Evidence: Medium50/100

eSentire accelerates AI-augmented threat investigation with Anthropic Claude in Amazon Bedrock

Use case typeRisk assessmentUpdated Jun 13, 2026

eSentire used Anthropic Claude in Amazon Bedrock to augment its managed detection and response security operations. The system formulates investigation hypotheses from threat indicators, dynamically selects and executes evidence-gathering tools, and produces interactive investigation reports with evidence and reasoning chains. The company validated model outputs against senior SOC experts and uses AWS services including Lambda, API Gateway, IAM, and CloudWatch to support the production workflow.

Organization
eSentire
Industry
Tech & Comms
Location
Canada
Published
May 2026

Reported outcomes

95%

quantified impactOther quantified impact

99.3%quantified impact

Strategic outcomes

Better decisions & insightDelivered expert-level threat analysis consistentlyCustomer experience & trustProvided explainable investigation reportsSpeed & agilityAccelerated development and deployment cyclesSpeed & agilityEnabled rapid creation of tools and workflows
Why do we believe this?Outcome claims, sources, and evidence checks

Normalized claim

Quantified impact: 95%

AWS Solutions Case StudyMay 27, 2026Customer storyInferred claimMedium evidence strength

95% alignment with senior SOC expert decisions across diverse endpoint scenarios.

Normalized claim

Quantified impact: 99.3%

AWS Solutions Case StudyMay 27, 2026Customer storyInferred claimMedium evidence strength

99.3% of attacks stopped at the first machine.

Why do we believe this deployment?Customer identity, provider attribution, maturity, and source checks
Customer
eSentire
Provider
AWS
Maturity
Unknown

No explicit deployment-stage evidence found.

Customer identity supportedSource describes one deploymentMaturity evidence evaluated

Primary read

Use case focus

Showing 3 of 5

  • 1Security investigation
  • 2Threat detection
  • 3Incident response
  • eSentire wanted to eliminate variability in SOC investigations and deliver expert-level threat analysis consistently across more than 2,000 customer organizations.
  • The company also wanted transparent, explainable reasoning for security decisions and faster investigation turnaround without sacrificing accuracy.
  • Claude in Amazon Bedrock generates investigation hypotheses from initial threat indicators.
  • The platform dynamically selects and executes tools in an agentic investigation loop and continues iterating until it reaches an evidence-based decision.
  • Interactive reports expose evidence and reasoning chains so analysts and customers can drill into decisions.
  • eSentire validated the approach against 1,000 real-world investigations and uses AWS Lambda, Amazon API Gateway, AWS IAM, and Amazon CloudWatch in the production architecture.
  • 95% alignment with senior SOC expert decisions across diverse endpoint scenarios.
  • 99.3% of attacks stopped at the first machine.
  • Development and deployment cycles reduced from months to days.
  • Threat hunting team can create new tools and workflows in hours using natural language interfaces.
Architecture

Claude in Amazon Bedrock is used for hypothesis generation and agentic investigation. AWS Lambda executes automated actions, Amazon API Gateway provides secure API access and integrations, AWS IAM provides fine-grained access control, and Amazon CloudWatch monitors performance and operational health.

Sources & evidence1
Evidence: Medium50/100Evidence strength
  • Customer explicitly identified
  • Primary source available
  • Quantified outcome available
  • Technical implementation details available
Type: Customer StoryPublished: May 27, 2026Publisher: AWSEvidence: PrimaryConfidence: High

AI-generated summary. Verify important details with the linked sources before relying on this case.

Explore related AI use cases

Was this useful?

Community

Comments

No published comments yet.