Security Center generates alerts when it detects intrusions, malware, or abnormal behavior on your assets. Promptly and correctly handling alerts is key to ensuring business stability and data security. This topic describes how to follow emergency response procedures to quickly assess risks, eliminate threats, and harden your systems.
Assess security alerts
Before responding to an alert, assess its potential impact, analyze the attack, and identify false positives. The alert details page provides the information you need for this assessment.
View alert details
Log on to Security Center console.
In the left-side navigation pane, choose . In the upper-left corner of the console, select your asset's region: Chinese Mainland or Outside Chinese Mainland.
NoteIf you have enabled Agentic SOC, the navigation path in the left-side navigation pane changes to .
On the CWPP tab, find the alert and click Details in the Actions column.
ImportantYou can enable alert notifications on the page. You can then use information from the notifications, such as the alert name, to quickly locate the alert.
The Ultimate Edition lets you filter alerts by asset type. Above the alert list, click All, host, container, K8s, or cloud service to view alerts for the corresponding asset type.
Security Center uses a new large model detection engine to intelligently identify malicious files. To view alerts detected by AI, set the AI Detected filter to Yes. View alerts for AI-detected malicious files.
Analyze alert details
Use the attack tracing, and Description to understand the alert's basis, frequency, and potential causes. This helps you determine whether the alert is a false positive and plan your response.
The alert details page contains multiple time fields:
First detection time: The time when Security Center first detected this alert.
Last detection time: The most recent time this alert was detected. If the same process or file triggers the alert multiple times, this time is updated continuously.
Alert report time: The time when the agent reported the alert data to the cloud.
For suspicious processes that appear multiple times, click the process path to view detailed detection timestamps. This helps you determine when and how frequently the alert was triggered.
The security alert viewing and handling features are available only in the web console. The Alibaba Cloud mobile app does not support these features.
Alert description
The alert description summarizes the detected abnormal activity, its risks and characteristics, and recommended response actions.
Assessment example:

Potential risk: A relevant configuration file was modified to create a logon backdoor.
Recommended response: Confirm with the appropriate business team if this process is normal. If not, terminate the process immediately. Then, investigate the system for other potential threats.
Attack tracing
Security Center provides automated attack tracing that integrates logs from multiple cloud services. Through big data analysis, it generates visualized intrusion path diagrams with raw data previews. This feature helps you quickly identify the intrusion cause and develop emergency strategies. It is applicable to emergency response and tracing for web intrusions, worm events, ransomware, and malicious download connections in cloud environments.
This feature is available only on servers with the Enterprise, Ultimate authorization, or the Comprehensive Host Protection or Hosts and Container Protection feature enabled.
Security Center generates the automated attack tracing path within 10 minutes after detecting a threat. Wait at least 10 minutes after the alert before viewing attack tracing information.
Automated attack tracing information is automatically deleted 3 months after the alert is triggered. Review the attack tracing information promptly.
Capabilities:
Assessment example:
In the traceability section of the details page, check whether the attack chain is complete and valid. The more complete the attack chain, the more urgently you need to handle the alert.
Click a node in the graph and check the details on the left to determine if the attack objective was achieved. For example:
Check endpoint activity: The attacker executed commands on the server, such as
whoamiornet user.Check for data exfiltration: Look for abnormal outbound connections (to mining pools or C2 servers) or sensitive file read/upload activities.
Check for persistence artifacts: Look for newly created backdoor accounts, scheduled tasks, or malicious services.
Click a node in the tracing graph and, in the node details section on the left, see if the raw logs are verifiable (for example, WAF interception records, host process creation logs, or network connection logs).
Verifiable: There are supporting underlying logs, such as WAF interception records or host process logs for malicious command execution. This proves the attack occurred. If the attack was intercepted, you can mark the alert as "Processed" and no further action is required. If it was not intercepted, you must respond immediately.
Not verifiable: No supporting logs are available. This could be due to log deletion or detection evasion. In this scenario, you must be highly vigilant as it may indicate an advanced attack.
Sandbox detection
Sandbox detection runs suspicious files in a secure, isolated environment to analyze their static and dynamic behavior. Use the results to identify and remediate malicious programs.
