Ensure that Malware Protection for EC2 is enabled for your Amazon GuardDuty detectors. Malware Protection for EC2 helps detect potential malware in Amazon EC2 instances and container workloads. Once enabled, the feature scans the EBS volumes attached to your Amazon EC2 instances.
This rule can help you work with the AWS Well-Architected Framework.
This rule resolution is part of the Conformity Security & Compliance tool for AWS.
Enabling GuardDuty Malware Protection for Amazon EC2 resources enhances security by detecting and analyzing malicious files, reducing the risk of data breaches or compromised workloads. It provides early threat detection, helping to identify malware infections and allowing for quicker remediation, thus ensuring the integrity and security of your AWS cloud environment.
Audit
To determine if Malware Protection for EC2 is enabled for your Amazon GuardDuty detectors, perform the following operations:
Remediation / Resolution
To enable Malware Protection for EC2 for your Amazon GuardDuty detectors, perform the following operations:
References
- AWS Documentation
- What is Amazon GuardDuty?
- Concepts and terminology
- GuardDuty Malware Protection for EC2
- GuardDuty-initiated malware scan
- On-demand malware scan in GuardDuty
- AWS Command Line Interface (CLI) Documentation
- list-detectors
- get-detector
- update-detector
- start-malware-scan