Skip to main content

Amazon Web Services security

AWS CloudTrail anomaly detection for small security teams

Flare turns recent regional CloudTrail management-event history into ranked, explained findings—without complete-log retention, per-GB ingestion fees, or detection rules for your team to author.

How it works

Turn AWS audit activity into an investigation queue

Analyze recent regional management-event history available through CloudTrail LookupEvents. Flare does not claim to ingest every CloudTrail event or retain a complete copy of your logs.

01

Connect read-only

Create a read-only IAM role using Flare’s CloudFormation template and protect role assumption with a connector-specific ExternalId.

02

Review ranked findings

Flare assesses current-window evidence with available historical context, then ranks noteworthy activity by severity and explains why it matters.

03

Investigate the evidence

Inspect selected source-event excerpts and ask follow-up questions using the retained analysis results and supporting evidence.

Built for small teams

Useful audit-log answers without a SIEM project

Start with real evidence

See what changed in AWS.

Connect read-only or upload a focused JSON, NDJSON, CSV, or plain-text log file. Flare is free during the open beta.

Start free