The sandbox detection feature is available only for some malware alerts. Its availability is indicated on the alert details page.
In the security alert list, find the target security alert and click Details in the Actions column.
In the Sandbox section, view the sandbox detection results.
Assessment example:
The sandbox detection results page displays file information at the top (file name, threat tags, SHA1/MD5/SHA256 hashes). Below that are five tabs: Behavior Tags, Process Details, Network Behavior, File Behavior, and ATT&CK Matrix. The ATT&CK Matrix view is organized into 12 columns by attack stage (Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact). Each column displays corresponding attack technique cards with hit counts. Red numbers indicate high-risk stages.
Behavior Tag: These tags label the file's characteristics and highlight its high-risk operations. Red tags indicate the most critical intrusive behaviors.
ATT&CK Matrix: Displays the process flow during the sandbox detection run and highlights high-risk operations performed by the file. Red highlighting indicates the most critical intrusive behaviors.
Quick reference for alert handling
If you determine that an alert is for legitimate activity or requires no action, you can ignore the alert or add it to the whitelist.
Security Center alerts only indicate potential security risks. They do not block your domain names or services. You do not need to request an unblock after receiving an alert. Simply remove the non-compliant content, or handle the alert by ignoring it or adding it to the whitelist.
For persistent virus threats or recurring alerts, handle the alert in the console and then follow the Security Hardening and Attack Prevention guidelines.
Alert type | Alert name | Recommended action |
Malware | Mining program | Virus Detection and Removal |
DDoS trojan | ||
Trojan program | ||
Malicious program | ||
Exploit program | ||
Suspicious PowerShell command | ||
Backdoor program | ||
Reverse shell backdoor | ||
File-infecting virus | Deep Cleanup | |
Unusual logon | Logon from a malicious IP address | Block |
Successful brute-force attack on ECS | ||
Logon to ECS with an unusual account | ||
Logon to ECS from an unusual location | ||
Logon with a backdoor account | ||
Website backdoor | Backdoor (Webshell) file detected | Quarantine |
Log/image file containing Webshell code | ||
Backdoor file for web trojan or hotlinking detected | ||
Arbitrary file write backdoor detected | ||
Abnormal process behavior | Java application executes abnormal commands | Terminate Process |
Suspicious process path | ||
Network proxy forwarding behavior | ||
Suspicious PowerShell command | ||
Persistent backdoor creation behavior | ||
SSH backdoor | ||
Suspicious encoded command | ||
Suspicious command execution | ||
Malicious script | Malicious script execution | Terminate Process |
Precision defense | Evasion of security software | Deep Cleanup |
Cloud product threat detection | RAM sub-account logon from an unusual location | Modify the account password or restrict the allowed source IP addresses for the user in RAMDisable a RAM user's access key. Change the alert status to Manually Handled. |
Hacking tool exploits AccessKey | Delete the RAM user's AccessKey or disable it. Change the alert status to Manually Handled. | |
Abnormal role permission enumeration | Log on to the RAM console as a RAM administrator and modify the RAM user permissions. Change the alert status to Manually Handled. | |
RAM user performs sensitive operations after logging on to the console | Manually Handled | |
Other | Security Center agent unexpectedly goes offline | Troubleshooting |
Manually handle alerts
If you use the Security Event Response feature to handle an event aggregated from Security Center alerts, Security Center automatically updates the status of the related alerts on the CWPP tab. You do not need to manually update the alert status.
Before you begin
Verify your edition and authorization: Alert remediation actions (such as quarantining files, blocking IPs, and adding alerts to the whitelist) are available only in the Antivirus edition or above. If you are on the Free edition or your authorization has expired, the Handle button on the alert details page is grayed out and cannot be clicked, and you can only view alerts. Purchase the Antivirus edition or above and ensure the affected server has an active authorization binding before proceeding.
Create a snapshot backup: Before handling an alert, create a snapshot backup of the server in the ECS console to prevent data loss. Create a snapshot.
