Threat report

unit42.paloaltonetworks.com/bypass-of-aws-sandbox-network-isolation-mode

https://unit42.paloaltonetworks.com/bypass-of-aws-sandbox-network-isolation-mode/
Published on
unit42.paloaltonetworks.com

ATT&CK techniques those detections carry

  • T1078Valid Accounts
  • T1078.004Cloud Accounts
  • T1552Unsecured Credentials
  • T1552.005Cloud Instance Metadata API
  • T1098Account Manipulation
Open the original

3 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
AWS Bedrock AgentCore with Public Network Browser or Code Interpreter SandboxHigh
AWS Bedrock AgentCore Runtime Prompt Targeting Credentials or Instance MetadataHigh
AWS Bedrock AgentCore Execution Role Used Outside Its RuntimeHigh

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice