AWS Bedrock model invocation logging deletion

Cortex XDR Analytics Alert Reference by Alert name

Product
Cortex XDR
Last date published
2025-12-08
Category
Analytics Alert Reference
Index by
Alert name

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

  • Requires:
    • AWS Audit Log

Detection Modules

AIDR

Detector Tags

Cloud AI Infrastructure Analytics

ATT&CK Tactic

Defense Evasion (TA0005)

ATT&CK Technique

Impair Defenses: Disable or Modify Cloud Logs (T1562.008)

Severity

Low

Description

A cloud identity deleted the model invocation logging.

Attacker's Goals

Avoid detection by limiting collected data from models.

Investigative actions

  • Investigate any unusual activity originating from the suspected identity.

Variations

AWS Bedrock model invocation logging deletion by an identity with administrative activity

Synopsis

ATT&CK Tactic

Defense Evasion (TA0005)

ATT&CK Technique

Impair Defenses: Disable or Modify Cloud Logs (T1562.008)

Severity

Informational

Description

A cloud identity with administrative activity deleted the model invocation logging.

Attacker's Goals

Avoid detection by limiting collected data from models.

Investigative actions

  • Investigate any unusual activity originating from the suspected identity.


AWS Bedrock model invocation logging was successfully deleted

Synopsis

ATT&CK Tactic

Defense Evasion (TA0005)

ATT&CK Technique

Impair Defenses: Disable or Modify Cloud Logs (T1562.008)

Severity

Low

Description

A cloud identity successfully deleted the model invocation logging.

Attacker's Goals

Avoid detection by limiting collected data from models.

Investigative actions

  • Investigate any unusual activity originating from the suspected identity.