AWS GuardDuty Runtime Monitoring: The Security Agent That Sees Inside Your Workloads

Standard GuardDuty analyzes VPC Flow Logs, CloudTrail events, and DNS queries — all metadata about what happened around your workloads. It sees that an EC2 instance connected to a suspicious IP, but it can’t tell you which process made that connection, what command-line arguments it used, or whether it escalated privileges first. Runtime Monitoring changes that. It deploys a lightweight security agent inside your EC2 instances, EKS pods, and ECS tasks that watches operating system events in real time. Process execution, file access, network connections, privilege changes — all visible to GuardDuty without you writing a single detection rule. ...

July 27, 2026 · 13 min · 2573 words · Javier Pulido

EKS Security Best Practices: RBAC, Pod Security & IRSA Hardening (2026)

10 actionable EKS security best practices covering IRSA, RBAC, network policies, pod security standards, image scanning, secrets encryption, and node hardening.

July 7, 2026 · 7 min · 1438 words · Javier Pulido

EKS Security Monitoring: Audit Logs, Falco Runtime Detection & GuardDuty

Practical EKS security checklist — control plane audit logs, Falco runtime detection, GuardDuty for containers, and the monitoring gaps most teams miss.

September 17, 2025 · 6 min · 1150 words · Javier Pulido