NeuBird for Amazon CloudWatch
AWS CloudWatch incident investigation, across every source you unify.
NeuBird is the Agentic Reliability Center. Connect it to AWS with one scoped IAM role, and the Production Ops Agent investigates everything CloudWatch holds: metrics, events, logs and traces from your AWS services, plus the CrowdStrike, Zscaler, Check Point, Cisco Umbrella and Ping Identity data you bring in with CloudWatch unified data. Telemetry is queried where it lives, with zero telemetry storage.
Finding: the laptop is contained and SSO is revoked, but access key AKIA…EXAMPLE for IAM user emp-4471 is still active. It has pulled 2.6 GB from finance-exports-prod since 2:03 PM, from 203.0.113.48, outside corporate egress.
Recommended: deactivate the key and deny emp-4471 all actions.
Step 1 · Connect
One scoped IAM role.You choose which AWS services NeuBird can reach.
NeuBird connects through a cross-account IAM role with an external ID, with no agents to install. Turn on the services it may access, such as CloudWatch, CloudTrail, EC2 and EKS, and the role grants those and nothing else. NeuBird then discovers the AWS calls the role allows and uses them to gather evidence; services you leave off are never called, and a call that changes something in your account runs only after an engineer approves it.
- 1
Create a scoped role
A cross-account IAM role with an external ID. No agents to install.
- 2
Choose the services
Turn on what NeuBird may reach. Services you leave off, like S3 here, are never called.
- 3
Changes need approval
A call that changes something, such as deactivating an access key, runs only after an engineer approves it.
- 4
Connected
NeuBird assumes the role and discovers the AWS calls it can make in each service.
123456789012arn:aws:iam::123456789012:role/NeuBirdInvestigatornb-7f3c-91ad-2e04us-east-1, us-west-2iam:UpdateAccessKeyiam:PutUserPolicyStep 2 · CloudWatch unified data
Your security and identity data, in CloudWatch too.One IAM role reaches all of it.
With CloudWatch unified data and telemetry, CloudWatch pipelines bring third-party data into CloudWatch: CrowdStrike Falcon, Zscaler, Check Point, Cisco Umbrella, Ping Identity and more than 30 platforms in all. Pipelines can convert security events to the Open Cybersecurity Schema Framework (OCSF), so one field means the same thing in every source. Once that data is in CloudWatch, NeuBird investigates it through the role you already granted, with no connector to build for each vendor and nothing copied out.
- 1
Third-party data arrives
CloudWatch pipelines collect from 30+ security, identity and network platforms, by API or S3 delivery.
- 2
One schema across vendors
Pipelines can convert security events to OCSF, so one field means the same thing in every source.
- 3
Log groups beside your AWS logs
Each source lands in a CloudWatch log group in your account, next to CloudTrail and VPC Flow Logs.
- 4
One role reaches all of it
NeuBird queries every log group in place, through the role you already granted. No connector per vendor.
/aws/pipelines/crowdstrike-falcon/aws/pipelines/zscaler-zia/aws/pipelines/checkpoint-ngfw/aws/pipelines/cisco-umbrella/aws/pipelines/pingfederateaws-cloudtrail-logs/aws/vpc/flow-logsStep 3 · Investigate
Targeted calls, not bulk pulls.Each query asks one question of one source.
The Production Ops Agent plans its calls before it makes them. Each Logs Insights query names one log group, one identity and one time window, so it scans what the question needs. In this sample investigation, a CloudWatch alarm fires on a CrowdStrike Falcon detection, a laptop contained for suspected data theft. NeuBird follows the same user through Zscaler, Ping Identity, IAM and CloudTrail data, all in CloudWatch, to a finding in under 5 minutes.
- 1
A CloudWatch alarm fires
An alarm on CrowdStrike Falcon detections fires in #sec-ops: a laptop contained for suspected exfiltration.
- 2
Plan the calls
NeuBird plans each query around one identity, one log group and one time window.
- 3
Follow the identity
The same user turns up in Zscaler, Ping Identity, IAM and CloudTrail data, all in CloudWatch.
