AWS Bedrock AgentCore with Public Network Browser or Code Interpreter Sandbox
Detects the successful creation of an Amazon Bedrock AgentCore Browser or Code Interpreter with an execution IAM role and public network access. These sandboxes run agent-generated code or automated browsing on the…
Description
Detects the successful creation of an Amazon Bedrock AgentCore Browser or Code Interpreter with an execution IAM role and public network access. These sandboxes run agent-generated code or automated browsing on the caller's behalf, and the attached role lets the sandbox call other AWS services. Public network mode removes the sandbox's network containment, so a sandbox steered by prompt injection, malicious tool output, or code-execution abuse can reach the internet and pivot into other AWS resources with the role's permissions. Review the role scope and whether public egress is required.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source category
- event_index
Known benign triggers
- Approved AgentCore Browsers or Code Interpreters that require public egress, such as a code interpreter installing packages or a browser tool reaching external sites, created by a known platform or CI/CD principal. Validate the caller, the attached execution role, and whether VPC or sandbox network mode was required by policy.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| sonraisecurity.com/blog/sandboxed-to-compromised-new-research-exposes-credential-exfiltration-paths-in-aws-code-interpreters/ | 2 |
| unit42.paloaltonetworks.com/bypass-of-aws-sandbox-network-isolation-mode/ | 3 |
| www.beyondtrust.com/blog/entry/aws-agentcore-privilege-escalation | 2 |
From the source
- At source
- Open at source
- Upstream identifier
- 86be0b1b-3984-4b26-bde6-46d33fe7bab1
- Tagged by the source as
- Mitre Atlas: AML.T0012Mitre Atlas: AML.T0103Data Source: Amazon Web ServicesData Source: AWSData Source: AWS CloudTrailDomain: CloudDomain: GenAIPlatform: AWSResources: Investigation GuideRule Type: Custom Query (KQL)Service: AWS BedrockService: AWS IAMTactic: PersistenceTactic: Privilege EscalationUse Case: Threat Detection
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Oct 8, 2026
- Version
- 1