Skip to content

Cross-Signal Correlation

AI SIEM automatically connects related events into one threat instead of leaving them as separate alerts. A compromised credential, unusual S3 access, port scanning, and a GuardDuty alert on the same actor become a single correlated threat.

Correlation works across sources by principal, IP, and resource, within aligned time windows. When AI SIEM is deployed with the rest of the suite, the correlation reaches further:

  • AI Monitor detects infrastructure anomalies (a CPU spike on an idle instance, a sudden database connection surge, an EBS write-volume explosion).
  • AI SIEM detects security events (IAM changes, credential probing, privilege escalation).
  • When both fire on the same resource within the same window, the threat timeline shows both signals together.

The result is an attack narrative rather than a stack of unrelated alerts — for example: "A role policy was modified, then CPU spiked to 100% on three instances, and network egress jumped 50x."

What this catches (examples)

Real attack patterns that need cross-product correlation; no single tool sees the full picture.

AI Monitor metrics → AI SIEM

  • Cryptomining: CPU spikes to 100% on an idle instance. AI SIEM correlates with CloudTrail showing a new key pair created from an unusual IP ten minutes earlier.
  • Data exfiltration: NetworkOut jumps 50x on one instance. AI SIEM runs a scoped Athena query over the captured flow logs, identifies the destination, and correlates with an IAM role modification that enabled it.
  • Ransomware: EBS WriteBytes explodes. AI SIEM finds a KMS key creation and cross-account policy in CloudTrail during the same window.
  • Alert suppression: SNS failed deliveries spike from zero. AI SIEM finds sns:SetTopicAttributes in CloudTrail removing the security team's subscription.
  • Defence evasion: OpenSearch indexing rate drops to zero. AI SIEM correlates with Lambda deletions and SQS purges that killed the ingestion pipeline.
  • SQL injection: RDS connection count jumps from 20 to 200. AI SIEM correlates with ALB 5xx spikes and Log Processor slow-query detection on the same database.

Log Processor patterns → AI SIEM

  • Credential brute-force: 500+ failed logins in five minutes against the app's own auth. AI SIEM checks VPC flow logs from the same source IP and whether any attempt succeeded.
  • Privilege escalation: A code path that never threw starts producing "access denied" errors. AI SIEM finds the role was modified in CloudTrail moments before.
  • Command & control: Application logs show repeated connection failures to an unknown external host. AI SIEM correlates with REJECT flows to the same destination.
  • Insider data theft: Bulk CSV export requests far exceeding normal usage. AI SIEM checks the NetworkOut metric for volume and the user's role-assignment history.
  • Logging disabled: A service that produced 1000 lines/min drops to zero. AI SIEM finds DeleteLogGroup in CloudTrail and raises a defence-evasion threat.
  • Session hijacking: "Invalid token" errors from IPs that never had valid sessions. AI SIEM correlates with the legitimate user's last known location and flags the attempt.