A threat detection service that continuously monitors AWS accounts and workloads for malicious activity and unauthorized behavior. It analyzes data from sources like VPC Flow Logs, CloudTrail, and DNS logs using machine learning and threat intelligence to identify anomalies, compromised instances, or credential misuse.