Purchase and activate SecOps Agent
SecOps Agent is an intelligent security operations service provided by Security Center. Use natural language conversations to run routine security operations such as alert triage and handling, vulnerability remediation, asset investigation, and report generation. This topic describes the service capabilities and walks you through purchasing and activating it.
What is SecOps Agent
SecOps Agent is built on Alibaba Cloud CLI (with full security product API integration) and multiple Security Center core skills. It uses multi-agent coordination to convert routine security operations into natural language interactions, so you no longer need to switch between console pages.
Natural language-driven operations — Complete real operations such as policy configuration, alert handling, vulnerability remediation, and asset management through conversations, rather than only receiving query assistance.
Multi-agent coordination — Uses a Leader + Member multi-agent team model, and the system dispatches tasks intelligently without requiring users to learn per-product APIs.
Security confirmation for sensitive operations — A built-in security policy framework identifies high-risk operations (for example, prompting you to confirm snapshot policies and retention periods before vulnerability remediation) and provides guided confirmation at sensitive checkpoints to prevent misoperations.
Extensible orchestration — Supports uploading custom skills to adapt to enterprise-specific business scenarios. Custom skills undergo static analysis and sandbox dynamic detection before upload to block malicious code.
Multi-account aggregated operations — Supports enterprise multi-account data aggregation and unified configuration management, with cross-account batch operations and report exports.
Secure execution environment — Each user operates in an isolated container sandbox with strong isolation. All agent actions generate comprehensive audit logs for full traceability.
Overview
Core capabilities
The following table describes the core capabilities of SecOps Agent.
Capability | Description |
Alert auto-triage and handling | Assess alert threat levels, batch-handle, ignore, or isolate alerts, and correlate event context. Supports scheduled task-triggered triage and handling based on Security Center alerts. |
Vulnerability and baseline management | Analyze vulnerability remediation priorities and execute fixes, generate baseline compliance reports, distribute baseline policies, and modify vulnerability settings. |
Asset panoramic investigation | Multi-dimensional asset correlation and cross-query, including fingerprint cross-query, attack chain reconstruction, and affected asset localization. |
Security weekly reports and overview | Generate security operations weekly reports, and view security posture trends and risk distribution statistics. |
Multi-account unified management | Retrieve cloud security account, risk, and asset data. Aggregate multi-account data and manage unified configurations. Batch-export vulnerability, baseline, and configuration check reports across accou |
Supported cloud security products
SecOps Agent operates across the following Alibaba Cloud security products: Security Center, Agent Security Center, SASE, Cloud Firewall, Anti-DDoS, Web Application Firewall (WAF), Data Security Center, and Bastionhost.
Purchase the service
Go to the SecOps Agent subscription page.
Configure the purchase settings based on the following description.
Number of seats: Only one seat can be purchased.
Subscription duration: 1 month or 12 months.
NoteEach month includes a complimentary 30,000 Credit quota. Unused credits expire at the end of the month and do not carry over.
Read the relevant agreements carefully, and click Buy Now to complete the payment.
ImportantAfter the service is activated, if the complimentary quota is exceeded, pay-as-you-go Credit billing is automatically enabled.
The pay-as-you-go service cannot be disabled independently (it is not affected by the Burstable Protection toggle). It is automatically disabled when the subscription expires or is unsubscribed.
Billing
Billing method: Base service subscription fee + excess Credits fee (pay-as-you-go).
ImportantThe base service subscription fee includes 30,000 credits (expire monthly). After the credits are used up, the pay-as-you-go mode is automatically enabled for credits.
The pay-as-you-go mode of SecOpsAgent cannot be disabled separately (that is, it is not affected by the Burstable Protection switch). After the subscription expires or is unsubscribed, the pay-as-you-go mode is automatically disabled.
Billing rules:
Base service subscription fee: CNY 500/month.
Credits pay-as-you-go: CNY 0.015/credit.
View bills (Expenses and Costs)
Go to Expenses and Costs - Bill Details and select the query time range.
For the product name, select Security O&M Agent - Pay-as-you-go or Security O&M Agent - Subscription, and then click Search.
Expiration and unsubscription
SecOpsAgent
Expiration: After the service expires, you can no longer use the features of Security Agent.
The instance and data are retained for 30 days. If you reactivate the service within the retention period, you can continue to use the existing data.
If you do not renew the service within 30 days, the instance is released and the historical data is permanently purged and cannot be recovered.
Unsubscription: Online unsubscription unavailable. Please contact your business representative for manual processing.