Server-side investigation: Log on to the server to investigate suspicious processes. Common commands:
Linux servers: Use
ps aux | grep <suspicious process name>to check whether a suspicious process is still running.Linux servers: Use
lsof -p <process PID>to view the files and network connections opened by the process.Windows servers: You can use Task Manager or log on to the server via VNC from the console to view process information. Suspicious processes are often located in directories such as
C:\Users\Administrator\AppData\Local. Confirm whether the process is required by your business before deleting it.
Choose a method
Handling methods are categorized as follows:
Threat Removal: Removes known threats, remediates infections, and blocks threat sources.
Alert Suppression: Handles false positives, known or acceptable risks by whitelisting or ignoring alerts, marking that "this alert is invalid or does not require handling", and controlling whether subsequent similar alerts continue to trigger notifications.
Troubleshooting: Troubleshoot and diagnose issues with the Security Center agent.
Threat removal
Virus Detection and Removal
Use cases
Confirmed malicious activity: Use when Security Center detects a running malicious process (virus, trojan, or ransomware) that must be stopped immediately.
Incident response: Use to contain an active virus or data leak before it spreads to other instances.
Before you begin
Virus Scan may cause service interruptions. Inspect the source file before proceeding:
Verify file properties: Confirm that the file is a virus by checking its path, signature, and hash value. This helps prevent the accidental deletion of system or business files.
Assess business dependencies: Check if the file is used by critical services, such as components related to
nginxormysql.
How it works
Immediately terminate the virus process and move the virus file to the quarantine area. Quarantined files cannot be executed, accessed, or spread.
WarningTerminating a process can disrupt dependent services, especially if the malicious process has replaced or infected a legitimate application.
If the quarantined file is a business file infected with malicious code, such as a core application component, quarantining it may lead to service interruptions.
Quarantined files can be restored within 30 days. After restoration, the file reappears in the alert list for continued monitoring. For more information, see View and restore quarantined files.
NoteFiles not restored within 30 days are permanently deleted.
Next steps
Review quarantined files within 30 days to prevent accidental permanent deletion. View and restore quarantined files.
Deep Cleanup
The Deep Cleanup feature is a specialized tool from Security Center experts designed to handle persistent and stubborn viruses.
Use cases
Deep Scan is a specialized solution for stubborn and file-infecting viruses. These viruses typically exhibit the following characteristics:
Infects host files: The virus injects itself into system files, application files, or your personal documents, making them part of the virus.
Difficult to eradicate: A standard virus scan may only remove the parent virus but cannot repair the infected files, causing the issue to recur.
NoteIf a virus does not fit this description, use the standard Virus Scan feature.
Before you begin
A Deep Cleanup carries risks of accidental file deletion, service interruption, and data integrity issues. Inspect the source file before proceeding:
Verify file properties: Confirm that the file is a virus by checking its path, signature, and hash value. This helps prevent the accidental deletion of system or business files.
Assess business dependencies: Check if the file is used by critical services, such as components related to
nginxormysql.
How it works
It cleans up persistent viruses by terminating malicious processes, quarantining malicious files, and removing persistence mechanisms used by viruses and trojans.
The feature can create a snapshot backup. If the deep scan accidentally removes useful data, restore it from the snapshot.
ImportantCreating and retaining snapshots incurs fees from the snapshot service. By default, the billing method is pay-as-you-go. You can consult pre-sales support for fee details.
Next steps
Review quarantined files within 30 days to prevent accidental permanent deletion. View and restore quarantined files.
Quarantine
Use cases
Use when you have confirmed that a file is malicious (backdoor or virus) and must stop it immediately.
How it works
The system moves the suspicious file to a quarantine area. Quarantined files cannot be executed, accessed, or spread.
WarningIf the quarantined file is a business file infected with malicious code, such as a core application component, quarantining it may lead to service interruptions.
Quarantined files can be restored within 30 days. After restoration, the file reappears in the alert list for continued monitoring. For more information, see View and restore quarantined files.
NoteFiles not restored within 30 days are permanently deleted.
Next steps
Review quarantined files within 30 days to prevent accidental permanent deletion. View and restore quarantined files.
Terminate Process
Use cases
Handles alerts related to abnormal process behavior, such as a MySQL process executing an unusual command or a web vulnerability exploit.
How it works
Security Center attempts to terminate the process. If this fails, you can try to terminate the process manually by running the
kill <process ID>command and then selecting the Manually Handled option.NoteYou can find the process ID in the More Information section on the alert details page.
Block
Use cases
This method is often used for IP-based attack scenarios, such as unusual logons and brute-force attacks.
How it works
This action generates a security group defense rule to block access from the malicious IP address.
You can click Show Details to view the basic information about the generated defense rule, such as Assets, Rule Direction, Port Range, and Rule Direction.
Security Center automatically selects a blocking mechanism based on the agent's installation status. The supported mechanisms are:
-
Security Center: Prioritizes using the Security Center agent to block login attempts. This mechanism is automatically used if you have the Advanced, Enterprise, or Ultimate edition of Security Center and the Malicious Network Behavior Prevention switch is enabled. For information about how to enable the Malicious Network Behavior Prevention switch, see Proactive Defense.
-
ECS Security Group: When this blocking rule is enabled, a corresponding rule is automatically created in the security group. The rule is automatically deleted when it expires or is disabled.
-
The Rule Validity Period defaults to 6 hours. You can select from the following durations: 30 minutes, 1 hour, 2 hours, 6 hours, 12 hours, 1 day, 7 days, 14 days, or 30 days.
You can view the generated blocking rules by navigating to and clicking the Defense Against Brute-force Attacks tab. The rules are listed under System Rules.
NoteIf you need to stop the blocking policy early, you can disable the rule on the System Rules page.
Alert suppression
Security Center primarily uses the Add to Whitelist and Ignore methods for alert suppression. For specific alerts, it also supports Do Not Intercept Rule, Protect Without Notification, and Manually Handled.
Add to Whitelist vs. Ignore
Difference | Add to Whitelist | Ignore |
Use case | Permanent exceptions | Temporary or occasional false positives and known issues. |
Scope of impact | When the same host asset has a file with the same MD5 hash at the same file path as this alert, and if you configure other whitelist rules, subsequent alerts matching those rules will also no longer trigger notifications. | Only affects the current alert. It has no impact on subsequent alerts. |
Add to Whitelist
After you add an alert to the whitelist, you will no longer be notified of identical alerts or alerts that match the whitelist rules. Use this option with caution.
Use cases
Use when the alert is a false positive or you need a permanent exception rule. For example, if a process making unusual outbound TCP connections is part of normal business, create a whitelist rule to suppress future alerts.
Result
For the current alert
The alert status changes to "Handled", and the specific status is Manually Allowlisted.
If an identical alert reoccurs, Security Center does not generate a new alert. Instead, it updates the last occurrence time of the existing one.
For subsequent alerts
If you set a specific whitelist rule, any future alert that matches the rule will automatically be moved to the handled list with the status Automatically Add to Whitelist. You will not receive a notification.
Set a specific whitelist rule (Optional)
In the alert handling dialog box, click the Add to Whitelist tab. Click Create Rule to add a new rule. Click the
icon to delete a rule.ImportantMultiple rules are combined with an OR operator, meaning an alert is whitelisted if it matches any single rule.
Ensure that your rules are precise to avoid an overly broad scope. For example, a rule like "Path contains: /data/" could unintentionally whitelist sensitive subdirectories, increasing security risks.
Each rule has four configuration fields from left to right:
Alert field: You can view the supported alert fields for the current alert in the More Information section on the details page.
Condition type: Supported operators include Matches regex, Greater than, Equals, Less than, and Contains. Details for some rules:
Matches regex: Use a regular expression to precisely match specific patterns. For example, to whitelist all content in the "/data/app/logs/" folder, you can set the rule "Path matches regex: ^/data/app/logs/.*". This rule matches all files and processes in that folder and its subdirectories.
Contains: If you set a rule "Path contains: D:\programs\test\", all events with paths that include this folder will be whitelisted.
Condition value: Supports constants and regular expressions.
Applicable assets:
All assets: The rule applies to all existing and newly added assets.
Current Asset: The rule applies only to the asset involved in the current alert.
Remove from whitelist
Cancel an automatic whitelist rule
ImportantThis action only affects future alerts. Alerts that match the rule will no longer be automatically whitelisted.
It does not affect alerts that have already been handled; their status remains unchanged.
Log on to the . In the left-side navigation pane, choose .
NoteIf you have subscribed to Agentic SOC, choose .
On the CWPP tab, click Cloud Workload Coverage Alert Management in the upper-right corner and select Alert Settings.
On the Alert Settings page, in the Alert Handling Rule section, select Automatically Add to Whitelist as the handling method.
Find the target rule and click Delete in the Actions column to cancel the automatic whitelist rule.
Remove an alert from the whitelist
ImportantAfter you remove an alert from the whitelist, it reappears in the Unhandled alert list, requiring you to evaluate and handle it again.
Log on to the . In the left-side navigation pane, choose .
NoteIf you have subscribed to Agentic SOC, choose .
On the CWPP tab, set the Handled or Not filter to Handled.
Find the alert you want to remove from the whitelist and click Remove from Whitelist in the Actions column.
NoteYou can also select multiple alerts and click Remove from Whitelist at the bottom of the list to perform a bulk removal.
Cancel a precision defense whitelist rule
Precision defense whitelist rules are managed through custom defense rules. To delete a rule, go to the malicious behavior defense page. Custom defense rules require the Advanced, Enterprise, or Ultimate edition of Security Center.
Log on to the Security Center console. In the left-side navigation pane, choose .
Click the Malicious Behavior Defense tab, and then click the Custom Defense Rule sub-tab.
Find the whitelist rule that you want to cancel and click Delete in the Actions column.
Ignore
Ignoring an alert is a status management action and does not resolve the underlying security issue.
Use this option only after you have confirmed that the alert is a false positive or a known, accepted risk. This helps avoid overlooking real attacks.
We recommend that you periodically review the list of ignored alerts, for example, weekly or monthly.
Use cases
Confirmed false positive or low priority.
Temporary or known issue: The issue exists but is a known, accepted risk or temporary non-malicious state (for example, authorized penetration testing or a maintenance window). Use when you cannot immediately fix the root cause but need to clear the alert list.
Test or development environment: In non-production environments, expected and non-critical alerts appear frequently, interfering with normal monitoring. You need to temporarily suppress them.
Result
For the current alert: The alert status changes to "Handled", and the specific status is Ignored.
For subsequent alerts: No impact. Security Center will generate a new alert if a similar incident occurs.
Stop ignoring an alert
Log on to the . In the left-side navigation pane, choose .
NoteIf you have subscribed to Agentic SOC, choose .
On the CWPP tab, set the Handled or Not filter to Handled.
Find the alert you want to stop ignoring and click Cancel Ignore in the Actions column.
NoteYou can also select multiple alerts and click Cancel Ignore at the bottom of the list to perform a bulk action.
Do Not Intercept Rule
Use cases
This option is currently available only for alerts generated by the Adaptive WebShell Communication Interception rule, which is a System Defense Rule within the Malicious Behavior Defense feature. You can find this feature under .
How it works
The system will stop blocking requests to the corresponding URI and will no longer generate alerts for it.
Protect Without Notification
You will no longer receive separate notifications for subsequent identical alerts. Use this option with caution.
Use cases
This applies to alerts generated by the Malicious Behavior Defense rules (alert type: precision defense), which are found under .
How it works
For the current alert: The alert status changes to "Handled".
For subsequent alerts: When the same defense rule is triggered again, the generated alert event is automatically moved to the handled list, and no notification is sent.
Cancel a "Defend Without Notification" rule
Log on to the . In the left-side navigation pane, choose .
NoteIf you have subscribed to Agentic SOC, choose .
On the CWPP tab, click Cloud Workload Coverage Alert Management in the upper-right corner and select Alert Settings.
On the Alert Settings page, in the Alert Handling Rule section, select Protect Without Notification as the handling method.
Find the target rule and click Delete in the Actions column to cancel the rule.
Manually Handled
If you resolved the alert manually, select Manually Handled. The alert's status will change to Manually Handled.
Troubleshooting
Use cases
This is only available for handling Security Center Agent is Offline alerts.
How it works
The diagnostic tool collects agent-related data (network, process, and log information) from the machine and reports it to Security Center for analysis.
This check consumes CPU and memory. Assess the potential impact before running it.
Select a problem mode:
Standard Mode: Collects and reports agent-related log data to Security Center for analysis.
Enhancement Mode: Collects and reports agent-related network, process, and log data to Security Center for analysis.
After you click Handle Now, a diagnostic task is generated. You can view the task progress and results by navigating to and clicking Agent Task Management in the upper-right corner. Agent troubleshooting.
NoteIf a solution is provided in the Result column, follow the recommended steps.
If no solution is provided in the Result column, click Download Diagnostic Logs in the Actions column. Provide the exported diagnostic log and your Alibaba Cloud account ID (AliUid) to the relevant personnel for further analysis.
Console handling
Log on to the Security Center console.
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region of the asset: Chinese Mainland or Outside Chinese Mainland.
NoteIf you have enabled Agentic SOC, the navigation path in the left-side navigation pane changes to .
On the Alert page, on the CWPP tab, locate the target alert. In the Actions column, click Handle. Select a handling method and click Handle Now.
NoteHandling methods vary by alert type. The options available in the console are definitive.
Add remarks to specify the handling reason and the operator. This practice improves the traceability of handled alerts.
Post-handling verification
Perform a full scan: After handling an alert, perform a full scan on the server to confirm no new alerts. The full scan requires Agentless Detection (pay-as-you-go).
Confirm no new alerts: After handling, monitor the alert list to ensure alerts of the same type do not reappear. Recurring alerts may indicate an unremoved persistent backdoor. See the troubleshooting section below.
Common Virus Alert Handling Tutorials
Emergency response
ECS brute-force login success response
When you receive an "ECS Brute-Force Login Success" alert, Security Center has detected that an external IP address has successfully logged on to your server after multiple password attempts. Your server is at risk of intrusion. Take the following steps immediately:
What does this alert mean?
The "ECS Brute-Force Login Success" alert differs from a general brute-force attempt alert. This alert confirms that an attacker has successfully logged on to your server through repeated password attempts, posing an actual intrusion risk that requires immediate action.
The logon location shown in the alert (such as "Shanghai") may be the location of a proxy IP address used by the attacker and does not necessarily represent the attacker's real location. Use the source IP address recorded in the Security Center alert details as the reference.
Emergency response steps
Log on to the Security Center console. On the Detection and Response > Security Alerts page, view the alert details to confirm the attack source IP address, logon time, and logon account.
Immediately change the server logon password. Set a complex password that contains uppercase and lowercase letters, digits, and special characters.
Enable SSH key-based logon and disable password-based logon to prevent brute-force attacks from recurring.
Check whether the server has abnormal processes, unknown user accounts, suspicious files, or outbound network traffic.
If intrusion is confirmed, back up important data, and then reset the system or restore from a clean snapshot. For more information, see the Security hardening and attack prevention section in this topic.
After completing the above steps, follow the Security hardening and attack prevention section to harden the system, and continue to monitor the alert list to confirm that similar alerts do not reappear.
Emergency response actions
Change passwords: After receiving an unusual logon alert, immediately change the ECS instance password if the logon was not initiated by you. You can use the "Reset Instance Password Online" feature in the ECS console. For SSH weak password intrusion scenarios, immediately change the root password to a complex combination containing uppercase and lowercase letters, digits, and special characters, enable SSH key-based logon and disable password-based logon to prevent brute-force attacks from recurring.
Block the attack source IP address: After confirming that related malicious processes have been terminated, block the attacker's source IP address in the security group. Configure the Alibaba Cloud security group to deny all port access from the related IP address to immediately block the unusual logon.
Check for persistent backdoors: Inspect scheduled tasks (crontab), startup items, and SSH public keys (~/.ssh/authorized_keys) for suspicious entries. Ensure that the attacker has not left persistent backdoors.
Local log investigation
In addition to using the attack tracing feature in Security Center, you can manually check server system logs to investigate the intrusion path:
Linux servers: Check
/var/log/secureor/var/log/auth.logfiles to confirm unusual logon records and attack sources.Windows servers: Use Event Viewer to check security logs. Focus on logon success/failure events.
