Detection

Detection built on behavior, not configuration

Eight detection groups, all from one log source.

reCost priority findings, ranked by risk score

Some events exist in no other log.

S3 lifecycle actions never reach CloudTrail. Expirations, delete markers, lifecycle rule changes, versioning and object-lock removal, replication to unknown destinations. In the SSE-C ransomware campaigns of 2025, the deletion step was exactly this.

Object expirations and delete markers
Lifecycle rules scheduling silent deletion
Versioning and object-lock removal
Replication to unknown destinations

Logging and log integrity

  • Logging disabled or redirected
  • AWS log delivery denied or failing
  • Log destination outside your organization

Ransomware and destruction

  • Encryption-based ransomware patterns
  • Bulk deletion bursts
  • Mass overwrite of existing objects
  • Recovery protections removed

AI agents and MCP

  • Agents writing where read-only was assumed
  • Guardrails disabled mid-session
  • Multi-account sweeps under privileged roles
  • Unregistered AI clients appearing

Exfiltration

  • Enumerate-then-download sequences
  • Dormant data suddenly read
  • Copies to unknown destinations
  • Unauthenticated access that succeeded
  • Presigned URL misuse

Identity and credentials

  • Concurrent sessions from separate locations
  • Behavior outside an identity's baseline
  • First-time access to new assets
  • Credential spraying and permission probing

Client and session integrity

  • Client swapped behind an established identity
  • Human sessions behaving like automation
  • End-of-life SDKs and known CVEs
  • Outdated encryption and signing

Boundary and platform

  • Development and production crossing over
  • Reads bypassing the data catalog
  • Unauthorized writers on infrastructure state
  • Credentials and database dumps in the wrong place

Noise control

Findings ship with the log lines that triggered them. A finding without evidence does not exist. Baselines suppress the routine: expired STS tokens mid-session, shared-role cleanup during business hours, and scanner traffic are labeled rather than alerted.

A curated stream, not a firehose.

Not everything is an alert

Access classification, client inventory, coverage gaps, and the full object record are collected continuously and stay queryable. Detections are what surfaces from it.

See the platform →

Start with proof,
not a pitch.

Scoped read-only role, 30-day lookback, results in 48 hours.