Responding to an AWS generated case - AWS Security Incident Response User Guide

Responding to an AWS generated case

AWS Security Incident Response may create an outbound notification or case when you need to act on or be aware of something that might impact your account or resources. This will only occur if you have enabled the proactive response and alert triaging workflows as part of your subscription.

These notifications will appear as Security Incident Response cases with the prefix "[Proactive case]" in the AWS Security Incident Response console. To view and manage these cases:

  • Open the Security Incident Response console at https://console.aws.amazon.com/security-ir/

  • Click "Cases" in the menu.

  • You should be able to see all the cases, including those with the "[Proactive case]" prefix.

These cases allow you to update, resolve, and reopen them as needed. You can communicate directly with the AWS Security Incident Response team through these cases, ensuring efficient handling of potential security issues.