How can the Security team suppress alerts about authorized security tests while still receiving alerts about the unauthorized activity?

2 Comments

  1. Michael
    Author

    If memory serves me right, the answer is:
    Add the Elastic IP addresses of the Security team’s EC2 instances to a trusted IP list in Amazon GuardDuty.

  2. Bryan
    Author

    I conclude that the answer is:
    Add the Elastic IP addresses of the Security team’s EC2 instances to a trusted IP list in Amazon GuardDuty.

Leave a Reply to Bryan Cancel reply

Your email address will not be published. Required fields are marked *

ten − 6 =