All Products
Search
Document Center

Security Center:Assess and handle security incidents - Agentic SOC

Last Updated:Apr 29, 2026

To handle a security incident, first assess its impact, analyze the attack surface, identify false positives, and contain the threat. Use recommended handling policies, update the incident status, add items to a whitelist, or run a playbook to ensure secure and normal system operation.

Security incident handling flowchart

image

Incident assessment

Before handling a security incident, assess its impact, analyze the attack surface, and identify any false positives to avoid disrupting normal operations. The incident details page provides the information required for this assessment.

Access the incident details page

  1. Log on to the Security Center console.

  2. In the left-side navigation pane, choose Agentic SOC > Security Incidents.

  3. Select an Occurrence time range to find the target security incident.

    Important
    • The Security Incidents page shows only incidents from the last 180 days.

    • You can enable incident-related notifications in System Settings > Notification Settings. This allows you to quickly locate a target incident by using information from the notification, such as the incident name.

  4. In the Details column, click Details to go to the incident details page.

Assessment methods and examples

  • To assess an incident's urgency, scope, and potential for false positives, you can use the Security AI Assistant and review information on the Overview, Timeline, Alert, Entity, and Agent Chain-of-Thought tabs.

  • If you upgrade Agentic SOC to Security Operations Agent, the system automatically investigates security incidents, generates an investigation report, and provides an AI analysis to determine if the incident is a real attack.

Security AI Assistant

The Security AI Assistant uses an entity analysis agent to assess the risk level of malicious entities and provides handling suggestions.

Example:

image

Investigation report and AI analysis

After you upgrade to Security Operations Agent, the system uses Agentic AI as its core engine. This engine integrates with Alibaba Cloud's native security data and infrastructure. It uses the agent's autonomous perception, reasoning, and execution capabilities to investigate security incidents and generate an Investigation Report.

  1. Run an AI Agent incident investigation:

    1. Initial investigation: After a security incident is generated (by an analysis rule or iGraph), the Event Investigation Agent automatically starts an investigation.

    2. Follow-up investigation: When incremental alerts are correlated with the current security incident, the Event Investigation Agent automatically triggers another investigation.

  2. View investigation results: Go to the target incident details page and click Full Report at the top to view the report details.

    Note

    You can also view the analysis result directly in the AI Analysis column on the security incident list page.

    • Conclusion:

      Conclusion

      Confidence interval

      Description

      Likely False Positive

      ≤10%

      The AI is highly confident this is benign activity, such as a routine scan from a known operations IP address.

      Unable to Determine

      30%–60%

      The AI cannot make a reliable determination due to missing key features, incomplete logs, or ambiguous behavior.

      Confirmed Attack

      >85%

      The AI found a multi-source evidence chain that matches known TTPs, confirming the activity as a real attack.

    • Attack details: Includes affected assets, attack chain, payload analysis, attack timeline, and attack process names.

  3. View investigation records

    1. Go to the target incident details page and click Response Activity in the upper-right corner.

    2. On the Activity Log tab, set the Response Scenario filter to Event Investigation.

    3. You can review the Event Investigation records and a summary of the investigation results for the current incident in the log list.

Agent Chain-of-Thought

On this tab, you can view the Agent Chain-of-Thought. It displays information like background context, reasoning steps, and a conclusion summary to help you understand the agent's investigation approach and decision-making basis.

  • Background Context: Provides a Clue Summary and the agent's Initial Hypothesis.

  • Reasoning Steps: The number of investigation steps depends on the complexity of the investigation. Each step typically shows the agent's Thinking, the Tool Call, and the results from those calls.

  • Analysis Summary: Presents the final conclusion of the investigation. It also displays any Excluded Noise and the Data Source Status used during the analysis.

Event chain diagram

The Event chain diagram tab shows the attack timeline and provenance graph. The big data analytics engine processes, aggregates, and visualizes event data to help you trace the attack's origin and build a response plan.

If you purchased the Security Operations Agent in Agentic SOC, the incident investigation agent automatically extracts key entity points, reconstructs key behaviors between entities as an event chain diagram, and provides a timeline explanation.

Use the timeline to evaluate urgency:

  • Act immediately if a small initial probing alert quickly escalates into multiple, closely related attack alerts of different types—especially with an accelerating pace and expanding asset scope.

  • Lower priority if no new related alerts appear over a long period and the attack shows no signs of spreading.

Alerts

On this tab, you can view all alerts aggregated into this incident. Analyzing multi-dimensional alert statistics—including alert counts, defense measures, and occurrence times—helps you determine attack methods, identify the attack stage, and decide on a handling plan. Assessment examples:

  • A large number of alerts of the same or related types may indicate a larger attack scale or a more severe threat.

