Detection rules › Sigma
AWS Bedrock Guardrail Deleted
Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety controls and allow unsafe or unauthorized model responses.
Known false positives
- Legitimate guardrail deletion by authorized identities.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Defense Impairment |
Telemetry coverage
Rules detecting the same action
These rules filter on the same operation.
Rule body
title: AWS Bedrock Guardrail Deleted
id: 59b70e4d-dd17-44a9-b740-acf07ae3eb6a
status: experimental
description: |
Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove
model safety controls and allow unsafe or unauthorized model responses.
references:
- https://docs.aws.amazon.com/bedrock/latest/APIReference/API_DeleteGuardrail.html
author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
date: 2026-07-10
tags:
- attack.defense-impairment
- attack.t1685
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventName: 'DeleteGuardrail'
eventSource: 'bedrock.amazonaws.com'
condition: selection
falsepositives:
- Legitimate guardrail deletion by authorized identities.
level: medium
Stages and Predicates
Stage 0: condition
selectionStage 1: selection
selection:
eventName: 'DeleteGuardrail'
eventSource: 'bedrock.amazonaws.com'
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
eventName | eq |
| field:"aws::eventName" kind:eq value:"DeleteGuardrail" |
eventSource | eq |
| field:"aws::eventSource" kind:eq value:"bedrock.amazonaws.com" |