From 93b00e955a864cc813a3ff5e57576207e51da1df Mon Sep 17 00:00:00 2001 From: Dusty <42273218+DustyStudy@users.noreply.github.com> Date: Fri, 18 Sep 2026 13:55:44 -0500 Subject: [PATCH] Deny guardduty:UpdateDetector in deny-disable-security-services SCP UpdateDetector can set Enable=false, disabling GuardDuty without any of the previously denied calls. Added to the JSON, CloudFormation and Terraform copies, and documented that it also blocks legitimate detector changes (including CloudFormation updates of AWS::GuardDuty::Detector, as used by the member-baseline StackSet). Co-Authored-By: Claude Sonnet 5 --- cloudformation/scp-guardrails/template.yaml | 3 ++- policies/scp-guardrails/README.md | 5 +++++ policies/scp-guardrails/deny-disable-security-services.json | 3 ++- terraform/scp-guardrails/main.tf | 1 + 4 files changed, 10 insertions(+), 2 deletions(-) diff --git a/cloudformation/scp-guardrails/template.yaml b/cloudformation/scp-guardrails/template.yaml index 75e7387..98ce710 100644 --- a/cloudformation/scp-guardrails/template.yaml +++ b/cloudformation/scp-guardrails/template.yaml @@ -134,7 +134,8 @@ Resources: "guardduty:DeleteDetector", "guardduty:DisassociateFromMasterAccount", "guardduty:DisassociateMembers", - "guardduty:DisableOrganizationAdminAccount" + "guardduty:DisableOrganizationAdminAccount", + "guardduty:UpdateDetector" ], "Resource": "*" }, diff --git a/policies/scp-guardrails/README.md b/policies/scp-guardrails/README.md index b973dc3..1e5d34f 100644 --- a/policies/scp-guardrails/README.md +++ b/policies/scp-guardrails/README.md @@ -104,6 +104,11 @@ Every policy has a matching `enable_*` boolean variable (see - `deny-disable-security-services.json` also blocks `cloudtrail:UpdateTrail` and `PutEventSelectors`, so legitimate trail changes need a break-glass path (or an exemption for your automation role) once it's attached. +- It also blocks `guardduty:UpdateDetector`, the call that can set a + detector's `Enable` flag to `false`. The same call is used for legitimate + changes (finding publishing frequency, feature toggles), and CloudFormation + issues it when a `AWS::GuardDuty::Detector` is updated - so change those + settings from an exempted role, or before attaching the policy. ## Before enabling in production diff --git a/policies/scp-guardrails/deny-disable-security-services.json b/policies/scp-guardrails/deny-disable-security-services.json index d6e352f..dc6bd85 100644 --- a/policies/scp-guardrails/deny-disable-security-services.json +++ b/policies/scp-guardrails/deny-disable-security-services.json @@ -31,7 +31,8 @@ "guardduty:DeleteDetector", "guardduty:DisassociateFromMasterAccount", "guardduty:DisassociateMembers", - "guardduty:DisableOrganizationAdminAccount" + "guardduty:DisableOrganizationAdminAccount", + "guardduty:UpdateDetector" ], "Resource": "*" }, diff --git a/terraform/scp-guardrails/main.tf b/terraform/scp-guardrails/main.tf index 9791e32..5af04db 100644 --- a/terraform/scp-guardrails/main.tf +++ b/terraform/scp-guardrails/main.tf @@ -44,6 +44,7 @@ locals { "guardduty:DisassociateFromMasterAccount", "guardduty:DisassociateMembers", "guardduty:DisableOrganizationAdminAccount", + "guardduty:UpdateDetector", ] Resource = "*" },