GuardDuty is disabled

Enable GuardDuty in the required accounts and Regions and connect findings to incident response.

Description

When GuardDuty is disabled, it does not perform threat detection in the affected account and Region. A detection layer for malicious activity or account misuse may be missing.

This does not mean that other security tools stop detecting threats. Enabling GuardDuty does not itself block threats; configure protection coverage and responses to findings separately.

Potential impact

  • Suspicious API calls or network activity may be discovered later.
  • Response may be delayed if findings do not reach the responsible team.

Remediation

Set Enable to true on AWS::GuardDuty::Detector and verify coverage in the required accounts and Regions. Review the protection features needed by the workload and connect findings to alerting, investigation and response procedures.

Examples

The examples compare the enabled state of the same Detector resource. FindingPublishingFrequency controls publication of updates to existing findings; it does not guarantee detection of every threat within that period.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  mydetector3:
    Type: AWS::GuardDuty::Detector
    Properties:
      Enable: false
      FindingPublishingFrequency: FIFTEEN_MINUTES

The Detector is disabled and does not perform GuardDuty analysis.

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  mydetector3:
    Type: AWS::GuardDuty::Detector
    Properties:
      Enable: true
      FindingPublishingFrequency: FIFTEEN_MINUTES

The same Detector is enabled. Also verify the required protection features and handling of findings.

References