AWS guardduty: Note nested field dependency and redacted CloudTrail fields
Summary
Adds a note that custom detection rules inspecting nested fields depend on the field being present, linking to documentation about CloudTrail redacted event fields.
Security assessment
The added note helps detection engineers understand that rules relying on nested fields may not fire when CloudTrail redacts those fields, improving detection-rule reliability; it is security-adjacent guidance rather than a fix for a specific vulnerability.
Evidence
A rule that inspects a nested field depends on that field being present in the event. For more information about fields that AWS CloudTrail does not record, see [Redacted event fields](./custom-detection-rules-how-it-works.html#custom-detection-rules-how-it-works-redacted-fields).
Diff
diff --git a/guardduty/latest/ug/custom-detection-rules-available.md b/guardduty/latest/ug/custom-detection-rules-available.md index f5d78e9e6..d37d7177c 100644 --- a//guardduty/latest/ug/custom-detection-rules-available.md +++ b//guardduty/latest/ug/custom-detection-rules-available.md @@ -39,0 +40,2 @@ Custom Detection Rules use SQL conditions that evaluate AWS CloudTrail event fie +A rule that inspects a nested field depends on that field being present in the event. For more information about fields that AWS CloudTrail does not record, see [Redacted event fields](./custom-detection-rules-how-it-works.html#custom-detection-rules-how-it-works-redacted-fields). +