AI SIEM — AI-Powered SIEM for AWS

Correlate CloudTrail, VPC Flow Logs, GuardDuty findings, and application events into a unified threat timeline. ML-driven behavioral analysis, real-time alert triage, and guided incident response — all running in your account.

Subscribe on AWS Marketplace Learn More

AI SIEM builds on the Perfware platform. It requires Log Processor for shared infrastructure, and optionally integrates with AI Monitor for metric-driven detection. Each works standalone; together they cover the full kill chain.

Log Processor required

Provides the shared VPC and OpenSearch domain AI SIEM deploys onto (no new cluster). It also does application-log pattern detection; those detections reach AI SIEM's timeline through AI Monitor, adding application-layer coverage that infrastructure tools can't see.

AI Monitor optional, advanced+

Watches CloudWatch metrics and detects anomalies. AI SIEM reads those anomalies from the shared OpenSearch domain and correlates them into threat timelines — and can trigger an on-demand flow-log query around a network-egress spike. Set its stack name at launch to enable it.

How the three products reinforce each other →

The Problem

AWS provides powerful security services, but they're fragmented. Without correlation, teams can't see the full picture:

  • GuardDuty findings lack context about what the attacker did before and after
  • CloudTrail is noisy — thousands of API calls with no behavioral baseline to distinguish anomalies
  • VPC Flow Logs sit in S3 unsearchable unless you build custom pipelines
  • Security Hub aggregates findings but doesn't correlate them into attack narratives
  • Incident response is manual — engineers spend hours piecing together timelines across consoles
  • Infrastructure and application signals live in yet another tool — a CPU spike that means cryptomining, or an auth-failure surge that means credential stuffing, never reaches the security timeline
  • Third-party SIEMs require data exfiltration and cost $50K–$500K/year — and each tool you bolt on is another vendor, another bill, another integration to maintain

The Solution

AI SIEM unifies all your AWS security signals into a single, intelligent platform:

  • Correlates events across CloudTrail, Flow Logs, GuardDuty, Security Hub, and Config into unified threat timelines
  • ML behavioral baselines learn normal per principal — no manual threshold tuning
  • AI-generated playbooks guide your team through step-by-step remediation
  • Deterministic scoring — rules and math decide every finding; AI only explains, and its output is validated
  • Built-in flow-log cost guardrail keeps VPC-scale ingestion from becoming a surprise bill
  • Runs entirely in your AWS account — no data exfiltration, no external dependencies
  • Deploys in 15 minutes on your existing Log Processor infrastructure
  • Part of one integrated suite — Log Processor log-pattern detections and AI Monitor metric anomalies correlate straight into the threat timeline, so infrastructure and application signals land beside the security events instead of in separate tools
  • One vendor, shared infrastructure — the three products reuse the same VPC and OpenSearch domain, so adding coverage does not mean another silo or another full-price SIEM
  • Predictable pricing starting at $79/mo — a fraction of third-party SIEMs
AI SIEM Architecture Overview

Details...

Features

Everything you need for AWS-native threat detection and response.

Unified Threat Timeline

Events from CloudTrail, VPC Flow Logs, GuardDuty, Config, and Security Hub merged into a single chronological incident view per threat actor. When deployed alongside the rest of the suite, Log Processor log-pattern detections and AI Monitor metric anomalies correlate into the same timeline — infrastructure and application signals appear next to the security events on the same resource and window.

ML Behavioral Baselines

Learns what "normal" looks like per IAM principal across nine behavioral dimensions — which APIs and API families, which times, which IPs, which regions, which resources, and the identity's own type. Alerts on deviations without manual threshold tuning.

Cross-Signal Correlation

Automatically connects related events: compromised credential + unusual S3 access + port scanning + GuardDuty alert = one correlated threat.

MITRE ATT&CK Mapping

Detections mapped deterministically across 13 of the 14 cloud ATT&CK tactics — Reconnaissance through Impact — from CloudTrail, GuardDuty, and VPC Flow signals. The timeline shows the kill chain advancing tactic by tactic. See the full coverage breakdown.

Custom Detection Rules

Author your own detections, not just ours. Point-and-click conditions on any normalized field (event, error, principal, IP, region, bytes, GuardDuty finding), with thresholds, time windows, severity, and an ATT&CK tag — or describe a detection in plain English and let AI draft it (advanced+), or paste a Sigma rule and import it. Every custom rule raises a threat score exactly like a built-in one and rides the same timeline, alerts, reports, and audit trail. Turns "our seven rules" into "our rules plus unlimited yours."

Context-Aware Severity

Advanced+ tiers score the same rule higher in riskier context: a match by the root principal, or from outside your trusted networks, raises the severity floor. Modifiers only ever raise a score, never suppress one, and key on identity and network facts — never on the anomaly signals the ML baseline already owns, so nothing is double-counted. Define your trusted IPs and it activates; leave them unset and it stays out of the way.

AI-Powered Playbooks

Bedrock generates contextual step-by-step remediation guidance for the specific threat. Every identifier comes from the actual threat record — the model fills placeholders, never invents resource names or ARNs, and any output that does is rejected.

Scheduled Threat Reports

On-demand or scheduled summary reports over a 1–30 day window, emailed with a time-boxed download link. Each carries an AI-written executive summary, threat breakdown by severity and MITRE tactic, a live SIEM health and ML-training snapshot, a point-in-time snapshot of the detection configuration (which built-in and custom rules are enabled or disabled, thresholds, auto-remediation posture), and the audit-activity log for the window — who did what, from where.

Auto-Remediation

Enterprise tier: automatically disable compromised keys, revoke sessions, isolate instances, and block IPs. Opt-in per action type, each written to the tamper-evident (WORM) audit trail.

Compliance Posture

Continuous scoring against SOC2, PCI, and HIPAA controls based on security events. Posture and trend analysis surface in the scheduled threat reports.

Tamper-Evident Audit Trail

Every analyst action (acknowledge, resolve, dismiss, false-positive, assign), every remediation, every configuration change — with a field-level diff — plus logins, logouts, and denied access attempts is recorded with who, when, their role, and origin IP to a write-once (WORM) S3 store with Object Lock. The application can append but never alter or erase records, so the chain of custody holds even if a component is compromised. Queryable in Athena and surfaced in scheduled reports; choose GOVERNANCE or fully immutable COMPLIANCE retention at deploy.

Configuration Integrity Monitoring

The SIEM watches its own configuration. Every save is sealed with a hash anchored in the tamper-evident audit trail; if the config is ever changed outside the editor — a direct S3 edit that bypasses the audited path — it is detected and raised as a high-severity threat, with a field-level diff of exactly what changed and whether it weakened your posture (a disabled detection, armed auto-remediation, removed approval gate).

Analyst Assignment & Queues

Assign threats to analysts for triage — admins assign to anyone, analysts claim their own — and each analyst filters to an "assigned to me" queue. Every assignment is captured in the audit trail (who assigned what to whom, and when), so ownership is both operational and provable.

Threat Intelligence

IP reputation enrichment from open threat feeds. Source IPs in CloudTrail and VPC Flow Logs tagged with known-malicious indicators.

Flow-Log Cost Guardrail

VPC Flow Logs are the runaway-cost risk in any SIEM. Processing is duty-cycled with an automatic circuit breaker — on by default — so a traffic spike can't trigger a surprise bill. Every flow is still retained in S3 and queryable on demand via Athena; only the streaming spend is bounded.

Deterministic by Design

The AI explains; it never decides. Every threat score, count, and severity is computed by rules and math — not a language model. Bedrock writes only the prose in playbooks and report summaries, with numbers templated in and invented identifiers rejected, so a model can't fabricate a finding or misstate a figure.

Log Processor + AI Monitor Integration

Shares OpenSearch with Log Processor for cross-domain correlation. When AI Monitor detects anomalous metrics during a security event, both signals are connected.

Better Together: The Perfware Security Platform

AI SIEM, Log Processor, and AI Monitor share infrastructure and reinforce each other. Each product works standalone; together they cover the full kill chain at a fraction of the cost of any one competitor.

Metric-Triggered Forensic Query

Full flow logs are captured to cheap S3 storage continuously — it is processing every record that is prohibitively expensive at scale, not storing it. AI Monitor watches VPC network metrics at 1-minute resolution for near-zero cost. When it detects an anomalous volume spike, AI SIEM runs a scoped Athena query against the already-captured flow data for just that resource and time window — pulling destination IPs, port details, and byte volumes for the minutes that matter.

Result: full forensic detail around incidents at query cost (pennies), while continuous processing is duty-cycled and circuit-broken so it never runs away. A capability no competitor offers at this price point.

