heroui logo

AWS Bedrock Guardrail Updated or Deleted

Panther Rules

View Source
Summary
This detection rule monitors actions related to Amazon Bedrock Guardrails, specifically focusing on updates or deletions. Amazon Bedrock Guardrails are crucial for enforcing safeguards in AI workloads, ensuring compliance with responsible AI policies. When a guardrail is updated or deleted, it could open up security vulnerabilities, making it essential to detect these changes promptly. The rule specifically looks for events logged by AWS CloudTrail that indicate either an update (UpdateGuardrail) or deletion (DeleteGuardrail) of a guardrail. It flags actions that could indicate an unauthorized change to these critical components of AI operations, and it demands investigation whenever such changes are reported.
Categories
  • Cloud
  • AWS
Data Sources
  • Cloud Storage
  • Application Log
ATT&CK Techniques
  • T0054
  • T1562.001
Created: 2025-01-28