Home / Services / Cloud Security / CSEM

Cloud Security / Cloud event monitoring

Don't miss what's happening
in your cloud.

CSEM (Cloud Security Event Monitoring) analyzes cloud and SaaS audit logs and flow logs to detect suspicious sign-ins, permission changes, external access, destructive operations and more. Without building a SIEM from scratch, you can start monitoring today with predefined rules, and AI explains what each detected event means and how to respond.

Challenges

Sound familiar?

Logs are collected but not reviewed

Logs such as CloudTrail are stored, but there is no process to check them daily, so breaches are noticed late.

Building and running a SIEM is heavy

Writing detection rules from scratch and keeping a team to tune them continuously is not easy.

Alerts are hard to interpret

Even when something is detected, few people can judge what it means and what to do next.

Features

CSEM key features

01Multi-cloud and SaaS logs

Monitor logs from AWS, Azure, Google Cloud and OCI, and audit logs from Microsoft 365 and Google Workspace, in one screen.

02Predefined detection rules

Start monitoring today with rules prepared for each cloud, covering admin account use, MFA being disabled, permission grants, logging being stopped and more.

03Detection every 15 minutes

Reads and analyzes logs in your storage every 15 minutes. No need to forward or copy logs, and little setup effort.

04Purpose-built views

Review activity across clouds and SaaS from four angles: sign-in history, operation history, external access and access denied.

05AI analysis and response suggestions

AI explains what a detected event means, steps to investigate and respond, and how to prevent recurrence. The AI runs on your Amazon Bedrock.

06Criticality-based prioritization

Adjusts event severity based on account and asset criticality, and also aggregates events by the systems CSPM detects.

07Rule tuning and exclusions

Enable or disable predefined rules and change their thresholds, create custom rules that combine conditions, and exclude known-good operations.

08Severity-filtered notifications

Sends only events at or above a specified severity to email, Slack or Webhook. You can narrow which events each destination receives.

Coverage

Monitor clouds and SaaS
from one screen

Attackers move between cloud consoles, identity platforms, and email and file-sharing SaaS. CSEM normalizes each log into a common format so you can view them side by side through common lenses: sign-ins, operations, external access and access denied.

SIGN-IN

Sign-ins

Review sign-ins to consoles and identity platforms, clusters of failures, and sign-ins from unusual locations.

OPERATIONS

Operations

Tracks high-impact operations such as permission grants, logging being stopped, security setting changes and mass deletions.

EXTERNAL ACCESS

External access

Identifies access from external IPs and accounts outside your organization, and connections to exposed resources.

ACCESS DENIED

Access denied

A cluster of denied operations is a sign of permission probing or account takeover. It also helps uncover misconfigurations.

AI assistant

When something is detected,
know what to do next

An alert is only as valuable as the recipient's ability to act on it. In CSEM, you can consult AI on each detected event, and it returns an explanation for security staff based on the rule, severity, actor, target resource and number of occurrences.

ANALYSIS

What happened

Explains why the event was detected and what risk it poses in your cloud environment.

RESPONSE

What to do

Gives concrete steps the security team should take to investigate and respond.

PREVENTION

How to prevent it

Gives best practices to prevent recurrence, and ways to reduce false positives if the operation was legitimate.

Please note: The AI runs on your Amazon Bedrock, and you control usage costs and model selection. Answers for the same event are reused.

Tuning

Refine detection
to fit your operations

Start with predefined rules and adjust them gradually to fit your environment. Reduce false positives while reliably catching what matters.

PREDEFINED

Rule enablement and thresholds

Enable or disable predefined rules per organization and adjust count thresholds.

CUSTOM

Custom rules

Create your own rules with thresholds by combining conditions on log fields, such as equals, not equals, contains, and greater or less than.

EXCLUSION

Exclusion rules

Exclude known-good operations, such as backup jobs and routine maintenance tasks, to reduce noise.

Specifications

Scope and delivery

Supported sources
  • AWS / Microsoft Azure / Google Cloud / Oracle Cloud (OCI)
  • Microsoft 365 / Google Workspace
Analysis method
  • Reads and analyzes logs in your storage every 15 minutes using integration permissions
  • Records of detected events are stored in CyberForces
Rules
  • Predefined rules (per cloud)
  • Custom rules / exclusion rules
AI
  • Per-event explanations of analysis, response and prevention (Japanese, English, Korean, Indonesian)
  • Runs on your Amazon Bedrock
Notifications
  • Email / Slack / Webhook (filtered by severity)
Pricing
  • Usage-based pricing according to the volume of logs analyzed

Please note: Log collection and retention settings (such as enabling CloudTrail) must be configured in your environment. AI explanations require Amazon Bedrock to be set up in your account.

Getting started

Getting started

  1. Connect log sources

    Register the cloud and SaaS log sources you want to monitor. For AWS, read permissions are created with CloudFormation.

  2. Review rules

    Monitoring starts with predefined rules. Adjust thresholds or add custom rules as needed.

  3. Set up notifications

    Configure notification destinations and the severity to notify on.

  4. Respond with AI

    When an event arrives, consult the AI and review the investigation and response steps.

FAQ

FAQ

Do I need to forward logs to CyberForces?

Logs stay in your storage and are read and analyzed using integration permissions. Records of detected events are stored in CyberForces so they can be displayed in the console.

How is this different from an existing SIEM?

CSEM focuses on cloud and SaaS audit logs, with an emphasis on getting started right away using predefined rules and AI explanations. You don't need to write rules from scratch.

Works well with

CSEM — details and demo requests

Our team will explain deployment options and pricing for your environment.