< Back to rules searchAWS EC2 instance communicating over unusual port
Set up the guardduty integration.
Overview
Goal
Detect when an EC2 instance is communicating over an unusual port.
Strategy
This rule lets you monitor this GuardDuty integration finding:
Triage & Response
- Determine which port triggered the signal. This can be found in the samples.
- If the instance is compromised:
- Review the AWS documentation on remediating a compromised EC2 instance.