All Products
Search
Document Center

Security Center:Respond to security alerts

Last Updated:Aug 03, 2026

Security Center generates alerts when it detects intrusions, malware, or abnormal behavior on your assets. Promptly and correctly handling alerts is key to ensuring business stability and data security. This topic describes how to follow emergency response procedures to quickly assess risks, eliminate threats, and harden your systems.

Assess security alerts

Before responding to an alert, assess its potential impact, analyze the attack, and identify false positives. The alert details page provides the information you need for this assessment.

View alert details

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Detection and Response > Alert. In the upper-left corner of the console, select your asset's region: Chinese Mainland or Outside Chinese Mainland.

    Note

    If you have enabled Agentic SOC, the navigation path in the left-side navigation pane changes to Agentic SOC (Legacy) > Alert.

  3. On the CWPP tab, find the alert and click Details in the Actions column.

    Important
    • You can enable alert notifications on the System Configuration > Notification Settings page. You can then use information from the notifications, such as the alert name, to quickly locate the alert.

    • The Ultimate Edition lets you filter alerts by asset type. Above the alert list, click All, host, container, K8s, or cloud service to view alerts for the corresponding asset type.

    • Security Center uses a new large model detection engine to intelligently identify malicious files. To view alerts detected by AI, set the AI Detected filter to Yes. View alerts for AI-detected malicious files.

Analyze alert details

Use the attack tracing, and Description to understand the alert's basis, frequency, and potential causes. This helps you determine whether the alert is a false positive and plan your response.

The alert details page contains multiple time fields:

  • First detection time: The time when Security Center first detected this alert.

  • Last detection time: The most recent time this alert was detected. If the same process or file triggers the alert multiple times, this time is updated continuously.

  • Alert report time: The time when the agent reported the alert data to the cloud.

For suspicious processes that appear multiple times, click the process path to view detailed detection timestamps. This helps you determine when and how frequently the alert was triggered.

Note

The security alert viewing and handling features are available only in the web console. The Alibaba Cloud mobile app does not support these features.

Alert description

The alert description summarizes the detected abnormal activity, its risks and characteristics, and recommended response actions.

Assessment example:

image

Potential risk: A relevant configuration file was modified to create a logon backdoor.

Recommended response: Confirm with the appropriate business team if this process is normal. If not, terminate the process immediately. Then, investigate the system for other potential threats.

Attack tracing

Security Center provides automated attack tracing that integrates logs from multiple cloud services. Through big data analysis, it generates visualized intrusion path diagrams with raw data previews. This feature helps you quickly identify the intrusion cause and develop emergency strategies. It is applicable to emergency response and tracing for web intrusions, worm events, ransomware, and malicious download connections in cloud environments.

  • This feature is available only on servers with the Enterprise, Ultimate authorization, or the Comprehensive Host Protection or Hosts and Container Protection feature enabled.

  • Security Center generates the automated attack tracing path within 10 minutes after detecting a threat. Wait at least 10 minutes after the alert before viewing attack tracing information.

  • Automated attack tracing information is automatically deleted 3 months after the alert is triggered. Review the attack tracing information promptly.

Capabilities:

Assessment example:

  • In the traceability section of the details page, check whether the attack chain is complete and valid. The more complete the attack chain, the more urgently you need to handle the alert.

    How do I determine whether an attack chain is valid?

    • Invalid chain: The tracing result shows only single-point scanning or probing activities, such as an isolated port scan or an unsuccessful vulnerability exploit attempt, without triggering subsequent actions like establishing a connection, executing a command, or downloading a malicious file.

    • Valid chain: The tracing graph shows a clear intrusion path. Example: vulnerability exploit → webshell write → internal network scan → malicious file download → lateral movement.

  • Click a node in the graph and check the details on the left to determine if the attack objective was achieved. For example:

    • Check endpoint activity: The attacker executed commands on the server, such as whoami or net user.

    • Check for data exfiltration: Look for abnormal outbound connections (to mining pools or C2 servers) or sensitive file read/upload activities.

    • Check for persistence artifacts: Look for newly created backdoor accounts, scheduled tasks, or malicious services.

  • Click a node in the tracing graph and, in the node details section on the left, see if the raw logs are verifiable (for example, WAF interception records, host process creation logs, or network connection logs).

    • Verifiable: There are supporting underlying logs, such as WAF interception records or host process logs for malicious command execution. This proves the attack occurred. If the attack was intercepted, you can mark the alert as "Processed" and no further action is required. If it was not intercepted, you must respond immediately.

