Skip to content

Per-VPC Threat Tuning

One sensitivity rarely fits a whole fleet. Set port-scan and data-exfiltration thresholds per VPC — tighten a sensitive production VPC, relax a noisy sandbox — and the scheduled Athena sweeps apply each VPC's own thresholds, scoped to that VPC.

Give a VPC a name and its own port-scan and large-egress thresholds. VPCs you do not name keep using the global defaults. The VPC picker is populated from the VPCs actually sending flow logs, so there is no hunting for IDs.

Scan unpinned VPCs

A single Scan unpinned VPCs checkbox decides what happens to VPCs with no per-VPC profile: scan them with the global thresholds (default), or ignore them entirely so detection runs only on the VPCs you explicitly list (an allowlist).

VPC attribution on threats and reports

Every flow-based threat (port scan, large egress) records and displays the VPC the activity came from, in the threat detail and forensic queries, so you can tell at a glance which network a detection belongs to. Threat reports include a Threats by VPC rollup for flow-sourced detections; threats with no VPC attribution are grouped as unattributed.

Available on essential tier and above (flow-log detection).