Amazon GuardDuty Gets 35 Custom Detection Rules for Tailored Threat Hunting
Amazon GuardDuty now lets you enable optional Custom Detection Rules—35 prebuilt threat detection rules for CloudTrail events that you can activate only where they matter in your environment. This means you can catch sneaky stuff like external AMI sharing or disabled flow logs without drowning in false positives, and it's available across all AWS commercial regions plus GovCloud.
source: [aws/whats-new]