Today, we’re announcing new enhancements to Amazon GuardDuty Extended Threat Detection with the addition of two attack sequence findings for Amazon Elastic Compute Cloud (Amazon EC2) instances and Amazon Elastic Container Service (Amazon ECS) tasks. These new findings build on the existing Extended Threat Detection capabilities, which already combine sequences involving AWS Identity and Access Management (IAM) credential misuse, unusual Amazon Simple Storage service (Amazon S3) bucket activity, and Amazon Elastic Kubernetes Service (Amazon EKS) cluster compromise. By adding coverage for EC2 instance groups and ECS clusters, this launch expands sequence-level visibility to virtual machine and container environments that support the same application. Together, these capabilities provide a more consistent and unified way to…
Related Posts

Optimizing Amazon FSx for Lustre storage consumption using automatic data tiering with Amazon S3 | Amazon Web Services
Managing high-performance file storage can be a significant operational and cost challenge for many organizations, especially those running compute-intensive workloads…

Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox
Executive Summary When researching the boundaries of cloud services, two of the main aspects that come to mind are network…

Map Earth’s vegetation in under 20 minutes with Amazon SageMaker | Amazon Web Services
In today’s rapidly changing world, monitoring the health of our planet’s vegetation is more critical than ever. Vegetation plays a…