Skip to content
Threat Feed

Product

GuardDuty

8 briefs RSS
medium advisory

AWS GuardDuty Publishing Destination Deletion

Adversaries with administrative access to AWS GuardDuty may delete publishing destinations to break security finding exports, effectively blinding SOC monitoring without triggering detector-disabling alerts.

GuardDuty cloud aws defense-evasion
1r 1t
medium advisory

Detection of Unauthorized AWS GuardDuty Threat Intelligence Set Deletion

Adversaries may delete Amazon GuardDuty threat intelligence sets to blind detection capabilities by removing custom feeds of known-malicious IP addresses and domains.

GuardDuty
1r 1t
high advisory

AWS GuardDuty Member Account Manipulation

Adversaries manipulate Amazon GuardDuty member accounts within an AWS organization by using API calls such as `DisassociateFromAdministratorAccount`, `DeleteMembers`, `StopMonitoringMembers`, or `DeleteInvitations` to break centralized security visibility, enabling them to operate undetected in compromised member accounts.

Amazon GuardDuty +1 cloud aws defense-evasion amazon-guardduty
1r 1t updated
high advisory

AWS GuardDuty Detector Deletion

Detection of AWS GuardDuty detector deletion via the DeleteDetector API, potentially indicating defense evasion by an attacker disabling threat monitoring and removing findings.

GuardDuty cloud aws defense-evasion
2r 1t
high advisory

AWS GuardDuty Detector Deletion or Disablement

Attackers may delete or disable AWS GuardDuty detectors to impair defenses and evade detection of malicious activities within the AWS environment.

GuardDuty defense-impairment aws cloudtrail
3r
medium advisory

AWS GuardDuty Member Account Manipulation

Adversaries may attempt to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization to break centralized visibility, allowing them to operate undetected in member accounts.

GuardDuty aws defense_evasion
2r 1t
high advisory

AWS Security Services Impairment via Deletion of Resources

Detection of adversaries attempting to impair or disable AWS security services by deleting resources across GuardDuty, AWS WAF, CloudWatch, Route 53, and CloudWatch Logs to evade detection and remove visibility.

CloudWatch +5 aws cloudtrail defense-evasion cloud
2r 1t
high advisory

AWS Security Services Configuration Deletion

Detection of deletion of critical AWS Security Services configurations like CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules to evade detection, potentially leading to data breaches and unauthorized access.

CloudWatch +5 aws cloudtrail defense-evasion security-service
2r 1t