High
GuardDuty
Regional
GuardDuty Malware Protection for EC2 should be enabled
FSBP
Description
Ensures GuardDuty Malware Protection is enabled across all accounts to detect malware on EBS volumes attached to EC2 instances and container workloads.
Remediation
To enable GuardDuty Malware Protection for EC2, you need to configure the Malware Protection settings in GuardDuty.
Steps
- Navigate to the Amazon GuardDuty console
- Go to 'Settings' in the left navigation
- Select 'Malware Protection'
- Enable 'Malware Protection for EC2'
- Configure scan options and exclusions as needed
- Set snapshot retention preferences
- Save the configuration
- Verify that Malware Protection is active
Compliance
FSBP