Skip to content

Changelog

AI SIEM is under active development, and these entries are intentionally detailed. While the product is evolving quickly, we document each change at a granular level — what changed, why, and how it behaves — so you can see exactly what a release alters and make informed upgrade decisions. As the product matures, entries will become higher level; for now the depth is deliberate.

Tags: NEW (new capability), FIXED (bug fix), IMPROVED (enhancement).

26h4 (October 2026)

In development — October 2–6, 2026 (updated as changes land).

  • NEW — AI Monitor anomalies become threats: any AI Monitor metric subscription you opt into for correlation can now raise a standalone AI SIEM threat when it flags an anomaly — not only enrich an existing timeline. Generic over any namespace, metric, and dimensions: a Log Processor regex-pattern spike or any AWS-service metric AI Monitor watches. AI Monitor owns the "is this anomalous?" decision via each subscription's own threshold; AI SIEM promotes the ones you selected into the threat queue, with a timeline and an on-demand playbook. The threat records only the metric identity, dimensions, value, and anomaly score — never the matched content. Requires correlation + AI Monitor (advanced+).
  • FIXED — AI Monitor correlation now matches reliably: metric-anomaly correlation is matched by the subscription's specification (namespace, metric, and dimensions resolved from AI Monitor's catalog) rather than an identifier the anomaly documents do not carry. Requires correlation + AI Monitor (advanced+).
  • IMPROVED — Human-readable timestamps in alert emails: threat alert emails render the detection time as a readable UTC timestamp and, when a display timezone is configured in Settings, append the same moment in that local zone. UTC remains the canonical value. All tiers.
  • IMPROVED — Flow-log analysis is Athena-first for flat, predictable cost: VPC flow-log detection runs entirely as scheduled, partition-pruned Athena queries — a 15-minute port-scan sweep and an hourly large-egress/exfiltration sweep — rather than scoring every flow record on a Lambda. Cost scales with query count, not traffic volume. Flow logs are always retained in S3 and remain fully queryable; detection can be turned off per deployment. Enterprise/flow tiers.
  • NEW — Threat lifecycle at a glance: a threat's Summary tab shows a compact lifecycle trail — the actual chronological path of status transitions with remediation milestones interleaved, and the current state called out. It reflects what really happened, including non-linear cycles, and never implies a stage that did not occur. Long histories collapse the oldest transitions into a hover-to-see "+N earlier" marker; the full record always remains in Audit History. All tiers.
  • NEW — Jump from an AI Monitor threat to its source: a threat promoted from an AI Monitor metric anomaly links its Source straight to Configure → Data Sources → AI Monitor Correlation. Requires correlation + AI Monitor (advanced+).
  • IMPROVED — Select all / none on the filtered threat list: the Threats toolbar's selection control is now an explicit Select all | none pair (with a tri-state checkbox), operating on the threats matching the current filters. All tiers.
  • IMPROVED — Clearer Data Sources guidance: the CloudTrail bucket field now explains it takes your existing trail bucket, that AI SIEM ingests objects on arrival with no partition layout required and never queries the bucket directly, and the cross-account grants a remote bucket needs. AWS Config now notes it can be high-volume and overlaps CloudTrail, with configuration/compliance drift as its distinct value. All tiers.
  • FIXED — AI group tuning (Analyze) and rule assessment no longer error: the privacy-mode guard the AI assist paths depend on was not initialized, which could raise an error when invoked. Identifier redaction before Bedrock is always on, as intended, and these actions now run cleanly. Requires custom rules + Bedrock (advanced+).
  • FIXED — Operational oversight documented: Getting Started now describes AI SIEM's monitor-the-monitor discipline — the CloudWatch alarms that give independent oversight of the SIEM itself. All tiers.
  • IMPROVED — Security response headers on the editor: the editor sends a baseline set of browser security headers on the console page and every API response — a Content-Security-Policy confining scripts, styles, and framing to the application's own origin (plus AWS S3 for signed report previews), HSTS, X-Content-Type-Options: nosniff, clickjacking protection, a referrer policy, and a permissions policy disabling geolocation/microphone/camera. All tiers.
  • FIXED — Report preview restored under the new security policy: the Content-Security-Policy's framing rule now permits the signed-URL report preview to load, without relaxing framing for any non-AWS origin. All tiers with reports (advanced+).
  • NEW — AI Monitor Correlation in Data Source Health: the dashboard's Data Source Health card includes an AI Monitor Correlation row, with state reflecting how correlation is wired (not configured, no subscriptions correlated yet, or healthy with a count). Requires correlation + AI Monitor (advanced+).
  • IMPROVED — Progress indicator for bulk threat actions: bulk status changes and bulk assign/unassign show a persistent in-progress indicator and disable the controls for the duration, so a large action can't be fired twice by accident. All tiers.
  • IMPROVED — Hardened AI Monitor correlation matching: dimension matching is guarded against pathological subscription patterns — an abnormally long or malformed dimension pattern degrades safely to an exact comparison. Internal hardening; no change to normal behavior. Requires correlation + AI Monitor (advanced+).
  • IMPROVED — Tidier threat Summary triage block: the status, assignment, origin ("fired by"), overview, and lifecycle lines on a threat's Summary tab are grouped into a single nested panel. All tiers.
  • IMPROVED — Clearer VPC Flow trend charts: the VPC Flow panel's Trends card shows three compact charts — threats found, sweep activity, and a threats-by-sweep-type breakdown (port scan vs large egress) over the last 24h — and says so plainly when flow detection is off. Enterprise/flow tiers.
  • FIXED — Lambda runtime logging no longer raises false threats: the detection engine recognises the Lambda runtime's awslambda-worker user agent as infrastructure plumbing — the same service-call gate that already skips CloudFormation, Auto Scaling, and other AWS-internal traffic — so routine CloudWatch Logs calls no longer score. Existing false threats are unaffected; no new ones are created. All tiers.
  • FIXED — Dismissed threats no longer counted as open findings: the compliance posture view now treats all three handled states (resolved, false positive, dismissed) consistently, so dismissing a threat removes its type from the open-findings tally. All tiers.

