Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • AWS Bedrock AI infrastructure enumeration activity Informational Cloud 1 variation

    Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Cloud Service Discovery (T1526)
    Required data: AWS Audit Log
    Detector tags: Cloud AI Infrastructure Analytics
    Attacker's goals: Discover deployed AI agents, knowledge bases, and foundation models. Assess AI model configurations, inference profiles, and provisioned throughputs to evaluate potential abuse paths. Enumerate AI infrastructure metadata for potential weaknesses or sensitive data. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts.
    Investigative actions: Identify and review the specific Bedrock enumeration API calls executed and their frequency. Verify the identity performing the calls and assess if this behavior is typical or anomalous. Correlate with other discovery activities and check related logs for suspicious patterns or subsequent actions.

    Variations

    Suspicious AWS Bedrock AI infrastructure enumeration by an identity with no prior AI activity

    Informational overridden

    Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. overridden