Correlate CloudTrail, VPC Flow Logs, GuardDuty findings, and application events into a unified threat timeline. ML-driven behavioral analysis, real-time alert triage, and guided incident response — all running in your account.
Subscribe on AWS Marketplace Learn MoreAI SIEM builds on the Perfware platform. It requires Log Processor for shared infrastructure, and optionally integrates with AI Monitor for metric-driven detection. Each works standalone; together they cover the full kill chain.
Provides the shared VPC and OpenSearch domain AI SIEM deploys onto (no new cluster). It also does application-log pattern detection; those detections reach AI SIEM's timeline through AI Monitor, adding application-layer coverage that infrastructure tools can't see.
Watches CloudWatch metrics and detects anomalies. AI SIEM reads those anomalies from the shared OpenSearch domain and correlates them into threat timelines — and can trigger an on-demand flow-log query around a network-egress spike. Set its stack name at launch to enable it.
AWS provides powerful security services, but they're fragmented. Without correlation, teams can't see the full picture:
AI SIEM unifies all your AWS security signals into a single, intelligent platform:
Everything you need for AWS-native threat detection and response.
Events from CloudTrail, VPC Flow Logs, GuardDuty, Config, and Security Hub merged into a single chronological incident view per threat actor. When deployed alongside the rest of the suite, Log Processor log-pattern detections and AI Monitor metric anomalies correlate into the same timeline — infrastructure and application signals appear next to the security events on the same resource and window.
Learns what "normal" looks like per IAM principal across nine behavioral dimensions — which APIs and API families, which times, which IPs, which regions, which resources, and the identity's own type. Alerts on deviations without manual threshold tuning.
Automatically connects related events: compromised credential + unusual S3 access + port scanning + GuardDuty alert = one correlated threat.
Detections mapped deterministically across 13 of the 14 cloud ATT&CK tactics — Reconnaissance through Impact — from CloudTrail, GuardDuty, and VPC Flow signals. The timeline shows the kill chain advancing tactic by tactic. See the full coverage breakdown.
Author your own detections, not just ours. Point-and-click conditions on any normalized field (event, error, principal, IP, region, bytes, GuardDuty finding), with thresholds, time windows, severity, and an ATT&CK tag — or describe a detection in plain English and let AI draft it (advanced+), or paste a Sigma rule and import it. Every custom rule raises a threat score exactly like a built-in one and rides the same timeline, alerts, reports, and audit trail. Turns "our seven rules" into "our rules plus unlimited yours."
Advanced+ tiers score the same rule higher in riskier context: a match by the root principal, or from outside your trusted networks, raises the severity floor. Modifiers only ever raise a score, never suppress one, and key on identity and network facts — never on the anomaly signals the ML baseline already owns, so nothing is double-counted. Define your trusted IPs and it activates; leave them unset and it stays out of the way.
Bedrock generates contextual step-by-step remediation guidance for the specific threat. Every identifier comes from the actual threat record — the model fills placeholders, never invents resource names or ARNs, and any output that does is rejected.
On-demand or scheduled summary reports over a 1–30 day window, emailed with a time-boxed download link. Each carries an AI-written executive summary, threat breakdown by severity and MITRE tactic, a live SIEM health and ML-training snapshot, a point-in-time snapshot of the detection configuration (which built-in and custom rules are enabled or disabled, thresholds, auto-remediation posture), and the audit-activity log for the window — who did what, from where.
Enterprise tier: automatically disable compromised keys, revoke sessions, isolate instances, and block IPs. Opt-in per action type, each written to the tamper-evident (WORM) audit trail.
Continuous scoring against SOC2, PCI, and HIPAA controls based on security events. Posture and trend analysis surface in the scheduled threat reports.
Every analyst action (acknowledge, resolve, dismiss, false-positive, assign), every remediation, every configuration change — with a field-level diff — plus logins, logouts, and denied access attempts is recorded with who, when, their role, and origin IP to a write-once (WORM) S3 store with Object Lock. The application can append but never alter or erase records, so the chain of custody holds even if a component is compromised. Queryable in Athena and surfaced in scheduled reports; choose GOVERNANCE or fully immutable COMPLIANCE retention at deploy.
The SIEM watches its own configuration. Every save is sealed with a hash anchored in the tamper-evident audit trail; if the config is ever changed outside the editor — a direct S3 edit that bypasses the audited path — it is detected and raised as a high-severity threat, with a field-level diff of exactly what changed and whether it weakened your posture (a disabled detection, armed auto-remediation, removed approval gate).
Assign threats to analysts for triage — admins assign to anyone, analysts claim their own — and each analyst filters to an "assigned to me" queue. Every assignment is captured in the audit trail (who assigned what to whom, and when), so ownership is both operational and provable.
IP reputation enrichment from open threat feeds. Source IPs in CloudTrail and VPC Flow Logs tagged with known-malicious indicators.
VPC Flow Logs are the runaway-cost risk in any SIEM. Processing is duty-cycled with an automatic circuit breaker — on by default — so a traffic spike can't trigger a surprise bill. Every flow is still retained in S3 and queryable on demand via Athena; only the streaming spend is bounded.
The AI explains; it never decides. Every threat score, count, and severity is computed by rules and math — not a language model. Bedrock writes only the prose in playbooks and report summaries, with numbers templated in and invented identifiers rejected, so a model can't fabricate a finding or misstate a figure.
Shares OpenSearch with Log Processor for cross-domain correlation. When AI Monitor detects anomalous metrics during a security event, both signals are connected.
AI SIEM, Log Processor, and AI Monitor share infrastructure and reinforce each other. Each product works standalone; together they cover the full kill chain at a fraction of the cost of any one competitor.
Full flow logs are captured to cheap S3 storage continuously — it is processing every record that is prohibitively expensive at scale, not storing it. AI Monitor watches VPC network metrics at 1-minute resolution for near-zero cost. When it detects an anomalous volume spike, AI SIEM runs a scoped Athena query against the already-captured flow data for just that resource and time window — pulling destination IPs, port details, and byte volumes for the minutes that matter.
Result: full forensic detail around incidents at query cost (pennies), while continuous processing is duty-cycled and circuit-broken so it never runs away. A capability no competitor offers at this price point.
AI Monitor detects infrastructure anomalies (CPU spike on an idle instance, sudden database connection surge, EBS write volume explosion). AI SIEM detects security events (IAM changes, credential probing, privilege escalation). When both fire on the same resource within the same window, the threat timeline shows both signals together.
Example: "A role policy was modified, then CPU spiked to 100% on three instances, and network egress jumped 50x" — that's a complete attack narrative, not three unrelated alerts.
GuardDuty and CloudTrail observe infrastructure. They cannot see your application’s auth system, your API error rates, or your database query patterns. Log Processor can — it ingests your application and service logs and runs pattern detection: error spikes, latency anomalies, crash loops, and unusual query patterns.
When Log Processor detects an application-layer anomaly, that finding surfaces in AI SIEM’s threat timeline. A credential brute-force visible only in your API’s 401 responses, an SQL injection manifesting only as slow queries, or a defence-evasion move revealed only by missing logs — all surface as correlated security events alongside the infrastructure signals.
This closes the biggest gap in AWS-native security: attacks that operate within permissions an application already has, never touching IAM, invisible to every infrastructure-layer tool.
All three products share one OpenSearch cluster (Log Processor owns it), one VPC, and one set of IAM roles. No additional domains, no redundant storage, no duplicated ingestion. AI SIEM adds security analytics on top of what's already running — incremental cost, not another $50K line item.
Real attack patterns that require cross-product correlation. No single tool sees the full picture.
Cryptomining: CPU spikes to 100% on an idle instance. AI SIEM correlates with CloudTrail showing a new key pair created from an unusual IP 10 minutes earlier.
Data exfiltration: NetworkOut jumps 50x on one instance. AI SIEM runs a scoped Athena query over the captured flow logs, identifies the destination, and correlates with an IAM role modification that enabled it.
Ransomware: EBS WriteBytes explodes. AI SIEM finds a KMS key creation and cross-account policy in CloudTrail during the same window.
Alert suppression: SNS failed deliveries spike from zero. AI SIEM finds sns:SetTopicAttributes in CloudTrail removing the security team’s subscription.
Defence evasion: OpenSearch indexing rate drops to zero. AI SIEM correlates with Lambda deletions and SQS purges that killed the ingestion pipeline.
SQL injection: RDS connection count jumps from 20 to 200. AI SIEM correlates with ALB 5xx spikes and Log Processor slow-query detection on the same database.
Credential brute-force: 500+ failed logins in 5 minutes against the app’s own auth. AI SIEM checks VPC flow logs from the same source IP and whether any attempt succeeded.
Privilege escalation: A code path that never threw starts producing “access denied” errors. AI SIEM finds the role was modified in CloudTrail moments before.
Command & control: Application logs repeated connection failures to an unknown external host. AI SIEM correlates with REJECT flows to the same destination.
Insider data theft: Bulk CSV export requests far exceeding normal usage. AI SIEM checks NetworkOut metric for volume and the user’s role assignment history.
Logging disabled: A service that produced 1000 lines/min drops to zero. AI SIEM finds DeleteLogGroup in CloudTrail and raises a defence-evasion threat.
Session hijacking: “Invalid token” errors from IPs that never had valid sessions. AI SIEM correlates with the legitimate user’s last known location and flags the attempt.
Deploy in 15 minutes. Start detecting threats immediately.
Single CloudFormation stack deploys on your existing Log Processor VPC and OpenSearch domain. No new infrastructure to manage.
Point to your CloudTrail bucket, enable VPC Flow Logs, and GuardDuty + Security Hub events flow automatically via EventBridge. If AI Monitor is deployed on the shared domain, its metric anomalies (and Log Processor patterns) correlate in with no extra wiring.
ML models learn normal behavior per principal within 7–14 days. Static rules catch known-bad patterns immediately.
Threats surface with full timeline context, MITRE mapping, and AI-generated playbooks. Enterprise tier can auto-remediate.
Software fee only. AWS infrastructure costs are billed directly by AWS to your account.
Yes. AI SIEM deploys on the VPC and OpenSearch domain created by Log Processor. This avoids duplicating infrastructure and enables cross-domain correlation between logs, metrics, and security events.
No. All processing happens within your account. The only external call is an entitlement check to verify your Marketplace subscription (no customer data is transmitted).
Static rules (known-bad patterns like impossible travel, credential stuffing) fire within minutes of event ingestion. ML behavioral anomalies require a 7–14 day baseline learning period before alerting.
Enterprise tier only, opt-in per action type: disable IAM access keys, revoke active sessions, attach deny-all policies, modify security groups to isolate instances. Every action is logged to DynamoDB with full audit trail.
AI SIEM correlates all of those into a single timeline with behavioral ML that learns YOUR account's normal patterns. GuardDuty detects; AI SIEM correlates, explains, and responds. Security Hub aggregates; AI SIEM connects the dots into attack narratives.
Depends on event volume. Typical: $20–$80/mo for Lambda, S3, DynamoDB, and Bedrock. OpenSearch is shared with Log Processor (no additional cluster cost). CloudTrail and VPC Flow Logs have their own AWS charges regardless of AI SIEM.
Yes, and this is where the platform becomes more than the sum of its parts. All three products share one OpenSearch domain, so integration is zero-infrastructure — AI SIEM reads the anomalies the others already record, with nothing new to wire up.
AI Monitor watches CloudWatch metrics (CPU, network, database connections) and records anomaly detections into the shared OpenSearch domain; AI SIEM reads them and merges them into its threat timeline. When both detect activity on the same resource within the same window, you get a complete attack narrative: the IAM change that enabled it (CloudTrail), the metric spike that revealed it (AI Monitor), the network flows that show where data went (VPC Flow Logs), and an AI-generated playbook to stop it. For severe network anomalies, AI SIEM can automatically enable detailed flow logging for just those minutes — capturing forensic detail at pennies instead of thousands per month. You control which subscriptions correlate from the editor.
Log Processor ingests application and service logs and runs pattern detection on them. A per-pattern CloudWatch metric — error spikes, unusual query patterns, crash loops, failed-login spikes against your app’s own auth, a sudden log-volume drop — is baselined by AI Monitor, and a spike surfaces in AI SIEM as a correlated security event. This closes the biggest gap in AWS-native security: attacks that operate within permissions an application already has — never touching IAM, invisible to CloudTrail and GuardDuty — surface as security events only because the application-layer anomaly was seen.
See the integration section for architecture detail and competitive advantages.
Update the Tier parameter in CloudFormation and run a stack update. Non-destructive — all data is preserved. Feature gates activate immediately.
Guides for deployment, configuration, and daily operations.