26h3 (September 2026)

Development milestone — September 29, 2026.

  • NEW — Delegated remediation via AWS Systems Manager Automation: response actions run as SSM Automation runbooks that you own, under an AutomationAssumeRole you create and scope — the AWS-managed prebuilts, the samples shipped, or your own. AI SIEM holds no standing IAM or EC2 write power: it only calls StartAutomationExecution and reads status. Map any threat type to a runbook entirely in config. A one-command add-on (deploy-remediation) creates the role and publishes its ARN to SSM so the editor auto-fills it. Cross-account is native via SSM multi-account targets. Replaces the earlier self-privileged auto-remediation. Enterprise tier.
  • NEW — Staged approval, scheduling, and a remediation watchdog: every action can be staged for one-click admin approval or auto-approved per runbook; deferred to a named window; and auto-resolve the threat on success. A remediation badge (pending, scheduled, remediating, remediated, failed, stalled) tracks each action independently of triage status, and you can filter the queue by remediation state. A scheduler tick starts due items once, and a watchdog flags remediations that run past a configurable limit (stalled) or were never picked up in time (late-start), with transient SSM throttling retried automatically. Enterprise tier.
  • NEW — VPC Flow panel: a dedicated view to choose the flow analysis mode (Athena or off), tune detection thresholds (including per-VPC overrides), and see live flow health — an estimated scan-cost indicator, flow-query Lambda activity, sweep runs and threats found, and an on-demand "top talkers" query. A CloudWatch dashboard section mirrors it. Enterprise/flow tiers.
  • NEW — Threat audit history from the archive: from an investigation result — or a threat that has aged out of the live store — you can pull that threat's full action history directly from the tamper-evident WORM audit archive. Advanced+.
  • IMPROVED — Safer configuration editing with multiple admins: the editor shows a non-blocking indicator of other administrators currently working, warns before remediating when you have unsaved configuration changes, and rejects a remediation whose underlying configuration changed out from under you. All tiers (admin).
  • NEW — Investigations, point-and-click threat search over any date range: a new Investigations view answers "what was detected between these two dates?" without SQL. Pick a From and To date and AI SIEM queries the long-retention forensic archive and lists every threat in the window. Queries run in the background: a fast one returns inline, a wide one appears under Previous investigations. Admin or analyst; advanced+.
  • IMPROVED — Report & investigation retention: generated reports and saved investigations expire automatically on a per-tier retention window (matching the audit-trail retention for that tier). All tiers with reports (advanced+).
  • IMPROVED — Safer remediation with multiple admins: remediation guards against acting on stale configuration (unsaved edits reminder, rejection on another admin's change), plus a lightweight, non-blocking presence indicator — advisory only, nobody is locked out. All tiers (admin).
  • NEW — "SLA breached" view for slow or overdue remediations: a breach is recorded as a durable flag on the threat and persists after the run finishes, so a remediation that eventually succeeded but took too long stays findable. A new SLA breached filter lists every one (labelled ran long or never started), the dashboard Remediations panel shows a running count, and the threat report's Remediation Summary flags how many breached. Enterprise tier.
  • IMPROVED — Remediation Summary counts each remediation once: the threat report's remediation section tallies each remediation by its final outcome (succeeded / failed / stalled / still in flight). Enterprise tier.
  • IMPROVED — Configuration integrity monitoring reliability: fixed a cold-start case where the configuration seal was not written, which could raise a spurious "configuration changed outside the editor" alert. All tiers.
  • NEW — Bedrock privacy mode, identifiers redacted before AI, encrypted at rest: real AWS identifiers (ARNs, account IDs, IAM principals, public/internal IPs) are replaced with type-preserving placeholders before anything is sent to Bedrock. The mapping back is encrypted with a dedicated KMS key and stored encrypted at rest; the editor restores real values only when you view the playbook. Requires playbooks (advanced+).
  • NEW — Playbook privacy provenance badge: each generated playbook shows how it was protected — redacted before AI & encrypted at rest, or a plain-template fallback. Advanced+.
  • IMPROVED — Playbook safety guard: before a generated playbook is stored, it is verified to contain no un-redacted real identifier; if anything slipped through, the model output is discarded and a safe deterministic template is used instead, with an operational alarm raised. Advanced+.
  • IMPROVED — Threat ID shown in the detail view: the selected threat's ID is displayed (and selectable) in the Summary and Details tabs. All tiers.
  • NEW — Investigations filters & export: a range investigation can be narrowed server-side by principal, source IP, threat type, MITRE tactic/technique, and minimum severity, and results export to CSV or JSON. Reopening a saved run repopulates the form. Admin or analyst; advanced+.
  • IMPROVED — Faster range investigations: the forensic threat archive is partitioned by day, so an investigation scans only the days in your window. Advanced+.
  • IMPROVED — Clearer Reports & Investigations views: opening a report preview or investigation result replaces the list with the detail and a Close control at the top. All tiers with reports (advanced+).
  • IMPROVED — Bedrock privacy is always on, every tier, and verified at read time: identifier redaction before the AI is no longer optional and cannot be turned off. The deterministic fallback playbook is also redacted and encrypted at rest, and the privacy badge is a verified claim re-checked against the stored playbook on open. A one-click shapes-only privacy report (identifier types only, never values) can be sent to support. All tiers.
  • IMPROVED — VPC Flow panel is honest about the active mode: the panel and dashboard card show the real bytes scanned by the sweeps, so a healthy, flat-cost deployment no longer looks idle. VPC Flow Logs are presented as a managed source (the stack owns the bucket). Essential+.
  • NEW — Per-VPC detection thresholds: flow-log detection can be tuned per VPC — give a VPC a name and its own port-scan and large-egress thresholds, and the scheduled Athena sweeps apply each VPC's own thresholds. VPCs you don't name keep the global defaults; the picker is populated from the VPCs actually sending flow logs. Essential+.
  • NEW — "Scan unpinned VPCs" control: a single checkbox decides what happens to VPCs with no per-VPC profile — scan them with the global thresholds (default), or ignore them entirely (an allowlist). Essential+.
  • IMPROVED — Threats name their VPC: flow-based threats (port scans, large egress) record and display the VPC the activity came from. Essential+.
  • IMPROVED — Threat reports break down flow threats by VPC: reports include a Threats by VPC rollup for flow-sourced detections; unattributed threats are grouped. Essential+.

26h2 (September 2026)

Development milestone — September 17, 2026.

