Threat Intelligence¶
IP reputation enrichment from open threat feeds (advanced tier and above). Source IPs in CloudTrail and VPC Flow Logs are tagged with known-malicious indicators, so an address with a bad reputation is flagged where it appears in a threat.
Threat-intel feed lookups are one of the few calls that leave AWS, and they are optional — you can disable them. With them off, no customer data and no outbound threat-intel request leaves your account; the rest of AI SIEM is unaffected.