Analytics BIOC
Low
✕
Bedrock model shared with a foreign account
A bedrock model was shared with a foreign account through AWS resource access manager.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Cloud AI Infrastructure Analytics
Attacker's goals:
Exfiltrate the proprietary model to a foreign account and establish persistent access to it.
Investigative actions:
Investigate the foreign cloud accounts that gained access to the models. Assess the sensitivity of the shared models to determine the potential impact of this exposure. Identify the actor and investigate their identity for compromise.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day