Schedule demo

Amazon Security Services Monitoring

Amazon Web Services (AWS) offers a comprehensive suite of security services to protect cloud workloads, data, applications, and users. It includes a range of functionalities, including Identity and Access Management, Threat Detection, Data Protection, Compliance and Governance, Network and Application Security, and Security Automation and Incident Response.

With Applications Manager's Amazon Security Services monitoring tool, you can ensure continuous protection, compliance, and threat mitigation in AWS environments. Leverage comprehensive monitoring for services like:

Amazon Certificate Manager Monitoring

AWS Certificate Manager (ACM) is a fully managed service that simplifies the provisioning, management, and deployment of SSL/TLS certificates used to secure applications and services running on AWS. It automates certificate issuance and renewal processes, helping organizations maintain encrypted communications and ensure secure connectivity across AWS resources.

With Applications Manager, you can:

  • Monitor certificate expiration timelines and tracking days remaining before certificate expiry to enable timely renewals and prevent unexpected service disruptions.
  • Track certificate status and renewal activity to identify failed renewals or pending validation issues, ensuring uninterrupted certificate lifecycle management.
  • Strengthen security compliance by tracking certificate validity and detecting expired, revoked, or improperly configured certificates across AWS environments.
  • Examine certificate associations and chains to help identify unused certificates and potential configuration gaps, improving visibility into certificate usage.
  • Reduce operational risks by proactively alerting on certificate-related issues, ensuring secure and continuous communication for applications and services.

Amazon CloudHSM Cluster Monitoring

AWS CloudHSM is a managed hardware security module (HSM) service that enables you to generate and use encryption keys securely while maintaining full control over them. The cluster-based approach of AWS CloudHSM ensures high availability and redundancy by distributing workloads across multiple HSMs, preventing single points of failure in key management.

With Applications Manager, you can:

  • Monitor Cluster information to gain comprehensive insights into the overall health and redundancy of HSM instances.
  • Track key usage metrics, such as session vs. token, to know how cryptographic keys are being utilized and ensure proper resource allocation.
  • Track network bandwidth usage and stability to identify potential packet loss using metrics like Ethernet data throughput and received vs. dropped packets.
  • Monitor HSM details and configurations to ensure your HSM instances comply with security policies.

Amazon Cognito App Client Monitoring

Amazon Cognito app clients define how applications connect to and authenticate against a user pool, handling sign-up, sign-in, and token refresh requests on behalf of connected applications. Monitoring app clients individually helps ensure each connected application stays correctly configured and able to authenticate users without disruption.

With Applications Manager, you can:

  • Track sign-up rates, including sign-up throttle rate and sign-up failed rate, alongside sign-up requests, successes, failures, and throttles, to catch onboarding issues specific to this app client before they affect new users.
  • Monitor sign-in rates, including sign-in throttle rate and sign-in failed rate, alongside sign-in requests, successes, failures, and throttles, to quickly identify authentication issues affecting this client's users.
  • Track token refresh rates, including token refresh throttle rate and token refresh failed rate, alongside token refresh requests, successes, failures, and throttles, to ensure sessions are renewed reliably without unexpected sign-outs.

Amazon Cognito Identity Pools Monitoring

Amazon Cognito Identity Pools enable applications to grant users temporary, limited-privilege AWS credentials, supporting both authenticated and unauthenticated access through federated identity providers. Monitoring identity pools helps ensure secure access management while providing visibility into identity usage patterns across your application.

With Applications Manager, you can:

  • Monitor identity distribution by tracking authenticated versus unauthenticated identities to understand user access patterns and identify unusual spikes in guest access.
  • Track identity provider and role mapping counts to ensure your federation setup is correctly configured and functioning as expected.
  • Gain visibility into individual identities by viewing associated logins, creation date, and last modified date to audit identity activity over time.
  • Monitor identity provider configurations, including client IDs and server-side token check status, to ensure your federation sources remain secure and properly validated.

Amazon Cognito User Pool Monitoring

Amazon Cognito User Pools serve as a fully managed user directory, handling sign-up, sign-in, and identity federation for your applications while integrating with external identity providers like Google and Amazon. Monitoring user pools helps ensure smooth user onboarding and reliable federation, keeping authentication issues from disrupting the end-user experience.

