<  Back to rules search

AWS EC2 instance network traffic volume unusual





WARNING: This rule is being deprecated on 6 March 2023.

  • Cloud SIEM team performs a regular audit of all detection rules to maintain high signal quality. We will be replacing this rule with an improved third party detection rule after the deprecation date. This rule will allow you to receive coverage with all GuardDuty detections and correlate them with other security signals fired.


Detect when an EC2 instance network traffic volume is unusual.


This rule lets you monitor this GuardDuty integration finding:

Triage and response

  1. Determine which port triggered the signal. This can be found in the samples.
  2. If the instance is compromised:
    • Review the AWS documentation on remediating a compromised EC2 instance.


  • 10 October 2022 - Updated tags.
  • 1 November 2022 - Updated links.