Panther medium experimental python
AWS Bedrock Guardrail Updated or Deleted
An Amazon Bedrock Guardrail was updated or deleted. Amazon Bedrock Guardrails are used to implement application-specific safeguards based on your use cases and responsible AI policies. Updating or deleting a guardrail can have security implications to your AI workloads.
Detection Logic
from panther_aws_helpers import aws_cloudtrail_success, aws_rule_context
GUARDRAIL_EVENTS = {"DeleteGuardrail", "UpdateGuardrail"}
def rule(event):
if (
event.get("eventSource") == "bedrock.amazonaws.com"
and event.get("eventName") in GUARDRAIL_EVENTS
and aws_cloudtrail_success(event)
):
return True
return False
def title(event):
user = event.udm("actor_user")
guardrail = event.deep_get("requestParameters", "guardrailIdentifier")
action = event.get("eventName").replace("Guardrail", "").lower()
return f"User [{user}] {action}d Bedrock guardrail [{guardrail}]"
def severity(event):
if event.get("eventName") == "UpdateGuardrail":
return "LOW"
return "DEFAULT"
def alert_context(event):
return aws_rule_context(event) Field Validations
Loading…
Comments (0)
Loading comments...