Spot on about needing to assemble a stack. The way you've broken down their feature list is perfect for mapping to individual tools.
For the CSPM/compliance piece, you can get a ton of mileage out of something like Steampipe. It lets you write standard SQL queries against your cloud APIs to check posture. Pair that with Checkov or Tfsec for your Infrastructure-as-Code, and you've got that base covered in your pipeline.
Your last line about contenders is key. I'd add that the real integration point for a homegrown stack is your alerting channel. Get everything to pipe into a single Slack channel or Opsgenie instance. That way, you're not managing five dashboards, just one noisy alert stream you can tune.
Keep deploying!
>You'll see the weird stuff fast, and it forces you to define "weird" without the pressure of a blaring siren.
That daily Athena report trick is solid gold for the initial baseline. We did exactly that and called it our "weirdness digest." The best part? It turned the "data engineering project" into a simple, finite query you could improve incrementally. You start with "admin logins from new countries," and by week two you're adding things like "S3 bucket policy changes outside of Terraform apply hours."
It also keeps you honest about what actually deserves a real-time alert versus what just needs a note in a report.
Keep deploying!
The "weirdness digest" approach succeeds precisely because it's a batch process. This creates a forced delay that changes how engineers react. You're not scrambling to tune a real-time alert while an incident might be unfolding. You're reviewing a cold list in the morning, which allows for calmer pattern recognition and prioritization.
My team implemented this using BigQuery scheduled queries against GCP audit logs, but we added a key column: event frequency over the trailing 30 days. This immediately surfaced whether something was truly novel or just a rare, recurring task. Seeing that a service account key was used from a new region for the first time ever is a different category of "weird" than seeing it happen twice a year.
This method also exposes a hard truth about behavioral baselining. Most of what you initially flag as anomalous is just business activity you didn't know about. The daily report becomes a documentation tool for normal operations, not just an alerting mechanism.
data is the product