Today, AWS announced the general availability of Amazon GuardDuty custom threat detection using entity lists. This new feature enhances threat detection capabilities in GuardDuty by extending support to incorporate your own domain-based threat intelligence into the service beyond originally supported custom IP list. You can now detect threats in GuardDuty using malicious domains or IP addresses defined in your custom threat list. As part of this update, GuardDuty introduces a new finding type, Impact:EC2/MaliciousDomainRequest.Custom, which is triggered when activity related to a domain in your custom threat list is detected. Additionally, you can use entity lists to suppress alerts from trusted sources, giving you greater control over your threat detection strategy.
Entity lists offer enhanced flexibility compared to the previous IP address lists. These new lists can include IP addresses, domains, or both, allowing for more comprehensive threat intelligence integration. Unlike the legacy IP list format, entity lists provides simplified permission management and avoids impacting IAM policy size limits across multiple AWS Regions, making it easier to implement and manage custom threat detection across your AWS environment.
GuardDuty custom entity list is available in all AWS Regions where GuardDuty is offered, excluding China Regions and GovCloud (US) Regions.
Categories: general:products/amazon-guardduty,marketing:marchitecture/security-identity-and-compliance
Source: Amazon Web Services
Latest Posts
- Updates available for Microsoft 365 Apps for Current Channel [MC1238604]
![Updates available for Microsoft 365 Apps for Current Channel [MC1238604] 2 pexels julioneryy 1839919](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Purview eDiscovery Configuration change for PowerShell cmdlet case and search synchronization changes [MC1238428]
![Microsoft Purview eDiscovery Configuration change for PowerShell cmdlet case and search synchronization changes [MC1238428] 3 pexels skitterphoto 390089](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Workspace IP Firewall rules (Public Preview) [MC1238430]
![Workspace IP Firewall rules (Public Preview) [MC1238430] 4 pexels mikhail nilov 7827963](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Updates to filtered message viewing in Outlook for iOS and Android [MC1238433]
![Updates to filtered message viewing in Outlook for iOS and Android [MC1238433] 5 pexels everson mayer 478307 1481309](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Updates available for Microsoft 365 Apps for Current Channel [MC1238604] 2 pexels julioneryy 1839919](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-julioneryy-1839919-150x150.webp)
![Microsoft Purview eDiscovery Configuration change for PowerShell cmdlet case and search synchronization changes [MC1238428] 3 pexels skitterphoto 390089](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-skitterphoto-390089-150x150.webp)
![Workspace IP Firewall rules (Public Preview) [MC1238430] 4 pexels mikhail nilov 7827963](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-mikhail-nilov-7827963-150x150.webp)
![Updates to filtered message viewing in Outlook for iOS and Android [MC1238433] 5 pexels everson mayer 478307 1481309](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-everson-mayer-478307-1481309-150x150.webp)
