NeuBird
LoginDemo

NeuBird for Amazon CloudWatch

AWS CloudWatch incident investigation, across every source you unify.

NeuBird is the Agentic Reliability Center. Connect it to AWS with one scoped IAM role, and the Production Ops Agent investigates everything CloudWatch holds: metrics, events, logs and traces from your AWS services, plus the CrowdStrike, Zscaler, Check Point, Cisco Umbrella and Ping Identity data you bring in with CloudWatch unified data. Telemetry is queried where it lives, with zero telemetry storage.

Step 1 · Connect

One scoped IAM role.You choose which AWS services NeuBird can reach.

NeuBird connects through a cross-account IAM role with an external ID, with no agents to install. Turn on the services it may access, such as CloudWatch, CloudTrail, EC2 and EKS, and the role grants those and nothing else. NeuBird then discovers the AWS calls the role allows and uses them to gather evidence; services you leave off are never called, and a call that changes something in your account runs only after an engineer approves it.

  1. 1

    Create a scoped role

    A cross-account IAM role with an external ID. No agents to install.

  2. 2

    Choose the services

    Turn on what NeuBird may reach. Services you leave off, like S3 here, are never called.

  3. 3

    Changes need approval

    A call that changes something, such as deactivating an access key, runs only after an engineer approves it.

  4. 4

    Connected

    NeuBird assumes the role and discovers the AWS calls it can make in each service.

Connect AWSNot connectedConnected
IAM role
Account ID123456789012
Role ARNarn:aws:iam::123456789012:role/NeuBirdInvestigator
External IDnb-7f3c-91ad-2e04
Regionsus-east-1, us-west-2
Actions · human approval required
iam:UpdateAccessKeyiam:PutUserPolicy
sts:AssumeRole succeeded · 6 services · 15 calls discovered
Services NeuBird may access
CloudWatchMetrics, alarms, Application Signals
CloudWatch LogsLog groups, Logs Insights, pipelines
CloudTrailAPI activity and identity
EC2Instances, security groups
EKSClusters, node groups
IAMUsers, access keys
S3Bucket configuration

Step 2 · CloudWatch unified data

Your security and identity data, in CloudWatch too.One IAM role reaches all of it.

With CloudWatch unified data and telemetry, CloudWatch pipelines bring third-party data into CloudWatch: CrowdStrike Falcon, Zscaler, Check Point, Cisco Umbrella, Ping Identity and more than 30 platforms in all. Pipelines can convert security events to the Open Cybersecurity Schema Framework (OCSF), so one field means the same thing in every source. Once that data is in CloudWatch, NeuBird investigates it through the role you already granted, with no connector to build for each vendor and nothing copied out.

  1. 1

    Third-party data arrives

    CloudWatch pipelines collect from 30+ security, identity and network platforms, by API or S3 delivery.

  2. 2

    One schema across vendors

    Pipelines can convert security events to OCSF, so one field means the same thing in every source.

  3. 3

    Log groups beside your AWS logs

    Each source lands in a CloudWatch log group in your account, next to CloudTrail and VPC Flow Logs.

  4. 4

    One role reaches all of it

    NeuBird queries every log group in place, through the role you already granted. No connector per vendor.

Step 3 · Investigate

Targeted calls, not bulk pulls.Each query asks one question of one source.

The Production Ops Agent plans its calls before it makes them. Each Logs Insights query names one log group, one identity and one time window, so it scans what the question needs. In this sample investigation, a CloudWatch alarm fires on a CrowdStrike Falcon detection, a laptop contained for suspected data theft. NeuBird follows the same user through Zscaler, Ping Identity, IAM and CloudTrail data, all in CloudWatch, to a finding in under 5 minutes.

  1. 1

    A CloudWatch alarm fires

    An alarm on CrowdStrike Falcon detections fires in #sec-ops: a laptop contained for suspected exfiltration.

  2. 2

    Plan the calls

    NeuBird plans each query around one identity, one log group and one time window.

  3. 3

    Follow the identity

    The same user turns up in Zscaler, Ping Identity, IAM and CloudTrail data, all in CloudWatch.

  4. 4

    Finding in under 5 minutes

    The endpoint and SSO are closed. An AWS access key is still open, and in use.