    • Not verifiable: No supporting logs are available. This could be due to log deletion or detection evasion. In this scenario, you must be highly vigilant as it may indicate an advanced attack.

Sandbox detection

Sandbox detection runs suspicious files in a secure, isolated environment to analyze their static and dynamic behavior. Use the results to identify and remediate malicious programs.

Note

The sandbox detection feature is available only for some malware alerts. Its availability is indicated on the alert details page.

  1. In the security alert list, find the target security alert and click Details in the Actions column.

  2. In the Sandbox section, view the sandbox detection results.

Assessment example:

The sandbox detection results page displays file information at the top (file name, threat tags, SHA1/MD5/SHA256 hashes). Below that are five tabs: Behavior Tags, Process Details, Network Behavior, File Behavior, and ATT&CK Matrix. The ATT&CK Matrix view is organized into 12 columns by attack stage (Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact). Each column displays corresponding attack technique cards with hit counts. Red numbers indicate high-risk stages.

  • Behavior Tag: These tags label the file's characteristics and highlight its high-risk operations. Red tags indicate the most critical intrusive behaviors.

  • ATT&CK Matrix: Displays the process flow during the sandbox detection run and highlights high-risk operations performed by the file. Red highlighting indicates the most critical intrusive behaviors.

Quick reference for alert handling

Important
  • If you determine that an alert is for legitimate activity or requires no action, you can ignore the alert or add it to the whitelist.

  • Security Center alerts only indicate potential security risks. They do not block your domain names or services. You do not need to request an unblock after receiving an alert. Simply remove the non-compliant content, or handle the alert by ignoring it or adding it to the whitelist.

  • For persistent virus threats or recurring alerts, handle the alert in the console and then follow the Security Hardening and Attack Prevention guidelines.

Alert type

Alert name

Recommended action

Malware

Mining program

Virus Detection and Removal

DDoS trojan

Trojan program

Malicious program

Exploit program

Suspicious PowerShell command

Backdoor program

Reverse shell backdoor

File-infecting virus

Deep Cleanup

Unusual logon

Logon from a malicious IP address

Block

Successful brute-force attack on ECS

Logon to ECS with an unusual account

Logon to ECS from an unusual location

Logon with a backdoor account

Website backdoor

Backdoor (Webshell) file detected

Quarantine

Log/image file containing Webshell code

Backdoor file for web trojan or hotlinking detected

Arbitrary file write backdoor detected

Abnormal process behavior

Java application executes abnormal commands

Terminate Process

Suspicious process path

Network proxy forwarding behavior

Suspicious PowerShell command

Persistent backdoor creation behavior

SSH backdoor

Suspicious encoded command

Suspicious command execution

Malicious script

Malicious script execution

Terminate Process

Precision defense

Evasion of security software

Deep Cleanup

Cloud product threat detection

RAM sub-account logon from an unusual location

Modify the account password or restrict the allowed source IP addresses for the user in RAMDisable a RAM user's access key. Change the alert status to Manually Handled.

Hacking tool exploits AccessKey

Delete the RAM user's AccessKey or disable it. Change the alert status to Manually Handled.

Abnormal role permission enumeration

Log on to the RAM console as a RAM administrator and modify the RAM user permissions. Change the alert status to Manually Handled.

RAM user performs sensitive operations after logging on to the console

Manually Handled

Other

Security Center agent unexpectedly goes offline

Troubleshooting

Manually handle alerts

Important

If you use the Security Event Response feature to handle an event aggregated from Security Center alerts, Security Center automatically updates the status of the related alerts on the CWPP tab. You do not need to manually update the alert status.

Before you begin

  • Verify your edition and authorization: Alert remediation actions (such as quarantining files, blocking IPs, and adding alerts to the whitelist) are available only in the Antivirus edition or above. If you are on the Free edition or your authorization has expired, the Handle button on the alert details page is grayed out and cannot be clicked, and you can only view alerts. Purchase the Antivirus edition or above and ensure the affected server has an active authorization binding before proceeding.

  • Create a snapshot backup: Before handling an alert, create a snapshot backup of the server in the ECS console to prevent data loss. Create a snapshot.

  • Server-side investigation: Log on to the server to investigate suspicious processes. Common commands:

    • Linux servers: Use ps aux | grep <suspicious process name> to check whether a suspicious process is still running.

    • Linux servers: Use lsof -p <process PID> to view the files and network connections opened by the process.

    • Windows servers: You can use Task Manager or log on to the server via VNC from the console to view process information. Suspicious processes are often located in directories such as C:\Users\Administrator\AppData\Local. Confirm whether the process is required by your business before deleting it.