  • Regarding defense measures, check whether the deployed defenses have effectively blocked the attack. If the measures have failed or are insufficient, the urgency of handling the incident increases.

  • If the occurrence time of recent alerts is concentrated within a specific period, it may indicate that the attack is in an active phase.

Overview

The Overview area shows the event's ATT&CK attack stage and key metrics—affected asset count, associated alert count, occurrence time, and alert source. Use these signals to decide whether to act and with what priority.

SignalWhat it tells youWhen to act immediately
Affected assetsA high count indicates significant impact.Core assets (database or application servers) are involved.
Associated alertsMore alerts suggest a broader scope and greater potential risk.Alert count is high and growing.
Occurrence timeRecent events may still be active.The event occurred recently and the attack may be ongoing.
Alert sourceSource determines detection credibility.Alerts come from authoritative modules, such as a dedicated virus scanning module.

Entity

The Entity tab shows all entities extracted from the event. Supported entity types: hosts, files, processes, IP addresses, and host accounts.

View entities from two perspectives:

  • All entities: Shows all extracted entities with counts of associated events, alerts, and handling tasks from the last 30 days. Run a playbook directly from this view.

  • Affected assets: Shows only the assets affected by the event, helping you quickly gauge the impact scope.

Use entity details to decide on a response:

  • If an IP address entity shows high counts of associated events, alerts, and handling tasks, an attacker may be continuously using that IP. Block it.

  • If multiple assets are attacked by the same IP within the same period, this likely indicates a targeted attack. Block the IP.

Response Activity

  • Core function: Response Activity provides a comprehensive record of the entire risk analysis and response process. It offers management access to key handling policies, tasks, and the Activity Log, enabling team members to share investigation progress and handling information for collaboration. It also facilitates post-incident reviews to summarize the incident activities and accumulate valuable experience.

  • Entry point: On the target incident details page, click Response Activity in the upper-right corner.

Respond to security incidents

Handle security incidents

Handling method

Description

Use a recommended handling policy

  • Security Center offers incident handling methods, known as recommended handling policies, based on the experience of Alibaba Cloud security experts.

  • After you use a recommended handling policy to handle malicious entities in a security incident, you can synchronously update the incident status and its correlated alerts.

Whitelist

  • Add Alert to Whitelist: Adds confirmed benign programs, IP addresses, or behaviors to a whitelist to prevent them from triggering future alerts.

    Important

    The Add Alert to Whitelist feature supports only Cloud Workload Protection Platform (CWPP) alerts, which include host and container alerts.

  • Add to Whitelist (automated response rule): When the same alert occurs again, its status is updated to Whitelisted, and it is no longer correlated with a security incident.

Run a playbook

Security Center provides built-in playbooks for alert entities to help you handle malicious entities. Based on the experience of Alibaba Cloud security experts, these playbooks support actions like investigating offline hosts, performing in-depth virus scans, and blocking IP addresses with WAF.

Update Incident Status

  • If an incident is determined to be a false positive or you have manually handled all related alerts and entities, you can change the incident status to Handled.

  • For incidents that are already handled, you can also reset the status to Unhandled or Handling.

Automatically handle security incidents

Agentic SOC provides a response rule orchestration feature to automatically handle security threat incidents in batches.

Recommended policy

Two types of recommended handling policies are available:

Comparison

System-recommended policy

Agent-recommended policy

Core capability

Combines graph computing and large security models to automatically select built-in automated playbooks for handling security incidents.

Analyzes the investigation conclusions from the Event Investigation Agent, reviews the root cause analysis and handling suggestions, and automatically selects a suitable built-in automated playbook.

Version requirements

Supported by Agentic SOC Basic Edition and Security Operations Agent.

Supported only after you upgrade to Security Operations Agent.

Policy management

Allows you to modify policy content, such as playbooks and action validity periods.

Policy content cannot be modified.

Decision basis

Alibaba Cloud security expert experience

Agent intelligent analysis

Procedure

  1. On the Security Incidents page, find the target incident and click Actions in the Recommended Response column.

    Note

    You can also go to the incident details page and click the Recommended Handling button in the lower-left corner.

  2. In the recommended handling policy panel, select the malicious entities that you want to handle.

  3. (Optional) Modify the handling policy: Click Edit in the Actions column for the corresponding entity. In the Edit Policy panel, you can modify parameters such as the target accounts for the blocking rule and the action validity period.

