GuardDuty detector is disabled

Enable GuardDuty in the accounts and Regions covered by security monitoring.

Description

When a GuardDuty detector has enable set to false, GuardDuty threat analysis is suspended in that account and Region.

Potential impact

Environments relying on GuardDuty can develop gaps in identifying and responding to suspicious activity.

Remediation

Set enable = true and check coverage across the required accounts and Regions. Assign responsibility and procedures for reviewing and responding to findings.

Examples

The examples enable the GuardDuty detector. Configure any additional protection features and finding notifications separately.

Before

hcl
resource "aws_guardduty_detector" "example" {
  enable = false
}

After

hcl
resource "aws_guardduty_detector" "example" {
  enable = true
}

References