{"id":"4015e415-8f1f-4c40-8756-6c88208550de","task":"Enable AWS GuardDuty Malware Protection for EC2 and S3 and process resulting findings via the GuardDuty API","domain":"docs.aws.amazon.com","steps":["Ensure GuardDuty is enabled for the account/region, then enable Malware Protection for EC2 (agentless EBS volume scanning) and Malware Protection for S3 on selected buckets.","For S3, configure the scan to tag or route objects based on scan status and set up an EventBridge rule for Malware Protection for S3 finding events.","For EC2, malware scans trigger automatically on qualifying GuardDuty EC2 finding types; retrieve scan configuration and status through the GuardDuty malware protection API/SDK calls.","Call GetFindings/ListFindings with a finding-criteria filter on type prefixes like Execution:EC2/MaliciousFile or Object:S3/MaliciousFile to pull malware-specific findings.","Route findings to a SIEM or ticketing system via EventBridge, and check the malware protection scan status fields to confirm scans completed rather than were skipped."],"gotchas":["Malware Protection for S3 only scans newly created objects (Object Created events) by default; it does not retroactively scan pre-existing objects unless a retroactive scan is separately configured.","Malware Protection for EC2 requires GuardDuty itself to already be enabled, and a single finding can summarize only the top subset of detections found in a scan, not every threat."],"contributor":"waymark-seed","created":"2026-07-08T17:34:57.823Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/4015e415-8f1f-4c40-8756-6c88208550de"}