Skip to content

AI SIEM

AI-powered Security Information and Event Management for AWS. AI SIEM correlates CloudTrail, VPC Flow Logs, GuardDuty findings, Security Hub, and Config changes into a unified, chronological threat timeline per threat actor, applies ML behavioral analysis per IAM principal, and guides incident response — all running inside your own AWS account.

One line: turn fragmented AWS security signals into correlated threat timelines with behavioral ML and guided response, without sending your data to a third-party vendor.

Who it is for

Security and platform teams running on AWS who already have CloudTrail, GuardDuty, Security Hub, or VPC Flow Logs producing signal, but no single place that correlates them into an attack narrative. AI SIEM is sold on AWS Marketplace as a flat monthly software fee per tier; AWS infrastructure is billed directly to your account at cost.

Where it runs in the suite

AI SIEM builds on the Perfware platform:

  • Requires Log Processor. It deploys onto the shared VPC and OpenSearch domain that Log Processor provides — no new cluster. Log Processor also does application-log pattern detection, which reaches AI SIEM's timeline through AI Monitor.
  • Optionally integrates with AI Monitor (advanced tier and above). AI Monitor watches CloudWatch metrics and detects anomalies; AI SIEM reads those from the shared OpenSearch domain and correlates them into threat timelines, and can trigger an on-demand flow-log query around a network-egress spike.

Each product works standalone; together they cover the full kill chain while reusing one VPC and OpenSearch domain. The Perfware Docs hub owns the shared Suite Architecture page.

AI SIEM architecture overview

What it does

  • Correlates events across CloudTrail, Flow Logs, GuardDuty, Security Hub, and Config into unified threat timelines.
  • Learns ML behavioral baselines per IAM principal — no manual threshold tuning.
  • Generates step-by-step remediation playbooks for the specific threat.
  • Deploys as a single CloudFormation stack on your existing Log Processor infrastructure, typically in under an hour.
  • Runs entirely in your AWS account. No customer data goes to any non-AWS endpoint. AI prose is generated by Amazon Bedrock in your own account (it does not retain or train on it); the only calls that leave AWS are the Marketplace entitlement check and optional threat-intel lookups you can disable.

Deterministic by design

Rules and math decide every finding; AI only explains, and its output is validated. Every threat score, count, and severity is computed by rules and math — not a language model. Bedrock writes only the prose in playbooks and report summaries, with numbers templated in and invented identifiers rejected, so a model cannot fabricate a finding or misstate a figure.

The problem it solves

AWS provides powerful security services, but they are fragmented. Without correlation, teams cannot see the full picture:

  • GuardDuty findings lack context about what the attacker did before and after.
  • CloudTrail is noisy — thousands of API calls with no behavioral baseline to distinguish anomalies.
  • VPC Flow Logs sit in S3 unsearchable unless you build custom pipelines.
  • Security Hub aggregates findings but does not correlate them into attack narratives.
  • Incident response is manual — engineers spend hours piecing together timelines across consoles.
  • Infrastructure and application signals live in yet another tool — a CPU spike that means cryptomining, or an auth-failure surge that means credential stuffing, never reaches the security timeline.
  • Third-party SIEMs typically send your logs to a vendor platform and carry significant annual licensing.

Next steps