The intelligence layer on top of your SIEM and SOAR: every finding triaged with evidence.
Keep your SIEM and SOAR. Agents sit on top of them, pick up every finding, pull the CloudTrail events, identity history and network flows behind it, and hand your analysts a verdict with the evidence attached. False positives are closed with a written reason. Confirmed threats arrive with a containment step ready to approve.
Unusual API calls from IAM role ci-deployer
Triaged in 2m 10s. Waiting for SOC approval
[The work behind every finding]
01The manual work
Triage
A finding is only a lead. Analysts still pivot across consoles, pull logs, check the identity and decide if it is real.
02The agent handoff
Verdict ready
Frontier agents enrich every finding, rebuild the attack path and prepare a verdict and a containment step for review.
03Your analysts’ role
Decide
Set which findings agents may close and which actions need sign-off. Review the evidence and approve the response.
[Where CloudThinker fits]
01Security signals
Already in your clouds
No change to collection
02SIEM and SOAR
Your system of record
System of record
03Investigation
CloudThinker
Read-only by default
04Response
Cases, not alerts
Playbooks run on approval
[Example scenario]
A fintech with 14 AWS accounts, Splunk as SIEM and a SOAR running playbooks. 1,200 findings a week, one analyst overnight, a regulator who wants every incident explained.
Finding lands in the queueSignal
GuardDuty: unusual API calls from IAM role ci-deployer. Splunk raises it as one of 41 open alerts.
Agent takes it firstAgent
Pulls CloudTrail for the role, the access key history, VPC flow logs and the last CI runs that used the key.
Verdict, with evidenceAgent
312 ListBuckets calls from a new ASN, no CI run at that time, key 214 days old. Verdict: leaked credential.
Containment readyAgent
Proposes deactivating the key and scoping the role to the CI runner. Posts to the SOC channel and pages the analyst.
Analyst approvesYour team
Checks the CloudTrail events in the case, approves containment. The SOAR playbook runs under that approval.
Case written upAgent
Key disabled, no further calls. Case closed in Splunk with a timeline, evidence and a ticket to rotate CI secrets.
Splunk03:47
Notable: GuardDuty UnauthorizedAccess:IAMUser/AnomalousBehavior on role ci-deployer (prod-core).
CloudThinker03:49
Verdict: threat confirmed. Key AKIA…7QX used from AS 209605 with no matching CI run. 312 ListBuckets calls, no writes yet. Proposed: deactivate key, scope role to runner. Evidence: 11 events.
SOC analyst03:53
Confirmed, no CI job at that time. Approved.
CloudThinker04:05
Key deactivated, 0 calls since 03:54. Case SEC-3307 closed with timeline. Follow-up: rotate CI secrets (SEC-3308).
An illustrative example. Team, systems and times are representative, not a specific customer.
[Frontier investigation agents]
Agents work as the intelligence layer between detection and response. Your SIEM keeps detecting, your SOAR keeps executing, and every finding arrives already investigated with a verdict you can check.
[What changes]
| Moment | Today | With frontier agents |
|---|---|---|
| First look at a finding | Whenever an analyst reaches it in the queue | Minutes after it lands |
| Enrichment | By hand, console by console | Identity, log and network context pulled automatically |
| False positives | Closed without a record of why | Closed with a written, auditable reason |
| Response | Playbooks started by hand | Containment step ready for approval |
| Detection quality | Tuned when someone has time | Noisy rules flagged from every investigation |
[Integrations]
[Adoption path]
The rollout follows the four phases of the AWS Cloud Adoption Framework, so it fits the plan your cloud team already runs.
01Envision
Pick one finding source
Connect one SIEM or GuardDuty feed read-only and let agents triage in shadow mode. Compare their verdicts with your analysts’.
02Align
Agree the response policy
Decide which findings agents may close alone, which containment steps need approval, and who approves.
03Launch
Roll out across accounts
Add every account and detection source on the same policies, verdict format and audit trail.
04Scale
Make it the SOC default
Every new detection launches with agent triage on. Verdicts feed rule tuning and incident reviews.
[AWS guidance]
[Trust and control]
[Questions]
[Go deeper]
Start with one finding source, read-only. See the verdicts agents reach before you grant a single permission more.

Up to $200K in AWS credits
Applied to your own AWS account.

AWS AI Services Competency
Validated for Agentic AI Consulting.

Covered 24/7, on your approval
Under HIPAA, GDPR and SOC 2 controls.