Skip to content

Improve AWS GuardDuty coverage evidence gates#1339

Open
MAUROCERON wants to merge 1 commit into
UnitOneAI:mainfrom
MAUROCERON:improve/aws-guardduty-coverage-1337
Open

Improve AWS GuardDuty coverage evidence gates#1339
MAUROCERON wants to merge 1 commit into
UnitOneAI:mainfrom
MAUROCERON:improve/aws-guardduty-coverage-1337

Conversation

@MAUROCERON

Copy link
Copy Markdown

Summary

  • Implements [REVIEW] aws-review: add GuardDuty protection-plan coverage evidence gates #1337.
  • Adds GuardDuty detector, delegated administrator, organization auto-enable,
    protection-plan, finding-delivery, Runtime Monitoring, and suppression-filter
    evidence gates to aws-review.
  • Updates the skill prerequisites, severity examples, output format, section
    map, pitfalls, and references so Security Hub is not treated as proof of
    GuardDuty coverage.
  • Adds edge-case fixtures for Security Hub-only evidence, organization
    auto-enable gaps, missing S3 protection, Runtime Monitoring without agent
    evidence, unrouted findings, and suppression filters without review evidence.

Validation

  • Checked Markdown fence balance for the edited skill, checklist, and new fixture.
  • Verified official AWS reference URLs return HTTP 200.
  • Scanned the changed public files for private payment/contact strings.

Bounty

  • I have read and agree to the CONTRIBUTING.md bounty terms.
  • Preferred payment method can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant