During a routine review, someone notices that an analytics account can read a bucket in production. Nobody remembers granting the access. On its own, the finding is a shrug — until it sits next to the broad role in that analytics account, the key policy that lets the role decrypt, and the region where logging was never fully enabled. Four ordinary findings. One path.
AWS defense begins with knowing what you have and isolating what matters: where sensitive data and keys live, who and what can reach them, and which over-broad permissions are holes that tireless automation is increasingly likely to find. Correlation is how you see that exposure. One finding becomes urgent when it connects to identity, data, keys, and activity — and automated adversaries can do that joining work quickly now, which means findings reviewed one dashboard at a time no longer count as a review.
Real attacks are chains — a small weakness here, a forgotten account there, linked step by patient step into a path — and walking those chains used to take rare skill and patience, spent only on the most valuable targets. AI is really good at connecting dots like that — it has the patience to walk through the chain, trying option after option until it finds one that works. Enumeration is cheap in AWS. IAM permissions, S3 exposure, public endpoints, and organization structure can all be walked mechanically, without the patience that used to be the barrier. That shifts the goal away from inventory hygiene toward something more pointed: an exposure queue — a ranked set of paths where someone could reach something valuable, expand privilege, or hide activity.
Security Hub helps aggregate and prioritize, but it is not the whole truth. It gets stronger when enriched with account ownership, environment labels, data sensitivity, known exceptions, and current incident context.
Each service answers one question. GuardDuty: is something suspicious happening now? Config: did a resource drift from its expected state? IAM Access Analyzer: is access crossing a boundary nobody intended?
CloudTrail and CloudWatch answer the control-plane questions — what changed, who changed it, and whether the important events are visible enough to investigate. Macie adds data-sensitivity context for S3. Detective helps an analyst connect activity when a signal needs deeper review.
Priority lives at the intersections. A broad role is worse near sensitive data. A public path is worse where key policy is permissive. A suspicious API call is worse where logging is incomplete. A stale exception is worse in a production account with no owner.
Start with coverage: every production account feeding the same findings pipeline, excluded regions intentional, and every high-risk finding tied to an owner who can actually remediate it.
Then review the intersections together — public and cross-account access, high-privilege identities, sensitive S3 data, key policies, missing trails, active threat signals. Do not let those reviews live in separate dashboards, run by separate people, on separate schedules. The multi-account estate needs an exposure queue, not another collection of disconnected dashboards.
The operating question is simple: if someone mapped this AWS estate today, which chain would they build first? The answer should already be sitting in the queue, assigned to an owner, and moving toward closure.