Skip to content

AI triage and investigation for AWS Security Hub

OwlSOC connects read-only to AWS Security Hub, investigates each finding, and returns a hedged verdict with a recommended action, typically in under two minutes, 24/7. A human on your team approves any containment before it runs.

What OwlSOC does with an AWS Security Hub finding

When a finding lands in AWS Security Hub, OwlSOC reads it, pulls the surrounding signals, and works it like an analyst would. It correlates related events, resolves the affected entities, maps the activity to MITRE ATT&CK, and writes an evidence-linked timeline where every claim cites a source log or pivot ID. You get a plain-language verdict and a recommended action, not a higher-priority queue.

It runs on every finding, not a sample. A mid-sized AWS estate can fire hundreds of findings a day across config drift, IAM, and threat detections, and most teams triage by gut feel under load. OwlSOC investigates each one and tells you which ones actually warrant attention.

  • IAM anomalies — unusual role assumption, new access keys, privilege changes
  • Exposed resources — public S3 buckets, open security groups, exposed snapshots
  • Suspicious API calls — from unfamiliar regions, principals, or sources
  • Affected-entity resolution across accounts, principals, and resources

Two tiers: standard triage and AI investigation

Standard deterministic triage runs on every finding. It scores the finding and applies repeatable rules; the default verdict is "uncertain — needs review" rather than a guess. This is the baseline on every alert.

The AI investigation is a separate step included in the paid tiers. It produces a calibrated confidence percentage, a root-cause narrative, and a hedged verdict: likely true positive, likely false positive, or uncertain — needs review. It never returns "confirmed threat". Confidence is deliberately conservative, and ambiguous cases are flagged for a human rather than miscalled.

Verdict, then human-approved containment

OwlSOC investigates and recommends; a human approves. For a Security Hub finding it will tell you what it thinks happened, how confident it is, and the action it would take, but it does not act on its own.

Containment is human-approval-gated and write-grant-gated. An action only runs after someone on your team approves the specific action, and only on the write scopes you have granted. Everything is logged. Reversible actions can be undone; the few that cannot are flagged before you approve. By default OwlSOC is read-only and takes no action at all.

Which AWS sources are supported

AWS Security Hub is the supported AWS connector. It aggregates findings from across your AWS security tooling, so connecting it read-only gives OwlSOC a single, normalised view to investigate against.

Other AWS sources are scoped on request, not shipped. If a source such as AWS GuardDuty matters to you and you want it investigated directly rather than via Security Hub, tell us and we will scope it. We add connectors against real pilot demand, not a roadmap slide.

  • Supported now: AWS Security Hub (read-only)
  • Scoped on request: AWS GuardDuty and other AWS sources — not yet shipped
  • Also supported: Microsoft Sentinel and Microsoft Defender (Endpoint and Office)

What you get and how it runs

The output is built to be checked, not trusted blindly. Your team can open any line of the timeline and see the exact log or finding behind it, disagree with the verdict, and follow the reasoning in the client portal. OwlSOC can also export case reports (incl. PDF) to support your own SOC 2, ISO 27001, or GDPR reporting.

Setup is light. Connection is read-only by default, there are no agents to install, and most pilots run their first investigations within about 48 hours of access. It starts with a £495, 30-day fully-refundable pilot, then from £495 per month per monitored environment, billed monthly with no minimum term.

Frequently asked

Does OwlSOC support AWS GuardDuty?

Not as a direct connector yet. AWS Security Hub is the supported AWS connector, and it aggregates findings from across your AWS security tooling. AWS GuardDuty is scoped on request rather than shipped — tell us if you need it investigated directly and we will scope it against real pilot demand.

How does OwlSOC connect to AWS Security Hub?

Read-only by default, with no agents to install. You grant the access OwlSOC needs to read findings and the surrounding signals, and it is auditable from your side. Most pilots run their first investigations within about 48 hours of access.

Will OwlSOC take action on an AWS finding automatically?

No. OwlSOC investigates and recommends; a human on your team approves any containment before it runs. Actions are human-approval-gated and only execute on the write scopes you have granted. By default OwlSOC is read-only and takes no action at all.

What kind of verdict does OwlSOC give on a Security Hub finding?

A hedged one: likely true positive, likely false positive, or uncertain — needs review. The AI investigation adds a calibrated confidence percentage and a root-cause narrative, with every claim in the timeline citing a source log or pivot ID. It never returns "confirmed threat".

See it on your alerts.

Start with a 30-day refundable pilot. £495, one environment, every alert investigated, a full report at week four. Read-only, live within 48 hours of access.