<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>IAMTrail - GuardDuty Announcements</title>
    <link>https://iamtrail.com/guardduty/</link>
    <description>Track AWS GuardDuty SNS announcements - new findings, features, and region launches. An unofficial archive by zoph.io.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 07 Aug 2026 22:04:32 GMT</lastBuildDate>
    <ttl>60</ttl>
    <atom:link href="https://iamtrail.com/feeds/guardduty.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>GuardDuty New Finding: UnauthorizedAccess:IAMUser/ResourceCredentialExfiltration.InsideAWS</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-07-17T14:49:35Z:NEW_FINDINGS:unauthorizedaccess-iamuser-resourcecredentialexfiltration-insideaws</guid>
      <pubDate>Fri, 17 Jul 2026 14:49:35 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>This finding informs you that a host within AWS has attempted to run AWS API operations using temporary AWS credentials that were created on an ECS resource in your AWS environment.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding: UnauthorizedAccess:IAMUser/ResourceCredentialExfiltration.OutsideAWS</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-07-17T14:49:35Z:NEW_FINDINGS:unauthorizedaccess-iamuser-resourcecredentialexfiltration-outsideaws</guid>
      <pubDate>Fri, 17 Jul 2026 14:49:35 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>This finding informs you that a host outside of AWS has attempted to run AWS API operations using temporary AWS credentials that were created on an ECS resource in your AWS environment.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty now offers AI Protection, expanding threat detection to AWS AI services including Amazon Bedrock and...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-07-14T20:37:24Z:NEW_FEATURES:amazon-guardduty-now-offers-ai-protection-expanding-threat-detection-to-aws-ai-s</guid>
      <pubDate>Tue, 14 Jul 2026 20:37:24 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty now offers AI Protection, expanding threat detection to AWS AI services including Amazon Bedrock and Amazon SageMaker. As organizations rapidly adopt AI, security teams may lack visibility into threats specifically targeting AI workloads, such as anomalous model invocations, cost harvesting attacks, and prompt injection attempts. GuardDuty AI Protection continuously monitors these workloads so security teams can detect and respond to AI-specific threats without manual configuration or custom tooling.

GuardDuty AI Protection analyzes both CloudTrail management and data events from AWS AI services to identify suspicious activity, including unusual invocation patterns, cost harvesting attacks where threat actors force AI resources to consume excessive GPU time and tokens, and prompt injection attempts through integration with Amazon Bedrock Guardrails. AI Protection introduces three new finding types: Impact:IAMUser/AnomalousModelInvocation, Impact:IAMUser/CostHarvesting, and Impact:IAMUser/PromptInjection.Direct. GuardDuty AI Protection can be enabled with a few steps in the GuardDuty or Security Hub console, and using AWS Organizations, can be centrally enabled for all accounts in an organization.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty now offers AI-powered investigations in public preview, a new capability that automatically analyzes...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-06-22T23:38:51Z:NEW_FEATURES:amazon-guardduty-now-offers-ai-powered-investigations-in-public-preview-a-new-ca</guid>
      <pubDate>Mon, 22 Jun 2026 23:38:51 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty now offers AI-powered investigations in public preview, a new capability that automatically analyzes GuardDuty findings and accounts to help you quickly distinguish true threats from benign findings. Each investigation delivers a structured summary in minutes with confidence-scored disposition, MITRE ATT&amp;CK technique classification, and actionable recommendations. You can initiate investigations from the GuardDuty console, CLI, API, or AWS MCP Server. This feature is available in 10 AWS Regions: US East (N. Virginia), US East (Ohio), US West (Oregon), Canada (Central), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Paris), Europe (Stockholm), and Asia Pacific (Tokyo). To learn more, visit the Amazon GuardDuty User Guide.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty has increased the Malware Protection for S3 archive extraction quotas. The maximum number of files...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-06-09T22:59:33Z:NEW_FEATURES:amazon-guardduty-has-increased-the-malware-protection-for-s3-archive-extraction-</guid>
      <pubDate>Tue, 09 Jun 2026 22:59:33 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty has increased the Malware Protection for S3 archive extraction quotas. The maximum number of files that can be extracted and analyzed from an archive has increased from 10,000 to 100,000, and the maximum archive depth levels have increased from 5 to 100.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Updated Finding: Persistence:Kubernetes/ContainerWithSensitiveMount</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-05-30T05:10:55Z:UPDATED_FINDINGS:persistence-kubernetes-containerwithsensitivemount</guid>
