AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox

Last updated a day ago on 2026-10-07
Created a day ago on 2026-10-07

About

Detects the successful creation of an Amazon Bedrock AgentCore Browser or Code Interpreter with an execution IAM role and public network access. These sandboxes run agent-generated code or automated browsing on the caller's behalf, and the attached role lets the sandbox call other AWS services. Public network mode removes the sandbox's network containment, so a sandbox steered by prompt injection, malicious tool output, or code-execution abuse can reach the internet and pivot into other AWS resources with the role's permissions. Review the role scope and whether public egress is required.
Tags
Domain: CloudData Source: AWSData Source: Amazon Web ServicesPlatform: AWSData Source: AWS CloudTrailService: AWS BedrockService: AWS IAMUse Case: Threat DetectionTactic: Privilege EscalationTactic: PersistenceRule Type: Custom Query (KQL)Domain: GenAIMitre Atlas: AML.T0012Mitre Atlas: AML.T0103Language: kuery
Severity
high
Risk Score
73
MITRE ATT&CK™

Privilege Escalation (TA0004)(external, opens in a new tab or window)

Persistence (TA0003)(external, opens in a new tab or window)

False Positive Examples
Approved AgentCore Browsers or Code Interpreters that require public egress, such as a code interpreter installing packages or a browser tool reaching external sites, created by a known platform or CI/CD principal. Validate the caller, the attached execution role, and whether VPC or sandbox network mode was required by policy.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Query (Kibana Query Language)
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-aws.cloudtrail-*
Related Integrations

aws(external, opens in a new tab or window)

Query
text code block:
event.dataset: "aws.cloudtrail" and event.provider: "bedrock-agentcore.amazonaws.com" and event.action: ( "CreateCodeInterpreter" or "CreateBrowser" ) and event.outcome: "success" and aws.cloudtrail.flattened.request_parameters.networkConfiguration.networkMode: "PUBLIC" and aws.cloudtrail.flattened.request_parameters.executionRoleArn: *

Install detection rules in Elastic Security

Detect AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).