Choose a method

Handling methods are categorized as follows:

  • Threat Removal: Removes known threats, remediates infections, and blocks threat sources.

  • Alert Suppression: Handles false positives, known or acceptable risks by whitelisting or ignoring alerts, marking that "this alert is invalid or does not require handling", and controlling whether subsequent similar alerts continue to trigger notifications.

  • Troubleshooting: Troubleshoot and diagnose issues with the Security Center agent.

Threat removal

Virus Detection and Removal

  • Use cases

    • Confirmed malicious activity: Use when Security Center detects a running malicious process (virus, trojan, or ransomware) that must be stopped immediately.

    • Incident response: Use to contain an active virus or data leak before it spreads to other instances.

  • Before you begin

    Virus Scan may cause service interruptions. Inspect the source file before proceeding:

    • Verify file properties: Confirm that the file is a virus by checking its path, signature, and hash value. This helps prevent the accidental deletion of system or business files.

    • Assess business dependencies: Check if the file is used by critical services, such as components related to nginx or mysql.

  • How it works

    • Immediately terminate the virus process and move the virus file to the quarantine area. Quarantined files cannot be executed, accessed, or spread.

      Warning
      • Terminating a process can disrupt dependent services, especially if the malicious process has replaced or infected a legitimate application.

      • If the quarantined file is a business file infected with malicious code, such as a core application component, quarantining it may lead to service interruptions.

    • Quarantined files can be restored within 30 days. After restoration, the file reappears in the alert list for continued monitoring. For more information, see View and restore quarantined files.

      Note

      Files not restored within 30 days are permanently deleted.

  • Next steps

    Review quarantined files within 30 days to prevent accidental permanent deletion. View and restore quarantined files.

Deep Cleanup

The Deep Cleanup feature is a specialized tool from Security Center experts designed to handle persistent and stubborn viruses.

  • Use cases

    Deep Scan is a specialized solution for stubborn and file-infecting viruses. These viruses typically exhibit the following characteristics:

    • Infects host files: The virus injects itself into system files, application files, or your personal documents, making them part of the virus.

    • Difficult to eradicate: A standard virus scan may only remove the parent virus but cannot repair the infected files, causing the issue to recur.

    Note

    If a virus does not fit this description, use the standard Virus Scan feature.

  • Before you begin

    A Deep Cleanup carries risks of accidental file deletion, service interruption, and data integrity issues. Inspect the source file before proceeding:

    • Verify file properties: Confirm that the file is a virus by checking its path, signature, and hash value. This helps prevent the accidental deletion of system or business files.

    • Assess business dependencies: Check if the file is used by critical services, such as components related to nginx or mysql.

  • How it works

    • It cleans up persistent viruses by terminating malicious processes, quarantining malicious files, and removing persistence mechanisms used by viruses and trojans.

    • The feature can create a snapshot backup. If the deep scan accidentally removes useful data, restore it from the snapshot.

      Important

      Creating and retaining snapshots incurs fees from the snapshot service. By default, the billing method is pay-as-you-go. You can consult pre-sales support for fee details.

  • Next steps

    Review quarantined files within 30 days to prevent accidental permanent deletion. View and restore quarantined files.

Quarantine

  • Use cases

    Use when you have confirmed that a file is malicious (backdoor or virus) and must stop it immediately.

  • How it works

    • The system moves the suspicious file to a quarantine area. Quarantined files cannot be executed, accessed, or spread.

      Warning

      If the quarantined file is a business file infected with malicious code, such as a core application component, quarantining it may lead to service interruptions.

    • Quarantined files can be restored within 30 days. After restoration, the file reappears in the alert list for continued monitoring. For more information, see View and restore quarantined files.

      Note

      Files not restored within 30 days are permanently deleted.

  • Next steps

    Review quarantined files within 30 days to prevent accidental permanent deletion. View and restore quarantined files.

Terminate Process

  • Use cases

    Handles alerts related to abnormal process behavior, such as a MySQL process executing an unusual command or a web vulnerability exploit.

  • How it works

    Security Center attempts to terminate the process. If this fails, you can try to terminate the process manually by running the kill <process ID> command and then selecting the Manually Handled option.

    Note

    You can find the process ID in the More Information section on the alert details page.

Block

  • Use cases

    This method is often used for IP-based attack scenarios, such as unusual logons and brute-force attacks.

  • How it works

    • This action generates a security group defense rule to block access from the malicious IP address.

      • You can click Show Details to view the basic information about the generated defense rule, such as Assets, Rule Direction, Port Range, and Rule Direction.

