LoFP
/
aws_bedrock
aws_bedrock rule
Title
Tags
authorized ai agent workflows that include shell or filesystem tools may trigger this rule. validate that the user identity and tool usage pattern are consistent with expected application behavior.
t1059
aws_bedrock
elastic
authorized heavy usage of the system that is business justified and monitored.
aws_bedrock
elastic
legitimate misunderstanding by users on accessing the bedrock models.
aws_bedrock
elastic
legitimate misunderstanding by users or overly strict policies
aws_bedrock
elastic
new model deployments.
aws_bedrock
elastic
prompts or completions that reference example or documentation keys (for example the aws sample access key ending in example) match the access-key pattern. review the matched value in \"gen_ai.prompt\" or \"gen_ai.completion\" and confirm whether it is a live credential before responding.
t1552
aws_bedrock
elastic
testing updates to compliance policies.
aws_bedrock
elastic
users testing new model deployments or updated compliance policies without amazon bedrock guardrails.
aws_bedrock
elastic