To handle a security incident, first assess its impact, analyze the attack surface, identify false positives, and contain the threat. Use recommended handling policies, update the incident status, add items to a whitelist, or run a playbook to ensure secure and normal system operation.
Security incident handling flowchart
Incident assessment
Before handling a security incident, assess its impact, analyze the attack surface, and identify any false positives to avoid disrupting normal operations. The incident details page provides the information required for this assessment.
Access the incident details page
Log on to the Security Center console.
In the left-side navigation pane, choose .
Select an Occurrence time range to find the target security incident.
ImportantThe Security Incidents page shows only incidents from the last 180 days.
You can enable incident-related notifications in . This allows you to quickly locate a target incident by using information from the notification, such as the incident name.
In the Details column, click Details to go to the incident details page.
Assessment methods and examples
To assess an incident's urgency, scope, and potential for false positives, you can use the Security AI Assistant and review information on the Overview, Timeline, Alert, Entity, and Agent Chain-of-Thought tabs.
If you upgrade Agentic SOC to Security Operations Agent, the system automatically investigates security incidents, generates an investigation report, and provides an AI analysis to determine if the incident is a real attack.
Security AI Assistant
The Security AI Assistant uses an entity analysis agent to assess the risk level of malicious entities and provides handling suggestions.
Example:

Investigation report and AI analysis
After you upgrade to Security Operations Agent, the system uses Agentic AI as its core engine. This engine integrates with Alibaba Cloud's native security data and infrastructure. It uses the agent's autonomous perception, reasoning, and execution capabilities to investigate security incidents and generate an Investigation Report.
Run an AI Agent incident investigation:
Initial investigation: After a security incident is generated (by an analysis rule or iGraph), the Event Investigation Agent automatically starts an investigation.
Follow-up investigation: When incremental alerts are correlated with the current security incident, the Event Investigation Agent automatically triggers another investigation.
View investigation results: Go to the target incident details page and click Full Report at the top to view the report details.
NoteYou can also view the analysis result directly in the AI Analysis column on the security incident list page.
Conclusion:
Conclusion
Confidence interval
Description
Likely False Positive
≤10%
The AI is highly confident this is benign activity, such as a routine scan from a known operations IP address.
Unable to Determine
30%–60%
The AI cannot make a reliable determination due to missing key features, incomplete logs, or ambiguous behavior.
Confirmed Attack
>85%
The AI found a multi-source evidence chain that matches known TTPs, confirming the activity as a real attack.
Attack details: Includes affected assets, attack chain, payload analysis, attack timeline, and attack process names.
View investigation records
Go to the target incident details page and click Response Activity in the upper-right corner.
On the Activity Log tab, set the Response Scenario filter to Event Investigation.
You can review the Event Investigation records and a summary of the investigation results for the current incident in the log list.
Agent Chain-of-Thought
On this tab, you can view the Agent Chain-of-Thought. It displays information like background context, reasoning steps, and a conclusion summary to help you understand the agent's investigation approach and decision-making basis.
Background Context: Provides a Clue Summary and the agent's Initial Hypothesis.
Reasoning Steps: The number of investigation steps depends on the complexity of the investigation. Each step typically shows the agent's Thinking, the Tool Call, and the results from those calls.
Analysis Summary: Presents the final conclusion of the investigation. It also displays any Excluded Noise and the Data Source Status used during the analysis.
Event chain diagram
The Event chain diagram tab shows the attack timeline and provenance graph. The big data analytics engine processes, aggregates, and visualizes event data to help you trace the attack's origin and build a response plan.
If you purchased the Security Operations Agent in Agentic SOC, the incident investigation agent automatically extracts key entity points, reconstructs key behaviors between entities as an event chain diagram, and provides a timeline explanation.
Use the timeline to evaluate urgency:
Act immediately if a small initial probing alert quickly escalates into multiple, closely related attack alerts of different types—especially with an accelerating pace and expanding asset scope.
Lower priority if no new related alerts appear over a long period and the attack shows no signs of spreading.
Alerts
On this tab, you can view all alerts aggregated into this incident. Analyzing multi-dimensional alert statistics—including alert counts, defense measures, and occurrence times—helps you determine attack methods, identify the attack stage, and decide on a handling plan. Assessment examples:
-
A large number of alerts of the same or related types may indicate a larger attack scale or a more severe threat.
-
Regarding defense measures, check whether the deployed defenses have effectively blocked the attack. If the measures have failed or are insufficient, the urgency of handling the incident increases.
-
If the occurrence time of recent alerts is concentrated within a specific period, it may indicate that the attack is in an active phase.
Overview
The Overview area shows the event's ATT&CK attack stage and key metrics—affected asset count, associated alert count, occurrence time, and alert source. Use these signals to decide whether to act and with what priority.
| Signal | What it tells you | When to act immediately |
|---|---|---|
| Affected assets | A high count indicates significant impact. | Core assets (database or application servers) are involved. |
| Associated alerts | More alerts suggest a broader scope and greater potential risk. | Alert count is high and growing. |
| Occurrence time | Recent events may still be active. | The event occurred recently and the attack may be ongoing. |
| Alert source | Source determines detection credibility. | Alerts come from authoritative modules, such as a dedicated virus scanning module. |
Entity
The Entity tab shows all entities extracted from the event. Supported entity types: hosts, files, processes, IP addresses, and host accounts.
View entities from two perspectives:
All entities: Shows all extracted entities with counts of associated events, alerts, and handling tasks from the last 30 days. Run a playbook directly from this view.
Affected assets: Shows only the assets affected by the event, helping you quickly gauge the impact scope.
Use entity details to decide on a response:
If an IP address entity shows high counts of associated events, alerts, and handling tasks, an attacker may be continuously using that IP. Block it.
If multiple assets are attacked by the same IP within the same period, this likely indicates a targeted attack. Block the IP.
Response Activity
-
Core function: Response Activity provides a comprehensive record of the entire risk analysis and response process. It offers management access to key handling policies, tasks, and the Activity Log, enabling team members to share investigation progress and handling information for collaboration. It also facilitates post-incident reviews to summarize the incident activities and accumulate valuable experience.
-
Entry point: On the target incident details page, click Response Activity in the upper-right corner.
Respond to security incidents
Handle security incidents
Handling method | Description |
Use a recommended handling policy |
|
Whitelist |
|
Run a playbook | Security Center provides built-in playbooks for alert entities to help you handle malicious entities. Based on the experience of Alibaba Cloud security experts, these playbooks support actions like investigating offline hosts, performing in-depth virus scans, and blocking IP addresses with WAF. |
Update Incident Status |
|
Automatically handle security incidents | Agentic SOC provides a response rule orchestration feature to automatically handle security threat incidents in batches. |
Recommended policy
Two types of recommended handling policies are available:
Comparison | System-recommended policy | Agent-recommended policy |
Core capability | Combines graph computing and large security models to automatically select built-in automated playbooks for handling security incidents. | Analyzes the investigation conclusions from the Event Investigation Agent, reviews the root cause analysis and handling suggestions, and automatically selects a suitable built-in automated playbook. |
Version requirements | Supported by Agentic SOC Basic Edition and Security Operations Agent. | Supported only after you upgrade to Security Operations Agent. |
Policy management | Allows you to modify policy content, such as playbooks and action validity periods. | Policy content cannot be modified. |
Decision basis | Alibaba Cloud security expert experience | Agent intelligent analysis |
Procedure
-
On the Security Incidents page, find the target incident and click Actions in the Recommended Response column.
NoteYou can also go to the incident details page and click the Recommended Handling button in the lower-left corner.
-
In the recommended handling policy panel, select the malicious entities that you want to handle.
(Optional) Modify the handling policy: Click Edit in the Actions column for the corresponding entity. In the Edit Policy panel, you can modify parameters such as the target accounts for the blocking rule and the action validity period.
NoteIf you upgraded to Security Operations Agent, the AI Agent automatically selects the appropriate playbook and configures the relevant parameters, so no manual modification is needed.
Action validity period: The period during which the handling policy is effective. It automatically expires after this period.
Target account: The current account and any manageable member accounts. For information about how to manage member accounts, see multi-account security management.
