turbot/aws_compliance

Control: 1 GuardDuty should be enabled

Description

This control checks whether Amazon GuardDuty is enabled in your AWS account and Region.

While GuardDuty can be effective against attacks that an intrusion detection system would typically protect, it might not be a complete solution for every environment. This rule also does not check for the generation of alerts to personnel. For more information about GuardDuty, see the Amazon GuardDuty User Guide.

Remediation

To remediate this issue, you enable GuardDuty.

Refer here for more Getting started with GuardDuty.

Usage

Run the control in your terminal:

powerpipe control run aws_compliance.control.foundational_security_guardduty_1

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run aws_compliance.control.foundational_security_guardduty_1 --share

SQL

This control uses a named query:

guardduty_enabled

Tags