Cloud Incident Investigation Runbook for AWS
Retrospective: this article looks back at events from March 2020, written in 2026 with the benefit of hindsight.
A short, consistent runbook helps small teams respond to AWS incidents calmly. Use this as a starting template.
1. Triage (first 30 minutes)
- Confirm the finding source (GuardDuty, Security Hub, alert, external report).
- Identify affected account, region, identity and resources.
- Assign an incident lead and open a ticket or channel.
2. Scope
- Review the identity's CloudTrail activity in all regions for the past 7 days (Detective or CloudTrail Lake).
- Identify new IAM users, roles, keys, policies or trust relationships created.
- Identify data accessed (S3 data events, database logs).
- Check for resources launched (EC2, Lambda, containers) in any region.
3. Contain
- Deactivate compromised access keys.
- Revoke active role sessions.
- Isolate compromised instances with a quarantine security group; snapshot volumes first.
- Restrict access to affected buckets.
4. Eradicate
- Remove attacker-created identities, resources and persistence (Lambda functions, EventBridge rules, new trust policies).
- Rotate secrets the identity could access.
5. Recover
- Restore affected resources from known-good backups or infrastructure as code.
- Monitor closely for 14 days.
6. Communicate
- Inform leadership, legal and, if required, customers and regulators.
- Open a case with AWS Support if needed.
7. Learn
- Root cause, timeline and preventive controls added.
- Update this runbook.
- Amazon Detective Goes GA (Mar 2020): Investigation Graphs for AWS Security Findings Platform Changes
- How to Investigate a GuardDuty Finding With Amazon Detective How-To & Hardening
- CIO Brief: Faster Investigations Mean Smaller Breaches CIO Briefings