{"repo":"BeyondTrust/bedrock-keys-security","free":true,"listed":false,"github":"https://github.com/BeyondTrust/bedrock-keys-security","clone":"git clone https://github.com/BeyondTrust/bedrock-keys-security.git","description":"Detect phantom IAM users, decode leaked AWS Bedrock and Claude Platform API keys, and prevent LLMjacking. CLI + SCPs + SIEM detection rules.","language":"Python","stars":36,"topics":["amazon-bedrock","api-keys","aws","aws-iam","aws-organizations","aws-security","cloudtrail","incident-response","python","service-control-policy"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"The AWS Bedrock API keys security toolkit tl;dr: AWS Bedrock API keys behave nothing like regular AWS credentials: generating one silently creates a hidden IAM user (a phantom user ) with a broad managed policy attached. BKS hunts these phantom users across both Bedrock and Claude Platform on AWS keys, with an offline key decoder, incident response, automated cleanup, preventive SCPs and SIEM-ready detection content. Contents : Quickstart · Motivation · Installation · Usage · Prevention · Detection · Migration to STS · Talks · Contributing Quickstart bks scan discovers every phantom user in the account ( BedrockAPIKey- and AeaApiKey- ), categorizes risk ( AT RISK / ACTIVE / ORPHANED ) and prints a summary table. Motivation AWS Bedrock API keys behave unlike regular AWS credentials. They authenticate via bearer tokens instead of SigV4, and they embed the AWS account ID and IAM username in plain base64. The most damaging behavior: when a user creates a long-term Bedrock API key through the AWS Console, AWS silently provisions an IAM user named BedrockAPIKey-xxxx and attaches the AmazonBedrockLimitedAccess managed policy. Despite its name, the policy is effectively administrative . As of July 2026 (version v8) it grants 48 actions across bedrock: (44) and bedrock-mantle: (4) covering create / read / update / delete across all Bedrock resources, plus cross-service reconnaissance ( iam:ListRoles , kms:DescribeKey , ec2:Describe{Vpcs,Subnets,SecurityGroups} ). These phantom users a","default_branch":null,"files":null,"tree":[],"storefront":"/r/BeyondTrust","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/BeyondTrust/bedrock-keys-security/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}