With Applications Manager, you can:

  • Monitor resource counts such as total users, app clients, and external providers to track the scale and configuration of your user pool at a glance.
  • Track sign-up rates, including sign-up failed rate and sign-up throttle rate, alongside sign-up requests, successes, failures, and throttles, to catch onboarding issues before they affect new users.
  • Gain visibility into individual users by viewing status, enabled state, creation date, and last modified date to audit user activity over time.
  • Identify problematic identity providers by tracking federation failures and throttle rates alongside federation requests, successes, failures, and throttles for each provider.
  • Monitor app client details, including creation date and health, to ensure the applications connected to your user pool remain properly configured and functioning.

AWS GuardDuty Monitoring

AWS GuardDuty is a threat detection service that continuously monitors your AWS accounts and workloads for malicious activity and unauthorized behavior by analyzing sources like CloudTrail events, VPC Flow Logs, and DNS logs. Monitoring GuardDuty findings helps security teams detect and respond to threats before they escalate into serious incidents.

With Applications Manager, you can:

  • Monitor finding summary, including total findings and active detectors, alongside findings broken down by high, medium, and low severity, to quickly gauge the overall threat posture of your environment.
  • Gain a consolidated view of threat activity by tracking findings aggregated by finding category across your entire account and all regions, for account-wide, multi-region visibility.
  • Track findings by region, including current and archived finding counts per region, to identify which parts of your infrastructure are most exposed.
  • Gain visibility into findings by resource type, such as EC2 instances, S3 buckets, and IAM access keys, to pinpoint which resources are being targeted most frequently.
  • Monitor findings by action type, including API calls, network connections, and DNS requests, to understand the nature of suspicious activity detected.
  • Track day-wise severity trends to observe how high, medium, and low severity findings evolve, helping you spot emerging patterns or sudden spikes in threat activity.
  • Track detector configuration details, including state, finding publishing frequency, and data sources, to ensure your detectors remain properly configured across regions.

Amazon Inspector Monitoring

Amazon Inspector is an automated vulnerability management service that continuously scans AWS workloads, including EC2 instances, container images, Lambda functions, and code repositories, for software vulnerabilities and unintended network exposure. Monitoring Inspector findings helps security teams prioritize remediation efforts and reduce the attack surface across cloud resources.

With Applications Manager, you can:

  • Monitor findings by severity, including critical, high, and medium severity counts and rates, to prioritize remediation based on the level of risk to your environment.
  • Track exploitable and fixable rates alongside exploitable and fixable finding counts to focus efforts on vulnerabilities that pose the most immediate risk and have available fixes.
  • Gain visibility into region-level finding details, including total, critical, high, and medium findings, as well as exploitable and fixable counts, per region, to identify which regions need the most attention.
  • Monitor region-level EC2 findings to identify which regions have the highest concentration of EC2-related vulnerabilities.
  • Identify high-risk instances by tracking Inspector score, severity, and exploitable/fixable status for top EC2 instances, along with their associated VPC, to accelerate targeted remediation.
  • Monitor ECR container image findings to detect vulnerabilities in your container images, and identify the top images contributing the most risk.
  • Track Lambda function findings to detect vulnerabilities in your functions, and identify the top functions contributing the most risk.
  • Monitor code repository findings to detect vulnerabilities in your source code, and identify the top repositories requiring the most attention.

Amazon Key Management Services Monitoring

Amazon Key Management Service (KMS) Monitoring involves tracking and analyzing the usage, performance, and security of cryptographic operations within AWS KMS. It provides encryption and decryption capabilities by integrating with various AWS services while adhering to high security and compliance standards.

With Applications Manager, you can:

  • Monitor key age and rotation schedules to ensure robust protection of cryptographic keys against potential vulnerabilities.
  • Perform regular key rotations to mitigate the security risks associated with prolonged key usage.
  • Keep an eye on grant details to prevent unauthorized access and reduce security risks, in addition to tracking server information to ensure the underlying infrastructure functions optimally.
  • Calculate and monitor the number of days until the next key rotation to enable proactive issue resolution and maintain data protection.

Amazon Network Firewall Monitoring

AWS Network Firewall is a managed service that enables you to deploy network protections across your Amazon VPCs. It provides fine-grained control over traffic entering and leaving your network with stateful and stateless rule engines, TLS inspection, intrusion prevention and detection capabilities, and customizable firewall policies.

