Amazon GuardDuty RDS Protection now detects data exfiltration and destruction in Aurora and RDS databases

Posted on: Oct 8, 2026

Amazon GuardDuty announces an expansion of RDS Protection that extends threat detection beyond login anomalies to identify data exfiltration and data destruction attacks targeting Amazon Aurora PostgreSQL and Amazon RDS for PostgreSQL databases. Available as RDS Protection for data activity, this new capability uses machine learning (ML)-based anomaly detection and integrated threat intelligence to continuously monitor database query patterns, helping you detect unusual data activity without requiring any agents, additional infrastructure, or database configuration changes.

As attackers increasingly target databases to exfiltrate or destroy critical data after obtaining valid credentials through phishing, social engineering, or misconfiguration, their malicious database activity can appear indistinguishable from legitimate application behavior.  RDS Protection for data activity establishes behavioral baselines for normal query patterns enabling GuardDuty to detect threats that traditional tools miss. 

You can enable GuardDuty RDS Protection for data activity as an add-on to RDS Protection for login activity. With a single click, they can enable it for their entire organization in the GuardDuty console, or programmatically via APIs, SDKs, CLI, or AWS CloudFormation. A 30-day free trial is available per account per Region.

This feature is available today in all AWS commercial Regions and AWS GovCloud (US) Regions, where Amazon GuardDuty RDS Protection is offered with support for Aurora PostgreSQL and Amazon RDS for PostgreSQL. For supported versions visit GuardDuty RDS Protection documentation.  

To learn more and start your free trial, visit the Amazon GuardDuty product page.