      • Security Center automatically selects a blocking mechanism based on the agent's installation status. The supported mechanisms are:

        • Security Center: Prioritizes using the Security Center agent to block login attempts. This mechanism is automatically used if you have the Advanced, Enterprise, or Ultimate edition of Security Center and the Malicious Network Behavior Prevention switch is enabled. For information about how to enable the Malicious Network Behavior Prevention switch, see Proactive Defense.

        • ECS Security Group: When this blocking rule is enabled, a corresponding rule is automatically created in the security group. The rule is automatically deleted when it expires or is disabled.

    • The Rule Validity Period defaults to 6 hours. You can select from the following durations: 30 minutes, 1 hour, 2 hours, 6 hours, 12 hours, 1 day, 7 days, 14 days, or 30 days.

    • You can view the generated blocking rules by navigating to Protection Configuration > Host Protection > Host-specific Rule Management and clicking the Defense Against Brute-force Attacks tab. The rules are listed under System Rules.

      Note

      If you need to stop the blocking policy early, you can disable the rule on the System Rules page.

Alert suppression

Security Center primarily uses the Add to Whitelist and Ignore methods for alert suppression. For specific alerts, it also supports Do Not Intercept Rule, Protect Without Notification, and Manually Handled.

Add to Whitelist vs. Ignore

Difference

Add to Whitelist

Ignore

Use case

Permanent exceptions

Temporary or occasional false positives and known issues.

Scope of impact

When the same host asset has a file with the same MD5 hash at the same file path as this alert, and if you configure other whitelist rules, subsequent alerts matching those rules will also no longer trigger notifications.

Only affects the current alert. It has no impact on subsequent alerts.

Add to Whitelist

Warning

After you add an alert to the whitelist, you will no longer be notified of identical alerts or alerts that match the whitelist rules. Use this option with caution.

  • Use cases

    Use when the alert is a false positive or you need a permanent exception rule. For example, if a process making unusual outbound TCP connections is part of normal business, create a whitelist rule to suppress future alerts.

  • Result

    • For the current alert

      • The alert status changes to "Handled", and the specific status is Manually Allowlisted.

      • If an identical alert reoccurs, Security Center does not generate a new alert. Instead, it updates the last occurrence time of the existing one.

        What is an identical alert?

        An identical alert is a security threat with highly consistent characteristics. Examples:

        • For virus alerts: same asset + same virus file path + same virus file MD5.

        • For unusual logon alerts: same asset + same logon IP address.

    • For subsequent alerts

      If you set a specific whitelist rule, any future alert that matches the rule will automatically be moved to the handled list with the status Automatically Add to Whitelist. You will not receive a notification.

  • Set a specific whitelist rule (Optional)

    In the alert handling dialog box, click the Add to Whitelist tab. Click Create Rule to add a new rule. Click the image icon to delete a rule.

    Important
    • Multiple rules are combined with an OR operator, meaning an alert is whitelisted if it matches any single rule.

    • Ensure that your rules are precise to avoid an overly broad scope. For example, a rule like "Path contains: /data/" could unintentionally whitelist sensitive subdirectories, increasing security risks.

    Each rule has four configuration fields from left to right:

    1. Alert field: You can view the supported alert fields for the current alert in the More Information section on the details page.

    2. Condition type: Supported operators include Matches regex, Greater than, Equals, Less than, and Contains. Details for some rules:

      • Matches regex: Use a regular expression to precisely match specific patterns. For example, to whitelist all content in the "/data/app/logs/" folder, you can set the rule "Path matches regex: ^/data/app/logs/.*". This rule matches all files and processes in that folder and its subdirectories.

      • Contains: If you set a rule "Path contains: D:\programs\test\", all events with paths that include this folder will be whitelisted.

    3. Condition value: Supports constants and regular expressions.

    4. Applicable assets:

      • All assets: The rule applies to all existing and newly added assets.

      • Current Asset: The rule applies only to the asset involved in the current alert.

  • Remove from whitelist

    • Cancel an automatic whitelist rule

      Important
      • This action only affects future alerts. Alerts that match the rule will no longer be automatically whitelisted.

      • It does not affect alerts that have already been handled; their status remains unchanged.

      1. Log on to the . In the left-side navigation pane, choose Detection and Response > Alert.

        Note

        If you have subscribed to Agentic SOC, choose Agentic SOC (Legacy) > Alert.

      2. On the CWPP tab, click Cloud Workload Coverage Alert Management in the upper-right corner and select Alert Settings.

      3. On the Alert Settings page, in the Alert Handling Rule section, select Automatically Add to Whitelist as the handling method.

