Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AWS re:Invent 2024 brought security announcements across threat detection, incident response, analytics, identity, network controls, governance and generative AI safeguards. Third-party launches from Wiz, Sweet Security and Skyhawk Security also targeted cloud threat detection and response, but with different approaches to telemetry, investigation and containment. The announcements below are a retrospective of what was reported at the event—not a claim that every feature is generally available today.

What AWS announced for security

AWS held re:Invent 2024 in Las Vegas from December 2–6. In its January 13, 2025 recap, AWS Security Blog authors Marshall Jones and Apurva More reported more than 54,000 attendees and over 2,300 sessions and hands-on labs. The recap groups announcements made both leading up to and during the event, so not every item listed was necessarily first announced during the conference itself.

Incident response and threat detection

AWS Security Incident Response combines automated monitoring and investigation with communications and coordination support, plus direct 24/7 access to the AWS Customer Incident Response Team, according to AWS. AWS says it can work with approved partners and monitor, investigate and escalate triaged findings from GuardDuty and other detection tools through Security Hub. The stated purpose is to help customers prepare for, respond to and recover from security events.

Amazon GuardDuty Extended Threat Detection is designed to identify multi-stage attack sequences by correlating signals across resources and data sources over time. AWS describes its findings as helping identify sophisticated threats targeting accounts, workloads and data, and characterizes the capability as using AI/ML to identify attack sequences. This is AWS’s description of the intended capability, not an independently established measure of detection effectiveness.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Security data analysis

Amazon OpenSearch Service with Amazon Security Lake gained a zero-ETL integration that AWS says lets customers query and analyze security data in place, avoiding the need to manage complex pipelines or duplicate data. AWS also says selective ingestion could potentially reduce analytics costs; that is a possible benefit, not a guaranteed saving.

Access, identity and governance

  • AWS Verified Access added VPN-less access to non-HTTPS resources, including TCP, SSH and RDP, according to AWS.
  • Amazon VPC Lattice added access to VPC resources across VPCs, accounts and on-premises environments over additional protocols, including TCP.
  • Organization-wide controls included Resource Control Policies, central management of root access, and declarative policies intended to enforce permissions and durable configuration intent.
  • Amazon Cognito added Essentials and Plus feature tiers, a developer-focused console, Managed Login, and passwordless sign-in using passkeys, email or SMS.

Network and DNS controls

Route 53 Resolver DNS Firewall added an advanced rule for monitoring and blocking suspicious DNS traffic associated with advanced DNS threats. Amazon VPC added a centrally implemented “block public access” control.

Rank #2
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

Generative AI safeguards

Amazon Bedrock Automated Reasoning checks were introduced to check outputs against policies authored by customers. Bedrock Guardrails added multimodal toxicity detection for image content in public preview, according to AWS’s recap. These are safeguards within AWS products; they should not be read as a guarantee that model output will always be correct or safe.

What cloud security products other vendors announced

SecurityWeek’s December 3, 2024 report named three third-party announcements made on December 2. The companies described overlapping cloud detection-and-response goals, but emphasized different data and response workflows.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
iStorage CloudAshur Hardware Security Module | Encryption Key | Password Protected | Dust & Water Resistant | Hardware Encryption. IS-EM-CA-256
  • Encrypt your data with the cloudAshur to ensure the ultimate protection of your data stored in the cloud, on your PC/MAC, transferred as an email attached or file sharing software
  • Share your encrypted data security with authorised users in the cloud, via email and file transfer services using the cloudAshur KeyWriter (not included)
  • Manage and monitor your cloudAshur devices centrally using the cloudAshur Remote Management Console (not included)
  • cloudAshur eliminates data security vulnerabilities associated with cloud platforms, such as lack of control and unauthorised access to your confidential data.
  • Take back control of your data - with the cloudAshur, you hold the KEY to your data!

Wiz Defend: cross-layer context and SecOps workflows

Wiz announced Wiz Defend in public preview on December 2, 2024. Wiz described it as combining cloud context and threat detections across layers, including runtime telemetry from an eBPF-based sensor. Its announcement also highlighted incident-story investigation through AskAI and response options such as runtime blocking or containment playbooks. Wiz said the product builds on its Wiz Security Graph and the acquisition of Gem Security. Those are vendor descriptions; customer testimonials in the announcement are not independent product evaluations.

Sweet Security: a unified cloud-native detection and response platform

Sweet Security announced a unified Cloud Native Detection and Response platform. The company said it combines application detection and response (ADR), cloud detection and response (CDR), and cloud workload protection platform (CWPP) capabilities. Its release also listed unified cloud visibility, vulnerability management, runtime cloud security posture management (CSPM), and identity threat detection and response. Performance and customer-result statements in the release are company-reported claims, not independently verified findings.