      <pubDate>Sat, 30 May 2026 05:10:55 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Updated Finding</category>
      <description><![CDATA[<p>This finding type is replaced by Persistence:Kubernetes/AnomalousBehavior.WorkloadDeployed!ContainerWithSensitiveMount, which provides enhanced detection coverage using anomaly-based machine learning.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Updated Finding: PrivilegeEscalation:Kubernetes/PrivilegedContainer</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-05-30T05:10:55Z:UPDATED_FINDINGS:privilegeescalation-kubernetes-privilegedcontainer</guid>
      <pubDate>Sat, 30 May 2026 05:10:55 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Updated Finding</category>
      <description><![CDATA[<p>This finding type is replaced by PrivilegeEscalation:Kubernetes/AnomalousBehavior.WorkloadDeployed!PrivilegedContainer, which provides enhanced detection coverage using anomaly-based machine learning.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty Malware Protection for AWS Backup now supports malware scanning for S3 continuous backups, also known...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-05-27T00:04:06Z:NEW_FEATURES:amazon-guardduty-malware-protection-for-aws-backup-now-supports-malware-scanning</guid>
      <pubDate>Wed, 27 May 2026 00:04:06 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty Malware Protection for AWS Backup now supports malware scanning for S3 continuous backups, also known as point-in-time recovery (PITR). You can now scan S3 continuous backup recovery points for malware, enabling you to confidently restore S3 data to any second within your retention period knowing the recovery point is clean. You can enable this capability even if GuardDuty foundational data sources are not enabled in your account.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: GuardDuty Extended Threat Detection now integrates exposure and vulnerability context from AWS Security Hub to enhance...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-05-20T19:09:35Z:NEW_FEATURES:guardduty-extended-threat-detection-now-integrates-exposure-and-vulnerability-co</guid>
      <pubDate>Wed, 20 May 2026 19:09:35 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>GuardDuty Extended Threat Detection now integrates exposure and vulnerability context from AWS Security Hub to enhance attack sequence findings. This capability improves prioritization accuracy and delivers more actionable critical-severity findings by correlating threat activity with resource exposure data, including known vulnerabilities, internet reachability, and misconfigurations. When available, attack sequence findings are enriched with exposure indicators, helping you prioritize the most critical remediation actions. To maximize detection coverage, enable Security Hub alongside GuardDuty Runtime Monitoring for EC2, EKS, and ECS Fargate. Feature availability varies in AWS GovCloud (US) and AWS China Regions.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Customers can now use their own threat lists to add SHA-256 file hash IOCs and GuardDuty will generate...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-05-13T22:28:46Z:NEW_FEATURES:customers-can-now-use-their-own-threat-lists-to-add-sha-256-file-hash-iocs-and-g</guid>
      <pubDate>Wed, 13 May 2026 22:28:46 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Customers can now use their own threat lists to add SHA-256 file hash IOCs and GuardDuty will generate Execution:Runtime/MaliciousFileExecuted.Custom findings on them. See for instructions on uploading threat lists.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty now supports creating suppression rules using any finding field, offering flexibility to filter...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-04-21T00:21:46Z:NEW_FEATURES:amazon-guardduty-now-supports-creating-suppression-rules-using-any-finding-field</guid>
      <pubDate>Tue, 21 Apr 2026 00:21:46 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty now supports creating suppression rules using any finding field, offering flexibility to filter findings based on all attributes of the finding JSON. This expanded capability allows creating more precise suppression rules tailored to security workflows, helping organizations focus on relevant findings by streamlining alert management.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: GuardDuty Malware Protection for Amazon S3 Object Scan Result notifications in EventBridge now includes statusReasons...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-04-13T21:16:42Z:NEW_FEATURES:guardduty-malware-protection-for-amazon-s3-object-scan-result-notifications-in-e</guid>
