Sigma Rule Library

AWS Bedrock Guardrail Updated

Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety controls and allow unsafe or unauthorized model responses.

View on GitHubOpen raw file

Detection logic

selection

eventName: UpdateGuardrail
eventSource: bedrock.amazonaws.com

Condition

selection

Raw YAML

title: AWS Bedrock Guardrail Updated
id: 1c722651-254a-4b04-a9f4-99b62a2d0a1f
status: experimental
description: |
    Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken
    model safety controls and allow unsafe or unauthorized model responses.
references:
    - https://docs.aws.amazon.com/bedrock/latest/APIReference/API_UpdateGuardrail.html
author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
date: 2026-07-10
tags:
    - attack.defense-impairment
    - attack.t1685
logsource:
    product: aws
    service: cloudtrail
detection:
    selection:
        eventName: 'UpdateGuardrail'
        eventSource: 'bedrock.amazonaws.com'
    condition: selection
falsepositives:
    - Legitimate guardrail updates by authorized identities.
level: medium

False positives

  • Legitimate guardrail updates by authorized identities.

References

Similar rules