Detection built on behavior, not configuration
Eight detection groups, all from one log source.

Some events exist in no other log.
S3 lifecycle actions never reach CloudTrail. Expirations, delete markers, lifecycle rule changes, versioning and object-lock removal, replication to unknown destinations. In the SSE-C ransomware campaigns of 2025, the deletion step was exactly this.
Logging and log integrity
- Logging disabled or redirected
- AWS log delivery denied or failing
- Log destination outside your organization
Ransomware and destruction
- Encryption-based ransomware patterns
- Bulk deletion bursts
- Mass overwrite of existing objects
- Recovery protections removed
AI agents and MCP
- Agents writing where read-only was assumed
- Guardrails disabled mid-session
- Multi-account sweeps under privileged roles
- Unregistered AI clients appearing
Exfiltration
- Enumerate-then-download sequences
- Dormant data suddenly read
- Copies to unknown destinations
- Unauthenticated access that succeeded
- Presigned URL misuse
Identity and credentials
- Concurrent sessions from separate locations
- Behavior outside an identity's baseline
- First-time access to new assets
- Credential spraying and permission probing
Client and session integrity
- Client swapped behind an established identity
- Human sessions behaving like automation
- End-of-life SDKs and known CVEs
- Outdated encryption and signing
Boundary and platform
- Development and production crossing over
- Reads bypassing the data catalog
- Unauthorized writers on infrastructure state
- Credentials and database dumps in the wrong place
Noise control
Findings ship with the log lines that triggered them. A finding without evidence does not exist. Baselines suppress the routine: expired STS tokens mid-session, shared-role cleanup during business hours, and scanner traffic are labeled rather than alerted.
A curated stream, not a firehose.
Not everything is an alert
Access classification, client inventory, coverage gaps, and the full object record are collected continuously and stay queryable. Detections are what surfaces from it.
Start with proof,
not a pitch.
Scoped read-only role, 30-day lookback, results in 48 hours.