Description
When GuardDuty is disabled, it does not perform threat detection in the affected account and Region. A detection layer for malicious activity or account misuse may be missing.
This does not mean that other security tools stop detecting threats. Enabling GuardDuty does not itself block threats; configure protection coverage and responses to findings separately.
Potential impact
- Suspicious API calls or network activity may be discovered later.
- Response may be delayed if findings do not reach the responsible team.
Remediation
Set Enable to true on AWS::GuardDuty::Detector and verify coverage in the required accounts and Regions. Review the protection features needed by the workload and connect findings to alerting, investigation and response procedures.
Examples
The examples compare the enabled state of the same Detector resource. FindingPublishingFrequency controls publication of updates to existing findings; it does not guarantee detection of every threat within that period.
Before
AWSTemplateFormatVersion: "2010-09-09"
Resources:
mydetector3:
Type: AWS::GuardDuty::Detector
Properties:
Enable: false
FindingPublishingFrequency: FIFTEEN_MINUTES
The Detector is disabled and does not perform GuardDuty analysis.
After
AWSTemplateFormatVersion: "2010-09-09"
Resources:
mydetector3:
Type: AWS::GuardDuty::Detector
Properties:
Enable: true
FindingPublishingFrequency: FIFTEEN_MINUTES
The same Detector is enabled. Also verify the required protection features and handling of findings.