      <pubDate>Mon, 13 Apr 2026 21:16:42 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>GuardDuty Malware Protection for Amazon S3 Object Scan Result notifications in EventBridge now includes statusReasons field to provide visibility into reason behind skipped scans.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Updated Finding: Impact:EC2/SuspiciousDomainRequest.Reputation</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-03-27T22:11:54Z:UPDATED_FINDINGS:impact-ec2-suspiciousdomainrequest-reputation</guid>
      <pubDate>Fri, 27 Mar 2026 22:11:54 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Updated Finding</category>
      <description><![CDATA[<p>GuardDuty has expanded its threat intelligence sources to include an additional vendor, providing broader coverage of known malicious domains. You may observe an increase in findings for this finding type as a result of this expanded coverage.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Updated Finding: Trojan:EC2/DriveBySourceTraffic!DNS</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-03-27T22:11:54Z:UPDATED_FINDINGS:trojan-ec2-drivebysourcetraffic-dns</guid>
      <pubDate>Fri, 27 Mar 2026 22:11:54 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Updated Finding</category>
      <description><![CDATA[<p>GuardDuty has expanded its threat intelligence sources to include an additional vendor, providing broader coverage of known malicious domains. You may observe an increase in findings for this finding type as a result of this expanded coverage.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Updated Finding: Backdoor:EC2/C&amp;CActivity.B!DNS</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-03-27T22:11:54Z:UPDATED_FINDINGS:backdoor-ec2-c-cactivity-b-dns</guid>
      <pubDate>Fri, 27 Mar 2026 22:11:54 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Updated Finding</category>
      <description><![CDATA[<p>GuardDuty has expanded its threat intelligence sources to include an additional vendor, providing broader coverage of known malicious domains. You may observe an increase in findings for this finding type as a result of this expanded coverage.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Updated Finding: Trojan:EC2/PhishingDomainRequest!DNS</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">iamtrail:guardduty:2026-03-27T22:11:54Z:UPDATED_FINDINGS:trojan-ec2-phishingdomainrequest-dns</guid>
      <pubDate>Fri, 27 Mar 2026 22:11:54 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Updated Finding</category>
      <description><![CDATA[<p>GuardDuty has expanded its threat intelligence sources to include an additional vendor, providing broader coverage of known malicious domains. You may observe an increase in findings for this finding type as a result of this expanded coverage.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding: CredentialAccess:IAMUser/CompromisedCredentials</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/bb70231965f086856333f279a2ee52d9</guid>
      <pubDate>Tue, 10 Mar 2026 22:45:12 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>Amazon GuardDuty now delivers findings for compromised IAM credentials. When abnormal credential activity is detected, you will receive notification through GuardDuty&apos;s standard channels.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding: UnauthorizedAccess:IAMUser/ResourceCredentialExfiltration.OutsideAWS</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/f90de69af608dfda6375a8f4528baede</guid>
      <pubDate>Wed, 17 Dec 2025 19:57:30 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>This finding informs you that a host outside of AWS has attempted to run AWS API operations using temporary AWS credentials that were created on a Lambda resource in your AWS environment.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty now supports wildcard characters (* and ?) in finding suppression rules. Wildcards are supported...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/e893fcb2fd444a643ccc56a470a63a74</guid>
      <pubDate>Wed, 03 Dec 2025 01:06:44 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty now supports wildcard characters (* and ?) in finding suppression rules. Wildcards are supported through new Matches and NotMatches operators, giving you more flexibility in managing security findings. The findings that match this criteria are automatically archived. Suppressed findings are also excluded from Extended Threat Detection sequencing, further helping you customize your security alerts.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: GuardDuty introduces two new critical-severity findings: AttackSequence:EC2/CompromisedInstanceGroup and...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/79c8c6b3d018b8f0417a36bbf5eaa3c0</guid>
      <pubDate>Wed, 03 Dec 2025 00:01:00 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>GuardDuty introduces two new critical-severity findings: AttackSequence:EC2/CompromisedInstanceGroup and AttackSequence:ECS/CompromisedCluster. These findings provide attack sequence information, allowing you to spend less time on initial analysis and more time responding to critical threats, minimizing business impact. For example, GuardDuty can identify suspicious processes followed by persistence attempts, crypto-mining activities, and reverse shell creation, representing these related events as a single, critical-severity finding. To improve attack sequence coverage and threat analysis of Amazon EC2 instances, enable Runtime Monitoring for EC2. To enable detection of compromised ECS clusters, enable Runtime Monitoring for Fargate or EC2 depending on your infrastructure.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding: DefenseEvasion:IAMUser/BedrockLoggingDisabled</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/37ee2438e7982ba87d5d120d60435791</guid>
      <pubDate>Sat, 22 Nov 2025 00:18:52 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>Amazon GuardDuty has added a new finding type that notifies you when logging for Amazon Bedrock model invocations is disabled. This finding helps detect attempts to evade detection by disabling audit logs that track AI workload activity.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty announces Malware Protection for AWS Backup. This fully managed feature simplifies malware scanning of...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/a4fd4bbb4dbefd416258fd6186dd54ab</guid>
      <pubDate>Thu, 20 Nov 2025 01:36:54 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty announces Malware Protection for AWS Backup. This fully managed feature simplifies malware scanning of your backups where it automatically scans new backups upon creation, lets you run on-demand scans of existing backups, and allows you to verify integrity of backups before restoration. Using this feature, you can now perform full and incremental malware scans on your EBS Snapshots, EC2 AMIs, and Backup Recovery Points by using the StartMalwareScan API. The feature publishes scan results to Amazon EventBridge. You can use this feature without enabling the foundational GuardDuty in your account.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty announces Scan on Demand for Malware Protection for S3. Using this feature you can use the new...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/af0d0bef44d4cb72fe2d7d71bbeac162</guid>
      <pubDate>Mon, 17 Nov 2025 23:26:24 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty announces Scan on Demand for Malware Protection for S3. Using this feature you can use the new SendObjectMalwareScan API to trigger scans on any already existing objects stored in your S3 buckets.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/163b6fa6001e8060b1cace51a36f3c5e</guid>
      <pubDate>Wed, 15 Oct 2025 23:49:16 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>GuardDuty New Finding</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty Malware Protection for S3 enhances archive processing to support up to 10,000 files per archive (up...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/74e06b2686793b4d497e04f21312d68f</guid>
      <pubDate>Thu, 04 Sep 2025 19:02:03 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty Malware Protection for S3 enhances archive processing to support up to 10,000 files per archive (up from 1,000 files).</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Customers can now use their own trusted and threat domain lists to customize how GuardDuty generates and alerts on...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/c32c2ed4f1659eb0b3d672c84011cf53</guid>
      <pubDate>Fri, 15 Aug 2025 19:44:04 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Customers can now use their own trusted and threat domain lists to customize how GuardDuty generates and alerts on findings, along with several other improvements, extending the existing support for trusted and threat IP lists.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty is now available in Asia Pacific (Taipei) Region</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/2304cfdd2ab465d1a599662d786815f8</guid>
      <pubDate>Fri, 01 Aug 2025 21:46:03 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty is now available in Asia Pacific (Taipei) Region</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty Malware Protection for S3 now supports scanning objects up to 100 GB, increased from 5 GB. This...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/4efad87b685e20a61b0f286eaa543660</guid>
      <pubDate>Wed, 23 Jul 2025 22:55:42 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty Malware Protection for S3 now supports scanning objects up to 100 GB, increased from 5 GB. This includes both individual objects and extracted archive files.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: GuardDuty Extended Threat Detection connects individual findings and signals into an attack sequence, a critical...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/8bb759f04b2cef6144ab0b5ed2158a3c</guid>
      <pubDate>Tue, 17 Jun 2025 16:41:54 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>GuardDuty Extended Threat Detection connects individual findings and signals into an attack sequence, a critical severity finding. This capability now includes coverage for multi-stage attacks targeting Amazon EKS clusters in your AWS environment. GuardDuty correlates multiple security signals across Amazon EKS audit logs, runtime behavior of processes, and AWS API activity to detect sophisticated attack patterns. Enable EKS Protection, Runtime Monitoring (EKS), or both to maximize your detection coverage. Feature availability varies in AWS GovCloud (US) and AWS China Regions.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty Malware Protection has added limited support for scanning instances with marketplace product codes in...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/d4c79d5144f9d55d2542e81e0320eefa</guid>
      <pubDate>Fri, 13 Jun 2025 22:47:00 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty Malware Protection has added limited support for scanning instances with marketplace product codes in AWS Commercial Regions. This applies to both GuardDuty-initiated and on-demand malware scans.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Now available: (1) New GuardDuty agent versions featuring security updates for Amazon EKS, Amazon EC2, and Amazon ECS...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/beecc3c6d1585a4927684962ed82f7cb</guid>
      <pubDate>Thu, 22 May 2025 22:45:58 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Now available: (1) New GuardDuty agent versions featuring security updates for Amazon EKS, Amazon EC2, and Amazon ECS Fargate; (2) Enhanced visibility into underlying runtime coverage issues. For assessing coverage across computes and troubleshooting steps, check in the Amazon GuardDuty User Guide.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty is now available in AWS Mexico (Central) Region</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/87d3fc1602267232268a0836a3c5f971</guid>
      <pubDate>Wed, 07 May 2025 20:14:37 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty is now available in AWS Mexico (Central) Region</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty is now available in AWS Asia Pacific (Thailand) Region</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/d8214fbb02f6fccf03640a22de95b302</guid>
      <pubDate>Wed, 02 Apr 2025 02:10:39 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty is now available in AWS Asia Pacific (Thailand) Region</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Announcement</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/7c1b4fd4efdcc004e5219977e51c7db8</guid>
      <pubDate>Tue, 25 Feb 2025 17:33:20 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Announcement</category>
      <description><![CDATA[<p>GuardDuty Announcement</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty is now available in AWS Asia Pacific (Malaysia) Region</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/bec498dacca46fefc21520d557647582</guid>
      <pubDate>Thu, 16 Jan 2025 22:53:18 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty is now available in AWS Asia Pacific (Malaysia) Region</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Now available: Amazon GuardDuty Extended Threat Detection automatically detects multi-stage attacks sequences. An...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/960e35f5ff959c60f2369e4f3297787c</guid>
      <pubDate>Tue, 03 Dec 2024 23:22:55 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Now available: Amazon GuardDuty Extended Threat Detection automatically detects multi-stage attacks sequences. An attack sequence is a critical severity finding that identifies a sophisticated attack across time and AWS resources. Extended Threat Detection connects individual findings and signals into a cohesive attack narrative. An attack sequence involves multiple steps, such as gaining initial access, escalating privileges, moving laterally, and exfiltrating data. Additionally, enable GuardDuty S3 Protection to further enhance the security value of the attack sequences.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty Malware Protection for EC2 has added three Runtime Monitoring finding types that invoke automatic...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/6b560b426662b270ef3bd4f8f38114bd</guid>
      <pubDate>Wed, 13 Nov 2024 01:11:20 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty Malware Protection for EC2 has added three Runtime Monitoring finding types that invoke automatic (GuardDuty-initiated) malware scans - Execution:Runtime/MaliciousFileExecuted, Execution:Runtime/SuspiciousShellCreated, and PrivilegeEscalation:Runtime/ElevationToRoot. AWS accounts that have the Malware Protection for EC2 feature enabled may observe malware scans being initiated when these findings are generated.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty expands its generally available RDS Protection feature to now also support monitoring login activity...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/4484e8d8153b209596c9be1cd4c08910</guid>
