How can the Security team suppress alerts about authorized security tests while still receiving alerts about the unauthorized activity?

1 Comment

  1. Michael
    Author

    If memory serves me right, the answer is:
    Add the Elastic IP addresses of the Security team’s EC2 instances to a trusted IP list in Amazon GuardDuty.

Leave a Reply

Your email address will not be published. Required fields are marked *

3 × 1 =