• English
  • 日本語
Log inRequest demo
Back to Technology Partners

Exaforce + AWS

Work every AWS finding to a verdict

Exaforce is an agentic SOC platform built on AWS. We read your AWS telemetry alongside the rest of your security stack, and work every detection to a verdict with the evidence attached.

AWS and Exaforce

How we partner

How we partner with AWS

AWS gives security teams excellent signal. Turning that signal into a decision is where teams get stuck, and the gap widens as the environment grows.

GuardDuty raises a finding, but the finding rarely tells the whole story. Answering who acted, what they touched and whether it actually mattered means pivoting through CloudTrail, configuration history, network flows and identity data by hand. Multiply that by the volume a growing AWS estate produces and most findings never get worked properly. They get sampled.

Exaforce closes that gap. It reads your AWS activity, configuration, network and identity data alongside GuardDuty findings, enriches all of it with context from the rest of your security stack, and works every finding to a verdict with the evidence attached. Benign activity closes with a written rationale you can audit. Real threats escalate with a timeline, root cause and a response, whether that’s 2pm or 2am.

Exaforce also builds its own detections from the same data, so coverage extends past what GuardDuty surfaces on its own.

Competencies

AWS competencies and validation

AWS Security Competency

Threat Detection and Response · Identity and Access Management

AWS AI Competency

Agentic AI Applications · Generative AI Applications

AWS Marketplace

Available for purchase, including private offers

Built on AWS

AWS-native architecture

Services

What we read, and what we act on

Exaforce connects to AWS two ways. It reads the services below to understand your environment, and it can act through your own AWS controls when something needs containing. Both are scoped by you.

Amazon GuardDuty

Every finding gets ingested and enriched with the identity behind the activity, the events that led to it, the resources affected and related activity elsewhere in the account. Findings become plain-language assessments that say what happened, why it matters and what to do next.

AWS CloudTrail

API activity across every account, stitched into complete sessions rather than left as isolated events, and queryable months back without a separate archive.

AWS Config

Resource configuration and change history, so an investigation can show what a resource looked like before and after the activity in question.

Amazon VPC Flow Logs

The network view. Where traffic went, how much moved, and whether a suspected exfiltration attempt actually transferred data.

AWS IAM

Users, roles, policies and access keys, mapped back to the human or workload behind them. This is what the identity permissions graph is built from.

AWS IAM Identity Center

Workforce identities, group memberships and permission sets, so a verdict accounts for what someone can actually reach across accounts.

Amazon EKS

Cluster audit activity and configuration, with Exaforce detections on top for the container layer most tools treat as a black box.

AWS Organizations

One connection covers every account and region, and new accounts are picked up as they’re created.

Amazon S3 · Amazon SQS

Anything else you can land in a bucket or a queue can be added as a source and gets the same detection and analysis.

Reading the data is not the same as understanding it. Exaforce knows how Amazon EC2, Amazon S3, AWS Lambda, Amazon RDS, Amazon ECS, Amazon ECR, Amazon EKS and Amazon VPC are normally used, which is what lets it tell routine administrative work apart from something that only looks routine.

That understanding is also what makes containment safe. When something needs stopping, Exaforce acts through the AWS controls you already have: isolate an EC2 instance or an EKS host, disable an IAM or IAM Identity Center user, update a security group or network ACL, etc. Every action runs automatically or waits for one-click approval, and you grant only the ones you intend to use.

Context

Every signal, in context

AWS produces a lot of volume, but it’s almost never where an investigation ends.

Exaforce reads more than 100 sources across identity, endpoint, SaaS, network, code, email and cloud security, and lands all of them in the same real-time model as your AWS data. Identities, sessions, resources and behavior are connected rather than sitting in separate tools, which is what lets a verdict account for things no single AWS service can see.

That changes what a finding means:

  • A GuardDuty finding on an access key becomes a confirmed compromise when Exaforce finds that key committed to a public GitHub repository hours earlier.
  • Unusual S3 activity becomes an insider case when the identity behind it belongs to someone your HR system says left the company two weeks ago.
  • An anomalous login location becomes routine when Okta shows the same device and CrowdStrike shows a healthy endpoint, and becomes urgent when it doesn’t.
  • A destination IP becomes evidence when threat intelligence ties it to known infrastructure, rather than a value an analyst has to go look up.

Enrichment runs the same way on everything: who owns the resource, what the data is worth, how that identity normally behaves, what the rest of your tooling already knows. It’s the work an analyst does by hand on the findings they have time for, applied to all of them.

Use cases

What this looks like in practice

Right-sized permissions

The question every AWS team struggles to answer on demand: what can this identity actually reach, and what does it actually use?

Once your accounts are connected, Exaforce resolves every policy attached to every identity into a plain answer, service by service and account by account, and marks each role and each permission used or unused. Human identities and non-human ones alike. You don’t have to ask for the analysis. It’s already there.

From there it tells you what to change: roles nobody has exercised, permissions assigned directly and never used, group memberships that do nothing, and identities holding admin privilege they don’t need. Each recommendation comes with the reasoning and the evidence behind it.

