Skip to content

Latest commit

 

History

History
37 lines (24 loc) · 1.19 KB

README.md

File metadata and controls

37 lines (24 loc) · 1.19 KB

GuardDuty S3 Malware

Demonstrates enabling GuardDuty S3 Malware Protection for an S3 bucket.

Options

  • If a threat is detected, send a notification.
  • If no threats are detected, move the file to another bucket or add the event to a queue.

Install

Follow instructions to install CDK and bootstrap your account.

Deploy

Set email in cdk.json if you'd like to receive an email notification when a threat is found.

Run cdk deploy

Test

Threats

  • Get an EICAR test file.
  • Verify a notification was emailed to you
  • Verify it is tagged with THREATS_FOUND

No Threats

  • Upload a clean file to the source bucket
  • Verify it was moved to the destination bucket
  • Verify it is tagged with NO_THREATS_FOUND
  • Verify the Guard Duty event was added to the queue