Demonstrates how to implement automated malware detection and quarantine workflows for AWS Backup recovery points using Amazon GuardDuty scanning combined with EventBridge and Lambda functions. The solution tags infected backups, enforces organization-wide restore denial through Service Control Policies, and provides real-time notifications via Amazon SNS to prevent compromised recovery points from being restored during active incidents.