Product
Detection of Unauthorized Amazon Bedrock Foundation Model Access Attempts
1 rule 1 TTPDetection of failed API calls attempting to enable Amazon Bedrock foundation model access, serving as a high-signal indicator for credential boundary-testing and potential LLMjacking.
Detection of Potential Prompt Injection in AWS Bedrock Claude
1 TTPThis detection identifies potential prompt injection or jailbreak attempts against Amazon Bedrock Claude models by monitoring for linguistic patterns designed to override system instructions or bypass safety guardrails.
AWS Bedrock Model Invocation Logging Deletion
2 rules 1 TTPDetection of AWS Bedrock model invocation logging configuration deletion via the DeleteModelInvocationLogging API in CloudTrail logs, potentially indicating an adversary attempting to evade detection of malicious AI model usage.
High Number of AWS Bedrock List Foundation Model Failures
2 rules 1 TTPDetection of a high number of AccessDenied errors when attempting to list AWS Bedrock foundation models, indicating potential reconnaissance activity after credential compromise to discover accessible AI models.
AWS Bedrock GuardRails Deletion Attempt
2 rules 1 TTPDetection of AWS Bedrock GuardRails deletion, which are security controls to prevent harmful AI outputs, could indicate an adversary attempting to remove safety measures after credential compromise to enable malicious model outputs.