Description
When a GuardDuty detector has enable set to false, GuardDuty threat analysis is suspended in that account and Region.
Potential impact
Environments relying on GuardDuty can develop gaps in identifying and responding to suspicious activity.
Remediation
Set enable = true and check coverage across the required accounts and Regions. Assign responsibility and procedures for reviewing and responding to findings.
Examples
The examples enable the GuardDuty detector. Configure any additional protection features and finding notifications separately.
Before
hcl
resource "aws_guardduty_detector" "example" {
enable = false
}
After
hcl
resource "aws_guardduty_detector" "example" {
enable = true
}