AWS Security Incident Response now provides agentic AI-powered investigation capabilities to help you prepare for, respond to, and recover from security events faster and more effectively. The new investigative agent automatically gathers evidence across multiple AWS data sources, correlates the data, then presents findings for you in clear, actionable summaries. This helps you reduce the time required to investigate and respond to potential security events, thereby minimizing business disruption.
When a security event case is created in the Security Incident Response console, the investigative agent immediately assesses the case details to identify missing information, such as potential indicators, resource names, and timeframes. It asks the case submitter clarifying questions to gather these details. This proactive approach helps minimize delays from back-and-forth communications that traditionally extend case resolution times. The investigative agent then collects relevant information from various data sources, such as AWS CloudTrail, AWS Identity and Access Management (IAM), Amazon EC2, and AWS Cost Explorer. It automatically correlates this data to provide you with a comprehensive analysis, reducing the need for manual evidence gathering and enabling faster investigation. Security teams can track all investigation activities directly through the AWS console and view summaries in their preferred integration tools.
This feature is automatically enabled for all Security Incident Response customers at no additional cost in all AWS Regions where the service is available.
To learn more and get started, visit the Security Incident Response overview page and console.
Categories: marketing:marchitecture/security-identity-and-compliance
Source: Amazon Web Services
Latest Posts
- (Updated) Microsoft Teams: Enhanced cross-platform join via Session Initiation Protocol (SIP) for Teams Rooms on Android [MC1294522]
![(Updated) Microsoft Teams: Enhanced cross-platform join via Session Initiation Protocol (SIP) for Teams Rooms on Android [MC1294522] 2 pexels jonathan einwechter 1312107 32482485](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Entra: App Instance Lock enabled by default for new applications [MC1300584]
![Microsoft Entra: App Instance Lock enabled by default for new applications [MC1300584] 3 pexels cottonbro 8721343](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Pipelines – Pipelines and R2 Data Catalog now supported in Terraform

- Power Pages – Use Dynamics 365 websites with Bootstrap 5 and enhanced data model [MC1300450]
![Power Pages - Use Dynamics 365 websites with Bootstrap 5 and enhanced data model [MC1300450] 5 pexels googledeepmind 25626442](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![(Updated) Microsoft Teams: Enhanced cross-platform join via Session Initiation Protocol (SIP) for Teams Rooms on Android [MC1294522] 2 pexels jonathan einwechter 1312107 32482485](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-jonathan-einwechter-1312107-32482485-150x150.webp)
![Microsoft Entra: App Instance Lock enabled by default for new applications [MC1300584] 3 pexels cottonbro 8721343](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-cottonbro-8721343-150x150.webp)

![Power Pages - Use Dynamics 365 websites with Bootstrap 5 and enhanced data model [MC1300450] 5 pexels googledeepmind 25626442](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-googledeepmind-25626442-150x150.webp)
