AWS announces further enhancements to Amazon GuardDuty Extended Threat Detection with new capabilities to detect multistage attacks targeting Amazon Elastic Compute Cloud (Amazon EC2) instances and Amazon Elastic Container Service (Amazon ECS) clusters running on AWS Fargate or Amazon EC2. GuardDuty Extended Threat Detection uses artificial intelligence and machine learning algorithms trained at AWS scale to automatically correlate security signals and detect critical threats. It analyzes multiple security signals across network activity, process runtime behavior, malware execution, and AWS API activity over extended periods to detect sophisticated attack patterns that might otherwise go unnoticed.
With this launch, GuardDuty introduces two new critical-severity findings: AttackSequence:EC2/CompromisedInstanceGroup and AttackSequence:ECS/CompromisedCluster. These findings provide attack sequence information, allowing you to spend less time on initial analysis and more time responding to critical threats, minimizing business impact. For example, GuardDuty can identify suspicious processes followed by persistence attempts, crypto-mining activities, and reverse shell creation, representing these related events as a single, critical-severity finding. Each finding includes a detailed summary, events timeline, mapping to MITRE ATT&CK® tactics and techniques, and remediation recommendations.
While GuardDuty Extended Threat Detection is automatically enabled for GuardDuty customers at no additional cost, its detection comprehensiveness depends on your enabled GuardDuty protection plans. To improve attack sequence coverage and threat analysis of Amazon EC2 instances, enable Runtime Monitoring for EC2. To enable detection of compromised ECS clusters, enable Runtime Monitoring for Fargate or EC2 depending on your infrastructure type.
To get started, enable GuardDuty protection plans via the Console or API. New GuardDuty customers can start with a 30-day free trial, and existing customers who haven’t used Runtime Monitoring can also try it free for 30 days. For additional information, visit the blog post and Amazon Guard Duty product page.
Categories: general:products/amazon-guardduty,marketing:marchitecture/management-tools,marketing:marchitecture/compute,marketing:marchitecture/containers
Source: Amazon Web Services
Latest Posts
- Microsoft 365 Copilot: Scheduling with Copilot in classic Outlook for Windows [MC1228333]
![Microsoft 365 Copilot: Scheduling with Copilot in classic Outlook for Windows [MC1228333] 2 pexels ir solyanaya 197121 634548](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Expand to full event details on iPad [MC1228329]
![Expand to full event details on iPad [MC1228329] 3 teddy bear 1835598 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Prevent/Fix (Planned) – Search by Meeting ID in Call Quality Dashboard [MC1228315]
![Prevent/Fix (Planned) - Search by Meeting ID in Call Quality Dashboard [MC1228315] 4 pexels googledeepmind 25626593](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft 365 Copilot: Prepare for meetings with Copilot in classic Outlook for Windows [MC1228331]
![Microsoft 365 Copilot: Prepare for meetings with Copilot in classic Outlook for Windows [MC1228331] 5 pexels padrinan 1111372](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Microsoft 365 Copilot: Scheduling with Copilot in classic Outlook for Windows [MC1228333] 2 pexels ir solyanaya 197121 634548](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-ir-solyanaya-197121-634548-150x150.webp)
![Expand to full event details on iPad [MC1228329] 3 teddy bear 1835598 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/teddy-bear-1835598_1920-150x150.webp)
![Prevent/Fix (Planned) - Search by Meeting ID in Call Quality Dashboard [MC1228315] 4 pexels googledeepmind 25626593](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-googledeepmind-25626593-150x150.webp)
![Microsoft 365 Copilot: Prepare for meetings with Copilot in classic Outlook for Windows [MC1228331] 5 pexels padrinan 1111372](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-padrinan-1111372-150x150.webp)
