On-demand S3 malware scan in GuardDuty
GuardDuty Malware Protection for S3 continuously monitors new S3 uploads. For objects that existed before enabling protection, or to re-scan previously scanned objects, you can initiate on-demand S3 malware scan once you've enabled the GuardDuty Malware Protection plan for your bucket.
On-demand malware scanning uses the Malware Protection Plan's IAM role for object access and applying configuration. The scan will override any prefix configured in the Malware Protection Plan for the bucket.
Note
The Malware Protection for S3 quota applies to on-demand malware scanning. For more information, See Quotas in Malware Protection for S3.
For more information about pricing, see Pricing and usage cost for Malware Protection for S3.
Prerequisites
Before you start an on-demand malware scan, your account must meet the following prerequisites:
-
Malware Protection for S3 is enabled on the target bucket. See Configuring Malware Protection for S3 for your bucket for more information.
-
The AWS managed policy: AmazonGuardDutyFullAccess_v2 (recommended) policy is attached to the IAM user or the IAM role invoking the API.
Start on-demand malware scan
Use the SendObjectMalwareScan API operation, which requires the S3 object path as input.
Important
A successful API call confirms that the scan request has been accepted. However, it is important to monitor the scan results to ensure successful completion and to identify any issues, such as errors accessing the object. For more information, see Monitoring S3 object scans in Malware Protection for S3.