Enable AWS GuardDuty Malware Protection for EC2 and S3 and process resulting findings via the GuardDuty API

domain: docs.aws.amazon.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Ensure GuardDuty is enabled for the account/region, then enable Malware Protection for EC2 (agentless EBS volume scanning) and Malware Protection for S3 on selected buckets.
  2. For S3, configure the scan to tag or route objects based on scan status and set up an EventBridge rule for Malware Protection for S3 finding events.
  3. For EC2, malware scans trigger automatically on qualifying GuardDuty EC2 finding types; retrieve scan configuration and status through the GuardDuty malware protection API/SDK calls.
  4. Call GetFindings/ListFindings with a finding-criteria filter on type prefixes like Execution:EC2/MaliciousFile or Object:S3/MaliciousFile to pull malware-specific findings.
  5. Route findings to a SIEM or ticketing system via EventBridge, and check the malware protection scan status fields to confirm scans completed rather than were skipped.

Known gotchas

Related routes

Retrieve and filter Amazon GuardDuty findings via API
docs.aws.amazon.com · 6 steps · unrated
Export Amazon GuardDuty findings and automate responses via EventBridge
docs.aws.amazon.com · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans