AI SIEM — Changelog
26h2 (August 2026)
- NEW Initial release
- NEW CloudTrail ingestion with S3 event-driven processing
- NEW VPC Flow Log ingestion
- NEW GuardDuty + Security Hub finding ingestion via EventBridge
- NEW ML behavioral baselines per IAM principal (RCF)
- NEW Unified threat timeline with cross-signal correlation
- NEW MITRE ATT&CK mapping (compact+)
- NEW AI-powered incident response playbooks via Bedrock (compact+)
- NEW Threat intelligence IP enrichment (advanced+)
- NEW Compliance posture scoring (advanced+)
- NEW Auto-remediation: disable keys, revoke sessions, isolate instances (enterprise)
- NEW Editor UI with threat dashboard, timeline viewer, source management
- NEW Deploys on existing Log Processor VPC + OpenSearch (no new cluster)
- NEW 5-tier entitlement system via AWS Marketplace