Recent Announcements
AWS Health introduces the version catalog for software lifecycle management
AWS Health introduces the version catalog for software lifecycle management
Amazon
AWS Health introduces the version catalog for software lifecycle management - AWS
Discover more about what's new at AWS with AWS Health introduces the version catalog for software lifecycle management
Recent Announcements
Amazon ECS adds Amazon VPC Lattice support for blue/green, linear, and canary deployments
Amazon ECS adds Amazon VPC Lattice support for blue/green, linear, and canary deployments
Amazon
Amazon ECS adds Amazon VPC Lattice support for blue/green, linear, and canary deployments - AWS
Discover more about what's new at AWS with Amazon ECS adds Amazon VPC Lattice support for blue/green, linear, and canary deployments
Feed Reader Bot
Recent Announcements GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan
@agent_dell001_bot explained this service, this new feature and were and how it can be used. Use simple terms but technically accurate.
Antonio Feijao UK
@agent_dell001_bot explained this service, this new feature and were and how it can be used. Use simple terms but technically accurate.
What is GuardDuty Runtime Monitoring? 🔍
Amazon GuardDuty is AWS’s threat-detection service. Runtime Monitoring looks at what’s happening while workloads are running—not just how they’re configured. A GuardDuty security agent observes operating-system, process, file, and network activity to spot suspicious behavior. It covers EC2 instances, EKS clusters, and ECS tasks on AWS Fargate; EKS clusters running on Fargate aren’t supported.[2]
For example, it may detect signs of a container escape, an attempt to gain higher privileges, or cryptomining activity.[1]
What’s new? 💡
Runtime Monitoring is now part of the Security Hub Threat Analytics plan—an optional add-on to Security Hub’s Essentials plan.[3] The main change is how it’s packaged and billed, not how it detects threats: AWS says the coverage, findings, and GuardDuty agents stay the same.[1]
If Security Hub is enabled for an account and Region, Runtime Monitoring charges for that account and Region move from separate GuardDuty line items to AWS Security Hub billing. It isn’t a new free trial, so check the plan’s pricing and your usage.[1]
Where and how do you use it? 🛠️
- In the AWS Security Hub console, enable Security Hub and add the Threat Analytics plan; the Essentials plan is its foundation.[3][4]
- Enable GuardDuty Runtime Monitoring for the workload types you want to protect. GuardDuty’s agent can be managed automatically or manually; ECS on Fargate uses a fully managed agent.[2]
- Review security findings and check usage in Security Hub and AWS Cost Explorer.[1]
Already using both Security Hub and Runtime Monitoring? AWS says no reconfiguration is needed for this billing change. If Runtime Monitoring or the Threat Analytics plan isn’t enabled, you’ll need to enable it to use this coverage through the plan.[1]
Sources
[1] https://aws.amazon.com/about-aws/whats-new/2026/10/aws-security-hub-runtime-monitoring — AWS announcement
[2] https://docs.aws.amazon.com/guardduty/latest/ug/runtime-monitoring.html — GuardDuty Runtime Monitoring documentation
[3] https://aws.amazon.com/security-hub/pricing — AWS Security Hub Pricing
[4] https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-v2-enable.html — Enabling Security Hub documentation
Amazon GuardDuty is AWS’s threat-detection service. Runtime Monitoring looks at what’s happening while workloads are running—not just how they’re configured. A GuardDuty security agent observes operating-system, process, file, and network activity to spot suspicious behavior. It covers EC2 instances, EKS clusters, and ECS tasks on AWS Fargate; EKS clusters running on Fargate aren’t supported.[2]
For example, it may detect signs of a container escape, an attempt to gain higher privileges, or cryptomining activity.[1]
What’s new? 💡
Runtime Monitoring is now part of the Security Hub Threat Analytics plan—an optional add-on to Security Hub’s Essentials plan.[3] The main change is how it’s packaged and billed, not how it detects threats: AWS says the coverage, findings, and GuardDuty agents stay the same.[1]
If Security Hub is enabled for an account and Region, Runtime Monitoring charges for that account and Region move from separate GuardDuty line items to AWS Security Hub billing. It isn’t a new free trial, so check the plan’s pricing and your usage.[1]
Where and how do you use it? 🛠️
- In the AWS Security Hub console, enable Security Hub and add the Threat Analytics plan; the Essentials plan is its foundation.[3][4]
- Enable GuardDuty Runtime Monitoring for the workload types you want to protect. GuardDuty’s agent can be managed automatically or manually; ECS on Fargate uses a fully managed agent.[2]
- Review security findings and check usage in Security Hub and AWS Cost Explorer.[1]
Already using both Security Hub and Runtime Monitoring? AWS says no reconfiguration is needed for this billing change. If Runtime Monitoring or the Threat Analytics plan isn’t enabled, you’ll need to enable it to use this coverage through the plan.[1]
Sources
[1] https://aws.amazon.com/about-aws/whats-new/2026/10/aws-security-hub-runtime-monitoring — AWS announcement
[2] https://docs.aws.amazon.com/guardduty/latest/ug/runtime-monitoring.html — GuardDuty Runtime Monitoring documentation
[3] https://aws.amazon.com/security-hub/pricing — AWS Security Hub Pricing
[4] https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-v2-enable.html — Enabling Security Hub documentation
Amazon
GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan - AWS
Discover more about what's new at AWS with GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan
Recent Announcements
AWS Continuum for Penetration Testing now supports continuous penetration testing integrated directly into your CI/CD pipeline
AWS Continuum for Penetration Testing now supports continuous penetration testing integrated directly into your CI/CD pipeline
Amazon
AWS Continuum for Penetration Testing now supports continuous penetration testing integrated directly into your CI/CD pipeline…
Discover more about what's new at AWS with AWS Continuum for Penetration Testing now supports continuous penetration testing integrated directly into your CI/CD pipeline
Recent Announcements
AWS IAM Identity Center now supports network access controls for Identity Store
AWS IAM Identity Center now supports network access controls for Identity Store
Amazon
AWS IAM Identity Center now supports network access controls for Identity Store - AWS
Discover more about what's new at AWS with AWS IAM Identity Center now supports network access controls for Identity Store
Recent Announcements
Amazon Redshift adds support for creating and refreshing Apache Iceberg materialized views
Amazon Redshift adds support for creating and refreshing Apache Iceberg materialized views
Amazon
Amazon Redshift adds support for creating and refreshing Apache Iceberg materialized views - AWS
Discover more about what's new at AWS with Amazon Redshift adds support for creating and refreshing Apache Iceberg materialized views
Recent Announcements
AWS Certificate Manager now supports ACME issuance through AWS PrivateLink
AWS Certificate Manager now supports ACME issuance through AWS PrivateLink
Amazon
AWS Certificate Manager now supports ACME issuance through AWS PrivateLink - AWS
Discover more about what's new at AWS with AWS Certificate Manager now supports ACME issuance through AWS PrivateLink