For periodic reviews, access review campaigns turn that analysis into a tracked process with a due date, an approver and one case per identity, routed by default to that person’s manager. Every case arrives with a suggested verdict, and reviewers certify or modify it with a recorded note. The campaign produces a downloadable report, so a quarterly review leaves an audit trail instead of a spreadsheet.

Across the environments we monitor there are 14.5 non-human identities for every human one. Permission sprawl is mostly not a people problem anymore.

Work every finding

Every finding gets worked, not sampled. Exaforce pulls the finding apart and rebuilds the picture around it: which identity, which session, which resource, where the activity came from, what that resource’s configuration actually permits, how the identity normally behaves, and what outside threat intelligence says about the source.

Minutes later it publishes a verdict with a confidence level attached, mapped to MITRE tactic and technique, and the reasoning written out. Not a score. A few sentences you can read and argue with, citing the specific evidence that decided it, including the evidence that pointed the other way.

Then it tells you what to do, in numbered steps written for your environment rather than a generic playbook. Benign findings close with a rationale you can audit. Anything unresolved keeps an SLA clock on it.

Go beyond GuardDuty

GuardDuty tells you what it was built to tell you. Exaforce writes its own detections from the same AWS telemetry, and because it reads your identity provider too, it can follow a chain GuardDuty cannot see: the SSO login, the role that got assumed, the temporary credentials that came back, and everything done with them, stitched into one session.

That catches what looks perfectly legal in CloudTrail. An engineer pulling administrator credentials from a city and a network that identity has never used before. A pattern of credential retrieval from shifting locations that no single event would ever flag.

Exaforce weighs it against 90 days of that identity’s own history and against how that person’s peers actually behave, then says how confident it is and what would settle the question, down to who to ask and which manager to include.

These land in the same queue as your GuardDuty findings, triaged the same way, on the same SLA. You can tune what gets suppressed, add rules of your own, and turn any investigation into a standing detection.

Results

A year of observations from real SOC environments running on Exaforce.

Aggregate findings across Exaforce customer environments during 2025, based on 79 billion events and 1.29 million alerts.

  • 97%of alerts needed no analyst investigation. Only 3%, or 41,000 of 1.29 million, needed a human look.
  • 98%of alerts turned out to be benign or false positives once reviewed.
  • 98%accuracy rate for Exabot recommendations, measured against confirmed human review.
  • 67%of all events came from AWS on average, and more than 90% in many environments. Far more than traditional tools were built to index and retain.
  • GuardDuty alerts used to eat up hours of our team’s time. With Exaforce MDR, that dropped to almost zero. We’re not just getting alerts, we’re getting answers.
    Srijan R ShettyCo-Founder & CTO at Fuze
  • Exaforce has significantly improved our SOC efficacy by augmenting threat detection and response for AWS and Azure with AI. Its auto-triage of third-party alerts and rule-free detection streamlines our response and saves us dozens of hours, letting our team focus on mitigating threats, while their exploration capabilities offer greater visibility into all our Cloud services.
    Paul KimCISO & CIO at Accton
  • Pioneering early with Exaforce and their novel agentic SOC platform has significantly enhanced our detection and response for cloud services, such as GitHub, used by our development teams, in spotting identity misuse. The platform delivered actionable cloud insights within 24 hours of onboarding - one example was identifying 3rd party vendor misuse of their credentials in our environment. The rich data platform provides quick answers to hard questions & tasks across our SaaS and IaaS environments.
    Daniel KrasnokuckiHead of Product Security at F500 Digital Infra Company
  • AI-driven analysis is essential for modern security operations, and Exaforce demonstrates how AI can act as a true investigation partner. The company's platform enables our team to operate with the depth and context that traditionally requires a full SOC and significant manual effort, helping us to scale our security efforts to meet our growing needs.
    Dan BorkowskiSVP, Security & IT at Function Health
  • I like Exaforce's approach to Security Operations. They have both human review and an AI platform to facilitate better data ingestion, alerting, case management, and investigation. They're very receptive to feedback and are collaborative on new features they release as well as one they want to develop. My team uses Exaforce almost every day for some sort of look up, investigation, or continuing to build out remediation automation.
    Patrick McKinneyVice President of Security at Invisible
  • Exaforce has absolutely changed how I rely on my SIEM day to day. Previously, it was just a repository of old logs. Now we can threat hunt very easily and respond to alerts very quickly.
    Mike ShannonDirector of Security Engineering, Guardant Health

Read customer stories

Compliance

Commitment to data protection

Exaforce is audited and certified by industry-leading third party standards.

  • SOC 2 Type 2Compliant
  • SOC 2 Type 1Compliant
  • ISO 27001Certified
  • PCI DSSCompliant
  • HIPAACompliant
  • GDPRCompliant
  • USDPCompliant
  • HITRUSTCertified

Solution brief

Go deeper on GuardDuty

A closer look at how Exaforce and Amazon GuardDuty work together: what Exaforce reads from your AWS environment, how a raw finding becomes a verdict with evidence attached, and what changes for the team that has to work the queue.

Download the solution brief (PDF)