AWS Bedrock Claude High Risk Filesystem and Exec Tool Invocation — Detection Rule

Detects identities invoking high-risk filesystem and execution tools via AWS Bedrock Claude. For each identity, monitors the usage of potentially dangerous commands and flags any anomalous activity that deviates from their historical baseline. This may indicate attempts to escalate privileges, exfiltrate data, or execute unauthorized commands.

Read the full analysis on IntelFusions