Investigation workflow - AWS Security Incident Response User Guide

Investigation workflow

AWS Security Incident Response engineers follow a structured incident response process aligned with the NIST 800-61r2 framework. During your investigation, you can expect the following phases:

  1. Initial triage - Security Incident Response engineers review your case details and confirm the incident scope

  2. Investigation - Security Incident Response engineers analyze logs, identify indicators of compromise, and determine root cause

  3. Containment - Security Incident Response engineers recommend actions to limit the incident's impact

  4. Eradication and recovery - Security Incident Response engineers help you remove threats and restore normal operations

  5. Post-incident review - Security Incident Response engineers provide findings and recommendations to prevent future incidents

Throughout these phases, your Security Incident Response engineer keeps you informed through case updates and may request additional information or actions from you.