View a markdown version of this page

Quotas for Malware Protection for Backup - Amazon GuardDuty
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Quotas for Malware Protection for Backup

Malware Protection for Backup quotas
Quota name Amazon default quota value Is it adjustable? Description
StartMalwareScan TPS limit for all resource types 10 No
Max snapshot size supported 2 TiB No

This limit applies to the full snapshot size (fullSnapshotSizeInBytes), not the incremental snapshot size. For more information, see Snapshot in the Amazon EC2 API Reference.

For an incremental scan, GuardDuty skips the scan if either the current snapshot or the base snapshot exceeds this limit.

Supported file systems for snapshot and AMI scans
  • New Technology File System (NTFS)

  • X File System (XFS)

  • Second extended (ext2) File System

  • Fourth extended (ext4) File System

  • File Allocation Table (FAT) File System

  • Virtual File Allocation Table (VFAT) File System

No
Max number of snapshots within an AMI supported for malware scanning 40 for full scan. If there are more than 40, GuardDuty will only scan 40 amongst all snapshots. For an incremental scan, scanning is skipped. No
Max size of an object within a S3 Recovery Point 100 GB No

The maximum S3 object size that GuardDuty will attempt to scan for malware.

Extracted archive bytes 100 GB No

The maximum amount of data that GuardDuty can extract and analyze from an archive file.

GuardDuty will skip archive files extracting to more than 100 GB.

Extracted archive files 10,000 No

The maximum number of files that GuardDuty can extract and analyze in an archive file. If the archive contains more than 10,000 files, then GuardDuty will have to skip the archived file.

Note

Compound files types are potentially subject to these limits. The file types include, but are not limited to, Multipurpose Internet Mail Extensions (MIME) encoded email messages, Compiled Python (PYC) files, Compiled HTML Help (CHM) files, all installers, and OpenDocument Format (ODF) documents.

Maximum archive depth levels 5 No The maximum levels of nested archives that GuardDuty can extract. If the archive includes files that are nested beyond this value, then GuardDuty will skip those nested files.