A company has Windows Amazon EC2 instances in a VPC that are joined to on-premises Active Directory servers for domain services. The security team has enabled Amazon GuardDuty on the AWS account to alert on issues with the instances.
During a weekly audit of network traffic, the Security Engineer notices that one of the EC2 instances is attempting to communicate with a known command-and- control server but failing. This alert does not show up in GuardDuty.
Why did GuardDuty fail to alert to this behavior?
examacc
Highly Voted 3 years, 8 months agoJohn129087
3 years, 7 months agoGustava6272
3 years, 7 months agof4bi4n
3 years, 5 months agojosellama2000
Highly Voted 3 years, 8 months agoDahMac
3 years, 7 months agoexams
3 years, 8 months agoEricJason
3 years, 8 months agoRaphaello
Most Recent 1 year, 4 months agoOCHT
2 years agovavofa5697
2 years, 1 month agoITGURU51
2 years, 2 months agotezawynn
3 years, 3 months agomx677
3 years, 3 months agoalghoundar
3 years, 4 months agoRadhaghosh
3 years, 4 months agoElva
3 years, 7 months agoPonzy
3 years, 7 months agojohnsm
3 years, 7 months agodevjava
3 years, 7 months agoAfricanCloudGuru
3 years, 7 months agoMr_Zaw
3 years, 7 months agosunilrch
3 years, 7 months ago