SecurityConfig / CentralSecurityServicesConfig / GuardDutyConfig

AWS GuardDuty configuration Use this configuration to enable Amazon GuardDuty for an AWS Organization, as well as other modular feature protections.

guardduty:
enable: true
excludeRegions: []
s3Protection:
enable: true
excludeRegions: []
eksProtection:
enable: true
excludeRegions: []
ec2Protection:
enable: true
keepSnapshots: true
excludeRegions: []
rdsProtection:
enable: true
excludeRegions: []
lambdaProtection:
enable: true
excludeRegions: []
exportConfiguration:
enable: true
overrideExisting: true
destinationType: S3
exportFrequency: FIFTEEN_MINUTES
lifecycleRules: []
interface IGuardDutyConfig {
    autoEnableOrgMembers?: boolean;
    deploymentTargets?: IDeploymentTargets;
    ec2Protection?: IGuardDutyEc2ProtectionConfig;
    eksProtection?: IGuardDutyEksProtectionConfig;
    enable: boolean;
    excludeRegions?: (
        | "af-south-1"
        | "ap-east-1"
        | "ap-east-2"
        | "ap-northeast-1"
        | "ap-northeast-2"
        | "ap-northeast-3"
        | "ap-south-1"
        | "ap-south-2"
        | "ap-southeast-1"
        | "ap-southeast-2"
        | "ap-southeast-3"
        | "ap-southeast-4"
        | "ap-southeast-5"
        | "ap-southeast-7"
        | "ca-central-1"
        | "ca-west-1"
        | "cn-north-1"
        | "cn-northwest-1"
        | "eu-central-1"
        | "eu-central-2"
        | "eu-north-1"
        | "eu-south-1"
        | "eu-south-2"
        | "eu-west-1"
        | "eu-west-2"
        | "eu-west-3"
        | "eu-isoe-west-1"
        | "il-central-1"
        | "me-central-1"
        | "me-south-1"
        | "mx-central-1"
        | "sa-east-1"
        | "us-east-1"
        | "us-east-2"
        | "us-gov-west-1"
        | "us-gov-east-1"
        | "us-iso-east-1"
        | "us-isob-east-1"
        | "us-iso-west-1"
        | "us-isof-south-1"
        | "us-isof-east-1"
        | "us-west-1"
        | "us-west-2")[];
    exportConfiguration: IGuardDutyExportFindingsConfig;
    lambdaProtection?: IGuardDutyLambdaProtectionConfig;
    lifecycleRules?: ILifecycleRule[];
    rdsProtection?: IGuardDutyRdsProtectionConfig;
    s3Protection: IGuardDutyS3ProtectionConfig;
}

Properties

autoEnableOrgMembers?: boolean

(OPTIONAL) Enables/disables the auto enabling of GuardDuty for any account including the new accounts joining the organization

It is recommended to set the value to false when using the deploymentTargets property to enable GuardDuty only on targeted accounts mentioned in the deploymentTargets. If you do not define or do not set it to false any new accounts joining the organization will automatically be enabled with GuardDuty.

true
deploymentTargets?: IDeploymentTargets

(OPTIONAL) Deployment targets for GuardDuty

We highly recommend enabling GuardDuty across all accounts and enabled regions within your organization. deploymentTargets should only be used when more granular control is required, not as a default configuration Please only specify one of the deploymentTargets or excludeRegions properties.

Note: The delegated admin account defined in centralSecurityServices will always have GuardDuty enabled

DeploymentTargets

(OPTIONAL) AWS GuardDuty EC2 Protection configuration.

(OPTIONAL) AWS GuardDuty EKS Protection configuration.

enable: boolean

Indicates whether AWS GuardDuty enabled.

Accelerator will try to set the organization admin account to the Audit account, but it cannot overwrite the existing organization admin account if one is already set. If your pipeline fails, remove the existing delegated admin and rerun the pipeline.

excludeRegions?: (
    | "af-south-1"
    | "ap-east-1"
    | "ap-east-2"
    | "ap-northeast-1"
    | "ap-northeast-2"
    | "ap-northeast-3"
    | "ap-south-1"
    | "ap-south-2"
    | "ap-southeast-1"
    | "ap-southeast-2"
    | "ap-southeast-3"
    | "ap-southeast-4"
    | "ap-southeast-5"
    | "ap-southeast-7"
    | "ca-central-1"
    | "ca-west-1"
    | "cn-north-1"
    | "cn-northwest-1"
    | "eu-central-1"
    | "eu-central-2"
    | "eu-north-1"
    | "eu-south-1"
    | "eu-south-2"
    | "eu-west-1"
    | "eu-west-2"
    | "eu-west-3"
    | "eu-isoe-west-1"
    | "il-central-1"
    | "me-central-1"
    | "me-south-1"
    | "mx-central-1"
    | "sa-east-1"
    | "us-east-1"
    | "us-east-2"
    | "us-gov-west-1"
    | "us-gov-east-1"
    | "us-iso-east-1"
    | "us-isob-east-1"
    | "us-iso-west-1"
    | "us-isof-south-1"
    | "us-isof-east-1"
    | "us-west-1"
    | "us-west-2")[]

(OPTIONAL) List of AWS Region names to be excluded from configuring Amazon GuardDuty

Please only specify one of the excludeRegions or deploymentTargets properties.

exportConfiguration: IGuardDutyExportFindingsConfig

AWS GuardDuty Export Findings configuration.

(OPTIONAL) AWS GuardDuty Lambda Protection configuration.

lifecycleRules?: ILifecycleRule[]

(OPTIONAL) Declaration of a S3 Lifecycle rule.

(OPTIONAL) AWS GuardDuty RDS Protection configuration.

AWS GuardDuty S3 Protection configuration.