Analytics
Informational
✕
AWS Bedrock AI infrastructure enumeration activity
Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Service Discovery (T1526)
Detector tags: Cloud AI Infrastructure Analytics
Attacker's goals:
Discover deployed AI agents, knowledge bases, and foundation models. Assess AI model configurations, inference profiles, and provisioned throughputs to evaluate potential abuse paths. Enumerate AI infrastructure metadata for potential weaknesses or sensitive data. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts.
Investigative actions:
Identify and review the specific Bedrock enumeration API calls executed and their frequency. Verify the identity performing the calls and assess if this behavior is typical or anomalous. Correlate with other discovery activities and check related logs for suspicious patterns or subsequent actions.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day
1 variation:
- Suspicious AWS Bedrock AI infrastructure enumeration by an identity with no prior AI activity Informational