heroui logo

AWS Bedrock Model Invocation Logging Configuration Deleted

Panther Rules

View Source
Summary
This rule detects the deletion of the Model Invocation Logging Configuration in AWS Bedrock, which is an essential security measure for monitoring AI workloads. Logging configurations are responsible for capturing critical metadata, requests, and responses related to model invocations. If this configuration is deleted, it can expose the AI workloads to security risks by impairing command history logging. Activities that lead to such deletion are logged by AWS CloudTrail, including details like user agent, source IP address, and the account from which the deletion was performed. The rule emphasizes the importance of being vigilant regarding unauthorized deletions and recommends a review of the actions taken around the deletion event to ensure compliance and security.
Categories
  • Cloud
  • AWS
  • Infrastructure
Data Sources
  • Cloud Service
  • Application Log
ATT&CK Techniques
  • T1562.003
Created: 2025-01-28