    Note

    If you upgraded to Security Operations Agent, the AI Agent automatically selects the appropriate playbook and configures the relevant parameters, so no manual modification is needed.

    • Action validity period: The period during which the handling policy is effective. It automatically expires after this period.

    • Target account: The current account and any manageable member accounts. For information about how to manage member accounts, see multi-account security management.

  4. Click Resolve. In the Update Incident Status dialog box, set the Event Status to Handling or Handled, and then click OK.

    Important

    After you complete this step, Security Center automatically creates a handling policy and runs a handling task. If the task fails, the incident status changes to Failed. Otherwise, the status updates to what you specified here.

    • Handling: Indicates that other actions related to incident handling, such as threat containment, source tracing, or Vulnerability Fixing, are still required.

    • Handled: No further handling actions are needed. This has the following effects:

      • The status of correlated alerts is updated to "Handled in the security incident."

      • Subsequent alerts will generate a new security incident instead of being correlated with the current one.

Effects

  • Interacts with other Alibaba Cloud services to respond to the incident and handle malicious entities, such as by blocking an IP address.

  • If you use a recommended handling policy to change the incident status to Handled, the system updates the status of all unhandled alerts correlated with the incident to Handled in the security incident and adds notes about the action to the alert details. After this, new alerts are no longer correlated with the current security incident but will generate a new one.

    Important

    The status of CWPP "Precision Defense" alerts defaults to "Handled" (defend only, no notification). Updating the security incident status does not affect the status of these alerts.

  • If you use a recommended handling policy to change the incident status to Handling, the status of correlated alerts remains unchanged, and subsequent alerts can still be correlated with the current incident.

  • Corresponding Incident Response and Handling Policies are generated on the Handling Tasks page.

Whitelist alert

You can whitelist alerts during incident handling by using either the Add to Whitelist (automated response rule) or Add Alert to Whitelist options. When the system generates alerts for normal activities (like routine business interactions over TCP or network detection scans), whitelisting prevents Security Center from repeatedly flagging these benign behaviors.

Difference

Add to Whitelist (automated)

Add Alert to Whitelist

Supported alerts

All alerts.

Cloud Workload Protection Platform (CWPP) alerts.

Effect on the current alert

None.

  • The status of the current alert changes to Manually Add to Whitelist.

  • When the same alert occurs again, new alert data is not generated, but the latest occurrence time of the alert is updated.

Rule mechanism

  • Uses the Response Rules feature to create an Automated Rules for alert filtering.

  • Whitelist conditions are required. The fields for these conditions are derived from alert feature fields and entity attribute fields extracted from the alert.

Whitelist conditions are optional. The fields for these conditions are derived from the current alert's information fields, such as the rule that generated the alert, tags, and image names.

Note

You can view this information in the More Information section of the alert details page.

Add Alert to Whitelist

Procedure

  1. Go to the incident details page. On the Alerts tab, select the alert you want to handle and click Add Alert to Whitelist in the Actions column.

  2. (Optional) Create a new whitelist rule: Click Create Rule to configure multiple whitelist rules.

    Important
    • Multiple rules have an OR relationship, meaning the whitelist is triggered if any one condition is met.

    • Ensure your rules are precise to avoid an overly broad scope. For example, a rule like "Path contains: /data/" could inadvertently whitelist sensitive subdirectories, increasing security risks.

    Each rule consists of four configuration fields from left to right:

    1. Alert information field: You can check which alert information fields are supported for the current alert in the More Information section of the details page.

    2. Condition type: Supported operations include regex match, greater than, equal to, less than, and contains. Examples:

      • Regular expression: Use a regular expression to precisely match a specific pattern. For example, to whitelist everything under the /data/app/logs/ folder, set the rule "Path matches regex: ^/data/app/logs/.*" to match that folder and all files or processes in its subdirectories.

      • Contains keyword: If you set a rule "Path contains: D:\programs\test\", any event whose path contains that folder is whitelisted.

    3. Condition value: Supports constants and regular expressions.

    4. Applicable assets:

      • All assets: Applies to all existing and newly added assets.

      • Only for the current asset: Applies only to the asset involved in the current alert.

  3. Click OK.

Effects

Warning

After you whitelist an alert, notifications for the same or matching alerts are no longer sent. Use this feature with caution.

  • On the current alert:

    • The current alert is marked as "Handled," and its status changes to Manually Add to Whitelist.

    • When the same alert occurs again, new alert data is not generated, but the latest occurrence time of this alert is updated.

      What are "same alerts?"

      "Same alerts" are security threats with highly consistent features. For example:

      • Virus alerts: same asset, same virus file path, and same virus file MD5.