- 4
Finding in under 5 minutes
The endpoint and SSO are closed. An AWS access key is still open, and in use.
logs:StartQuery/aws/pipelines/crowdstrike-falcon · user emp-4471 · 13:30–14:05Running…Archive staging at 1:58 PM · host contained 2:02 PMlogs:StartQuery/aws/pipelines/zscaler-zia · user emp-4471 · 13:00–14:05Running…DLP blocked q3-forecast.7z to personal storage, 1:41 PMlogs:StartQuery/aws/pipelines/pingfederate · user emp-4471 · 13:30–14:05Running…SSO sessions revoked 2:03 PMiam:ListAccessKeysuser emp-4471Running…1 key active · AKIA…EXAMPLEiam:GetAccessKeyLastUsedAKIA…EXAMPLERunning…Last used 2:05 PM · s3 · us-east-1logs:StartQueryaws-cloudtrail-logs · accessKeyId AKIA…EXAMPLE · 14:00–14:06Running…1,214 GetObject on finance-exports-prod from 203.0.113.48logs:StartQuery/aws/pipelines/zscaler-zia · source IP 203.0.113.48Running…No match: the IP is outside corporate egressThe finding
The laptop was contained.The AWS key was still open.
Falcon contained the laptop and PingFederate revoked the SSO session. A long-lived IAM user access key works without either, and it was downloading from a finance bucket from an IP address outside the corporate network. NeuBird lines the four sources up on one timeline, names the open path and stages the fix. Nothing runs until Andrew Lee, the on-call engineer, approves it at an auditable approval gate, and the conclusion is saved to memory, with zero telemetry storage.
- 1
One timeline
Four sources line up by user and time: Zscaler, CrowdStrike, Ping Identity and CloudTrail.
- 2
The open path
A long-lived IAM user access key works without the laptop or the SSO session.
- 3
Recommend, then approve
NeuBird stages the change. Andrew Lee, on call, approves it at the gate.
- 4
Closed and remembered
The key is inactive, downloads stop, and the conclusion is saved to memory.
- 1:41 PM
DLP blocks upload of q3-forecast.7z (1.8 GB) to personal cloud storage
- 1:58 PM
Falcon detects archive staging on LT-0447
- 2:02 PM
Falcon network-contains LT-0447
- 2:03 PM
PingFederate revokes SSO sessions for emp-4471
- 2:03 PM
CloudTrailAccess key AKIA…EXAMPLE lists finance-exports-prod from 203.0.113.48
- 2:03–2:06
CloudTrail1,214 GetObject calls, 2.6 GB, same key, same IP
- 1Deactivate access key AKIA…EXAMPLE
iam:UpdateAccessKey - 2Deny all actions for user emp-4471
iam:PutUserPolicy - 3Keep the CloudTrail evidence for the security team
Linked in the incident
FAQ
Common questions
How does NeuBird connect to AWS CloudWatch?
NeuBird connects through a cross-account IAM role with an external ID, with no agents to install. You choose which AWS services the role may reach, such as CloudWatch, CloudWatch Logs, CloudTrail, EC2 and EKS, and its policy grants those and nothing else.
Which AWS calls can NeuBird make?
Only the ones your IAM role allows. After you connect, NeuBird discovers the AWS API calls the role permits and uses them to gather evidence for an investigation. Services you leave out show as not granted and are never called. Any call that changes something in your account waits for human approval.
What CloudWatch data does NeuBird investigate?
Everything CloudWatch holds for your AWS services: metrics and alarms, CloudTrail events delivered to CloudWatch Logs, application and service logs such as VPC Flow Logs and EKS control plane logs, and traces from AWS X-Ray and CloudWatch Application Signals. It also investigates third-party data brought in with CloudWatch unified data and telemetry.
Does NeuBird support CloudWatch unified data and telemetry?
Yes. When CloudWatch pipelines bring third-party data into CloudWatch, NeuBird investigates it through the same IAM role as your AWS telemetry. That includes CrowdStrike Falcon, Zscaler, Check Point, Cisco Umbrella, Ping Identity, Okta, Microsoft Entra ID, Palo Alto Networks and the other sources CloudWatch pipelines support, with no separate connector per vendor.
Does NeuBird copy or store our CloudWatch data?
No. NeuBird queries CloudWatch where the data lives, with zero telemetry storage. Its memory holds conclusions, causal chains and approvals, never logs, metrics or traces.
Can NeuBird make changes in our AWS account?
Only with human approval. Every action follows the policy you set for that environment: Suggest, Recommend or Act. In production, NeuBird typically recommends a change, such as deactivating an access key, and an engineer approves it. Every approval is recorded in the audit trail.
NeuBird for Amazon CloudWatch
Every source in CloudWatch, investigated from one role.
See NeuBird investigate across AWS telemetry and CloudWatch unified data, with every action approved by your team.
