For the complete documentation index, see llms.txt. This page is also available as Markdown.

AWS Bedrock AI infrastructure enumeration activity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

10 Minutes

Deduplication Period

1 Day

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

Cloud AI Infrastructure Analytics

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Cloud Service Discovery (T1526)

Severity

Informational

Description

Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources.

Attacker's Goals

  • Discover deployed AI agents, knowledge bases, and foundation models.

  • Assess AI model configurations, inference profiles, and provisioned throughputs to evaluate potential abuse paths.

  • Enumerate AI infrastructure metadata for potential weaknesses or sensitive data.

  • MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts.

Investigative actions

  • Identify and review the specific Bedrock enumeration API calls executed and their frequency.

  • Verify the identity performing the calls and assess if this behavior is typical or anomalous.

  • Correlate with other discovery activities and check related logs for suspicious patterns or subsequent actions.

Variations

Suspicious AWS Bedrock AI infrastructure enumeration by an identity with no prior AI activity

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Cloud Service Discovery (T1526)

Severity

Informational

Description

Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources.

Attacker's Goals

  • Discover deployed AI agents, knowledge bases, and foundation models.

  • Assess AI model configurations, inference profiles, and provisioned throughputs to evaluate potential abuse paths.

  • Enumerate AI infrastructure metadata for potential weaknesses or sensitive data.

  • MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts.

Investigative actions

  • Identify and review the specific Bedrock enumeration API calls executed and their frequency.

  • Verify the identity performing the calls and assess if this behavior is typical or anomalous.

  • Correlate with other discovery activities and check related logs for suspicious patterns or subsequent actions.

Was this helpful?