AWS Security ChangesHomeSearch

AWS guardduty: Document redacted CloudTrail event fields for Custom Detection Rules

Service: guardduty · 2026-09-27 · Documentation low

File: guardduty/latest/ug/custom-detection-rules-how-it-works.md · Type: logging

Summary

Adds a new 'Redacted event fields' section explaining that AWS services can redact sensitive field values in CloudTrail events upstream of GuardDuty, that rules depending on redacted fields will not match, and that Custom Detection Rules are not a complete audit record.

Security assessment

Documents a detection blind spot: redacted fields cause rules to silently not match, and directs users to CloudTrail for audit confirmation. This is security-relevant guidance about data protection and detection coverage, but does not address a specific vulnerability or CVE.

Evidence

+Custom Detection Rules evaluate the fields that AWS CloudTrail records in an event. Redaction happens upstream of GuardDuty. An AWS service can redact the value of a field in the events that it publishes. This redaction protects potentially sensitive data. When a field is redacted, AWS CloudTrail records that the field was present but does not record its value.

Diff

diff --git a/guardduty/latest/ug/custom-detection-rules-how-it-works.md b/guardduty/latest/ug/custom-detection-rules-how-it-works.md
index cb1814f29..bb4258348 100644
--- a//guardduty/latest/ug/custom-detection-rules-how-it-works.md
+++ b//guardduty/latest/ug/custom-detection-rules-how-it-works.md
@@ -7 +7 @@
-Data sources and signalsModesFinding aggregation
+Data sources and signalsModesFinding aggregationRedacted event fields
@@ -35,0 +36,14 @@ For more information about the finding structure and fields, see [Custom Detecti
+## Redacted event fields
+
+Custom Detection Rules evaluate the fields that AWS CloudTrail records in an event. Redaction happens upstream of GuardDuty. An AWS service can redact the value of a field in the events that it publishes. This redaction protects potentially sensitive data. When a field is redacted, AWS CloudTrail records that the field was present but does not record its value.
+
+The service that publishes the event decides which fields it redacts. A service redacts a field when that field can carry sensitive information. The redaction applies to the field, not to a specific value. A service therefore redacts a field even when the value in a particular request is not sensitive. It redacts those fields for every request, regardless of whether you use the AWS Management Console, the AWS CLI, or an AWS SDK.
+
+GuardDuty cannot evaluate a value that is not in the event. If a rule's detection logic depends on a redacted field, the rule does not match. GuardDuty then produces no signal and no finding, even though the activity occurred. A rule is unaffected if it inspects only fields that services do not redact, such as the event name, the AWS service, and the calling identity.
+
+Redaction can also make a rule match one request but not another that had the same effect. When an API operation accepts more than one field for the same change, one field might be redacted and another might not. Whether the rule matches then depends on which field the request used.
+
+###### Note
+
+Custom Detection Rules are a detection capability, not a complete audit record. To confirm whether a specific API call occurred in your account, review the event in AWS CloudTrail. For more information, see [Viewing events with AWS CloudTrail Event history](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/view-cloudtrail-events.html).
+