      <pubDate>Wed, 06 Nov 2024 20:20:13 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty expands its generally available RDS Protection feature to now also support monitoring login activity from Amazon Aurora PostgreSQL Limitless Databases. As a part of this expansion, GuardDuty will automatically begin monitoring login data from Aurora PostgreSQL Limitless Databases for accounts that currently have RDS Protection enabled. For accounts that have not yet enabled RDS Protection, enable the feature with a single step in the GuardDuty console. This will begin continuous monitoring of existing and new databases in your account.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: GuardDuty Malware Protection for S3 launches zero-click role creation when enabling protection on a bucket. GuardDuty...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/5622f5c1155cd54d8e848ead7900e53a</guid>
      <pubDate>Wed, 23 Oct 2024 23:52:10 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>GuardDuty Malware Protection for S3 launches zero-click role creation when enabling protection on a bucket. GuardDuty now allows you to use a pre-existing role or can automatically create a new role with permissions scoped down to perform actions on that specific bucket.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/799b2be82945874f810fd1dd4360c8bb</guid>
      <pubDate>Mon, 21 Oct 2024 18:00:28 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>GuardDuty New Finding</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/8e7c49f92c6338048f3836ffa1388cf2</guid>
      <pubDate>Fri, 11 Oct 2024 00:23:28 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>GuardDuty New Finding</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: AWS PrivateLink now available with GuardDuty. You can now establish a private connection between your VPC and Amazon...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/2f2d4fa96d4de01ad46ce3867b729b49</guid>
      <pubDate>Wed, 18 Sep 2024 01:42:25 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>AWS PrivateLink now available with GuardDuty. You can now establish a private connection between your VPC and Amazon GuardDuty.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty adds new functionality to the GetFindingsStatistics API. Customers can now query aggregate finding...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/6f2a6e688a1d19a43af5e9f7775ff858</guid>
      <pubDate>Fri, 13 Sep 2024 00:04:34 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty adds new functionality to the GetFindingsStatistics API. Customers can now query aggregate finding counts broken down by: account, daily counts, finding type, finding severity and affected resources. Link:</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty Malware Protection for S3 has increased the quota for the number of Amazon S3 buckets that you can...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/56e78fe78d63565ebc64ef843073c431</guid>
      <pubDate>Fri, 09 Aug 2024 19:55:04 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty Malware Protection for S3 has increased the quota for the number of Amazon S3 buckets that you can protect, from 10 to 25 buckets per AWS account in each AWS Region.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Finding</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/9fba56fcccdc3fd1dae6c6c2a85109e4</guid>
      <pubDate>Wed, 07 Aug 2024 02:39:16 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Finding</category>
      <description><![CDATA[<p>GuardDuty New Finding</p>]]></description>
    </item>
    <item>
      <title>GuardDuty Announcement: Amazon GuardDuty observed a trend where threat actors are setting up malicious domains to compromise organizations...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/71d698b03aa97257fc5f147325697995</guid>
      <pubDate>Wed, 24 Jul 2024 21:17:33 GMT</pubDate>
      <category>GuardDuty</category>
      <category>Announcement</category>
      <description><![CDATA[<p>Amazon GuardDuty observed a trend where threat actors are setting up malicious domains to compromise organizations working on software patching related to CrowdStrike&apos;s recent sensor issue. Currently, GuardDuty is observing an uptick in Command and Control (C&amp;C) Activity findings that correspond with domains identified in CrowdStrike CSA-240832. As a proactive measure, we strongly advise all customers to increase vigilance regarding DNS-related findings. Recommended steps include:
1. Monitor DNS-related findings: Pay close attention to alerts such as Backdoor:EC2/ C&amp;CActivity.B!DNS findings and Backdoor:Runtime/C&amp;CActivity.B!DNS (if using GuardDuty&apos;s runtime protection for EKS, ECS Fargate, and EC2). They indicate potential communication with suspicious and malicious command and control (C&amp;C) activities, which could be part of or evolve into a broader attacks targeting your workloads.
