Active threat defense now enabled by default in AWS Network Firewall
Share
Services
Starting today, AWS Network Firewall enables active threat defense by default in alert mode when you create new firewall policies in the AWS Management Console. Active threat defense provides automated, intelligence-driven protection against dynamic, ongoing threat activities observed across AWS infrastructure.
With this default setting you get visibility into threat activity and indicator groups, types, and threat names you are protected against. You can switch to block mode to automatically prevent suspicious traffic, such as command-and-control (C2) communication, embedded URLs, and malicious domains, or disable the feature entirely. AWS verifies threat indicators to ensure high accuracy and minimize false positives.
Active threat defense is available in all regions where AWS Network Firewall is available, including AWS GovCloud (US) and China Regions. To learn more about active threat defense and pricing, see the AWS Network Firewall [product page](https://aws.amazon.com/network-firewall/) and [documentation](https://docs.aws.amazon.com/network-firewall/latest/developerguide/aws-managed-rule-groups-atd.html).
What else is happening at Amazon Web Services?
AWS Shield network security director now supports multi-account analysis
about 15 hours ago
Services
Share
Read update
Services
Share
Amazon EMR Managed Scaling is now available in 7 additional AWS regions
about 15 hours ago
Services
Share
Amazon EC2 X2iedn instances now available in AWS Europe (Zurich) region
about 22 hours ago
Services
Share
AWS DataSync introduces Terraform support for Enhanced mode
about 22 hours ago
Services
Share
Validate best practice compliance for SAP ABAP applications with AWS Systems Manager
about 22 hours ago
Services
Share