-
Click Resolve. In the Update Incident Status dialog box, set the Event Status to Handling or Handled, and then click OK.
ImportantAfter you complete this step, Security Center automatically creates a handling policy and runs a handling task. If the task fails, the incident status changes to Failed. Otherwise, the status updates to what you specified here.
-
Handling: Indicates that other actions related to incident handling, such as threat containment, source tracing, or Vulnerability Fixing, are still required.
-
Handled: No further handling actions are needed. This has the following effects:
-
The status of correlated alerts is updated to "Handled in the security incident."
-
Subsequent alerts will generate a new security incident instead of being correlated with the current one.
-
-
Effects
-
Interacts with other Alibaba Cloud services to respond to the incident and handle malicious entities, such as by blocking an IP address.
-
If you use a recommended handling policy to change the incident status to Handled, the system updates the status of all unhandled alerts correlated with the incident to Handled in the security incident and adds notes about the action to the alert details. After this, new alerts are no longer correlated with the current security incident but will generate a new one.
ImportantThe status of CWPP "Precision Defense" alerts defaults to "Handled" (defend only, no notification). Updating the security incident status does not affect the status of these alerts.
-
If you use a recommended handling policy to change the incident status to Handling, the status of correlated alerts remains unchanged, and subsequent alerts can still be correlated with the current incident.
-
Corresponding Incident Response and Handling Policies are generated on the Handling Tasks page.
Whitelist alert
You can whitelist alerts during incident handling by using either the Add to Whitelist (automated response rule) or Add Alert to Whitelist options. When the system generates alerts for normal activities (like routine business interactions over TCP or network detection scans), whitelisting prevents Security Center from repeatedly flagging these benign behaviors.
Difference | Add to Whitelist (automated) | Add Alert to Whitelist |
Supported alerts | All alerts. | Cloud Workload Protection Platform (CWPP) alerts. |
Effect on the current alert | None. |
|
Rule mechanism |
| Whitelist conditions are optional. The fields for these conditions are derived from the current alert's information fields, such as the rule that generated the alert, tags, and image names. Note You can view this information in the More Information section of the alert details page. |
Add Alert to Whitelist
Procedure
-
Go to the incident details page. On the Alerts tab, select the alert you want to handle and click Add Alert to Whitelist in the Actions column.
-
(Optional) Create a new whitelist rule: Click Create Rule to configure multiple whitelist rules.
Important-
Multiple rules have an OR relationship, meaning the whitelist is triggered if any one condition is met.
-
Ensure your rules are precise to avoid an overly broad scope. For example, a rule like "Path contains: /data/" could inadvertently whitelist sensitive subdirectories, increasing security risks.
Each rule consists of four configuration fields from left to right:
-
Alert information field: You can check which alert information fields are supported for the current alert in the More Information section of the details page.
-
Condition type: Supported operations include regex match, greater than, equal to, less than, and contains. Examples:
-
Regular expression: Use a regular expression to precisely match a specific pattern. For example, to whitelist everything under the
/data/app/logs/folder, set the rule "Path matches regex:^/data/app/logs/.*" to match that folder and all files or processes in its subdirectories. -
Contains keyword: If you set a rule "Path contains:
D:\programs\test\", any event whose path contains that folder is whitelisted.
-
-
Condition value: Supports constants and regular expressions.
-
Applicable assets:
-
All assets: Applies to all existing and newly added assets.
-
Only for the current asset: Applies only to the asset involved in the current alert.
-
-
-
Click OK.
Effects
After you whitelist an alert, notifications for the same or matching alerts are no longer sent. Use this feature with caution.
-
On the current alert:
-
The current alert is marked as "Handled," and its status changes to Manually Add to Whitelist.
-
When the same alert occurs again, new alert data is not generated, but the latest occurrence time of this alert is updated.
-
-
On subsequent alerts:
-
If a specific whitelist rule is set, Security Center no longer correlates alerts that match this rule with a security incident.
-
When an alert matching a custom whitelist rule occurs again, it is automatically moved to the handled list with a status of Automatically Add to Whitelist, and no notification is sent.
