Unusual identity activity
Prioritize first-seen principals, unexpected role assumptions, access-key changes, and IAM policy activity for verification.
Security monitoring for lean cloud teams
Flare helps small businesses and lean security teams investigate unusual AWS and Google Cloud administrative activity. Connect supported audit sources read-only, then review ranked findings without building a SIEM pipeline or authoring detection rules.
Security anomalies, not billing anomalies
“Cloud anomaly detection” can mean either billing changes or security activity. Flare focuses on the security side: who changed access, which administrative actions were unusual, and what evidence your team should verify first. For spending spikes, use the native AWS or Google Cloud cost-anomaly products.
Prioritize first-seen principals, unexpected role assumptions, access-key changes, and IAM policy activity for verification.
Review noteworthy API calls, new Regions or services, destructive changes, and bursts of failed activity in context.
Start with ranked findings, plain-English reasoning, and selected source-event excerpts instead of an undifferentiated log stream.
One investigation workflow
Review recent regional management-event history through a customer-created read-only IAM role protected by a connector-specific ExternalId.
AWS CloudTrail anomaly detection →CloudTrail investigation guide →Review Admin Activity, System Event, and Policy Denied logs available to the connection. Data Access requires separate enablement and authorization.
GCP Audit Log anomaly detection →GCP Audit Log investigation guide →GCP access requirements →Know the boundary
Flare is useful when a founder, developer, IT generalist, or small security team needs to triage supported cloud-audit evidence. It does not provide real-time containment, complete log ingestion, or guaranteed threat detection, and it does not replace durable logging or incident response.
Security vs cost anomaly detection Compare AWS and GCP audit logsNo. Flare focuses on security-relevant administrative and audit activity. AWS Cost Anomaly Detection and Google Cloud cost anomaly detection are separate billing products.
Not for every investigation workflow. Flare gives small teams a bounded way to review and prioritize supported AWS CloudTrail and GCP Cloud Audit Log activity. It does not replace full log retention, a SIEM, or an incident-response program.
Flare reviews supported GCP Cloud Audit Logs and recent regional AWS CloudTrail management-event history, then ranks noteworthy activity and preserves selected supporting evidence.
Start with real evidence
Connect a supported source read-only or upload a focused log file. Flare is free during the open beta.
Start free