      • Abnormal logon alerts: same asset and same logon IP address.

  • On subsequent alerts:

    • If a specific whitelist rule is set, Security Center no longer correlates alerts that match this rule with a security incident.

    • When an alert matching a custom whitelist rule occurs again, it is automatically moved to the handled list with a status of Automatically Add to Whitelist, and no notification is sent.

  • Other alerts: The whitelist rule applies only to alerts with the specified alert name that meet the conditions. Other alerts are not affected.

Remove from whitelist

  • Cancel an automatic whitelist rule

    Important
    • This action only affects future alerts. Alerts that match the rule will no longer be automatically whitelisted.

    • It does not affect alerts that have already been handled; their status remains unchanged.

    1. Log on to the . In the left-side navigation pane, choose Detection and Response > Alert.

      Note

      If you have subscribed to Agentic SOC, choose Agentic SOC > Alert in the left-side navigation pane.

    2. On the CWPP tab, click Cloud Workload Alert Management in the upper-right corner and select Alert Settings.

    3. On the Alert Settings page, in the Alert Handling Rule section, select Automatically Add to Whitelist as the handling method.

    4. Find the target rule and click Delete in the Actions column to cancel the automatic whitelist rule.

  • Remove an alert from the whitelist

    Important

    After you remove an alert from the whitelist, it reappears in the Unhandled alert list, requiring you to evaluate and handle it again.

    1. Log on to the . In the left-side navigation pane, choose Detection and Response > Alert.

      Note

      If you have subscribed to Agentic SOC, choose Agentic SOC > Alert in the left-side navigation pane.

    2. On the CWPP tab, set the Handled or Not filter to Handled.

    3. Find the alert you want to remove from the whitelist and click Remove from Whitelist in the Actions column.

      Note

      You can also select multiple alerts and click Remove from Whitelist at the bottom of the list to perform a bulk removal.

    image

Add to Whitelist (automated)

Procedure
  1. In the Security Incidents list, find the target incident, click the Actions drop-down menu in the Response column, and select Add to Whitelist.

    Note

    You can also go to the incident details page, open the Alerts tab, and click Add to Whitelist in the Actions column for the alert.

  2. Configure the rule as described in the following list, then click OK.

    • Rule Name: Set a clear, descriptive name for the rule, such as "Incident Handling Whitelist_Backdoor Shell".

    • Trigger: Defaults to Alert Occurrence and cannot be modified.

    • Rule Action: Defaults to Add Alert to Whitelist and cannot be modified.

    • Other configurations: See Configure trigger and execution rules.

Effects
  • Current incident: The incident status remains unchanged. To change it, you must manually perform the Update Incident Status action.

  • Current alert: No effect.

  • Subsequent alerts: For alerts that match the whitelist rule (automated response rule), the following changes occur:

    • For a CWPP alert, the alert status is automatically updated to "Automatically Add to Whitelist". For an Agentic SOC alert, the Add to Whitelist field is updated to Yes. In both cases, no further alert notifications are sent.

    • Alerts that match the whitelist rule (automated response rule) are no longer correlated with the current incident.

Cancel whitelist policy

To cancel a whitelist policy, allowing subsequent alerts to be correlated with an incident or to generate new incidents, follow these steps:

Note

The original Add Event to Whitelist feature can be managed by navigating to the Agentic SOC > Security Incidents page and using the Incident Whitelist Settings in the upper-right corner.

  1. Go to the Automated Rules tab on the Agentic SOC > Response Rules page.

  2. Find the target rule and turn off the Enabling Status switch.

  3. Click Actions in the Delete column.

Update Incident Status

Procedure

  1. On the incident details page, click the Incident Response drop-down menu in the upper-right corner and select Update Incident Status. Alternatively, on the security incident list page, find the target incident, click the Response drop-down menu in the Actions column, and select Update Incident Status.

  2. In the Update Incident Status dialog box, select Handled, Unhandled, or Handling.

  3. (Optional) Add a remark, such as "Handled manually," "Ignore," "Manually whitelisted," or "Re-handle."

Effects

  • If you update the status to Handled:

    • The status of all unhandled alerts correlated with the incident is updated to Handled in the security incident, and information about the action is added to the alert details.

      Important

      The status of CWPP "Precision Defense" alerts defaults to "Handled" (defend only, no notification). Updating the security incident status does not affect the status of these alerts.

    • Subsequent alerts are no longer correlated with the current security incident but will generate a new one.

  • If you update the status to Unhandled or Handling, you can re-select a handling method for the current incident.

