heroui logo

AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox

Elastic Detection Rules

View Source
Summary
Detects creation of Amazon Bedrock AgentCore Browser or Code Interpreter with an IAM execution role and public network access. These sandboxes execute agent-generated code or automated browsing on behalf of the caller, and the attached executionRoleArn allows the sandbox to call other AWS services. Setting networkMode to PUBLIC removes network containment, enabling potential prompt-injection or code-execution abuse to reach the internet and pivot to other AWS resources using the execution role. The rule fires on CreateBrowser or CreateCodeInterpreter events (CloudTrail, management-plane) with outcome success, and requires the presence of an executionRoleArn and networkMode=PUBLIC. Investigations should verify the caller identity, source address, the necessity of public egress, and the scope of the attached role. Remediation includes revoking or deleting unapproved sandboxes, constraining or removing public egress, least-privilege adjustments on the execution role, and enforcing iam:PassedToService conditions. Enable data-plane logging for subsequent StartBrowserSession/StartCodeInterpreterSession to detect post-creation activity. False positives may include sanctioned pipelines or platform defaults that require public egress; in such cases verify principal, role, and network configuration. This rule maps to Privilege Escalation and Cloud-based abuse in MITRE ATT&CK/ATLAS ((T1078/T1078.004, AML.T0103, AML.T0012)) and is prioritized as high risk given potential credential access and resource compromise.
Categories
  • Cloud
  • Infrastructure
Data Sources
  • Cloud Service
  • Application Log
ATT&CK Techniques
  • T0012
  • T0103
  • T1078
  • T1078.004
  • T1098
Created: 2026-10-07