Bedrock model shared with a foreign account
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud AI Infrastructure Analytics
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Low
Description
A bedrock model was shared with a foreign account through AWS resource access manager.
Attacker's Goals
Exfiltrate the proprietary model to a foreign account and establish persistent access to it.
Investigative actions
Investigate the foreign cloud accounts that gained access to the models.
Assess the sensitivity of the shared models to determine the potential impact of this exposure.
Identify the actor and investigate their identity for compromise.
PreviousAzure VM extension abuse attempt
NextBigQuery table or query results exfiltrated to a foreign project
Was this helpful?