Investigation · falcon-high-severity-detectionQuerying CloudWatchFinding in 4m 31s
Trigger CloudWatch alarm falcon-high-severity-detection · Falcon contained host LT-0447 · user emp-4471
#CallScopeResult
1CrowdStrikelogs:StartQuery/aws/pipelines/crowdstrike-falcon · user emp-4471 · 13:30–14:05Running…Archive staging at 1:58 PM · host contained 2:02 PM
2Zscalerlogs:StartQuery/aws/pipelines/zscaler-zia · user emp-4471 · 13:00–14:05Running…DLP blocked q3-forecast.7z to personal storage, 1:41 PM
3Ping Identitylogs:StartQuery/aws/pipelines/pingfederate · user emp-4471 · 13:30–14:05Running…SSO sessions revoked 2:03 PM
4IAMiam:ListAccessKeysuser emp-4471Running…1 key active · AKIA…EXAMPLE
5IAMiam:GetAccessKeyLastUsedAKIA…EXAMPLERunning…Last used 2:05 PM · s3 · us-east-1
6CloudTraillogs:StartQueryaws-cloudtrail-logs · accessKeyId AKIA…EXAMPLE · 14:00–14:06Running…1,214 GetObject on finance-exports-prod from 203.0.113.48
7Zscalerlogs:StartQuery/aws/pipelines/zscaler-zia · source IP 203.0.113.48Running…No match: the IP is outside corporate egress
7 targeted calls · 4 sources, all in CloudWatch · each query scoped to one identity, one log group, one time window

The finding

The laptop was contained.The AWS key was still open.

Falcon contained the laptop and PingFederate revoked the SSO session. A long-lived IAM user access key works without either, and it was downloading from a finance bucket from an IP address outside the corporate network. NeuBird lines the four sources up on one timeline, names the open path and stages the fix. Nothing runs until Andrew Lee, the on-call engineer, approves it at an auditable approval gate, and the conclusion is saved to memory, with zero telemetry storage.

  1. 1

    One timeline

    Four sources line up by user and time: Zscaler, CrowdStrike, Ping Identity and CloudTrail.

  2. 2

    The open path

    A long-lived IAM user access key works without the laptop or the SSO session.

  3. 3

    Recommend, then approve

    NeuBird stages the change. Andrew Lee, on call, approves it at the gate.

  4. 4

    Closed and remembered

    The key is inactive, downloads stop, and the conclusion is saved to memory.

Timeline · emp-44714 sources · 1 identity
  1. 1:41 PMDLP blocks upload of q3-forecast.7z (1.8 GB) to personal cloud storage
  2. 1:58 PMFalcon detects archive staging on LT-0447
  3. 2:02 PMFalcon network-contains LT-0447
  4. 2:03 PMPingFederate revokes SSO sessions for emp-4471
  5. 2:03 PMAccess key AKIA…EXAMPLE lists finance-exports-prod from 203.0.113.48
  6. 2:03–2:061,214 GetObject calls, 2.6 GB, same key, same IP
Open path: IAM user access key, outside both the endpoint and SSO
Recommended actionsPolicy: Recommend
  1. 1Deactivate access key AKIA…EXAMPLEiam:UpdateAccessKey
  2. 2Deny all actions for user emp-4471iam:PutUserPolicy
  3. 3Keep the CloudTrail evidence for the security teamLinked in the incident
Auditable approval gate · awaiting Andrew LeeApproved by Andrew Lee · 2:08 PM
Key inactive. Further GetObject calls return AccessDenied.Saved to memory: conclusion, evidence citations and approval. Zero telemetry storage.

FAQ

Common questions

How does NeuBird connect to AWS CloudWatch?

NeuBird connects through a cross-account IAM role with an external ID, with no agents to install. You choose which AWS services the role may reach, such as CloudWatch, CloudWatch Logs, CloudTrail, EC2 and EKS, and its policy grants those and nothing else.

Which AWS calls can NeuBird make?

Only the ones your IAM role allows. After you connect, NeuBird discovers the AWS API calls the role permits and uses them to gather evidence for an investigation. Services you leave out show as not granted and are never called. Any call that changes something in your account waits for human approval.

What CloudWatch data does NeuBird investigate?

Everything CloudWatch holds for your AWS services: metrics and alarms, CloudTrail events delivered to CloudWatch Logs, application and service logs such as VPC Flow Logs and EKS control plane logs, and traces from AWS X-Ray and CloudWatch Application Signals. It also investigates third-party data brought in with CloudWatch unified data and telemetry.

Does NeuBird support CloudWatch unified data and telemetry?

Yes. When CloudWatch pipelines bring third-party data into CloudWatch, NeuBird investigates it through the same IAM role as your AWS telemetry. That includes CrowdStrike Falcon, Zscaler, Check Point, Cisco Umbrella, Ping Identity, Okta, Microsoft Entra ID, Palo Alto Networks and the other sources CloudWatch pipelines support, with no separate connector per vendor.

Does NeuBird copy or store our CloudWatch data?

No. NeuBird queries CloudWatch where the data lives, with zero telemetry storage. Its memory holds conclusions, causal chains and approvals, never logs, metrics or traces.

Can NeuBird make changes in our AWS account?

Only with human approval. Every action follows the policy you set for that environment: Suggest, Recommend or Act. In production, NeuBird typically recommends a change, such as deactivating an access key, and an engineer approves it. Every approval is recorded in the audit trail.

NeuBird for Amazon CloudWatch

Every source in CloudWatch, investigated from one role.

See NeuBird investigate across AWS telemetry and CloudWatch unified data, with every action approved by your team.