So, what is great about cloud today? Automation my friends.
Lambda functions could help a lot, but implement a serverless security response framework is something great and not usual.
Below we have an slide shared by AWS in a Security Webinar last week. How to autonomously detect a compromised autoscaling group member, stabilize the system and generate forensic data:

Great, isnt it?
See you around,
Leo