aws AWS What's New ·

Amazon GuardDuty Adds Custom Detection Rules for Tailored Threat Detection

securityawsgaarchitectaws-sns
feature

Amazon GuardDuty now offers Custom Detection Rules, a library of 35 prebuilt, opt-in rules designed to extend threat detection coverage for CloudTrail management events. These rules allow users to tailor their security posture by enabling detections for activities that are indicators of compromise in some accounts but routine in others. The feature produces 26 unique finding types mapped to 10 MITRE ATT&CK tactics without requiring extensive log processing. It is available in all AWS commercial and GovCloud regions, with a dry-run mode for efficacy evaluation.

Features (1)
  • Introduce Custom Detection Rules

    Amazon GuardDuty now provides Custom Detection Rules, offering 35 prebuilt, opt-in rules for CloudTrail management events. This feature extends threat detection coverage by generating 26 unique finding types mapped to 10 MITRE ATT&CK tactics, allowing users to enable detections for specific activities only where they are unexpected.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/09/guardduty-optional-detection-rules/

Related releases