Unified Threat Timeline¶
Events from CloudTrail, VPC Flow Logs, GuardDuty, Config, and Security Hub are merged into a single chronological incident view per threat actor. Instead of jumping between consoles, you see one timeline that shows what a principal did, in order, across every source.
When deployed alongside the rest of the suite, Log Processor log-pattern detections and AI Monitor metric anomalies correlate into the same timeline — infrastructure and application signals appear next to the security events on the same resource and window.
A threat's Summary tab shows a compact lifecycle trail: the actual chronological path of status transitions (acknowledged, investigating, dismissed, resolved, and so on) with remediation milestones interleaved, and the current state called out. It reflects what really happened, including non-linear cycles (dismiss then restore), rather than an idealized forward stepper. Long histories collapse the oldest transitions into a hover-to-see "+N earlier" marker; the full record always remains in Audit History. It is derived from the existing audit trail — no new data.
Each detected threat is also mirrored into the AI SIEM — Threat Overview OpenSearch dashboard, which shows total and active threat counts and an active-by-severity breakdown. Status changes propagate so the active views track triage, and a daily reconcile self-heals the projection after any transient outage. The editor dashboard remains the authoritative live count.