Amazon GuardDuty Adds Custom Detection Rules for Tailored Threat Detection
Amazon GuardDuty now offers Custom Detection Rules, a library of 35 prebuilt, opt-in rules designed to extend threat detection coverage for CloudTrail management events. These rules allow users to tailor their security posture by enabling detections for activities that are indicators of compromise in some accounts but routine in others. The feature produces 26 unique finding types mapped to 10 MITRE ATT&CK tactics without requiring extensive log processing. It is available in all AWS commercial and GovCloud regions, with a dry-run mode for efficacy evaluation.
Features (1) ›
- Introduce Custom Detection Rules
Amazon GuardDuty now provides Custom Detection Rules, offering 35 prebuilt, opt-in rules for CloudTrail management events. This feature extends threat detection coverage by generating 26 unique finding types mapped to 10 MITRE ATT&CK tactics, allowing users to enable detections for specific activities only where they are unexpected.
https://aws.amazon.com/about-aws/whats-new/2026/09/guardduty-optional-detection-rules/
Related releases
- AWS MCP Server adds serverless diagnostics for Lambda functions with AI agents AWS What's New ·
- AWS Lambda Recursive Loop Detection Extends to All Commercial Regions AWS What's New ·
- Amazon SES adds bot event detection to open and click notifications AWS What's New ·
- AWS Secrets Manager integrates with EventBridge for secret update notifications AWS What's New ·
- S3 Event Notifications Include System-Generated Tags AWS What's New ·
- AWS Config adds 191 managed rules for AI and core services AWS What's New ·