Skip to main content

๐Ÿ’ผ [GuardDuty.11] GuardDuty Runtime Monitoring should be enabled

  • Contextual name: ๐Ÿ’ผ [GuardDuty.11] GuardDuty Runtime Monitoring should be enabled
  • ID: /frameworks/aws-fsbp-v1.0.0/guardduty/11
  • Located in: ๐Ÿ’ผ GuardDuty

Descriptionโ€‹

GuardDuty Runtime Monitoring observes and analyzes operating system-level, networking, and file events to help you detect potential threats in specific AWS workloads in your environment. It uses GuardDuty security agents that add visibility into runtime behavior, such as file access, process execution, command line arguments, and network connections. You can enable and manage the security agent for each type of resource that you want to monitor for potential threats, such as Amazon EKS clusters and Amazon EC2 instances.

Similarโ€‹

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags