AWSHow-To & HardeningRetrospectives

Cloud Incident Investigation Runbook for AWS

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.

A short, consistent runbook helps small teams respond to AWS incidents calmly. Use this as a starting template.

1. Triage (first 30 minutes)

  • Confirm the finding source (GuardDuty, Security Hub, alert, external report).
  • Identify affected account, region, identity and resources.
  • Assign an incident lead and open a ticket or channel.

2. Scope

  • Review the identity's CloudTrail activity in all regions for the past 7 days (Detective or CloudTrail Lake).
  • Identify new IAM users, roles, keys, policies or trust relationships created.
  • Identify data accessed (S3 data events, database logs).
  • Check for resources launched (EC2, Lambda, containers) in any region.

3. Contain

  • Deactivate compromised access keys.
  • Revoke active role sessions.
  • Isolate compromised instances with a quarantine security group; snapshot volumes first.
  • Restrict access to affected buckets.

4. Eradicate

  • Remove attacker-created identities, resources and persistence (Lambda functions, EventBridge rules, new trust policies).
  • Rotate secrets the identity could access.

5. Recover

  • Restore affected resources from known-good backups or infrastructure as code.
  • Monitor closely for 14 days.

6. Communicate

  • Inform leadership, legal and, if required, customers and regulators.
  • Open a case with AWS Support if needed.

7. Learn

  • Root cause, timeline and preventive controls added.
  • Update this runbook.
aws incident investigation runbook checklistAmazon Detective GA2020

More on this story