Skip to content

Threat Reports

On-demand or scheduled summary reports over a 1–30 day window, emailed with a time-boxed download link (advanced tier and above). Each report carries:

  • An AI-written executive summary.
  • A threat breakdown by severity and MITRE tactic.
  • A live SIEM health and ML-training snapshot.
  • A point-in-time snapshot of the detection configuration — which built-in and custom rules are enabled or disabled, thresholds, and auto-remediation posture.
  • The audit-activity log for the window — who did what, from where.

The Audit Activity section summarizes analyst status changes, remediations, and config changes by actor and action (so a bulk triage does not flood the report with near-identical rows), shows the most-recent events as a preview with an accurate window total, and points to the shipped Athena saved query "Audit activity (who did what)" for the full row-by-row export.

For flow-sourced detections, reports include a Threats by VPC rollup, so a report shows which networks are generating port-scan and exfiltration activity; threats with no VPC attribution are grouped as unattributed.

The written prose follows the deterministic framing: Bedrock writes the summary, every number is templated in from the computed results, and invented identifiers are rejected.

Investigations — point-and-click threat search over any date range

A separate Investigations view answers the post-mortem question "what was detected between these two dates?" without writing SQL. Pick a From and To date and AI SIEM queries the long-retention forensic archive — reaching further back than the live queue — and lists every threat in the window, newest first. Each result opens the full threat for its current status, timeline, and playbook (or, for a threat that has aged out of the live store, its detection-time record from the archive).

Queries run in the background: a fast one returns in seconds inline; a wide one keeps working and appears under Previous investigations to reopen later. A range investigation can be narrowed server-side by principal, source IP, threat type, MITRE tactic/technique, and minimum severity, and results export to CSV or JSON for an incident ticket or compliance evidence. Reopening a saved run repopulates the form. Admin or analyst; advanced+.

Generated reports and saved investigations expire automatically on a per-tier retention window (matching the audit-trail retention for that tier).