High GuardDuty Regional

GuardDuty Malware Protection for EC2 should be enabled

FSBP

Description

Ensures GuardDuty Malware Protection is enabled across all accounts to detect malware on EBS volumes attached to EC2 instances and container workloads.


Remediation

To enable GuardDuty Malware Protection for EC2, you need to configure the Malware Protection settings in GuardDuty.

Steps

  1. Navigate to the Amazon GuardDuty console
  2. Go to 'Settings' in the left navigation
  3. Select 'Malware Protection'
  4. Enable 'Malware Protection for EC2'
  5. Configure scan options and exclusions as needed
  6. Set snapshot retention preferences
  7. Save the configuration
  8. Verify that Malware Protection is active

Compliance

FSBP