🔹Detects high-severity findings from GuardDuty, Security Hub, CloudTrail, and CloudWatch.
🔹 Correlates logs and infrastructure events to build a complete incident timeline.
🔹 Uses Claude to analyze the security context, identify likely attack patterns, and generate an investigation summary with recommended remediation steps.
🔹 Creates Jira tickets, notifies teams via Slack, and can trigger approved automation workflows while keeping production changes under human approval.