Response & Remediation¶
Enterprise tier. Map any threat type to an AWS Systems Manager Automation runbook — the AWS-managed prebuilts (disable a key, isolate an instance, block public access), the samples AI SIEM ships, or your own — and AI SIEM runs it under a role you own. Your permissions, your runbooks, with cross-account support.
AI SIEM itself only calls StartAutomationExecution and reads status; it holds no standing IAM or EC2 write power, so a runbook can never do more than the role you granted. Mapping a threat type to a runbook and its parameters is entirely a config change — adding a remediation is never a code or template change. A one-command add-on (deploy-remediation) creates the AutomationAssumeRole and publishes its ARN to SSM, so the editor auto-fills it in the mapping picker. Cross-account is native via SSM multi-account targets.
Built for how SOC teams actually work¶
- Approve before it runs — every action can be staged for one-click admin approval, or auto-approved per runbook when you trust it.
- Schedule it — run now, or defer to a named window you create (off-peak, weekends, a maintenance window) so disruptive fixes land when they should.
- Auto-resolve on success — a threat whose remediation succeeds can close itself, or prompt you to — your choice per runbook.
- See it live — nothing gets silently stuck — a remediation badge (pending, scheduled, remediating, remediated, failed, stalled) tracks every action independently of triage status, and you can filter the queue by state. A watchdog flags any remediation that runs too long or was never picked up in its window, so a stalled or missed fix surfaces instead of disappearing.
- Fully accountable — the request, approval, start, and outcome (with the runbook's own output) all land in the tamper-evident WORM audit trail.
SLA-breach tracking¶
When a remediation runs past its stall limit or a scheduled one is never picked up in time, that breach is recorded as a durable flag on the threat — and it persists after the run finishes, so a remediation that eventually succeeded (or later failed) but took too long stays findable instead of disappearing behind its final badge. A SLA breached filter in the Threats toolbar lists every one (each labelled ran long or never started), the dashboard Remediations panel shows a running SLA-breached count, and the threat report's Remediation Summary flags, per outcome, how many breached.
Safer remediation with multiple admins¶
Remediation guards against acting on stale configuration. If you have unsaved edits, Remediate reminds you it runs against the last-saved config. If another admin changed the remediation configuration since you loaded the page, the request is safely rejected with a prompt to reload and review. A lightweight, non-blocking presence indicator shows when other administrators are in the editor — advisory only; nobody is ever locked out.