turbot/aws_compliance

Control: GuardDuty Detector should not have high severity findings

Description

GuardDuty generates a finding whenever it detects unexpected and potentially malicious activity in your AWS environment. If critical findings are not addressed threats can spread in the environment. This rule is non-compliant if there are high severity findings.

Usage

Run the control in your terminal:

powerpipe control run aws_compliance.control.guardduty_no_high_severity_findings

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run aws_compliance.control.guardduty_no_high_severity_findings --share

SQL

This control uses a named query:

guardduty_no_high_severity_findings

Tags