Today, AWS announced the general availability of Amazon GuardDuty custom threat detection using entity lists. This new feature enhances threat detection capabilities in GuardDuty by extending support to incorporate your own domain-based threat intelligence into the service beyond originally supported custom IP list. You can now detect threats in GuardDuty using malicious domains or IP addresses defined in your custom threat list. As part of this update, GuardDuty introduces a new finding type, Impact:EC2/MaliciousDomainRequest.Custom, which is triggered when activity related to a domain in your custom threat list is detected. Additionally, you can use entity lists to suppress alerts from trusted sources, giving you greater control over your threat detection strategy.
Entity lists offer enhanced flexibility compared to the previous IP address lists. These new lists can include IP addresses, domains, or both, allowing for more comprehensive threat intelligence integration. Unlike the legacy IP list format, entity lists provides simplified permission management and avoids impacting IAM policy size limits across multiple AWS Regions, making it easier to implement and manage custom threat detection across your AWS environment.
GuardDuty custom entity list is available in all AWS Regions where GuardDuty is offered, excluding China Regions and GovCloud (US) Regions.
Categories: general:products/amazon-guardduty,marketing:marchitecture/security-identity-and-compliance
Source: Amazon Web Services
Latest Posts
- Amazon EC2 X8i instances are now available in the South America (São Paulo) Region

- Microsoft 365 Weekly Change Intelligence – 2 Critical & 20 High Impact Changes

- MC1474455: Microsoft Copilot App Adds In-App Browsing on Windows and Mac

- MC1474461: Microsoft 365 Admin Center Adds Granular Browser Access Controls for Copilot Cowork