Run a playbook

  1. On the event details page, click the Entity tab. Find the entity you want to handle.

  2. In the Actions column, click Handle. Configure the playbook parameters:

    • Playbook: The system automatically selects the appropriate built-in playbook based on the entity type. > Important: If built-in playbooks don't meet your needs, create custom playbooks using the Response Orchestration feature in Agentic SOC.

    • Action validity period: How long the playbook runs. The playbook stops after this period expires.

    • Destination account: The current account or any member accounts you manage. See Multi-account security management.

  3. Click Resolve.

The event is handled based on the playbook's configured process—for example, blocking an IP address—and the event status changes to Handled.

Automatic handling

To automate the handling of security incidents, you can use the response rule orchestration feature provided by Agentic SOC. By configuring playbooks and automated response rules, you can automatically handle security threat incidents in batches. For more information, see Response Rules.

Manage event properties

OperationWhen to use it
Update OwnerAssign or transfer the event to the appropriate team member as the response progresses.
Update Incident LevelCorrect the risk level if the automatically assigned severity is too high or too low, so your team can prioritize accurately.

Update the event owner

  1. On the event details page, click Incident Response > Update Owner in the upper-right corner. Alternatively, on the Security Events page, click Response > Update Owner in the Actions column.

  2. In the dialog, set the following and click OK:

    • Owner: Select the current account or a Resource Access Management (RAM) user. > Important: Make sure the target owner (RAM user) has the necessary permissions to handle security events.

    • Remarks: Enter handover instructions or notes to help the new owner understand the context and start handling the event.

After the operation, the system creates a change record. View it in Response Activity > Activity Log on the event details page.

Update the incident level

  1. On the event details page, click Incident Response > Update Incident Level in the upper-right corner. Alternatively, on the Security Events page, click Response > Update Incident Level in the Actions column.

  2. In the dialog, modify the Incident Severity and Remarks.

After the change, the system records the operation. View it in Response Activity > Activity Log on the event details page.

Export security events

Export security event details to a local Excel file for cross-team collaboration and internal tracking.

  1. (Optional) On the Security Events page, set filters such as event risk level, status, and occurrence time.

  2. Select the events to export (up to 1,000 records), then click the image.png icon in the upper-right corner of the event list.

  3. After the export completes, click Download to save the file.

The exported file has three tabs: a list of security event records, a list of affected assets, and a list of involved entities.

Risk prevention

To prevent future virus attacks, implement server hardening measures. This increases the attacker’s cost and makes it more difficult to breach your defenses.

  • Upgrade Security Center Edition: Enterprise editionandUltimate editionsupport automatic virus isolation(i.e., automatic virus scanning and removal)(i.e., automatic virus scanning and removal) to provide you with precise defense capabilities. More security detection items are supported.

  • Restrict access control: Only open necessary business ports (such as 80 and 443). Configure strict IP whitelist access policies for management ports (such as 22 and 3389) and database ports (such as 3306).

    Note

    For Alibaba Cloud ECS instances, seeManage security groupsperformoperation.

  • Set complex server passwords: Set complex passwords containing uppercase and lowercase letters, numbers, and special symbols for servers and applications.

  • Upgrade software: Keep application software updated to the latest official version, and avoid using outdated versions that are no longer maintained or have known security vulnerabilities.

  • Regular backup: Create scheduled snapshot policies for important data and server system disks.

    Note

    For Alibaba Cloud ECS instances, seeCreate an automatic snapshot policyperformoperation.

  • Fix vulnerabilities promptly: Regularly use Security Center Vulnerability fixfeature to promptly fix critical system vulnerabilities and application vulnerabilities.

  • Reset the server system (use with caution).

    If the virus intrusion is deep, involving low-level system components, it is strongly recommended that you reset the server system after backing up important data. The specific steps are as follows:

    1. Create a snapshot to back up important data on the server. For more information, seeManually create a single snapshot.

    2. Initialize the server operating system. For more information, seeRe-initialize a system disk.

    3. Use the snapshot to create a cloud disk. For more information, seeCreate a data disk from a snapshot.

    4. Attach the cloud disk to the server after the system reinstallation. For more information, seeAttach a data disk.

Quotas and limits

  • Data retention: The security incident page supports only viewing and handling incidents from the last 180 days.

  • Entity details: On an entity's details page, the counts of correlated incidents, alerts, and handling tasks reflect only data from the last 30 days.

  • Export limit: You can export a maximum of 1,000 security incident records at a time.

  • Status synchronization: Updating the status of a security incident does not affect the status of Cloud Workload Protection Platform (CWPP) "Precision Defense" alerts. These alerts default to "Handled" (defend only, no notification).