This post is cowritten by Tal Shapira and Tamir Friedman from Reco.
Reco helps organizations strengthen the security of their software as a service (SaaS) applications and accelerate business without compromise. Using Anthropic Claude in Amazon Bedrock, Reco tackles the challenge of machine-readable security alerts that SOC teams struggle to quickly interpret. This implementation helps transform raw alerts into intuitive, human-readable insights, optimizing security operations with AI-powered analytics that help enhance threat detection, streamline alert processing, and provide the contextual intelligence needed for faster response times and improved risk mitigation.
In this blog post, we show you how Reco implemented Amazon Bedrock to help transform security alerts and achieve significant improvements in incident response times.
Reco selected Amazon Bedrock for this solution because of its comprehensive advantages in deploying generative AI capabilities. Amazon Bedrock provides access to multiple foundation models from leading AI providers, enabling the flexibility to choose the optimal model for specific use cases. The service offers built-in security features including data encryption, virtual private cloud (VPC) integration, and compliance alignment with industry standards, helping to ensure that sensitive data remains protected throughout the AI workflow. Its pay-per-use pricing model removes upfront infrastructure costs and scales automatically with demand, making it cost-effective for variable workloads. Additionally, developers can use the API-based architecture of Amazon Bedrock to integrate AI capabilities into their applications, so they can build sophisticated AI-powered solutions while maintaining control over their application architecture and data flow.
Modern security alerts are often highly technical, requiring security engineers to manually analyze raw event data, cross-reference indicators across multiple security alerts, determine potential impact and appropriate responses, derive actionable insights, and communicate findings to non-technical stakeholders. This process is time-consuming and increases the risk of missing critical threats. This raises two challenges:
Reco’s Alert Story Generator is a core component of the Reco solution that addresses these challenges through four key capabilities:
The Alert Story Generator uses a sophisticated prompt engineering approach that combines:
This AI-powered approach helps transform what was traditionally a manual, time-intensive process into an automated workflow that can deliver immediate insights while maintaining the depth and accuracy security teams require.
To understand how these technical components work together, let’s examine the end-to-end processing pipeline that powers Reco’s alert transformation system, as shown in the following chart:

The workflow follows these key steps, orchestrating data from raw alert to actionable insight:
The workflow, shown in the following image, runs on the AWS cloud using microservices deployed on Amazon Elastic Kubernetes Service (Amazon EKS), a fully managed Kubernetes service, and Amazon RDS for PostgreSQL, a relational database service that holds the related contextual data for the prompts. Users’ access to the chat is guarded by AWS WAF, which helps protect the backend from common exploits, and is served by Amazon CloudFront, which helps deliver content with low latency and high transfer speeds.

The following image is an example Reco Alert Story Generator result generated on mock data:

By using Anthropic Claude in Amazon Bedrock, Reco has built a cutting-edge alert summarization tool that helps transform raw security alerts into actionable intelligence. This innovation empowers security teams to respond more effectively, collaborate seamlessly, and mitigate risks faster than ever before.
The integration of Amazon Bedrock has significantly helped enhance the way Reco customers manage and respond to security incidents. Some key benefits include:
To further explore how AI can help transform security alerts, enhance incident response, and implement Amazon Bedrock for your security operations, check out these essential resources:
Manuel Rioux est fièrement propulsé par WordPress