build1 publisher
A resource-by-resource AWS audit passes an account with GuardDuty disabled
In HackerOne report #3022516 the trail was multi-region, the metric filter for unauthorised API calls existed and the alarm published to an SNS topic, while threat_detection.enabled read false. Turning it on costs one CLI call.
Publishers:dev.to
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives65
- Confidence60