Skip to main content

๐Ÿ’ผ [GuardDuty.8] GuardDuty Malware Protection for EC2 should be enabled

  • Contextual name: ๐Ÿ’ผ [GuardDuty.8] GuardDuty Malware Protection for EC2 should be enabled
  • ID: /frameworks/aws-fsbp-v1.0.0/guardduty/08
  • Located in: ๐Ÿ’ผ GuardDuty

Descriptionโ€‹

GuardDuty Malware Protection for EC2 helps you detect the potential presence of malware by scanning the Amazon Elastic Block Store (Amazon EBS) volumes that are attached to Amazon Elastic Compute Cloud (Amazon EC2) instances and container workloads. Malware Protection provides scan options where you can decide if you want to include or exclude specific EC2 instances and container workloads at the time of scanning. It also provides an option to retain the snapshots of EBS volumes attached to the EC2 instances or container workloads, in your GuardDuty accounts. The snapshots get retained only when malware is found and Malware Protection findings are generated.

Similarโ€‹

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags