amazon GuardDuty now offers Custom Detection Rules, a library of 35 prebuilt opt-in rules for CloudTrail management events that extend threat detection coverage to match your environment.
- 35 prebuilt rules for CloudTrail management events with no log ingestion or storage overhead
- Produces 26 unique finding types mapped to 10 MITRE ATT&CK tactics
- Enable detections selectively for environment-specific threats like external AMI sharing or disabled flow logs
- Dry-run mode available to evaluate detection efficacy before enabling
- Available in all AWS commercial Regions and AWS GovCloud (US)
Custom Detection Rules enables organizations to tailor threat detection to their specific environments without managing log infrastructure.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Dec 2
2024
2024
Amazon GuardDuty introduces GuardDuty Extended Threat Detection
Dec 2
2025
2025
Amazon GuardDuty adds Extended Threat Detection for Amazon EC2 and Amazon ECS
Jul 1
2026
2026
Amazon GuardDuty adds sensitive file modification threat detections
Dec 2
2025
2025
Amazon GuardDuty Extended Threat Detection now supports Amazon EC2 and Amazon ECS
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.