  • NEW — Assign threats in bulk: select any set of threats and assign them all to a user (admins) or claim them for yourself (analysts) in one action, with an Unassign option. Before reassigning threats that already have an owner, you're told how many will change hands. Every assignment is recorded individually in the tamper-evident audit trail. Analysts can only assign or unassign their own; viewers cannot assign. All tiers.
  • NEW — Threats populate the OpenSearch dashboards: each detected threat is mirrored into the AI SIEM — Threat Overview OpenSearch dashboard, which shows total and active threat counts and an active-by-severity breakdown. Status changes propagate, and a daily reconcile self-heals the projection after any transient outage. The editor dashboard remains the authoritative live count. All tiers.
  • IMPROVED — Operational visibility: the CloudWatch operations dashboard leads with an alarm-status panel summarizing every AI SIEM alarm, and a new alarm fires on sustained OpenSearch write failures. The bulk threat-action buttons gained explanatory tooltips.
  • IMPROVED — Playbooks are generated on demand: an incident-response playbook is created the first time you open a threat and click Generate Playbook (then cached and reused), instead of being pre-generated for every alert-worthy threat. This ties Bedrock usage to the threats you actually work. Requires playbooks (advanced+).
  • NEW — Per-detection email alerts: every detection — built-in and custom — has an Email alerts toggle under Detection Rules. Turn it off to keep a detection scoring threats, building timelines, and showing on the dashboard while silencing its email. When several rules raise the same threat, the email is muted only if all of them are muted. Threats raised purely by the ML baseline still alert on score. All tiers (admin).
  • IMPROVED — Configuration editing is one working copy with a single Save: edits across Detection Rules, Settings, Data Sources, and the report schedule accumulate together. A header Save commits everything at once (with the conflict check) and Undo discards all unsaved edits; an "Unsaved changes" indicator shows whenever the working copy differs from what's saved. All tiers (admin).
  • NEW — Autosave draft & crash/expiry recovery: in-progress configuration is periodically saved as a private, per-user draft (never applied to the live config). If your session expires or the tab closes mid-edit, the next sign-in offers to restore the draft. All tiers (admin).
  • NEW — Review unsaved changes (in-memory diff): under Settings → Configuration History, the current version's Diff shows a field-level, colour-coded comparison of your unsaved edits against the saved configuration. All tiers.
  • IMPROVED — Clearer duplicate-rule handling: adding a custom rule that duplicates an existing one (by name, or by identical conditions/severity/sources/window) now points you straight at the existing rule instead of a dead-end message. All tiers.
  • IMPROVED — Collapsible Data Sources panel: the Data Sources and AI Monitor Correlation cards collapse/expand and remember their state per user (server-side). All tiers.
  • IMPROVED — Cleaner Audit Activity in threat reports: the report's Audit Activity section summarizes analyst status changes, remediations, and config changes by actor and action, shows the most-recent events as a preview with an accurate window total, and points to the shipped Athena saved query "Audit activity (who did what)". Advanced+.
  • NEW — Real-time dashboard totals: the Threat Overview donuts show true whole-table counts by status and severity, kept live as threats are created and triaged. A "live totals" note shows when they were last reconciled and how many threats have been archived all-time. All tiers.
  • NEW — Server-side threat filtering & pagination: the Threats list filters by status and severity across the whole table and pages through results with Load more, backed by a new index. Search, type, time, and assignee still refine the loaded page. All tiers.
  • NEW — Automatic threat retention & archive: a daily pass retires old threats from the live list while keeping the dashboard totals exact and recording every removal in the tamper-evident audit trail. The forensic copy in the datalake and the audit archive keep their own longer retention. Tunable under Settings → Threat Retention & Archive, monitored with CloudWatch alarms, and safe on very large tables (self-continuing, with a mass-delete circuit breaker). All tiers.
