Link Search Menu Expand Document

Handle AWS SSH Quarantine Approvals

Workflow #0007

This workflow is triggered when an Approval Task generated by Quarantine AWS Instances from Alerts is approved, denied, or expires. If approved, SSH quarantine restrictions are removed from the AWS security group.

Note: This workflow is designed to respond to approval tasks generated by this workflow!



  • The following atomic actions must be imported before you can import this workflow:
  • The targets and account keys listed below
  • An Amazon Web Services account with instances monitored by SCA
  • (Optional) A Webex Teams access token and room name to post messages to

Note: You may have an old version of the Webex Teams - Post Message to Room atomic. To ensure the best experience with this workflow, be sure to import the latest version of this atomic from the GitHub_Target_Atomics repository!

Workflow Steps

  1. (Optional) Add global variables to local variables
  2. Extract the AWS instance ID from the Approval Task
  3. If a Teams room name was provided, translate it into a room ID
  4. Make sure we got an instance ID (if not, post an error to webex)
  5. Check the approval result. If the user selected to leave the instance quarantined or the task expired, do nothing. If they want to remove quarantine:
    • Get information about the instance from AWS and extract its security group
    • Restore normal SSH access
    • Send a Webex Teams notification


  • Set your AWS region in the AWS Region local variable
  • See this page for information on configuring the workflow for Webex Teams


Target Group: Default TargetGroup

Target Name Type Details Account Keys Notes
Amazon Web Services AWS Endpoint Region: Your Region
Your AWS Account Key  
Webex Teams HTTP Endpoint Protocol: HTTPS
Path: None
None Not necessary if Webex Teams activities are removed

Account Keys

Account Key Name Type Details Notes
Your AWS Account Key AWS Credentials Access Key: AWS API Access Key
Secret Key: AWS API Secret Key