Purchase and activate the service
Security Operations Agent (SecOps Agent) is an intelligent security operations service provided by Security Center. You can complete routine security operations such as alert triage and handling, vulnerability remediation, asset investigation, and report generation through natural language conversations. This topic describes the core capabilities and usage of SecOps Agent.
What is SecOps Agent
SecOps Agent is built on Alibaba Cloud CLI, which integrates the APIs of all security products, and multiple core skills of Security Center. Through multi-agent coordination, SecOps Agent converts routine multi-product security operations based on cloud consoles into natural language interactions, eliminating the need to switch between multiple console pages. The service has the following core features:
Natural language-driven operations: Complete actual operations such as policy configuration, alert handling, vulnerability remediation, and asset management in a conversational manner, rather than only providing query assistance.
Multi-agent coordination: Uses a Leader + Member multi-agent team model, in which the system intelligently dispatches tasks without learning costs.
Security confirmation for sensitive operations: A built-in security policy framework automatically identifies high-risk operations (for example, guiding you to confirm snapshot policies and retention periods before vulnerabilities are fixed) and provides guided confirmation at sensitive checkpoints to prevent misoperations.
Extensible orchestration: Supports uploading custom skills to adapt to unique enterprise business scenarios. Custom skills undergo static analysis and sandbox dynamic detection before upload to block malicious code.
Multi-account aggregated operations: Supports data aggregation and unified configuration management across enterprise accounts, and batch operations and report export across accounts.
Secure execution environment: Each user works in an independent container sandbox with strict isolation. All agent actions generate complete operation audit logs and are traceable.
Feature overview
Core capability scenarios
Capability scenario | Description |
Alert auto-triage and handling | Assess alert threat levels, batch-handle, ignore, or isolate alerts, and correlate event context. Supports scheduled task-triggered triage and handling based on Security Center alerts. |
Vulnerability and baseline management | Analyze vulnerability remediation priorities and perform remediation, generate baseline compliance reports, distribute baseline policies, and modify vulnerability settings. |
Asset panorama investigation | Multi-dimensional asset correlation and cross-query, including fingerprint cross-query, attack chain reconstruction, and affected asset localization. |
Security weekly reports and overview | Generate weekly reports on security operations outcomes, and view security posture trends and risk distribution statistics. |
Multi-account unified management | Retrieve cloud security account, risk, and asset data, aggregate multi-account data, and manage configurations in a unified manner. Batch-export vulnerability, baseline, and configuration check reports across accounts. |
Supported cloud security products
Security Center, Agent Security Center, SASE, Cloud Firewall, Anti-DDoS, Web Application Firewall (WAF), Data Security Center, and Operation Security Center (Bastionhost).
Purchase and activate the service
Go to the SecOps AgentSecOps Agent subscriptionSecOps AgentSecOps Agent page.
Complete the purchase configuration based on the following descriptions:
Select an edition: You can select multiple editions at the same time (Professional, Ultimate, and Unlimited). Each edition provides a different complimentary monthly Credits quota. For more information, see the billing description later in this topic.
NoteA complimentary quota is granted each month, and the unused quota is automatically cleared in the next month without being carried over.
Number of seats: Only one seat can be purchased for each edition.
Subscription duration: You can select 1 month or 12 months.
Read the relevant agreements carefully, and then click Buy Now and complete the payment.
Billing
-
Billing method: Base service subscription fee + excess Credits fee (pay-as-you-go).
Important-
The base service subscription fee includes complimentary Credits that expire on a monthly basis. After the complimentary Credits are used up, Credits pay-as-you-go billing is automatically enabled.
-
The pay-as-you-go mode of SecOpsAgent cannot be disabled separately (that is, it is not affected by the Burstable Protection switch). After the subscription expires or is unsubscribed, the pay-as-you-go mode is automatically disabled.
-
-
Billing rules:
-
Base service subscription fee:
-
Professional: CNY 500/month, which includes 30,000 complimentary Credits.
-
Ultimate: CNY 50,000/month, which includes 6 million complimentary Credits.
-
Unlimited: CNY 100,000/month, which includes 12 million complimentary Credits.
-
-
Credits pay-as-you-go: CNY 0.015/credit.
-
Expiration or unsubscription
SecOpsAgent
Expiration: After the service expires, you can no longer use the features of Security Agent.
The instance and data are retained for 30 days. If you reactivate the service within the retention period, you can continue to use the existing data.
If you do not renew the service within 30 days, the instance is released and the historical data is permanently purged and cannot be recovered.
Unsubscription: Online unsubscription unavailable. Please contact your business representative for manual processing.
View bills (Expenses and Costs)
Go to Expenses and Costs - Bill Details and select the query time.
For the product name, select secopsagent_service_subscription_cn or secopsagent_PayAsYouGo_cn, and then click Search.