This document is a cheat sheet designed for security professionals to navigate incident response in AWS environments, covering best practices, data sources, and tools. It outlines responsibilities across three domains: cloud security incident, infrastructure incidents, and application incidents, and describes various open-source and AWS native tools for forensic analysis and data collection. Additionally, it provides command examples for monitoring and logging, as well as guidance for responding to specific incident types, including those involving EC2 and Lambda instances.