  • IMPROVED — Faster threat triage: applying a status (single or bulk) writes directly and in parallel instead of one round-trip per threat. Active filters in the Threats toolbar are highlighted. All tiers.
  • NEW — AI group tuning: on an expanded group of similar threats, Analyze asks AI to assess whether they're false positives and propose a rule exclusion, shown with the deterministic facts they share. Two explicit actions follow — apply the exclusion (opens the rule for review, then Save, fully audited) and mark the group false-positive. Suggestion only and exclusion-only: it can never broaden a rule or open a blind spot. Requires custom rules + Bedrock (advanced+).
  • NEW — Built-in rule exclusions: every built-in detection can carry exclusions — if a condition matches (e.g. deploys from your office CIDR, a known service principal), that rule does not fire. Edit per rule under Detection Rules, or click "(exclude this)" on a built-in-fired threat. Suppresses only (never hides a real anomaly — the behavioral baseline still scores independently), audited, all tiers. Source-IP exclusions work on flow-log rules too.
  • NEW — Assess a rule with AI: in the custom-rule builder, Assess sanity-checks the rule you're editing. The critique is grounded in a field-capability contract plus deterministic checks, so structural facts don't depend on the model. Advisory only. Requires custom rules + Bedrock (advanced+).
  • IMPROVED — Expanded ML behavioral baselines: the per-principal model now spans nine behavioral dimensions, adding region novelty, resource-service novelty, and principal identity type alongside the existing API, time, IP, error, and write signals. Baselines re-learn once on upgrade, then continue online. All tiers.
  • NEW — Context-aware severity modifiers (advanced+): a matched rule scores higher when the actor is the root principal or the source IP is outside your configured trusted networks. Modifiers only raise a score, never suppress one, and never key on the ML anomaly signal (no double-counting). The untrusted-IP modifier is inert until you set severityModifiers.trustedIps.
  • NEW — Threat detail redesigned with Summary and Details tabs: Summary is an at-a-glance triage view; Details holds the full evidence, timeline, correlated events, audit history, and playbook. All tiers.
  • NEW — Analyst notes on threats: add free-text notes as you work an incident. Notes are append-only, shown in the threat's Audit History, and recorded in the tamper-evident audit trail. All tiers (admin/analyst).
  • NEW — Threat assignment: admins can assign a threat to any admin/analyst or claim it; analysts can claim it for themselves. The Threats toolbar adds an admin "Assigned to" filter and an "Assigned to me" toggle. Every assignment is audited. All tiers.
  • NEW — Time-window filter on the Threats list: narrow to the last 24 hours, 48 hours, week, month, 2 months, or older. Composes with the other filters and with bulk actions. All tiers.
  • NEW — Download incident report: export a self-contained HTML report for a threat (facts, evidence, timeline, correlated identities, full audit trail, and playbook), including live links back to the threat and to any custom rule that fired. All tiers, all roles.
  • NEW — Jump to the rule that fired: on a threat, the rule that fired it is shown on the Summary tab and in Evidence as a link, with a "Back to threat" breadcrumb. Any role can follow the link to view; editing still requires admin.
  • NEW — More custom-rule condition operators: added does-not-contain, does-not-exist, ends-with, the "or-equal" numeric comparisons (≥, ≤), and in-CIDR / not-in-CIDR for IP fields. Requires custom rules (advanced+).
  • IMPROVED — Sigma import handles more rules: the importer translates ends-with, numeric comparisons, CIDR matching, and exists modifiers, and an OR condition imports as several rules, one per branch. It remains a bounded translator that never silently mistranslates — regex, |all, and nested/AND-across-selection conditions are listed for you to add by hand. Requires custom rules (advanced+).
  • IMPROVED — Configurable retention per tier for threat timelines and the audit trail, plus S3 noncurrent-version expiration for the config bucket.
  • NEW — Cold log-retention override: the DatalakeRetentionDays stack parameter lets you keep raw events and threat evidence in the S3 datalake (Athena-queryable) longer than your tier's default — e.g. 2555 for a 7-year policy — without a tier change. OpenSearch hot-search retention stays tier-governed.

Initial release (26h2, August 2026)

Development milestone — August 10, 2026.

  • NEW — Initial release.
  • NEW — CloudTrail ingestion with S3 event-driven processing.
  • NEW — VPC Flow Log ingestion.
  • NEW — GuardDuty + Security Hub finding ingestion via EventBridge.
  • NEW — ML behavioral baselines per IAM principal.
  • NEW — Unified threat timeline with cross-signal correlation.
  • NEW — MITRE ATT&CK mapping (advanced+).
  • NEW — AI-powered incident response playbooks via Bedrock (advanced+).
  • NEW — Threat intelligence IP enrichment (advanced+).
  • NEW — Compliance posture scoring (advanced+).
  • NEW — Auto-remediation: disable keys, revoke sessions, isolate instances (enterprise) — superseded in 26h3 by delegated SSM-Automation remediation (buyer-owned runbooks and role).
  • NEW — Editor UI with threat dashboard, timeline viewer, source management.
  • NEW — Deploys on existing Log Processor VPC + OpenSearch (no new cluster).
  • NEW — 5-tier entitlement system via AWS Marketplace.
  • NEW — AI Monitor metric-anomaly correlation (advanced+): metric anomalies are read from the shared OpenSearch domain and merged into threat timelines on the same resource and window. Per-subscription opt-in in the editor Data Sources panel.
  • NEW — Log Processor pattern detections reach AI SIEM through AI Monitor: a per-pattern CloudWatch metric is baselined by AI Monitor, and a spike surfaces as a correlated timeline event.
  • NEW — On-demand flow query: VPC flow logs are captured to S3 continuously (ALL traffic; cheap), and an anomalous network-egress spike triggers a scoped Athena query over that data for the affected resource and window.
  • NEW — Flat-cost flow-log analysis: VPC flow logs are retained in S3 and analyzed by scheduled Athena sweeps, so cost scales with query cadence rather than traffic volume.