AWS re:Invent 2025 Security, Identity & Compliance Top Announcements
In this article you can find a summarization of the top announcements at AWS re:Invent 2025 in the category Security, Identity & Compliance.
New AWS Security Agent secures applications proactively from design to deployment (preview)
AWS has launched AWS Security Agent in preview—an automated tool that continuously secures applications throughout the development lifecycle. It conducts automated application security reviews and delivers context-aware penetration testing.
Traditional security tools lack application context: Static application security testing (SAST) analyzes code without runtime awareness, while dynamic application security testing (DAST) tests running applications without understanding the code. This forces manual reviews and weeks-long waits for penetration testing. The result: 60% of organizations update applications weekly, but 75% test security only monthly. Checkmarx's 2025 report found 81% knowingly deploy vulnerable code to meet deadlines.
AWS Security Agent understands application design, code, and security requirements. It performs continuous automated scans and instant penetration tests, generating customized attack strategies that adapt in real-time to uncover sophisticated vulnerabilities before production.
Amazon GuardDuty adds Extended Threat Detection for Amazon EC2 and Amazon ECS
Amazon GuardDuty's Extended Threat Detection now includes attack sequence findings for EC2 instances and ECS tasks, expanding coverage across virtual machines and containers alongside existing IAM, S3, and EKS capabilities.
The system uses AI and ML to automatically link security signals—runtime activity, malware, VPC Flow Logs, DNS queries, and CloudTrail events—into complete attack patterns. New findings consolidate behaviors into critical-severity sequences with incident summaries, timelines, MITRE ATT&CK mappings, and remediation guidance.
Since EC2 instances and ECS tasks often share infrastructure components, activity across them may indicate a single compromise. The system analyzes shared attributes and consolidates related signals accordingly.
Critical sequences appear on the GuardDuty console with affected resources identified and integrate with AWS Security Hub for unified risk assessment, helping teams prioritize remediation.
AWS Security Hub now generally available with near real-time analytics and risk prioritization
AWS Security Hub is now generally available, unifying security operations by correlating signals across GuardDuty, Inspector, AWS Security Hub CSPM, and Macie to provide near real-time risk analytics and automated insights.
Key capabilities:
Historical trends – Up to 1 year of data with customizable dashboards showing period-over-period analysis and security coverage gaps across accounts and Regions.
Near real-time risk analytics – Automatically correlates threats, vulnerabilities, and misconfigurations, updating exposures immediately. The Exposure page displays findings by severity with 90-day trends, potential attack path visualizations, and prioritized remediation guidance.
Partner integrations – Direct Jira and ServiceNow ticket creation, OCSF format support for partners like CrowdStrike, Splunk, and DataDog, plus EventBridge automation for programmatic remediation.
Security Hub uses resource-based pricing with a cost estimator. Near real-time exposure calculation and Trends included at no additional charge.
Simplify IAM policy creation with IAM Policy Autopilot, a new open source MCP server for builders
AWS has launched IAM Policy Autopilot, an open source MCP server that analyzes application code and helps AI coding assistants generate AWS IAM identity-based policies. It integrates with assistants like Kiro, Claude Code, Cursor, and Cline, runs locally at no cost, and is available on GitHub.
Developers often use AI assistants for policy creation, but these tools frequently miss permissions or suggest invalid actions. IAM Policy Autopilot uses deterministic code analysis to generate reliable, valid policies directly from code, incorporating AWS service reference implementations to stay current with the latest services and operations.
As an MCP server, it operates in the background while developers work with AI assistants, analyzing AWS SDK calls to generate required permissions and troubleshooting Access Denied errors. It also functions as a standalone CLI tool. The tool generates identity-based policies only and prioritizes functionality over minimal permissions—policies should be reviewed before deployment.
IAM Policy Autopilot integrates with core AWS services including S3, Lambda, DynamoDB, EC2, and CloudWatch Logs. Policies can be copied into CloudFormation templates, AWS CDK stacks, or Terraform configurations. It complements IAM Access Analyzer for policy validation and refinement.
Available on GitHub at no cost, it currently supports Python, TypeScript, and Go applications.
References:
https://aws.amazon.com/blogs/aws/new-aws-security-agent-secures-applications-proactively-from-design-to-deployment-preview/
https://aws.amazon.com/blogs/aws/amazon-guardduty-adds-extended-threat-detection-for-amazon-ec2-and-amazon-ecs/
https://aws.amazon.com/blogs/aws/aws-security-hub-now-generally-available-with-near-real-time-analytics-and-risk-prioritization/
https://aws.amazon.com/blogs/aws/simplify-iam-policy-creation-with-iam-policy-autopilot-a-new-open-source-mcp-server-for-builders/
Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article