Overview
WitFoo Conductor is an end to end SecOps data platform offered through World Wide Technology (WWT) on AWS Marketplace, providing the same powerful solution with a streamlined procurement experience. It ingests and normalizes raw security signals from any source, correlates and analyzes events to pinpoint threats, intelligently prioritizes alerts, and exports ready to use data to your security tools, all with minimal manual effort. By transacting via WWT, customers get a seamless AWS Marketplace purchase of WitFoo Conductor without any added complexity.
EXTRACT: Turnkey Data Ingestion: Conductor ingests raw security signals from any source (endpoint agents, Syslog, APIs, SIEMs, etc.) into a single intake stream. It is ready to deploy out of the box, handling any data format without manual customization or integration hassles.
TRANSFORM: Parserless Comprehension: Conductor uses NLP driven semantic analysis to understand each messages intent, not just its syntax. Powered by WitFoo Adaptive Parsing, it automatically normalizes all fields and timestamps, eliminating the need for your team to write or maintain parser rules.
ANALYZE: Security Event Correlation: Leveraging ProtoGraph Analysis, Conductor enriches logs with expert driven intelligence by mapping relationships between users, files, and network assets. It then overlays known attack frameworks onto this context rich graph to pinpoint suspicious activity that would otherwise be hard to detect.
PRIORITIZATION: Intelligent Threat Ranking: Using the contextual graph, Conductor employs a deterministic approach (replacing broad statistical sampling) to capture every valid signal, resulting in no false negatives and no lost context. Duplicate alerts are automatically suppressed, and threats are ranked via algorithmic scoring based on impact, asset value, and observed threat behavior.
LOAD: Destination Ready Output: Conductor exports enriched, structured data in universal formats (like JSON or CEF) via security APIs or Syslog. This ensures clean ingestion into any SIEM, SOAR, or data lake with no reformatting or manual transformation required on the customers end.
Highlights
- Cost Contained Licensing Licensed by Compute, Not Data - Priced by CPU cores. Never by data volume, so you are free to scale ingestion and retention without surprise fees. No Hidden Labor Costs - Automation handles upkeep and adapts to new data formats with no manual tuning or maintenance required. Purchasing through WWT on AWS Marketplace is straightforward and incurs no additional overhead, ensuring a frictionless buying process.
- Unlimited Integrations and Zero Parsers or Rules to Maintain Connect to Everything - Integrates with your full security stack with no added fees or engineering burden. Self Adapting Parsing - Automatically adjusts to evolving formats, no more building or fixing parsers.
- Minimal Hardware & Storage Lean Footprint - Built for maximum efficiency with the smallest industry hardware requirements. Lower Data Costs - Data is compressed and encrypted in motion and at rest to dramatically reduce network and disk (IOPS) costs.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Cost/hour |
|---|---|
c7a.2xlarge Recommended | $8.40 |
c7a.24xlarge | $100.80 |
c7a.48xlarge | $201.60 |
c7a.8xlarge | $33.60 |
c7a.12xlarge | $50.40 |
c7a.16xlarge | $67.20 |
c7a.4xlarge | $16.80 |
c7a.32xlarge | $134.40 |
Vendor refund policy
15-day trial is free; No refunds after purchase
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Initial Release
Additional details
Resources
Vendor resources
Support
Vendor support
Email: support@witfoo.com Guides and Ticket Creation:
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.