Home icon

Amazon GuardDuty adds optional threat detection rules

News



Amazon GuardDuty now offers Custom Detection Rules, a library of 35 prebuilt opt-in rules for CloudTrail management events that extend threat detection coverage to match your environment.

  • 35 prebuilt rules for CloudTrail management events with no log ingestion or storage overhead
  • Produces 26 unique finding types mapped to 10 MITRE ATT&CK tactics
  • Enable detections selectively for environment-specific threats like external AMI sharing or disabled flow logs
  • Dry-run mode available to evaluate detection efficacy before enabling
  • Available in all AWS commercial Regions and AWS GovCloud (US)

Custom Detection Rules enables organizations to tailor threat detection to their specific environments without managing log infrastructure.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Dec 2
2024
Amazon GuardDuty introduces GuardDuty Extended Threat Detection
Dec 2
2025
Amazon GuardDuty adds Extended Threat Detection for Amazon EC2 and Amazon ECS
Jul 1
2026
Amazon GuardDuty adds sensitive file modification threat detections
Dec 2
2025
Amazon GuardDuty Extended Threat Detection now supports Amazon EC2 and Amazon ECS

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.