Security hardening and attack prevention
Upgrade Security Center Edition: The Enterprise and Ultimate editions support the virus automatic isolation (i.e., automatic virus detection and removal) feature, providing you with precise defense capabilities and supporting more security detection items.
Tighten Access Control: Open only necessary business ports (such as 80 and 443), and configure strict IP whitelist access policies for management ports (such as 22 and 3389) and database ports (such as 3306).
NoteFor Alibaba Cloud ECS servers, see Manage security groups for operations.
Set Complex Server Passwords: Set complex passwords containing uppercase letters, lowercase letters, numbers, and special symbols for servers and applications.
Upgrade Software: Promptly update your application software to the latest official version to avoid using outdated versions that are no longer maintained or have known security vulnerabilities.
Regular Backups: Create a regular snapshot policy for important data and server system disks.
NoteFor Alibaba Cloud ECS servers, see Create policy for operations.
Fix Vulnerabilities Promptly: Regularly use the Security Center Vulnerability Management feature to promptly patch system and application vulnerabilities.
Reset Server System (Use with Caution).
If the virus intrusion is deep and involves underlying system components, it is strongly recommended that you reset the server system after backing up important data. Follow these steps:
Create a snapshot to back up important data on the server. For more information, see Manually create a single snapshot.
Initialize the server operating system. For more information, see Re-initialize system disk (reset OS).
Create a cloud disk from the snapshot. For more information, see Create a data disk from a snapshot.
Attach the cloud disk to the server after reinstalling the system. For more information, see Attach a data disk.
FAQ
Alert handling issues
What should I do if handling fails or a handled alert recurs?
If you click Handle and receive an error, or if the same alert clears and then reappears, troubleshoot in the following order:
Symptom
Common cause
Resolution
Quarantine or process termination fails
The Security Center agent is offline or running an outdated version, and the remediation command cannot be delivered.
In Assets, verify that the agent is online. See Agent troubleshooting to bring the client back online, then retry.
File quarantine fails
The malicious process is still running and has the file locked, or the file has already been self-deleted.
Terminate the malicious process first (for example, use the
killcommand), then quarantine the file.If the file no longer exists, mark the alert as handled.
Alert recurs (common for worms and mining programs)
Only the child process or virus file was removed; the parent process, scheduled tasks, startup items, or other persistence mechanisms are still active.
Use the process tree in the alert details to locate the parent process. Remove crontab scheduled tasks, startup items, SSH public keys, and any suspicious accounts. See Best practices for handling mining programs.
Alert recurs on a fixed schedule
A remotely scheduled task periodically downloads and executes payloads, or other compromised hosts on the same network segment are spreading the infection.
Audit scheduled tasks on all servers. Run a virus scan on other hosts in the same VPC.
Handle button is grayed out or unavailable
Free edition or expired authorization.
Purchase Security Center at the Antivirus edition or above, and bind the authorization to the asset.
Other
Weak password: SSH/RDP/database passwords are too simple.
Unpatched vulnerabilities: High-risk vulnerabilities exist in applications such as Redis, XXL-JOB, or WebLogic.
Latent backdoors: Incomplete initial cleanup left a hidden backdoor.
Data contamination: You restored a backup or snapshot that contained a virus.
Change your passwords and patch vulnerabilities promptly.
Perform a comprehensive virus scan on the server.
If alerts continue to recur after following these steps, your server may have an undetected persistent backdoor. We recommend that you back up your data and reset the server's operating system.
Why can't I delete a virus file (such as a trojan or mining program)?
The file and its parent directory have an immutable attribute. Use the
chattr -icommand to remove the immutable attribute from the file and its parent directory before deleting them.I received a DDoS trojan alert. Why does the alert persist even after I manually deleted the file?
The file was not completely removed. To resolve this issue, perform the following steps:
If you are using the Free edition of Security Center, you can start a 7-day free trial of the Enterprise or Ultimate edition. Alternatively, see Upgrade Security Center to upgrade to the Antivirus or Enterprise edition.
After the upgrade, go to the security alert handling page, find the DDoS trojan alert, click Handle, and select Antivirus. The system automatically terminates the trojan process and quarantines the file.
