AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox
Description
Detects the successful creation of an Amazon Bedrock AgentCore Browser or Code Interpreter with an execution IAM role and public network access. These sandboxes run agent-generated code or automated browsing on the caller's behalf, and the attached role lets the sandbox call other AWS services. Public network mode removes the sandbox's network containment, so a sandbox steered by prompt injection, malicious tool output, or code-execution abuse can reach the internet and pivot into other AWS resources with the role's permissions. Review the role scope and whether public egress is required.
Query · kuery
event.dataset: "aws.cloudtrail" and
event.provider: "bedrock-agentcore.amazonaws.com" and
event.action: (
"CreateCodeInterpreter" or
"CreateBrowser"
) and
event.outcome: "success" and
aws.cloudtrail.flattened.request_parameters.networkConfiguration.networkMode: "PUBLIC" and
aws.cloudtrail.flattened.request_parameters.executionRoleArn: *
Investigation fields
Pivot points the source recommends for triage.
@timestampuser.nameuser_agent.originalsource.ipaws.cloudtrail.user_identity.arnaws.cloudtrail.user_identity.typeaws.cloudtrail.user_identity.access_key_idevent.actionevent.providerevent.outcomecloud.account.idcloud.regionaws.cloudtrail.request_parametersaws.cloudtrail.flattened.request_parameters.executionRoleArnaws.cloudtrail.flattened.request_parameters.networkConfiguration.networkModeaws.cloudtrail.response_elements
Known false positives
- Approved AgentCore Browsers or Code Interpreters that require public egress, such as a code interpreter installing packages or a browser tool reaching external sites, created by a known platform or CI/CD principal. Validate the caller, the attached execution role, and whether VPC or sandbox network mode was required by policy.
Analyst notes
Investigating AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox
Amazon Bedrock AgentCore Code Interpreter and Browser sandboxes act for the caller. The Code Interpreter executes agent-generated code, and the Browser drives automated web sessions. Either can be created with an IAM execution role (executionRoleArn) that the sandbox assumes when it calls other AWS services. Setting networkMode=PUBLIC removes network-level containment. A sandbox then compromised through prompt injection, malicious tool output, or code-execution abuse can reach the public internet and pivot into other AWS resources using that role. Researchers have also shown paths for stealing the role's temporary credentials from a Code Interpreter and reusing them outside the sandbox.
CreateBrowser and CreateCodeInterpreter are management-plane events logged to CloudTrail by default. Later StartBrowserSession and StartCodeInterpreterSession calls are data-plane events and are not in a default management-events trail.
Possible investigation steps
- Check the caller identity (
aws.cloudtrail.user_identity.arn) andsource.ipagainst expected provisioning principals. Unexpected users, roles, or source addresses creating a public AgentCore Browser or Code Interpreter should be investigated. - Examine
aws.cloudtrail.request_parametersforexecutionRoleArnandnetworkMode=PUBLIC. Treat the role as the permissions a compromised sandbox would inherit: list the AWS services it can call, and decide whether public egress is required or whether VPC or sandbox network mode would keep the workload contained. - Review the IAM PassRole permission of the calling identity and whether it is constrained by
iam:PassedToServiceconditions. - Check for a subsequent
StartBrowserSessionorStartCodeInterpreterSessionfrom the same caller against the new resource. Those events require data-plane logging. - Pivot on the execution role for later AWS API calls from outside AgentCore, which can indicate the role's credentials were used beyond the workload.
False positive analysis
- Platform engineering or infrastructure-as-code pipelines that intentionally create a public Browser or Code Interpreter with a scoped execution role. Confirm the principal, role, and network mode match the approved design.
- Workloads that must reach the public internet. Prefer VPC network mode with explicit egress where isolation is required.
Response and remediation
- If the configuration is not approved, delete the Browser or Code Interpreter to stop new sessions and revoke active sessions of the execution role. Assume a public sandbox may already have been steered by untrusted prompts, tool output, or executed code.
- Replace public network mode with a VPC whose routing and egress controls explicitly block outbound internet access, or use sandbox mode where supported, and reduce the execution role to the minimum AWS API permissions the workload needs.
- Constrain
iam:PassRolefor AgentCore creators withiam:PassedToServiceand a permissions boundary on roles that can be passed. - Enable data-plane logging for
bedrock-agentcoreso later session starts are visible.