AWS Bedrock Guardrail Updated


Description

Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety controls and allow unsafe or unauthorized model responses.

Query · sigma

selection:
  eventName: UpdateGuardrail
  eventSource: bedrock.amazonaws.com
condition: selection

Known false positives

  • Legitimate guardrail updates by authorized identities.
Raw source AWS Bedrock Guardrail Updated · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: AWS Bedrock Guardrail Updated
id: 1c722651-254a-4b04-a9f4-99b62a2d0a1f
status: experimental
description: |
    Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken
    model safety controls and allow unsafe or unauthorized model responses.
references:
    - https://docs.aws.amazon.com/bedrock/latest/APIReference/API_UpdateGuardrail.html
author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
date: 2026-07-10
tags:
    - attack.defense-impairment
    - attack.t1685
logsource:
    product: aws
    service: cloudtrail
detection:
    selection:
        eventName: 'UpdateGuardrail'
        eventSource: 'bedrock.amazonaws.com'
    condition: selection
falsepositives:
    - Legitimate guardrail updates by authorized identities.
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.