AWS guardduty: GuardDuty doc history: SLR permissions, AI Protection, redacted fields
Summary
Adds changelog entries for Runtime Monitoring agent 1.17.1, a consolidated supported-platforms page, redacted CloudTrail event fields guidance, AI Protection contributing to Extended Threat Detection, and an updated service-linked role adding vpc-lattice permissions.
Security assessment
Changelog entry documents an expansion of the GuardDuty service-linked role with new VPC Lattice IAM permissions, which is IAM-permission-relevant, plus other security capability updates. It is documentation of a permission change rather than a fix for a specific vulnerability.
Evidence
+Updated GuardDuty service-linked role (SLR)| GuardDuty has updated the service-linked role (SLR) to include the `vpc-lattice:CreateServiceNetworkVpcAssociation` and `vpc-lattice:AssociateViaAWSService` permissions. These permissions allow GuardDuty to use Amazon VPC Lattice actions to enable connectivity for the Runtime Monitoring agent. For more information, see [Service-linked role permissions for GuardDuty](https://docs.aws.amazon.com/guardduty/latest/ug/slr-permissions.html).| September 9, 2026
Diff
diff --git a/guardduty/latest/ug/doc-history.md b/guardduty/latest/ug/doc-history.md index 47a0706ea..35e97e88c 100644 --- a//guardduty/latest/ug/doc-history.md +++ b//guardduty/latest/ug/doc-history.md @@ -14,0 +15,5 @@ Change| Description| Date +Updated functionality - Runtime Monitoring| GuardDuty Runtime Monitoring releases the new security agent version 1.17.1 for Amazon EKS, Amazon EC2, and Amazon ECS-AWS Fargate resources. For more information about the new agent version and a list of additional resources to update your security agent, see [GuardDuty security agent release versions](https://docs.aws.amazon.com/guardduty/latest/ug/runtime-monitoring-agent-release-history.html).| September 18, 2026 +Updated documentation - Runtime Monitoring supported platforms| GuardDuty Runtime Monitoring added a consolidated [Supported CPU architectures, operating systems, and kernel versions](https://docs.aws.amazon.com/guardduty/latest/ug/prereq-runtime-monitoring-cpu-os-kernel-support.html) page. The prerequisites pages for Amazon EC2 instances, AWS Fargate (Amazon ECS only), and Amazon EKS clusters now reference this page for the verified CPU architectures, OS distributions, and kernel versions. This page now include Bottlerocket kernel version 6.18.| September 18, 2026 +Documented redacted AWS CloudTrail event fields for Custom Detection Rules| Added guidance explaining that an AWS service can redact the value of a field in the AWS CloudTrail events that it publishes, and that a Custom Detection Rule whose detection logic depends on a redacted field does not match. For more information, see [Redacted event fields](https://docs.aws.amazon.com/guardduty/latest/ug/custom-detection-rules-how-it-works.html#custom-detection-rules-how-it-works-redacted-fields).| September 18, 2026 +AI Protection contributes to attack sequence detection| GuardDuty Extended Threat Detection now includes GuardDuty AI Protection findings among the signals that it correlates to detect an attack sequence. For more information, see [GuardDuty Extended Threat Detection](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty-extended-threat-detection.html) and [GuardDuty AI Protection](https://docs.aws.amazon.com/guardduty/latest/ug/ai-protection.html).| September 17, 2026 +Updated GuardDuty service-linked role (SLR)| GuardDuty has updated the service-linked role (SLR) to include the `vpc-lattice:CreateServiceNetworkVpcAssociation` and `vpc-lattice:AssociateViaAWSService` permissions. These permissions allow GuardDuty to use Amazon VPC Lattice actions to enable connectivity for the Runtime Monitoring agent. For more information, see [Service-linked role permissions for GuardDuty](https://docs.aws.amazon.com/guardduty/latest/ug/slr-permissions.html).| September 9, 2026