Every source, one query
CloudTrail, flow logs, DNS, GuardDuty and your own
Form a hypothesis, backtest against your entire log history, and ship detections as code. Turn every incident finding into telemetry your next detection builds on.
Every source, one query
CloudTrail, flow logs, DNS, GuardDuty and your own
All your history
hunt back as far as you keep, not 90 days
Every feature, every plan
SSO, SCIM, MFA and your own keys from $499
Deploy one CloudFormation stack; CloudTrail, flow logs, DNS, S3 access logs and GuardDuty arrive as OCSF tables you can join.
You are alerted at 80% and 100%; at the cap ingestion pauses until you top up, so a log spike is never a surprise invoice.
A detection is a query over every source and your whole history, and its findings are a table the next detection reads.
Detection chaining is multi-stage detection without a state machine or a graph database: a rule’s findings are a table, and a table is something the next rule joins.
and writes every finding to a table it names: iam_findings.
cloudtrail_logs
| where eventName == 'AssumeRole' and errorCode == 'AccessDenied'
| summarize denials = count() by sourceIPAddress
| where denials > 20to catch the egress that follows, on its own schedule.
vpc_flow_logs
| where action == 'ACCEPT' and bytes > 100000000
| join kind=inner (iam_findings) on srcaddr == sourceIPAddress
| project srcaddr, dstaddr, bytes, denialsA dedicated AWS account per customer, with its own storage, query engine, keys and user pool. Nothing is shared with another tenant.
One stack per AWS account. Logs flow the same day.
Write detections in VFQL and run them on a schedule.
Pivot from any finding to the raw events, over all your history.
Prepaid. At the cap ingestion pauses and your logs wait at the source until you top up — never an overage bill.
$499 per month
Billed yearly, $5,988
Sized for a small team’s first AWS footprint.
$1,499 per month
Billed yearly, $17,988
Sized for multi-account environments.
Contact us
Priced to your volume and terms
Sized for organization-wide coverage.
Yes. We run the platform; you deploy one stack per AWS account and write detections in VFQL.
You are alerted at 80% and 100%. At the cap, ingestion pauses; your logs wait in your own CloudWatch groups and buckets and catch up when you top up or the month rolls over. Nothing is dropped, and nothing is billed past what you prepaid.
It covers the logging evidence auditors ask for: retention, SSO access control, detection run history and an audit trail.
In a dedicated AWS account per customer, under a key we manage or one you do. Export everything to your own S3 at any time.
A 30-minute walkthrough of how Vigilfield would run on your AWS logs.