Create an AWS supported case - AWS Security Incident Response User Guide

Create an AWS supported case

You can create an AWS supported case for AWS Security Incident Response through the Console, the API, or the AWS Command Line Interface. AWS supported cases allow you to receive support from the AWS Customer Incident Response Team (CIRT).

Note

AWS CIRT will respond to your case within 15 minutes. Response time is for a first response from AWS CIRT. We will make every reasonable effort to respond to your initial request within this time frame. This response time does not apply to subsequent responses.

The following example covers use of the console.

  1. Sign into AWS Security Incident Response via the AWS Management Console at https://console.aws.amazon.com/security-ir/.

  2. Choose Create Case

  3. Choose Resolve case with AWS

  4. Select the type of request

    1. Active Security Incident: This type is for urgent incident response support and services.

    2. Investigations: Investigations allow you to get support for perceived security incidents where the AWS CIRT can support in log dive and secondary confirmation of incident response investigation.

  5. Set the start date estimate to the date of your earliest indicator of the incident. For example, when you experienced abnormal behavior for the first time or when you received the first related security alert.

  6. Define a title for the case

  7. Provide a detailed description of the case.  Consider the following aspects which can help incident responders with the case resolution:

    1. What happened?

    2. Who discovered and reported the incident?

    3. Who is affected by the case?

    4. What is the known impact?

    5. What is the urgency for this case?

    6. Add one or multiple AWS account IDs that are in scope of the case.

  8. Add optional case details:

    1. Select the main services that are impacted from the drop-down list.

    2. Select the main regions that are impacted from the drop-down list.

    3. Add one or many threat actor IP addresses that you identified as part of this case. 

  9. Add optional additional incident responders to the case that will receive notifications. To add an individual, do the following:

    1. Add an email address.

    2. Add an optional first and last name.

    3. Choose Add new to add another individual.

    4. To remove an individual, choose the Remove option for an individual.

    5. Choose Add to add all listed individuals to the case.

      1. You can select multiple individuals and choose Remove to delete them from the list.

  10. Add optional tags to the case.

    1. To add a tag, do the following:

    2. Choose Add new tag.

    3. For Key, enter the name of the tag.

    4. For Value, enter the value of the tag.

    5. To remove a tag, choose the Remove option for that tag.

After a AWS supported case has been created, the AWS CIRT and your incident response team are immediately notified.