Scenario 2, Automated Incident Classification. An EventBridge -> SQS -> Lambda workflow reads Security Hub, GuardDuty, AWS Config, CloudWatch, and manual incident alerts, classifies each one into five categories with a local NLP model, escalates low-confidence alerts to Claude Haiku 4.5 on Amazon Bedrock, and routes the result with a reviewed runbook to the owning team's SNS topic.
| Path | Purpose |
|---|---|
src/handler.py |
Lambda entry point: text extraction, two-tier decision, DynamoDB write, SNS publish |
src/classifier.py |
Pure-Python TF-IDF + logistic regression inference (no dependencies) |
src/llm_fallback.py |
Bedrock Converse call with forced, enum-bound tool output |
src/routing.py |
Category -> team topic and static remediation runbooks |
training/generate_dataset.py |
Synthetic labeled alert corpus (seed 605) |
training/train.py |
scikit-learn training, log-loss model selection, export, parity check |
training/evaluate.py |
Keyword baseline vs AI classifier, metrics, confusion matrix |
infra/template.yaml |
Main CloudFormation stack (45 resources) |
infra/config-recorder.yaml |
AWS Config recorder + encrypted delivery bucket |
scripts/deploy.sh |
Test, package, deploy, upload model, close default SG |
scripts/send_test_events.sh |
Six sample alerts, including a prompt-injection attempt |
scripts/verify_controls.sh |
Writes evidence files E1-E8 for the report appendix |
scripts/eval_bedrock.py |
Live measurement of the Bedrock tier on the hard set |
scripts/teardown.sh |
Deletes the main stack |
tests/test_pipeline.py |
15 offline unit tests with in-memory AWS fakes |
results/ |
metrics.json, evaluation.txt, confusion matrix, test output, diagram |
report/build_report.py |
Rebuilds the PDF report, embedding evidence/E*.png if present |
pip install scikit-learn matplotlib # training and evaluation only
python training/generate_dataset.py
python training/train.py
python training/evaluate.py
python -m unittest discover -s tests -v- Submit the one-time Anthropic use-case form in Amazon Bedrock. New accounts sometimes start with a zero daily token quota for Bedrock models; if the Playground returns "Too many tokens per day," open an Account and billing support case. The pipeline still runs and routes low-confidence alerts to MANUAL_TRIAGE.
git clone <this repo> && cd ai-incident-classifier && chmod +x scripts/*.shALERT_EMAIL=you@example.com ./scripts/deploy.shOptional:RESERVED=5(reserved concurrency) andCSPM=true(enable Security Hub CSPM with CIS v3.0.0).- Confirm the SNS subscription email.
./scripts/send_test_events.sh./scripts/verify_controls.shpython3 scripts/eval_bedrock.py(needs boto3 and bedrock:InvokeModel)./scripts/teardown.shwhen finished. The two interface endpoints cost about $0.96 per day.
pip install reportlab
REPO_URL=https://github.com/<you>/ai-incident-classifier python report/build_report.py