Rank #4
GoTrust Idem Key C USB Security Key NFC FIDO2 L2 Certified
  • Protect accounts with USB-C & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
  • FIDO2 Level 2 certified Security Key. Works with Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Compatible with Chrome, Safari & Edge on all major OS.
  • Plug & play USB-C Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
  • Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication & identity protection.
  • IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise & daily use.

Skyhawk Security: interactive validation and containment

Skyhawk Security announced Interactive Cloud Threat Detection and Response. Its described workflow notifies the owner of an anomalous user, role, machine or function and asks that person to validate the activity, using enterprise applications such as Teams or Slack or the Skyhawk mobile app. Skyhawk also described automatic containment options, including disabling an identity and its sessions. These capabilities and any efficacy claims should be understood as the company’s account of its product.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the announcements differ—and what to evaluate

The launch materials point to distinct emphases rather than an apples-to-apples product ranking. Wiz foregrounded cross-layer context and SecOps investigation and response. Sweet presented a broader combined set of application, cloud and workload detection and protection capabilities. Skyhawk emphasized involving an identity owner in validating suspicious activity and then taking containment action.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
GoTrust Idem Key A USB Security Key NFC FIDO2 L2 Certified
  • Protect accounts with USB-A & NFC 2FA security key. Hardware-based authentication blocks phishing, credential theft & unauthorized access across cloud, enterprise & personal platforms.
  • FIDO2 Level 2 certified Security Key. TAA compliant and supports Apple ID, Microsoft Azure/Entra ID, AWS, Google, Facebook, Salesforce, DUO & more. Works with Chrome, Safari & Edge across major OS.
  • Plug & play USB-A Security Key with NFC tap login. No software, drivers or batteries required. Works with Windows PC, MacBook, iPhone, Android & Chromebook for fast, secure authentication.
  • Built with FIPS 140-2 Level 3 secure element for advanced encryption. Trusted by IT teams, healthcare, education & government for secure authentication and identity protection.
  • IP68 waterproof, dustproof & crush-resistant design. Supports FIDO2, U2F, OTP, PIV, Mini Driver & smart card login. Durable USB security key for long-term enterprise and daily use.
Announcement Emphasis in the announcement Availability stated at announcement
Wiz Defend (Wiz, December 2, 2024) Cross-layer detections and cloud context, runtime telemetry, AskAI investigation, and response options. Public preview.
Sweet Security unified Cloud Native Detection and Response platform (Sweet Security, December 2, 2024) Combined ADR, CDR and CWPP capabilities, alongside visibility, vulnerability, runtime posture and identity features. Not stated in the cited company release.
Interactive Cloud Threat Detection and Response (Skyhawk Security, December 2, 2024) Identity-owner validation through collaboration or mobile tools, with described containment actions. Not stated in the cited company release.

For an enterprise evaluation, check the details that determine operational fit rather than relying on category labels:

  • Coverage: Which cloud providers, resources, identities and workloads are visible? Does coverage include runtime behavior as well as configuration?
  • Telemetry and context: Which data sources feed detections, and how does the product connect alerts to the affected identity, workload and event sequence?
  • Workflow fit: Which SIEM, SOAR and collaboration tools integrate with the product? Can analysts investigate in their existing workflow?
  • Response authority: What can be blocked or contained automatically, which actions require human approval, and how are actions logged or reversed?
  • Maturity and cost: Is the specific feature generally available or in preview in the relevant environment? Confirm current availability, supported regions and pricing with the vendor; the cited announcements do not establish a stable, comparable price or independent head-to-head performance results.

AWS’s partner and AI-security context

AWS’s recap also described an AI Security category in its Security competency, with partner validation areas including sensitive-data disclosure, injection threats, security posture management and responsible AI filtering. It mentioned Security Lake Ready and Security Incident Response specializations as well. These are AWS partner categories and validation areas; they do not establish that any particular vendor named above belongs to a category.

Sources and announcement timing

The event scale and AWS product descriptions above are attributed to the AWS Security Blog recap, “AWS re:Invent 2024: Security, identity, and compliance recap,” by Marshall Jones and Apurva More, published January 13, 2025, and AWS News Blog, “Top announcements of AWS re:Invent 2024,” published December 1, 2024. The vendor descriptions are based on Wiz’s December 2, 2024 “Wiz Defend is Here: Threat detection and response born for the cloud,” Sweet Security’s December 2, 2024 press release distributed via GlobeNewswire, and Skyhawk Security’s December 2, 2024 press release distributed via GlobeNewswire. SecurityWeek’s December 3, 2024 report by Eduard Kovacs covered the third-party launches.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.