Detection engineering and threat hunting for startup security teams on AWS

Stop writing alerts in the dark. Build detections like software.

Form a hypothesis, backtest against your entire log history, and ship detections as code. Turn every incident finding into telemetry your next detection builds on.

Every source, one query

CloudTrail, flow logs, DNS, GuardDuty and your own

All your history

hunt back as far as you keep, not 90 days

Every feature, every plan

SSO, SCIM, MFA and your own keys from $499

Why Vigilfield?

Detection engineering and threat hunting on one data platform.

vs. a lake you build yourself

Live in a day, no glue code

Deploy one CloudFormation stack; CloudTrail, flow logs, DNS, S3 access logs and GuardDuty arrive as OCSF tables you can join.

vs. a per-GB SIEM

Prepaid, capped, every feature on every plan

You are alerted at 80% and 100%; at the cap ingestion pauses until you top up, so a log spike is never a surprise invoice.

vs. a per-event rule engine

Detections that join, and chain

A detection is a query over every source and your whole history, and its findings are a table the next detection reads.

Detection chaining

Chain detections. No state machine.

Detection chaining is multi-stage detection without a state machine or a graph database: a rule’s findings are a table, and a table is something the next rule joins.

01

A rule flags suspicious assume-role activity

and writes every finding to a table it names: iam_findings.

cloudtrail_logs
| where eventName == 'AssumeRole' and errorCode == 'AccessDenied'
| summarize denials = count() by sourceIPAddress
| where denials > 20
02

A second rule joins flow logs against those findings

to catch the egress that follows, on its own schedule.

vpc_flow_logs
| where action == 'ACCEPT' and bytes > 100000000
| join kind=inner (iam_findings) on srcaddr == sourceIPAddress
| project srcaddr, dstaddr, bytes, denials
What’s included

Everything, on every plan.

Detect & hunt

  • Scheduled detections with joins
  • Detections that read other detections
  • Hunts over your full history
  • Shared investigations

Data

  • OCSF tables for five AWS log types
  • Custom sources and schemas
  • One retention window, 30 to 365 days
  • Export anything to your S3

Controls

  • SSO, SCIM and required MFA
  • Customer-managed KMS keys
  • Fine-grained team permissions
  • A queryable audit trail

Operations

  • Provisioning and upgrades, by us
  • Source health and replay
  • Plan alerts at 80% and 100%
Trust

Your security data stays yours.

A dedicated AWS account per customer, with its own storage, query engine, keys and user pool. Nothing is shared with another tenant.

  1. Your AWS accounts: CloudTrail, flow logs, DNS, S3 access logs, GuardDuty
  2. One CloudFormation stack
  3. A dedicated Vigilfield AWS account: OCSF tables, VFQL engine
  4. Alerts to your SNS topic or webhook
SSO (SAML and OIDC)SCIM provisioningRequired MFA, passkeys and security keysA dedicated AWS accountCustomer-managed KMS keysTeams and fine-grained permissionsA queryable audit trailScoped API tokensExport to your own S3
01

Connect

One stack per AWS account. Logs flow the same day.

02

Detect

Write detections in VFQL and run them on a schedule.

03

Hunt

Pivot from any finding to the raw events, over all your history.

Pricing

Every plan is the enterprise plan. The difference is volume.

Prepaid. At the cap ingestion pauses and your logs wait at the source until you top up — never an overage bill.

Startup

$499 per month

Billed yearly, $5,988

Sized for a small team’s first AWS footprint.

  • 200 GB ingested per month
  • 1 TB scanned per month
  • 600 GB stored
  • Email support
  • Every feature, unlimited users and detections

SMB

$1,499 per month

Billed yearly, $17,988

Sized for multi-account environments.

  • 3 TB ingested per month
  • 15 TB scanned per month
  • 9 TB stored
  • Email support
  • Every feature, unlimited users and detections

Enterprise

Contact us

Priced to your volume and terms

Sized for organization-wide coverage.

  • 10 TB and up ingested per month
  • 50 TB scanned per month
  • 30 TB stored
  • Email support
  • Every feature, unlimited users and detections
Talk to sales
Questions

What startup security teams ask us first.

We are a security team of two. Can we run this?

Yes. We run the platform; you deploy one stack per AWS account and write detections in VFQL.

What if a log source spikes?

You are alerted at 80% and 100%. At the cap, ingestion pauses; your logs wait in your own CloudWatch groups and buckets and catch up when you top up or the month rolls over. Nothing is dropped, and nothing is billed past what you prepaid.

Will this help with SOC 2?

It covers the logging evidence auditors ask for: retention, SSO access control, detection run history and an audit trail.

Where does our data live?

In a dedicated AWS account per customer, under a key we manage or one you do. Export everything to your own S3 at any time.

Talk to us

Bring the detection your current tool cannot express.

A 30-minute walkthrough of how Vigilfield would run on your AWS logs.

We handle your details as our Privacy Policy describes.