AWS - What's new RSS feed.
97 subscribers
17.3K links
AWS "What's news" channel managed by #AntonioFeijaoUK.
Currently posting "What's new", from the AWS RSS feed.

>> Join this other channel for comments and discussion about services https://t.me/awscloud_chatter_group
Download Telegram
Feed Reader Bot
Recent Announcements GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan
@agent_dell001_bot explained this service, this new feature and were and how it can be used. Use simple terms but technically accurate.
Antonio Feijao UK
@agent_dell001_bot explained this service, this new feature and were and how it can be used. Use simple terms but technically accurate.
What is GuardDuty Runtime Monitoring? 🔍

Amazon GuardDuty is AWS’s threat-detection service. Runtime Monitoring looks at what’s happening while workloads are running—not just how they’re configured. A GuardDuty security agent observes operating-system, process, file, and network activity to spot suspicious behavior. It covers EC2 instances, EKS clusters, and ECS tasks on AWS Fargate; EKS clusters running on Fargate aren’t supported.[2]

For example, it may detect signs of a container escape, an attempt to gain higher privileges, or cryptomining activity.[1]

What’s new? 💡

Runtime Monitoring is now part of the Security Hub Threat Analytics plan—an optional add-on to Security Hub’s Essentials plan.[3] The main change is how it’s packaged and billed, not how it detects threats: AWS says the coverage, findings, and GuardDuty agents stay the same.[1]

If Security Hub is enabled for an account and Region, Runtime Monitoring charges for that account and Region move from separate GuardDuty line items to AWS Security Hub billing. It isn’t a new free trial, so check the plan’s pricing and your usage.[1]

Where and how do you use it? 🛠️

- In the AWS Security Hub console, enable Security Hub and add the Threat Analytics plan; the Essentials plan is its foundation.[3][4]
- Enable GuardDuty Runtime Monitoring for the workload types you want to protect. GuardDuty’s agent can be managed automatically or manually; ECS on Fargate uses a fully managed agent.[2]
- Review security findings and check usage in Security Hub and AWS Cost Explorer.[1]

Already using both Security Hub and Runtime Monitoring? AWS says no reconfiguration is needed for this billing change. If Runtime Monitoring or the Threat Analytics plan isn’t enabled, you’ll need to enable it to use this coverage through the plan.[1]

Sources
[1] https://aws.amazon.com/about-aws/whats-new/2026/10/aws-security-hub-runtime-monitoring — AWS announcement
[2] https://docs.aws.amazon.com/guardduty/latest/ug/runtime-monitoring.html — GuardDuty Runtime Monitoring documentation
[3] https://aws.amazon.com/security-hub/pricing — AWS Security Hub Pricing
[4] https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-v2-enable.html — Enabling Security Hub documentation