Tag: Incident response
All the articles with the tag "Incident response".

Wazuh Active Response: automatically banning, isolating, and responding to incidents (part 4/6)
Part 4 of the Wazuh series: turning a fired detection into an automatic reaction — the anatomy of Active Response, the built-in firewall-drop, a custom nftables blocking script with a timeout and an admin-subnet safety exception, and how not to ban yourself.

Guardrails for AI SRE agents: automating remediation without losing control
AWS DevOps Agent and Azure SRE Agent have been GA since March 2026, and neither pushes production changes without human confirmation. Here's how to design an approval gate on top of your own incident pipeline: three levels of autonomy, a narrow executor instead of direct cluster access for the agent, and what to log for audit.

AI SRE agents in 2026: what they actually do and where they break
AWS DevOps Agent and Azure SRE Agent both hit GA in March 2026. We break down the working model of AI SRE agents: what they actually do (triage, correlation, runbook execution), where they break, and how to build human-in-the-loop with approval gates so the agent stays a co-pilot instead of a new source of incidents.