2026/07/22 - 1 updated api methods
Changes Amazon GuardDuty now returns filter lifecycle metadata in GetFilter responses. The response includes createdAt and updatedAt timestamps and a version number that increments on each update, giving you visibility into when a filter was created and last modified.
2026/07/13 - 11 updated api methods
Changes GuardDuty AI Protection is now publicly available. Findings include Bedrock guardrail details, model details, observation numbers, and continuous scan details. GuardrailArn and GuardrailVersion are deprecated in favor of the guardrails list.
2026/07/09 - 3 updated api methods
Changes Adding "AI Analyst" enum value for detector
2026/06/22 - 3 new api methods
Changes Added AI-powered investigations that automatically analyze security findings, correlate related activity, and produce structured summaries with risk assessment, confidence scoring, MITRE technique classification, and actionable next steps.
2026/06/02 - 1 updated api methods
Changes Amazon GuardDuty Runtime Monitoring now supports 3 new SensitiveFileModified finding types (Persistence, PrivilegeEscalation, DefenseEvasion) that detect when security-sensitive system files are modified on EC2 instances or containers, indicating potential compromise through file tampering.
2026/05/26 - 3 updated api methods
Changes Add malware scan support for Continuous Backups, also known as Point-In-Time Recovery Points (PITR).
2026/05/19 - 1 updated api methods
Changes Adding support for exposure and vulnerability context from AWS Security Hub in GuardDuty Extended Threat Detection attack sequence findings.
2026/03/05 - 1 updated api methods
Changes Added MALICIOUS FILE to IndicatorType enum in MDC Sequence
2026/01/22 - 1 updated api methods
Changes Adding new enum value for ScanStatusReason
2025/12/17 - 1 updated api methods
Changes Add support for dbiResourceId in finding.
2025/12/02 - 6 updated api methods
Changes Adding support for extended threat detection for Amazon EC2 and Amazon ECS. Adding support for wild card suppression rules.
2025/11/19 - 2 new 3 updated api methods
Changes Add support for scanning and viewing scan results for backup resource types
2025/11/17 - 1 new api methods
Changes Add S3 On-Demand Object Scanning
2025/11/10 - 2 updated api methods
Changes Include tags filed in CreatePublishingDestinationRequest and DescribePublishingDestinationResponse.
2025/08/14 - 10 new api methods
Changes Added support for entity lists.
2025/08/07 - 1 updated api methods
Changes Added support for VPC owner account ID associated with DNS request in the GuardDuty finding.
2025/07/16 - 6 updated api methods
Changes Add expectedBucketOwner parameter to ThreatIntel and IPSet APIs.
2025/06/17 - 1 updated api methods
Changes Adding support for extended threat detection for EKS Audit Logs and EKS Runtime Monitoring.
2024/12/02 - 1 updated api methods
Changes Add new Multi Domain Correlation findings.
2024/11/06 - 1 updated api methods
Changes GuardDuty RDS Protection expands support for Amazon Aurora PostgreSQL Limitless Databases.
2024/10/11 - 1 updated api methods
Changes Added a new field for network connection details.
2024/09/18 - 1 updated api methods
Changes Add `launchType` and `sourceIPs` fields to GuardDuty findings.
2024/09/11 - 1 updated api methods
Changes Add support for new statistic types in GetFindingsStatistics.