With Applications Manager, you can:

  • Safeguard applications and workloads by monitoring stateful and stateless packet flows, including packets received, passed, dropped, or rejected, along with drop/reject percentages.
  • Strengthen encryption security through TLS inspection metrics, tracking dropped or rejected packets, TLS errors, connection timeouts, and certificate revocation statuses.
  • Gain visibility into firewall configuration and readiness, including sync states, firewall status, association counts, policy details, transit gateway attachments, and protection settings.
  • Ensure operational reliability by identifying traffic anomalies, excessive drops, or misconfigurations in firewall policies, helping you optimize both security and performance.

Amazon Secrets Manager Monitoring

AWS Secrets Manager is a fully managed service that securely stores, manages, and retrieves sensitive information such as database credentials, API keys, and other secrets. It enables automatic secret rotation, eliminating the need for hard-coded credentials in applications, thereby enhancing security.

With Applications Manager, you can:

  • Maintain effective management of sensitive credentials by monitoring the secret lifecycle, reducing both unused secrets and potential exposure.
  • Protect against accidental loss of critical secrets by calculating and tracking days until scheduled deletion, allowing for timely recovery.
  • Identify and mitigate security risks associated with outdated credentials by monitoring secret age and days since the last change, prompting regular rotation.
  • Ensures consistent credential refresh and minimizes the risk of unauthorized access or credential leaks through comprehensive secret rotation tracking.

Amazon Secrets Manager Regional Monitoring

The Secrets Manager Regional monitor provides an aggregated, account-wide view of secret inventory and rotation trends across all secrets within a region. While the Secrets Manager monitor tracks the lifecycle and rotation health of an individual secret, the Regional monitor rolls up activity across the entire region for a broader perspective.

With Applications Manager, you can:

  • Monitor secret inventory by tracking total secrets and secrets scheduled for deletion to maintain an accurate view of your active secret landscape.
  • Track rotate secret call volume to ensure your rotation policies are executing as expected and functioning without interruption.
  • Gain visibility into the last changed secret, including its ARN, to quickly identify the most recently modified secret in the region.
  • Monitor individual secret details, including creation date, deletion date, and last/next rotation dates, to stay ahead of upcoming rotations and catch overdue ones.

Amazon Web Application Firewalls (ACLs) Monitoring

Web Application Firewall (WAF) Access Control Lists (ACLs) are rule-based security configurations that help protect web applications from common threats such as SQL injection, cross-site scripting (XSS), and distributed denial-of-service (DDoS) attacks. WAF ACLs define rules that filter and monitor incoming traffic based on conditions such as IP addresses, HTTP headers, request patterns, or geographic location. By enforcing these rules, WAF ACLs help prevent malicious requests from reaching web applications while allowing legitimate traffic to pass through.

With Applications Manager, you can:

  • Analyze how WAF rules are applied and ensure that legitimate traffic is allowed while threats are blocked by tracking request actions.
  • Monitor request throughput to gain insights into traffic volume, helping detect anomalies such as sudden spikes that may indicate potential DDoS attacks.
  • Monitor rule and client device type based request actions to ensure performance optimization. Rule-based metrics help detect and mitigate threats by analyzing how often specific rules trigger, while client-based metrics identify bot traffic and unusual client behavior.
  • Monitor incoming requests based on client device types (e.g., mobile, tablet, desktop) to identify potential risks and unusual behaviors. This helps detect bot traffic, enforce device-specific security policies, and optimize response actions such as blocking, redirecting, or applying stricter rules to high-risk devices.
  • Monitor rule-specific request actions to analyze how often specific rules are triggered. This helps detect and mitigate threats by identifying abnormal traffic patterns, reducing false positives, and optimizing rule performance. Tracking rule-based metrics allows for fine-tuning security policies and improving overall WAF efficiency.
  • Guarantee effective filtering of malicious traffic without disrupting user access by observing allowed and blocked requests.
  • Assess the effectiveness of bot mitigation strategies with the help of CAPTCHA and challenge requests.
  • Obtain visibility into traffic patterns and rule evaluations without immediate enforcement.

Ready to monitor your Amazon Security Services?

Applications Manager offers comprehensive monitoring for a variety of Amazon services like:

Start your 30-day free trial today!

Loved by customers all over the world

"Standout Tool With Extensive Monitoring Capabilities"

★★★★★

It allows us to track crucial metrics such as response times, resource utilization, error rates, and transaction performance. The real-time monitoring alerts promptly notify us of any issues or anomalies, enabling us to take immediate action.

Reviewer Role: Research and Development

carlos-rivero
"I like Applications Manager because it helps us to detect issues present in our servers and SQL databases."
Carlos Rivero

Tech Support Manager, Lexmark

Trusted by thousands of leading businesses globally