GuardDuty now lets you write custom detection rules and roll them out organization-wide
On September 1, 2026, AWS opened GuardDuty to custom detection rules, associable per account and controllable at the organization level with a dry-run mode and an expiry date. Security teams can now code their own detection scenarios instead of waiting for vendor findings.