      4. Find the target rule and click Delete in the Actions column to cancel the automatic whitelist rule.

    • Remove an alert from the whitelist

      Important

      After you remove an alert from the whitelist, it reappears in the Unhandled alert list, requiring you to evaluate and handle it again.

      1. Log on to the . In the left-side navigation pane, choose Detection and Response > Alert.

        Note

        If you have subscribed to Agentic SOC, choose Agentic SOC (Legacy) > Alert.

      2. On the CWPP tab, set the Handled or Not filter to Handled.

      3. Find the alert you want to remove from the whitelist and click Remove from Whitelist in the Actions column.

        Note

        You can also select multiple alerts and click Remove from Whitelist at the bottom of the list to perform a bulk removal.

  • Cancel a precision defense whitelist rule

    Precision defense whitelist rules are managed through custom defense rules. To delete a rule, go to the malicious behavior defense page. Custom defense rules require the Advanced, Enterprise, or Ultimate edition of Security Center.

    1. Log on to the Security Center console. In the left-side navigation pane, choose Protection Configuration > Host Protection > Host-specific Rule Management.

    2. Click the Malicious Behavior Defense tab, and then click the Custom Defense Rule sub-tab.

    3. Find the whitelist rule that you want to cancel and click Delete in the Actions column.

Ignore

Important
  • Ignoring an alert is a status management action and does not resolve the underlying security issue.

  • Use this option only after you have confirmed that the alert is a false positive or a known, accepted risk. This helps avoid overlooking real attacks.

  • We recommend that you periodically review the list of ignored alerts, for example, weekly or monthly.

  • Use cases

    • Confirmed false positive or low priority.

    • Temporary or known issue: The issue exists but is a known, accepted risk or temporary non-malicious state (for example, authorized penetration testing or a maintenance window). Use when you cannot immediately fix the root cause but need to clear the alert list.

    • Test or development environment: In non-production environments, expected and non-critical alerts appear frequently, interfering with normal monitoring. You need to temporarily suppress them.

  • Result

    • For the current alert: The alert status changes to "Handled", and the specific status is Ignored.

    • For subsequent alerts: No impact. Security Center will generate a new alert if a similar incident occurs.

  • Stop ignoring an alert

    1. Log on to the . In the left-side navigation pane, choose Detection and Response > Alert.

      Note

      If you have subscribed to Agentic SOC, choose Agentic SOC (Legacy) > Alert.

    2. On the CWPP tab, set the Handled or Not filter to Handled.

    3. Find the alert you want to stop ignoring and click Cancel Ignore in the Actions column.

      Note

      You can also select multiple alerts and click Cancel Ignore at the bottom of the list to perform a bulk action.

Do Not Intercept Rule

  • Use cases

    This option is currently available only for alerts generated by the Adaptive WebShell Communication Interception rule, which is a System Defense Rule within the Malicious Behavior Defense feature. You can find this feature under Protection Configuration > Host Protection > Host-specific Rule Management.

  • How it works

    The system will stop blocking requests to the corresponding URI and will no longer generate alerts for it.

Protect Without Notification

Warning

You will no longer receive separate notifications for subsequent identical alerts. Use this option with caution.

  • Use cases

    This applies to alerts generated by the Malicious Behavior Defense rules (alert type: precision defense), which are found under Protection Configuration > Host Protection > Host-specific Rule Management.

  • How it works

    • For the current alert: The alert status changes to "Handled".

    • For subsequent alerts: When the same defense rule is triggered again, the generated alert event is automatically moved to the handled list, and no notification is sent.

  • Cancel a "Defend Without Notification" rule

    1. Log on to the . In the left-side navigation pane, choose Detection and Response > Alert.

      Note

      If you have subscribed to Agentic SOC, choose Agentic SOC (Legacy) > Alert.

    2. On the CWPP tab, click Cloud Workload Coverage Alert Management in the upper-right corner and select Alert Settings.

    3. On the Alert Settings page, in the Alert Handling Rule section, select Protect Without Notification as the handling method.

    4. Find the target rule and click Delete in the Actions column to cancel the rule.

Manually Handled

If you resolved the alert manually, select Manually Handled. The alert's status will change to Manually Handled.

Troubleshooting

Use cases

This is only available for handling Security Center Agent is Offline alerts.

How it works

The diagnostic tool collects agent-related data (network, process, and log information) from the machine and reports it to Security Center for analysis.

Important

This check consumes CPU and memory. Assess the potential impact before running it.

  • Select a problem mode:

    • Standard Mode: Collects and reports agent-related log data to Security Center for analysis.

