LoFP LoFP / approved agentcore browsers or code interpreters that require public egress, such as a code interpreter installing packages or a browser tool reaching external sites, created by a known platform or ci/cd principal. validate the caller, the attached execution role, and whether vpc or sandbox network mode was required by policy.

Techniques

Sample rules

AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox

Description

Detects the successful creation of an Amazon Bedrock AgentCore Browser or Code Interpreter with an execution IAM role and public network access. These sandboxes run agent-generated code or automated browsing on the caller’s behalf, and the attached role lets the sandbox call other AWS services. Public network mode removes the sandbox’s network containment, so a sandbox steered by prompt injection, malicious tool output, or code-execution abuse can reach the internet and pivot into other AWS resources with the role’s permissions. Review the role scope and whether public egress is required.

Detection logic

event.dataset: "aws.cloudtrail" and
  event.provider: "bedrock-agentcore.amazonaws.com" and
  event.action: (
    "CreateCodeInterpreter" or
    "CreateBrowser"
  ) and
  event.outcome: "success" and
  aws.cloudtrail.flattened.request_parameters.networkConfiguration.networkMode: "PUBLIC" and
  aws.cloudtrail.flattened.request_parameters.executionRoleArn: *