01 / AWS CloudTrail triage — no SOC required

Know which AWS alerts actually matter — without a security team.

Send a read-only CloudTrail export. Gideon investigates every notable event against your account’s own history — the context that tells a real attack from your normal — then returns the short list that needs you, and dismisses the rest with reasons.

Get your free triage report See a sample report

Read-only export  /  no agent, no access to your environment  /  logs deleted after the report

GIDEON / INVESTIGATION REPORT ACCT 1234…3123
131 EVENTS · 4 ACTORS · 30–90 DAY WINDOW
7 TRIAGED 2 NEED ATTENTION 5 DISMISSED · 71%
MALICIOUS · 95% 185.220.101.34
GetObject by assumed-role BankingWAFRole/…
SSRF → S3 exfiltration. Revoke the session, rotate creds, block the IP.
DISMISSED · ROUTINE 10.0.4.20
GetObject by devops-svc
Matches the account’s 8-week weekly cadence. No action needed.
ILLUSTRATIVE — BASED ON A REAL PUBLIC INTRUSION DATASET
71%
of the noise dismissed — tested on real attack data
0
real attacks missed in that same test
~15 MIN
a day to run your security — not 3,000 alerts
02 / What you get back

A report you can act on — not another dashboard to learn.

A sample run on a public attack dataset — an S3 data-exfiltration intrusion mixed with routine activity. 131 events, 4 actors, 7 notable actions triaged. Here are two of them.

MALICIOUS · 95% from 185.220.101.34
GetObject by assumed-role BankingWAFRole/…

Part of a multi-stage intrusion: an external IP enumerated the environment as user pedro, then pivoted through an assumed role to read S3 — a classic SSRF → exfiltration chain.

Recommended: revoke the role’s session, rotate pedro’s credentials, block the IP.
DISMISSED · ROUTINE from 10.0.4.20
GetObject by devops-svc

The same API call — opposite verdict. This one runs on a fixed weekly cadence from an internal IP, consistent with the account’s eight-week history.

No action needed. Verified against your own baseline.
The point

Same action, opposite verdict — because Gideon judges each event against your normal, not a generic rule.

03 / How it works

Connect once. Get the short list.

01

Send your CloudTrail

A read-only export covering the last 30–90 days. No agent to install, no role in your account.

02

Judged against your history

Every notable action is triaged against your account’s own baseline — pulling timelines, checking IPs, reconstructing what happened — not matched to a generic rule.

03

You get the short list

A report: what needs you, with explanations and fixes — and what we safely dismissed, and why.

In scope: AWS CloudTrail management events from the window you send — a focused triage of the notable actions, not a full audit and not a replacement for monitoring. Each verdict is a real investigation — timeline, enrichment, and reasoning against your own history, with the evidence shown — automated end to end and a starting point you can verify. We never touch your environment.

04 / Why the verdicts hold up

Running AI over logs is the easy part.

The hard part is knowing what’s normal for your account — so it can safely dismiss the 90% that’s noise and stand behind the few things it won’t. That’s what we built, and it’s why pasting logs into a chatbot doesn’t hold up.

Your logs don’t fit

90 days of CloudTrail is millions of events — far past any chat window. Gideon queries your full history instead of reading it all at once.

Context decides the verdict

Without your baseline, an AI flags everything as suspicious. Gideon knows what’s normal for you — so it can safely dismiss the noise.

An investigation, not a prompt

Each alert gets a real workup — timeline, enrichment, related events — not one shallow pass over a truncated paste.

Built for no-SOC teams

No detection engineering, no analyst, no daily log-wrangling. Connect once; the short list lands in your inbox.

05 / Pricing

Simple, flat pricing.

No usage meters, no per-GB ingest, no surprise bill at the end of the month — the thing you’re probably trying to get away from. The price is the price.

FREE REPORT
$0
one-time snapshot · one per company
  • Full investigation of your CloudTrail export
  • The short list that needs you, with fixes
  • Delivered within 1 business day
  • No commitment, no card
Get your report
MOST TEAMS START HERE
CONTINUOUS
$249 /mo
per AWS account
  • Always-on — no manual export, ever
  • Real-time alerts on what matters
  • Daily digest to email or Slack
  • Investigated against your living history
Talk to us
GROWTH
$699 /mo
multiple AWS accounts
  • Everything in Continuous
  • Multi-account coverage
  • Longer history & retention
  • Priority response & integrations
Talk to us

All prices in USD, billed monthly per AWS account; cancel anytime — see our Refund Policy. Payments and tax are handled by Paddle.com, our Merchant of Record. A fraction of what MDR or a SIEM seat costs — and you’ll never get a usage-based surprise. Need a fully managed, analyst-in-the-loop tier? Talk to us.

Get started

Get your free triage report.

Send a read-only CloudTrail export and we’ll send back what actually matters — within one business day. Free, no commitment.

Upload your CloudTrail → get your report

…or just email audit@gideonhq.io

06 / FAQ

Questions, answered.

What data do you need?+

A read-only export of your AWS CloudTrail for the last 30–90 days. Nothing else — no agent, no role in your account.

Why 30–90 days?+

The history is what lets Gideon tell routine activity from a real attack. A short snapshot makes everything look suspicious.

What do you do with my logs?+

We use them only to generate your report, then delete them within 7 days. We never share them. We’re early — happy to talk through specifics before you send anything.

What does it cost?+

The first report is free — one per company. Continuous monitoring is flat-rate from $249/mo per AWS account — no usage meters, no surprise bill. You only move to paid once you’ve seen the value.

How do I export CloudTrail?+

Easiest path, no setup: AWS Console → CloudTrailEvent history → set the time range as wide as available (up to 90 days) → Download eventsDownload as JSON. That single file is exactly what we need — upload it on the report page.

Prefer the CLI? aws cloudtrail lookup-events over your date range works too. Already deliver CloudTrail to an S3 bucket? Send a 30–90 day range of those .json.gz files. Any standard CloudTrail JSON is fine — no reformatting.