    • Enhancement Mode: Collects and reports agent-related network, process, and log data to Security Center for analysis.

  • After you click Handle Now, a diagnostic task is generated. You can view the task progress and results by navigating to Asset Center > Host and clicking Agent Task Management in the upper-right corner. Agent troubleshooting.

    Note
    • If a solution is provided in the Result column, follow the recommended steps.

    • If no solution is provided in the Result column, click Download Diagnostic Logs in the Actions column. Provide the exported diagnostic log and your Alibaba Cloud account ID (AliUid) to the relevant personnel for further analysis.

Console handling

  1. Log on to the Security Center console.

  2. In the left-side navigation pane, choose Detection and Response > Alert. In the upper-left corner of the console, select the region of the asset: Chinese Mainland or Outside Chinese Mainland.

    Note

    If you have enabled Agentic SOC, the navigation path in the left-side navigation pane changes to Agentic SOC > Alert.

  3. On the Alert page, on the CWPP tab, locate the target alert. In the Actions column, click Handle. Select a handling method and click Handle Now.

    Note
    • Handling methods vary by alert type. The options available in the console are definitive.

    • Add remarks to specify the handling reason and the operator. This practice improves the traceability of handled alerts.

Post-handling verification

  • Perform a full scan: After handling an alert, perform a full scan on the server to confirm no new alerts. The full scan requires Agentless Detection (pay-as-you-go).

  • Confirm no new alerts: After handling, monitor the alert list to ensure alerts of the same type do not reappear. Recurring alerts may indicate an unremoved persistent backdoor. See the troubleshooting section below.

Common Virus Alert Handling Tutorials

Emergency response

ECS brute-force login success response

When you receive an "ECS Brute-Force Login Success" alert, Security Center has detected that an external IP address has successfully logged on to your server after multiple password attempts. Your server is at risk of intrusion. Take the following steps immediately:

What does this alert mean?

The "ECS Brute-Force Login Success" alert differs from a general brute-force attempt alert. This alert confirms that an attacker has successfully logged on to your server through repeated password attempts, posing an actual intrusion risk that requires immediate action.

Note

The logon location shown in the alert (such as "Shanghai") may be the location of a proxy IP address used by the attacker and does not necessarily represent the attacker's real location. Use the source IP address recorded in the Security Center alert details as the reference.

Emergency response steps

  1. Log on to the Security Center console. On the Detection and Response > Security Alerts page, view the alert details to confirm the attack source IP address, logon time, and logon account.

  2. Immediately change the server logon password. Set a complex password that contains uppercase and lowercase letters, digits, and special characters.

  3. Enable SSH key-based logon and disable password-based logon to prevent brute-force attacks from recurring.

  4. Check whether the server has abnormal processes, unknown user accounts, suspicious files, or outbound network traffic.

  5. If intrusion is confirmed, back up important data, and then reset the system or restore from a clean snapshot. For more information, see the Security hardening and attack prevention section in this topic.

After completing the above steps, follow the Security hardening and attack prevention section to harden the system, and continue to monitor the alert list to confirm that similar alerts do not reappear.

Emergency response actions

  • Change passwords: After receiving an unusual logon alert, immediately change the ECS instance password if the logon was not initiated by you. You can use the "Reset Instance Password Online" feature in the ECS console. For SSH weak password intrusion scenarios, immediately change the root password to a complex combination containing uppercase and lowercase letters, digits, and special characters, enable SSH key-based logon and disable password-based logon to prevent brute-force attacks from recurring.

  • Block the attack source IP address: After confirming that related malicious processes have been terminated, block the attacker's source IP address in the security group. Configure the Alibaba Cloud security group to deny all port access from the related IP address to immediately block the unusual logon.

  • Check for persistent backdoors: Inspect scheduled tasks (crontab), startup items, and SSH public keys (~/.ssh/authorized_keys) for suspicious entries. Ensure that the attacker has not left persistent backdoors.

Local log investigation

In addition to using the attack tracing feature in Security Center, you can manually check server system logs to investigate the intrusion path:

  • Linux servers: Check /var/log/secure or /var/log/auth.log files to confirm unusual logon records and attack sources.

  • Windows servers: Use Event Viewer to check security logs. Focus on logon success/failure events.

Security hardening and attack prevention

  • Upgrade Security Center Edition: The Enterprise and Ultimate editions support the virus automatic isolation (i.e., automatic virus detection and removal) feature, providing you with precise defense capabilities and supporting more security detection items.

  • Tighten Access Control: Open only necessary business ports (such as 80 and 443), and configure strict IP whitelist access policies for management ports (such as 22 and 3389) and database ports (such as 3306).