How do I whitelist precision defense alerts?
Alerts generated by the precision defense feature rely on a defense plug-in and are automatically blocked. You must manually add these alerts to a whitelist in the Host Rule Management section.
Go to the Security Center console > Protection Settings > Host Protection > Host Rule Management. In the upper-left corner of the page, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.
On the Malicious Behavior Defense tab, select the Custom Defense Rule sub-tab and click Create Rule. The following types are supported for whitelisting:
-
Process hash
-
Command line
-
Process Network
-
File Read/Write
-
Registry Operation
-
Load Dynamic-link Library
-
File Rename
-
I received a notification about suspicious server behavior, such as large-scale SSH port scanning or outbound attacks. What should I do?
Server is decommissioned: If the server is no longer in use, you can ignore the notification.
Server is still in use: Reinstall the operating system to thoroughly remove the virus. In the ECS console, find the instance, and choose All Operations > Reinitialize Disk in the upper-right corner (the instance must be stopped first). After reinstallation, harden the server: set strong passwords, restrict security group rules to allow remote logon only from specified IP addresses, and open only the required business ports.
About platform restrictions: After you reinstall the operating system, if no outbound attacks are detected, the platform typically does not impose restrictions. If you still experience access issues after virus removal, check other potential causes, such as security group configurations and server-side firewall rules.
Why do I still receive alert notifications after deleting a virus or malicious file?
Security Center retains historical threat records for approximately one year. Even after you delete the virus file, the system continues to send notifications if you have not performed a handling action on the alert, such as ignoring or marking it as handled manually. Recommendations:
After you confirm that the threat is cleared, select Ignore or Handled Manually for the related alerts in the alert list.
If the alert timestamp is before your security remediation, you can safely ignore the alert after confirming that the threat no longer exists.
I changed my public IP address but still receive unusual logon alerts for the old IP address. What should I do?
Alerts for the old IP address are typically triggered based on historical logon behavior recorded by Security Center. Recommendations:
If the alert timestamp is before the IP address change, you can ignore the alert.
Sync the latest asset information in the Asset Center to ensure that Security Center records your current IP address.
Why can't I find the specific weak-password user and credentials in the alert details?
In the alert list, click Details in the Actions column to view the detected weak-password username and password. If the details page does not display this information, the alert may be a historical alert or the data may have expired. We recommend that you change the related account passwords to complex passwords that contain uppercase and lowercase letters, digits, and special characters.
Console feature issues
What should I do if an alert reports a nonexistent file?
This can happen if the virus was removed by another method or if the virus cleaned up its own traces. To clear this alert, click "Ignore" or "Handled Manually" in the alert list.
I received a security alert, but I cannot find the related data in the console. What should I do?
Security Center displays alert data by region. You can switch between Chinese Mainland and Outside Chinese Mainland in the upper-left corner of the Security Alerts page. If you receive an alert notification but cannot find the corresponding alert, switch to the other region.
Check your current Security Center edition. The Free edition has limited functionality. We recommend that you see Upgrade Security Center to upgrade to the Antivirus or Enterprise edition.
Use the Antivirus feature to scan for and handle threats.
How do I handle multiple alerts in bulk?
Security Center currently supports bulk actions such as whitelisting, ignoring, removing from a whitelist, and undoing an ignore action.
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland. In the security alert list, select the alerts you want to handle.
In the lower-left corner, click Ignore This Time, Add to Whitelist, Remove from Whitelist, or Cancel Ignore.
Why is the Handle button for a security alert grayed out?
Common causes are as follows:
Free edition or no active protection authorization: The Free edition only supports viewing some alerts and does not support remediation actions (quarantine, block IP, whitelist, and so on). Purchase the Antivirus edition or above and ensure the affected server has an active authorization binding.
Subscription instance has expired: After a subscription instance expires, the remediation capability becomes unavailable. Renew the instance and try again.
Insufficient RAM user permissions: The operation requires the
AliyunYundunSASFullAccesspolicy. Read-only permissions (ReadOnlyAccess) do not allow remediation actions.Security Center agent for the corresponding server is offline: The remediation command cannot be delivered to the server. Troubleshoot the agent to bring it back online, then retry.