A list of demo models to trigger Workbench alerts for your cloud account.
The following are a list of demonstration models used to test your XDR for Cloud -
AWS CloudTrail integration. Running the listed models creates an alert in the Workbench
app. Trend Micro recommends using an IAM user in AWS to run the demo models so you can also test the
Revoke Access Permission response task.
Demo Model - AWS Bedrock successful guardrail deletion detected
Use these steps to trigger the detection model and create a Workbench alert.
Procedure
- Open AWS CloudShell.
- Create a guardrail for the demo.Use the following command, making sure to provide the required attributes.
aws bedrock create-guardrail --name <guardrail name> --blocked-input-messaging "test" --blocked-outputs-messaging "test" --word-policy-config wordsConfig=[{text=string1},{text=string2}]
- Verify the guardrail creation and copy the guardrail ID.Use the command
aws bedrock list-guardrails
. - To trigger the demo model, delete the guardrail you created.Use the following command to delete the guardrail you created.
aws bedrock delete-guardrail --guardrail-identifier <guardrail id>
- In the Trend Vision One console, go to to view the generated alert.
Demo Model- AWS Bedrock model invocation logs successful deletion detected
Use these steps to trigger the detection model and create a Workbench alert.
Procedure
- In your AWS console, go to .
- Enable Model invocation logging.
- Select the log location.
- Click Save settings.
- To trigger the demo model, disable Model invocation logging.
- In the Trend Vision One console, go to to view the generated alert.
Demo Model - AWS IAM login MFA deactivated for a user
Use these steps to trigger the detection model and create a Workbench alert.
ImportantYou must have IAM access permissions in AWS to trigger this model.
|
Procedure
- In your AWS console, access the IAM dashboard.
- Go to .
- Select a user for the test, or create a test user.
- In the user settings, go to Security credentials and click Assign MFA device.
- Follow the on-screen steps to add an MFA device to the user.
- To trigger the model, access the AWS CloudShell.
- Get the user name and the serial ID of the MFA device you set up.Use the following command to list all MFA devices. Copy the user name and the serial ID of the test device.
aws iam list-virtual-mfa-devices
- Deactivate the MFA device.Use the following command to deactivate the test MFA device.
aws iam deactivate-mfa-device --user-name <username> --serial-number <serial number or ARN>
- In the Trend Vision One console, go to to view the generated alert.
Demo Model - AWS EC2 EBS snapshot shared publicly or to external account
Use these steps to trigger the detection model and create a Workbench alert.
Procedure
- In your AWS console, access the EC2 console and go to .
- Click Create snapshot.
- To trigger the model, click the snapshot you created and go to Snapshot settings.
- Click Modify permissions.
- Under Sharing options, select Public.
- Click Modify permissions.
- In the Trend Vision One console, go to to view the generated alert.
Demo Model - AWS IAM administrator access policy attached to a role
Use these steps to trigger the detection model and create a Workbench alert.
Procedure
- In your AWS console, access the IAM dashboard.
- Select an existing role, or create a new IAM role to test the model.
- Attach an admin policy to the role.
- To trigger the model, access the AWS CloudShell.
- Run the following command.
aws iam attach-role-policy --role-name <name of role you just created> --policy-arn arn:aws:iam::aws:policy/AdministratorAccess
- In the Trend Vision One console, go to to view the generated alert.