    Note

    For Alibaba Cloud ECS servers, see Manage security groups for operations.

  • Set Complex Server Passwords: Set complex passwords containing uppercase letters, lowercase letters, numbers, and special symbols for servers and applications.

  • Upgrade Software: Promptly update your application software to the latest official version to avoid using outdated versions that are no longer maintained or have known security vulnerabilities.

  • Regular Backups: Create a regular snapshot policy for important data and server system disks.

    Note

    For Alibaba Cloud ECS servers, see Create policy for operations.

  • Fix Vulnerabilities Promptly: Regularly use the Security Center Vulnerability Management feature to promptly patch system and application vulnerabilities.

  • Reset Server System (Use with Caution).

    If the virus intrusion is deep and involves underlying system components, it is strongly recommended that you reset the server system after backing up important data. Follow these steps:

    1. Create a snapshot to back up important data on the server. For more information, see Manually create a single snapshot.

    2. Initialize the server operating system. For more information, see Re-initialize system disk (reset OS).

    3. Create a cloud disk from the snapshot. For more information, see Create a data disk from a snapshot.

    4. Attach the cloud disk to the server after reinstalling the system. For more information, see Attach a data disk.

FAQ

Alert handling issues

  • What should I do if handling fails or a handled alert recurs?

    1. If you click Handle and receive an error, or if the same alert clears and then reappears, troubleshoot in the following order:

      Symptom

      Common cause

      Resolution

      Quarantine or process termination fails

      The Security Center agent is offline or running an outdated version, and the remediation command cannot be delivered.

      In Assets, verify that the agent is online. See Agent troubleshooting to bring the client back online, then retry.

      File quarantine fails

      The malicious process is still running and has the file locked, or the file has already been self-deleted.

      • Terminate the malicious process first (for example, use the kill command), then quarantine the file.

      • If the file no longer exists, mark the alert as handled.

      Alert recurs (common for worms and mining programs)

      Only the child process or virus file was removed; the parent process, scheduled tasks, startup items, or other persistence mechanisms are still active.

      Use the process tree in the alert details to locate the parent process. Remove crontab scheduled tasks, startup items, SSH public keys, and any suspicious accounts. See Best practices for handling mining programs.

      Alert recurs on a fixed schedule

      A remotely scheduled task periodically downloads and executes payloads, or other compromised hosts on the same network segment are spreading the infection.

      Audit scheduled tasks on all servers. Run a virus scan on other hosts in the same VPC.

      Handle button is grayed out or unavailable

      Free edition or expired authorization.

      Purchase Security Center at the Antivirus edition or above, and bind the authorization to the asset.

      Other

      • Weak password: SSH/RDP/database passwords are too simple.

      • Unpatched vulnerabilities: High-risk vulnerabilities exist in applications such as Redis, XXL-JOB, or WebLogic.

      • Latent backdoors: Incomplete initial cleanup left a hidden backdoor.

      • Data contamination: You restored a backup or snapshot that contained a virus.

    2. If alerts continue to recur after following these steps, your server may have an undetected persistent backdoor. We recommend that you back up your data and reset the server's operating system.

      How to Reset the Server System?

      1. Create a snapshot to back up important data on the server. For more information, see Manually create a single snapshot.

      2. Initialize the server operating system. For more information, see Re-initialize system disk (reset OS).

      3. Create a cloud disk from the snapshot. For more information, see Create a data disk from a snapshot.

      4. Attach the cloud disk to the server after reinstalling the system. For more information, see Attach a data disk.

  • Why can't I delete a virus file (such as a trojan or mining program)?

    The file and its parent directory have an immutable attribute. Use the chattr -i command to remove the immutable attribute from the file and its parent directory before deleting them.

  • I received a DDoS trojan alert. Why does the alert persist even after I manually deleted the file?

    The file was not completely removed. To resolve this issue, perform the following steps:

    1. If you are using the Free edition of Security Center, you can start a 7-day free trial of the Enterprise or Ultimate edition. Alternatively, see Upgrade Security Center to upgrade to the Antivirus or Enterprise edition.

    2. After the upgrade, go to the security alert handling page, find the DDoS trojan alert, click Handle, and select Antivirus. The system automatically terminates the trojan process and quarantines the file.

  • How do I whitelist precision defense alerts?

    Alerts generated by the precision defense feature rely on a defense plug-in and are automatically blocked. You must manually add these alerts to a whitelist in the Host Rule Management section.