Cross-Signal Correlation

AI Monitor detects infrastructure anomalies (CPU spike on an idle instance, sudden database connection surge, EBS write volume explosion). AI SIEM detects security events (IAM changes, credential probing, privilege escalation). When both fire on the same resource within the same window, the threat timeline shows both signals together.

Example: "A role policy was modified, then CPU spiked to 100% on three instances, and network egress jumped 50x" — that's a complete attack narrative, not three unrelated alerts.

Log Processor Pattern Detection

GuardDuty and CloudTrail observe infrastructure. They cannot see your application’s auth system, your API error rates, or your database query patterns. Log Processor can — it ingests your application and service logs and runs pattern detection: error spikes, latency anomalies, crash loops, and unusual query patterns.

When Log Processor detects an application-layer anomaly, that finding surfaces in AI SIEM’s threat timeline. A credential brute-force visible only in your API’s 401 responses, an SQL injection manifesting only as slow queries, or a defence-evasion move revealed only by missing logs — all surface as correlated security events alongside the infrastructure signals.

This closes the biggest gap in AWS-native security: attacks that operate within permissions an application already has, never touching IAM, invisible to every infrastructure-layer tool.

Shared Infrastructure, No Duplication

All three products share one OpenSearch cluster (Log Processor owns it), one VPC, and one set of IAM roles. No additional domains, no redundant storage, no duplicated ingestion. AI SIEM adds security analytics on top of what's already running — incremental cost, not another $50K line item.

Advantages Over Standalone SIEMs

  • No data exfiltration — everything stays in your account
  • No per-GB ingestion pricing that punishes volume
  • Metrics catch what logs can't: cryptomining, ransomware encryption, exfiltration volume
  • On-demand Athena forensics over always-captured flow logs — same detail at query cost, with processing duty-cycled and circuit-broken so it never runs away
  • Correlation between infrastructure health and security events — attacks show up in both
  • One vendor, one integrated suite — three products built to work together, not stitched together

What This Catches (Examples)

Real attack patterns that require cross-product correlation. No single tool sees the full picture.

AI Monitor Metrics → AI SIEM

Cryptomining: CPU spikes to 100% on an idle instance. AI SIEM correlates with CloudTrail showing a new key pair created from an unusual IP 10 minutes earlier.

Data exfiltration: NetworkOut jumps 50x on one instance. AI SIEM runs a scoped Athena query over the captured flow logs, identifies the destination, and correlates with an IAM role modification that enabled it.

Ransomware: EBS WriteBytes explodes. AI SIEM finds a KMS key creation and cross-account policy in CloudTrail during the same window.

Alert suppression: SNS failed deliveries spike from zero. AI SIEM finds sns:SetTopicAttributes in CloudTrail removing the security team’s subscription.

Defence evasion: OpenSearch indexing rate drops to zero. AI SIEM correlates with Lambda deletions and SQS purges that killed the ingestion pipeline.

SQL injection: RDS connection count jumps from 20 to 200. AI SIEM correlates with ALB 5xx spikes and Log Processor slow-query detection on the same database.

Log Processor Patterns → AI SIEM

Credential brute-force: 500+ failed logins in 5 minutes against the app’s own auth. AI SIEM checks VPC flow logs from the same source IP and whether any attempt succeeded.

Privilege escalation: A code path that never threw starts producing “access denied” errors. AI SIEM finds the role was modified in CloudTrail moments before.

Command & control: Application logs repeated connection failures to an unknown external host. AI SIEM correlates with REJECT flows to the same destination.

Insider data theft: Bulk CSV export requests far exceeding normal usage. AI SIEM checks NetworkOut metric for volume and the user’s role assignment history.

Logging disabled: A service that produced 1000 lines/min drops to zero. AI SIEM finds DeleteLogGroup in CloudTrail and raises a defence-evasion threat.

Session hijacking: “Invalid token” errors from IPs that never had valid sessions. AI SIEM correlates with the legitimate user’s last known location and flags the attempt.

How It Works

Deploy in 15 minutes. Start detecting threats immediately.

1

Deploy

Single CloudFormation stack deploys on your existing Log Processor VPC and OpenSearch domain. No new infrastructure to manage.

2

Connect Sources

Point to your CloudTrail bucket, enable VPC Flow Logs, and GuardDuty + Security Hub events flow automatically via EventBridge. If AI Monitor is deployed on the shared domain, its metric anomalies (and Log Processor patterns) correlate in with no extra wiring.