-
-
Other alerts: The whitelist rule applies only to alerts with the specified alert name that meet the conditions. Other alerts are not affected.
Remove from whitelist
Cancel an automatic whitelist rule
ImportantThis action only affects future alerts. Alerts that match the rule will no longer be automatically whitelisted.
It does not affect alerts that have already been handled; their status remains unchanged.
Log on to the . In the left-side navigation pane, choose .
NoteIf you have subscribed to Agentic SOC, choose in the left-side navigation pane.
On the CWPP tab, click Cloud Workload Alert Management in the upper-right corner and select Alert Settings.
On the Alert Settings page, in the Alert Handling Rule section, select Automatically Add to Whitelist as the handling method.
Find the target rule and click Delete in the Actions column to cancel the automatic whitelist rule.
Remove an alert from the whitelist
ImportantAfter you remove an alert from the whitelist, it reappears in the Unhandled alert list, requiring you to evaluate and handle it again.
Log on to the . In the left-side navigation pane, choose .
NoteIf you have subscribed to Agentic SOC, choose in the left-side navigation pane.
On the CWPP tab, set the Handled or Not filter to Handled.
Find the alert you want to remove from the whitelist and click Remove from Whitelist in the Actions column.
NoteYou can also select multiple alerts and click Remove from Whitelist at the bottom of the list to perform a bulk removal.

Add to Whitelist (automated)
Procedure
In the Security Incidents list, find the target incident, click the Actions drop-down menu in the Response column, and select Add to Whitelist.
NoteYou can also go to the incident details page, open the Alerts tab, and click Add to Whitelist in the Actions column for the alert.
Configure the rule as described in the following list, then click OK.
Rule Name: Set a clear, descriptive name for the rule, such as "Incident Handling Whitelist_Backdoor Shell".
Trigger: Defaults to Alert Occurrence and cannot be modified.
Rule Action: Defaults to Add Alert to Whitelist and cannot be modified.
Other configurations: See Configure trigger and execution rules.
Effects
Current incident: The incident status remains unchanged. To change it, you must manually perform the Update Incident Status action.
Current alert: No effect.
Subsequent alerts: For alerts that match the whitelist rule (automated response rule), the following changes occur:
For a CWPP alert, the alert status is automatically updated to "Automatically Add to Whitelist". For an Agentic SOC alert, the Add to Whitelist field is updated to Yes. In both cases, no further alert notifications are sent.
Alerts that match the whitelist rule (automated response rule) are no longer correlated with the current incident.
Cancel whitelist policy
To cancel a whitelist policy, allowing subsequent alerts to be correlated with an incident or to generate new incidents, follow these steps:
The original Add Event to Whitelist feature can be managed by navigating to the page and using the Incident Whitelist Settings in the upper-right corner.
Go to the Automated Rules tab on the page.
Find the target rule and turn off the Enabling Status switch.
Click Actions in the Delete column.
Update Incident Status
Procedure
-
On the incident details page, click the Incident Response drop-down menu in the upper-right corner and select Update Incident Status. Alternatively, on the security incident list page, find the target incident, click the Response drop-down menu in the Actions column, and select Update Incident Status.
-
In the Update Incident Status dialog box, select Handled, Unhandled, or Handling.
-
(Optional) Add a remark, such as "Handled manually," "Ignore," "Manually whitelisted," or "Re-handle."
Effects
-
If you update the status to Handled:
-
The status of all unhandled alerts correlated with the incident is updated to Handled in the security incident, and information about the action is added to the alert details.
ImportantThe status of CWPP "Precision Defense" alerts defaults to "Handled" (defend only, no notification). Updating the security incident status does not affect the status of these alerts.
-
Subsequent alerts are no longer correlated with the current security incident but will generate a new one.
-
-
If you update the status to Unhandled or Handling, you can re-select a handling method for the current incident.
Run a playbook
On the event details page, click the Entity tab. Find the entity you want to handle.
In the Actions column, click Handle. Configure the playbook parameters:
Playbook: The system automatically selects the appropriate built-in playbook based on the entity type. > Important: If built-in playbooks don't meet your needs, create custom playbooks using the Response Orchestration feature in Agentic SOC.
