AWS Security ChangesHomeSearch

AWS guardduty medium security documentation change

Service: guardduty · 2025-12-07 · Security-related medium

File: guardduty/latest/ug/doc-history.md

Summary

Added entries for Runtime Monitoring agent updates (v1.9.1 EC2, v1.12.1 EKS), wildcard support in suppression rules, and CloudWatch usage metrics

Security assessment

Security agent updates (v1.9.1 and v1.12.1) likely include security improvements (though not explicitly stated). Wildcard support in suppression rules enhances security management capabilities. Agent updates could address vulnerabilities, warranting 'security_issue_related' flag.

Diff

diff --git a/guardduty/latest/ug/doc-history.md b/guardduty/latest/ug/doc-history.md
index e9dc8cb62..e0c3cffbe 100644
--- a//guardduty/latest/ug/doc-history.md
+++ b//guardduty/latest/ug/doc-history.md
@@ -12,0 +13,2 @@ Change| Description| Date
+Updated functionality - Runtime Monitoring| GuardDuty Runtime Monitoring releases new security agent version 1.9.1 for Amazon EC2 resources. For more information about new agent versions and a list of additional resources to update your security agent, see [GuardDuty security agent release versions](https://docs.aws.amazon.com/guardduty/latest/ug/runtime-monitoring-agent-release-history.html). | December 2, 2025  
+Updated functionality - Runtime Monitoring| GuardDuty Runtime Monitoring releases the new security agent version 1.12.1 for Amazon EKS resources. For more information about the new agent version and a list of additional resources to update your security agent, see [GuardDuty security agent release versions](https://docs.aws.amazon.com/guardduty/latest/ug/runtime-monitoring-agent-release-history.html). | December 2, 2025  
@@ -13,0 +16,2 @@ Updated functionality - Extended Threat Detection| GuardDuty Extended Threat Det
+New feature - Wildcards in Suppression Rules| GuardDuty has enhanced its suppression capabilities with the introduction of Matches and NotMatches Conditions that support wildcards. Customers can now use * (to match any number of characters) and ? (to match at most 1 character) as wildcards when creating suppression rules. [Suppression rules](https://docs.aws.amazon.com/guardduty/latest/ug/findings_suppression-rule.html). | December 2, 2025  
+New feature - Amazon CloudWatch Usage Metrics Support| GuardDuty introduces publishing usage metrics in Amazon CloudWatch for all protection plans, enabling customers to monitor usage. For more information, see [Monitoring GuardDuty Usage and Estimating Costs](https://docs.aws.amazon.com/guardduty/latest/ug/monitoring_costs.html) | November 25, 2025