    1. Go to the Security Center console > Protection Settings > Host Protection > Host Rule Management. In the upper-left corner of the page, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

    2. On the Malicious Behavior Defense tab, select the Custom Defense Rule sub-tab and click Create Rule. The following types are supported for whitelisting:

      • Process hash

      • Command line

      • Process Network

      • File Read/Write

      • Registry Operation

      • Load Dynamic-link Library

      • File Rename

  • I received a notification about suspicious server behavior, such as large-scale SSH port scanning or outbound attacks. What should I do?

    • Server is decommissioned: If the server is no longer in use, you can ignore the notification.

    • Server is still in use: Reinstall the operating system to thoroughly remove the virus. In the ECS console, find the instance, and choose All Operations > Reinitialize Disk in the upper-right corner (the instance must be stopped first). After reinstallation, harden the server: set strong passwords, restrict security group rules to allow remote logon only from specified IP addresses, and open only the required business ports.

    • About platform restrictions: After you reinstall the operating system, if no outbound attacks are detected, the platform typically does not impose restrictions. If you still experience access issues after virus removal, check other potential causes, such as security group configurations and server-side firewall rules.

  • Why do I still receive alert notifications after deleting a virus or malicious file?

    Security Center retains historical threat records for approximately one year. Even after you delete the virus file, the system continues to send notifications if you have not performed a handling action on the alert, such as ignoring or marking it as handled manually. Recommendations:

    • After you confirm that the threat is cleared, select Ignore or Handled Manually for the related alerts in the alert list.

    • If the alert timestamp is before your security remediation, you can safely ignore the alert after confirming that the threat no longer exists.

  • I changed my public IP address but still receive unusual logon alerts for the old IP address. What should I do?

    Alerts for the old IP address are typically triggered based on historical logon behavior recorded by Security Center. Recommendations:

    • If the alert timestamp is before the IP address change, you can ignore the alert.

    • Sync the latest asset information in the Asset Center to ensure that Security Center records your current IP address.

  • Why can't I find the specific weak-password user and credentials in the alert details?

    In the alert list, click Details in the Actions column to view the detected weak-password username and password. If the details page does not display this information, the alert may be a historical alert or the data may have expired. We recommend that you change the related account passwords to complex passwords that contain uppercase and lowercase letters, digits, and special characters.

  • How do I authorize Alibaba Cloud engineers to access my server to investigate and handle viruses?

    • Submit a ticket that includes your authorization information and server credentials to allow Alibaba Cloud engineers to remotely access your server.

    • Prerequisite: Create a snapshot backup before authorizing engineer access. Engineers cannot create snapshots on your behalf. Complete the snapshot backup yourself before submitting the ticket.

    • If you do not know the server password, reset the instance password in the ECS console.

Console feature issues

  • What should I do if an alert reports a nonexistent file?

    This can happen if the virus was removed by another method or if the virus cleaned up its own traces. To clear this alert, click "Ignore" or "Handled Manually" in the alert list.

  • I received a security alert, but I cannot find the related data in the console. What should I do?

    1. Security Center displays alert data by region. You can switch between Chinese Mainland and Outside Chinese Mainland in the upper-left corner of the Security Alerts page. If you receive an alert notification but cannot find the corresponding alert, switch to the other region.

    2. Check your current Security Center edition. The Free edition has limited functionality. We recommend that you see Upgrade Security Center to upgrade to the Antivirus or Enterprise edition.

    3. Use the Antivirus feature to scan for and handle threats.

  • How do I handle multiple alerts in bulk?

    Security Center currently supports bulk actions such as whitelisting, ignoring, removing from a whitelist, and undoing an ignore action.

    1. In the left-side navigation pane, choose Detection and Response > Alert. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland. In the security alert list, select the alerts you want to handle.

    2. In the lower-left corner, click Ignore This Time, Add to Whitelist, Remove from Whitelist, or Cancel Ignore.

  • Why is the Handle button for a security alert grayed out?

    Common causes are as follows:

    1. Free edition or no active protection authorization: The Free edition only supports viewing some alerts and does not support remediation actions (quarantine, block IP, whitelist, and so on). Purchase the Antivirus edition or above and ensure the affected server has an active authorization binding.

    2. Subscription instance has expired: After a subscription instance expires, the remediation capability becomes unavailable. Renew the instance and try again.

    3. Insufficient RAM user permissions: The operation requires the AliyunYundunSASFullAccess policy. Read-only permissions (ReadOnlyAccess) do not allow remediation actions.

    4. Security Center agent for the corresponding server is offline: The remediation command cannot be delivered to the server. Troubleshoot the agent to bring it back online, then retry.