Action validity period: How long the playbook runs. The playbook stops after this period expires.
Destination account: The current account or any member accounts you manage. See Multi-account security management.
Click Resolve.
The event is handled based on the playbook's configured process—for example, blocking an IP address—and the event status changes to Handled.
Automatic handling
To automate the handling of security incidents, you can use the response rule orchestration feature provided by Agentic SOC. By configuring playbooks and automated response rules, you can automatically handle security threat incidents in batches. For more information, see Response Rules.
Manage event properties
| Operation | When to use it |
|---|---|
| Update Owner | Assign or transfer the event to the appropriate team member as the response progresses. |
| Update Incident Level | Correct the risk level if the automatically assigned severity is too high or too low, so your team can prioritize accurately. |
Update the event owner
On the event details page, click Incident Response > Update Owner in the upper-right corner. Alternatively, on the Security Events page, click Response > Update Owner in the Actions column.
In the dialog, set the following and click OK:
Owner: Select the current account or a Resource Access Management (RAM) user. > Important: Make sure the target owner (RAM user) has the necessary permissions to handle security events.
Remarks: Enter handover instructions or notes to help the new owner understand the context and start handling the event.
After the operation, the system creates a change record. View it in Response Activity > Activity Log on the event details page.
Update the incident level
On the event details page, click Incident Response > Update Incident Level in the upper-right corner. Alternatively, on the Security Events page, click Response > Update Incident Level in the Actions column.
In the dialog, modify the Incident Severity and Remarks.
After the change, the system records the operation. View it in Response Activity > Activity Log on the event details page.
Export security events
Export security event details to a local Excel file for cross-team collaboration and internal tracking.
(Optional) On the Security Events page, set filters such as event risk level, status, and occurrence time.
Select the events to export (up to 1,000 records), then click the
icon in the upper-right corner of the event list.After the export completes, click Download to save the file.
The exported file has three tabs: a list of security event records, a list of affected assets, and a list of involved entities.
Risk prevention
To prevent future virus attacks, implement server hardening measures. This increases the attacker’s cost and makes it more difficult to breach your defenses.
Upgrade Security Center Edition: Enterprise editionandUltimate editionsupport automatic virus isolation(i.e., automatic virus scanning and removal)(i.e., automatic virus scanning and removal) to provide you with precise defense capabilities. More security detection items are supported.
Restrict access control: Only open necessary business ports (such as 80 and 443). Configure strict IP whitelist access policies for management ports (such as 22 and 3389) and database ports (such as 3306).
NoteFor Alibaba Cloud ECS instances, seeManage security groupsperformoperation.
Set complex server passwords: Set complex passwords containing uppercase and lowercase letters, numbers, and special symbols for servers and applications.
Upgrade software: Keep application software updated to the latest official version, and avoid using outdated versions that are no longer maintained or have known security vulnerabilities.
Regular backup: Create scheduled snapshot policies for important data and server system disks.
NoteFor Alibaba Cloud ECS instances, seeCreate an automatic snapshot policyperformoperation.
Fix vulnerabilities promptly: Regularly use Security Center Vulnerability fixfeature to promptly fix critical system vulnerabilities and application vulnerabilities.
Reset the server system (use with caution).
If the virus intrusion is deep, involving low-level system components, it is strongly recommended that you reset the server system after backing up important data. The specific steps are as follows:
Create a snapshot to back up important data on the server. For more information, seeManually create a single snapshot.
Initialize the server operating system. For more information, seeRe-initialize a system disk.
Use the snapshot to create a cloud disk. For more information, seeCreate a data disk from a snapshot.
Attach the cloud disk to the server after the system reinstallation. For more information, seeAttach a data disk.
Quotas and limits
Data retention: The security incident page supports only viewing and handling incidents from the last 180 days.
Entity details: On an entity's details page, the counts of correlated incidents, alerts, and handling tasks reflect only data from the last 30 days.
Export limit: You can export a maximum of 1,000 security incident records at a time.
Status synchronization: Updating the status of a security incident does not affect the status of Cloud Workload Protection Platform (CWPP) "Precision Defense" alerts. These alerts default to "Handled" (defend only, no notification).