Unauthorized AWS Bedrock Agent Creation for Persistence
Adversaries with compromised human IAM credentials can create rogue Bedrock Agents to establish persistent AI-driven footholds for data exfiltration, service pivoting, or C2 signaling.
Adversaries possessing compromised AWS IAM user or root account credentials can leverage Amazon Bedrock to create rogue autonomous agents. These agents serve as persistent, AI-driven footholds that operate independently of the initial compromise point. By configuring these agents with specific system instructions and malicious action groups (Lambda functions), attackers can execute multi-step tasks, query internal knowledge bases, and pivot to external services.
Defenders must differentiate between legitimate automated deployment pipelines, which typically utilize AssumedRole sessions, and interactive creation via human IAM identities. The creation of Bedrock agents by IAM users or the root account is a high-signal indicator of potential unauthorized activity, as production infrastructure is almost exclusively managed via service-linked roles. This threat is particularly concerning because the AI agent itself acts as a persistent command-and-control channel that can perform actions autonomously over extended periods without further interaction from the adversary.
Impact
Successful deployment of rogue Bedrock Agents grants attackers an autonomous capability to interact with cloud environments, potentially leading to unauthorized data exfiltration through Lambda-based action groups, lateral movement into internal services, and the establishment of a persistent, non-traditional C2 channel that is difficult to detect using standard network-based traffic analysis.
Recommendation
- Deploy detection logic to monitor 'CreateAgent' API calls originating from human IAM identities (IAMUser or Root).
- Restrict the 'bedrock:CreateAgent' permission to authorized CI/CD roles using IAM policies or Service Control Policies (SCPs).
- Audit existing Bedrock agent configurations, specifically reviewing the 'instruction' system prompt and the 'actionGroupExecutor' Lambda ARNs for anomalous or unauthorized code.
- Investigate 'PrepareAgent', 'CreateAgentAlias', and 'AssociateAgentKnowledgeBase' events following any detected agent creation to determine the scope of agent deployment.
Immediate actions
Deploy the provided detection rule and alert on CreateAgent events by IAM Users.
Mitigations
Restrict bedrock:CreateAgent IAM permissions to authorized service roles only.
Unauthorized Bedrock Agent creation
Detection coverage 1
Detect Unauthorized AWS Bedrock Agent Creation by IAM User or Root
lowDetects the creation of an Amazon Bedrock Agent performed directly by an IAM User or Root account, which is a potential indicator of persistence via rogue AI agents.
Detection queries are available on the platform. Get full rules →