3

Learn Baselines

ML models learn normal behavior per principal within 7–14 days. Static rules catch known-bad patterns immediately.

4

Detect & Respond

Threats surface with full timeline context, MITRE mapping, and AI-generated playbooks. Enterprise tier can auto-remediate.

Simple, Predictable Pricing

Software fee only. AWS infrastructure costs are billed directly by AWS to your account.

Basic

$79/mo
  • CloudTrail ingestion + timeline
  • Static threat rules
  • Up to 5 data sources
  • 7-day event retention
  • Editor UI

Essential

$199/mo
  • Everything in Basic, plus:
  • + VPC Flow Logs + GuardDuty
  • + Flow-log cost guardrail
  • + ML behavioral baselines
  • + Up to 25 data sources
  • + 90-day searchable retention (PCI 3-month hot floor)

Enterprise

$999/mo
  • Everything in Advanced, plus:
  • + Auto-remediation (opt-in)
  • + SSO + RBAC
  • + Unlimited sources
  • + 365-day retention (audit extendable to 7 yrs for HIPAA/SOX)
  • + Log Processor cross-correlation
  • + Email support (2 business days)
  • + Onboarding call + quarterly review

FAQ

Does AI SIEM require Log Processor?

Yes. AI SIEM deploys on the VPC and OpenSearch domain created by Log Processor. This avoids duplicating infrastructure and enables cross-domain correlation between logs, metrics, and security events.

Does any data leave my AWS account?

No. All processing happens within your account. The only external call is an entitlement check to verify your Marketplace subscription (no customer data is transmitted).

How quickly does it detect threats?

Static rules (known-bad patterns like impossible travel, credential stuffing) fire within minutes of event ingestion. ML behavioral anomalies require a 7–14 day baseline learning period before alerting.

What does auto-remediation actually do?

Enterprise tier only, opt-in per action type: disable IAM access keys, revoke active sessions, attach deny-all policies, modify security groups to isolate instances. Every action is logged to DynamoDB with full audit trail.

How does it compare to AWS Security Hub / GuardDuty / Detective?

AI SIEM correlates all of those into a single timeline with behavioral ML that learns YOUR account's normal patterns. GuardDuty detects; AI SIEM correlates, explains, and responds. Security Hub aggregates; AI SIEM connects the dots into attack narratives.

What AWS infrastructure costs should I expect?

Depends on event volume. Typical: $20–$80/mo for Lambda, S3, DynamoDB, and Bedrock. OpenSearch is shared with Log Processor (no additional cluster cost). CloudTrail and VPC Flow Logs have their own AWS charges regardless of AI SIEM.

Can I use it with AI Monitor and Log Processor?

Yes, and this is where the platform becomes more than the sum of its parts. All three products share one OpenSearch domain, so integration is zero-infrastructure — AI SIEM reads the anomalies the others already record, with nothing new to wire up.

AI Monitor watches CloudWatch metrics (CPU, network, database connections) and records anomaly detections into the shared OpenSearch domain; AI SIEM reads them and merges them into its threat timeline. When both detect activity on the same resource within the same window, you get a complete attack narrative: the IAM change that enabled it (CloudTrail), the metric spike that revealed it (AI Monitor), the network flows that show where data went (VPC Flow Logs), and an AI-generated playbook to stop it. For severe network anomalies, AI SIEM can automatically enable detailed flow logging for just those minutes — capturing forensic detail at pennies instead of thousands per month. You control which subscriptions correlate from the editor.

Log Processor ingests application and service logs and runs pattern detection on them. A per-pattern CloudWatch metric — error spikes, unusual query patterns, crash loops, failed-login spikes against your app’s own auth, a sudden log-volume drop — is baselined by AI Monitor, and a spike surfaces in AI SIEM as a correlated security event. This closes the biggest gap in AWS-native security: attacks that operate within permissions an application already has — never touching IAM, invisible to CloudTrail and GuardDuty — surface as security events only because the application-layer anomaly was seen.

See the integration section for architecture detail and competitive advantages.

How do I upgrade tiers?

Update the Tier parameter in CloudFormation and run a stack update. Non-destructive — all data is preserved. Feature gates activate immediately.

Documentation

Guides for deployment, configuration, and daily operations.

Getting Started Guide

Deploy and configure in 15 minutes

User Guide

Editor UI, threat management, response workflows

SSO Guide

Okta, Azure AD, and SAML configuration