2. Validate and evaluate findings: Get started with the GuardDuty console, API, or other preferred method to review findings promptly. Start with a finding&apos;s severity label, which would be marked as “High” for more important ones. GuardDuty continually updates its threat intelligence from CrowdStrike and other AWS internal and external sources, which helps ensure a current list of suspicious and malicious domains.
3 Take action on suspicious activity: If the flagged activity is unexpected, your instance may be compromised. Consider quickly taking action on affected resources, conducting a thorough investigation, and remediating any identified threats. For more information, see remediating a potentially compromised Amazon EC2 instance.
Maintaining heightened awareness and promptly responding to GuardDuty findings can help you reduce the risk of malicious actors compromising your environments. For further assistance, refer to the AWS GuardDuty documentation or contact AWS Support.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Now available: Extending operating systems support to Ubuntu and Debian OS for Amazon GuardDuty for EC2 runtime...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/2fefd99a44f247746314b3a623c16829</guid>
      <pubDate>Wed, 19 Jun 2024 23:31:42 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Now available: Extending operating systems support to Ubuntu and Debian OS for Amazon GuardDuty for EC2 runtime monitoring. Get visibility into operating system-level, network and file activities and container-level context of the identified threats.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty announces Malware Protection for S3 that automatically scans newly uploaded objects to your selected...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/1123291e9d6a86b21a487d080fae621c</guid>
      <pubDate>Thu, 13 Jun 2024 00:33:34 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty announces Malware Protection for S3 that automatically scans newly uploaded objects to your selected Amazon S3 buckets for potential malware, viruses, and other suspicious uploads. The feature provides an option to add tags to your scanned objects and publishes the S3 object scan result to Amazon EventBridge. You can further build downstream workflows, such as isolation to a quarantine bucket, or define bucket policies using tags that prevent users or applications from accessing certain objects. You can use this feature without enabling the GuardDuty service in your account.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: Amazon GuardDuty expands its generally-available RDS Protection feature to now also support RDS for PostgreSQL login...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/8977c915ba2957b6ab1788a7b96ab607</guid>
      <pubDate>Thu, 06 Jun 2024 21:53:48 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>Amazon GuardDuty expands its generally-available RDS Protection feature to now also support RDS for PostgreSQL login activity monitoring, in addition to already monitoring Amazon Aurora databases. As part of this expansion, GuardDuty will automatically begin monitoring login data from RDS for PostgreSQL databases for accounts that are currently enabled with GuardDuty RDS Protection monitors. For new accounts that are not enabled with GuardDuty RDS Protection yet, customers can enable the feature with a single step in the GuardDuty console that will begin continuous monitoring for existing and new Amazon Aurora and RDS for PostgreSQL database workloads.</p>]]></description>
    </item>
    <item>
      <title>GuardDuty New Feature: GuardDuty Malware Protection has increased the EBS volume size limit for malware scanning from 1 TB to 2TB. This...</title>
      <link>https://iamtrail.com/guardduty/</link>
      <guid isPermaLink="false">https://gist.github.com/z0ph/5eb00819a6d98fed52daddaf52d3328c</guid>
      <pubDate>Thu, 30 May 2024 00:42:45 GMT</pubDate>
      <category>GuardDuty</category>
      <category>New Feature</category>
      <description><![CDATA[<p>GuardDuty Malware Protection has increased the EBS volume size limit for malware scanning from 1 TB to 2TB. This applies to both GuardDuty-initiated and on-demand malware scans.</p>]]></description>
    </item>
  </channel>
</rss>