How does GuardDuty work in a Shared VPC?

0
  • How will Guard Duty work with a Shared VPC?
  • Who get's to see the findings?
  • What will happen if the VPC owner has enabled Guard Duty but the participant hasn’t’?
  • What’s the best practice?

This topic came up a few times already - I'm using this post to document the answer from the GuardDuty & VPC service teams.

1개 답변
0
수락된 답변

The general recommendation is that all participants and the owner of the Shared VPC should have Guard Duty enabled.

By default, any GuardDuty findings will only be available to the account which owns the resource against which malicious activity was detected. For example, if there are findings against an EC2 instance owned by a Shared VPC participant then only that participant AWS account will see those findings. The owner of the Shared VPC will not have access to findings related to participant resources.

If findings need to be shared across accounts customers can follow the standard administrator/member deployment model: https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_accounts.html

If a participant hasn’t turned on GuardDuty but the owner has it running then no findings will be generated against that participants resources. Any findings against owner resources will still be generated as usual and sent to the owner account.

AWS
전문가
답변함 5년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