Home / Services / Cloud Security / CSEM
Cloud Security / Cloud event monitoringDon't miss what's happening
in your cloud.
CSEM (Cloud Security Event Monitoring) analyzes cloud and SaaS audit logs and flow logs to detect suspicious sign-ins, permission changes, external access, destructive operations and more. Without building a SIEM from scratch, you can start monitoring today with predefined rules, and AI explains what each detected event means and how to respond.
Challenges
Sound familiar?
Logs are collected but not reviewed
Logs such as CloudTrail are stored, but there is no process to check them daily, so breaches are noticed late.
Building and running a SIEM is heavy
Writing detection rules from scratch and keeping a team to tune them continuously is not easy.
Alerts are hard to interpret
Even when something is detected, few people can judge what it means and what to do next.
Features
CSEM key features
01Multi-cloud and SaaS logs
Monitor logs from AWS, Azure, Google Cloud and OCI, and audit logs from Microsoft 365 and Google Workspace, in one screen.
02Predefined detection rules
Start monitoring today with rules prepared for each cloud, covering admin account use, MFA being disabled, permission grants, logging being stopped and more.
03Detection every 15 minutes
Reads and analyzes logs in your storage every 15 minutes. No need to forward or copy logs, and little setup effort.
04Purpose-built views
Review activity across clouds and SaaS from four angles: sign-in history, operation history, external access and access denied.
05AI analysis and response suggestions
AI explains what a detected event means, steps to investigate and respond, and how to prevent recurrence. The AI runs on your Amazon Bedrock.
06Criticality-based prioritization
Adjusts event severity based on account and asset criticality, and also aggregates events by the systems CSPM detects.
07Rule tuning and exclusions
Enable or disable predefined rules and change their thresholds, create custom rules that combine conditions, and exclude known-good operations.
08Severity-filtered notifications
Sends only events at or above a specified severity to email, Slack or Webhook. You can narrow which events each destination receives.
Coverage
Monitor clouds and SaaS
from one screen
Attackers move between cloud consoles, identity platforms, and email and file-sharing SaaS. CSEM normalizes each log into a common format so you can view them side by side through common lenses: sign-ins, operations, external access and access denied.
Sign-ins
Review sign-ins to consoles and identity platforms, clusters of failures, and sign-ins from unusual locations.
Operations
Tracks high-impact operations such as permission grants, logging being stopped, security setting changes and mass deletions.
External access
Identifies access from external IPs and accounts outside your organization, and connections to exposed resources.
Access denied
A cluster of denied operations is a sign of permission probing or account takeover. It also helps uncover misconfigurations.
AI assistant
When something is detected,
know what to do next
An alert is only as valuable as the recipient's ability to act on it. In CSEM, you can consult AI on each detected event, and it returns an explanation for security staff based on the rule, severity, actor, target resource and number of occurrences.
What happened
Explains why the event was detected and what risk it poses in your cloud environment.
What to do
Gives concrete steps the security team should take to investigate and respond.
How to prevent it
Gives best practices to prevent recurrence, and ways to reduce false positives if the operation was legitimate.
Please note: The AI runs on your Amazon Bedrock, and you control usage costs and model selection. Answers for the same event are reused.
Tuning
Refine detection
to fit your operations
Start with predefined rules and adjust them gradually to fit your environment. Reduce false positives while reliably catching what matters.
Rule enablement and thresholds
Enable or disable predefined rules per organization and adjust count thresholds.
Custom rules
Create your own rules with thresholds by combining conditions on log fields, such as equals, not equals, contains, and greater or less than.
Exclusion rules
Exclude known-good operations, such as backup jobs and routine maintenance tasks, to reduce noise.
Specifications
Scope and delivery
| Supported sources |
|
|---|---|
| Analysis method |
|
| Rules |
|
| AI |
|
| Notifications |
|
| Pricing |
|
Please note: Log collection and retention settings (such as enabling CloudTrail) must be configured in your environment. AI explanations require Amazon Bedrock to be set up in your account.
Getting started
Getting started
Connect log sources
Register the cloud and SaaS log sources you want to monitor. For AWS, read permissions are created with CloudFormation.
Review rules
Monitoring starts with predefined rules. Adjust thresholds or add custom rules as needed.
Set up notifications
Configure notification destinations and the severity to notify on.
Respond with AI
When an event arrives, consult the AI and review the investigation and response steps.
FAQ
FAQ
Do I need to forward logs to CyberForces?
Logs stay in your storage and are read and analyzed using integration permissions. Records of detected events are stored in CyberForces so they can be displayed in the console.
How is this different from an existing SIEM?
CSEM focuses on cloud and SaaS audit logs, with an emphasis on getting started right away using predefined rules and AI explanations. You don't need to write rules from scratch.
Works well with
CSEM — details and demo requests
Our team will explain deployment options and pricing for your environment.