AI security
AI workload security
See how an attacker reaches your models — not just a list of AI misconfigurations.
10ETLabs reads AI services the same way it reads buckets and clusters: a read-only API inventory. It then links each model to the buckets it trains on and loads weights from, and to the IAM role it runs as, and links each Bedrock agent to its knowledge bases, their S3 data sources, and the Lambda functions its action groups call. That turns single findings into attack paths: an internet-facing notebook whose role is account admin, a public bucket feeding a fine-tuned model or an agent’s knowledge base, an agent whose action-group Lambda runs as admin, SageMaker data capture (recorded inference requests and responses) written to a public bucket. For prompt-level risks, the open-source 10et-ai-test CLI runs prompt-injection, leakage and tool-abuse tests that you run yourself, on your machine or in CI with your own credentials. 10ETLabs never calls your models; you can upload just the pass/fail verdicts to see them next to the asset.

AI security
SageMaker, Bedrock, Azure AI Foundry and Vertex AI linked to the buckets they train on, the images they serve and the identities they run as.
See it work
Two more paths to a model, hop by hop
Each hop is a setting we read from SageMaker, S3, or IAM. The path exists only when every hop does.
AI attack paths · SageMaker
01Public artifact bucket
The bucket holding model artifacts is public, per its bucket policy or ACL.
Illustrative resource names. Paths today cover AWS SageMaker, Bedrock custom models, agents and knowledge bases, and Lambda URLs with no auth; Azure ML and AI Foundry endpoints, models, training jobs, data connections and compute instances; and Vertex AI models, training and tuning jobs, Vector Search, RAG corpora, Agent Engine and Workbench.
What you get
AI service inventory
SageMaker notebooks and endpoints, Bedrock custom models, agents, and knowledge bases; Azure OpenAI and AI Services deployments, AI Foundry hubs and projects, Azure ML online endpoints, models, jobs and compute instances, AI Search; Vertex AI endpoints, models, datasets, training and tuning jobs, Vector Search, feature stores, RAG corpora, Agent Engine, and Workbench land in the AI category with the rest of the estate.
Public path checks
Direct internet or public IPs on notebooks and Workbench, endpoints reachable from the internet, key-based auth on Azure AI accounts, deployments with content filtering off, and registries with anonymous pull become findings in the AI category.
AI attack paths
Every path is built from evidence we collected — a real link between the model, its bucket, and its role. If we could not read a hop, there is no path.
Prompt tests you run
The 10et-ai-test CLI tests OpenAI-compatible APIs, Azure OpenAI, Bedrock models and agents, Vertex AI and your own HTTP apps for prompt injection, system-prompt and data leakage, jailbreaks, tool abuse, unsafe output and runaway token use (OWASP LLM Top 10), with canaries instead of harmful content. It runs where your credentials are; only verdicts are uploaded, and only if you choose.
Honest scope
We read configuration, never prompts or weights, and never invoke your models. On-demand Bedrock calls leave no control-plane trace, so Bedrock region checks run only where custom models, provisioned throughput, guardrails, or logging exist. Agents and knowledge bases are read wherever Bedrock Agents is offered.
In this module
Step 1
Inventory the model plane
SageMaker, Bedrock, Azure AI Foundry, Azure OpenAI, Azure ML and Vertex AI models, endpoints, jobs, notebooks, and agents land in category AI.
Step 2
Link the supply chain
Models are joined to their training data and artifact buckets or containers, the jobs that produced them, their serving images, and the role, managed identity or service account they run as; agents and indexes to their retrieval sources. Exposed links become AI attack paths.
Step 3
Open AI inventory
Triage under the same RBAC as any finding. Prompts and weights are not collected.
In this release
- SageMaker notebook, endpoint, and model inventory
- Bedrock custom models, guardrails, and invocation logging
- Bedrock agents and knowledge bases: roles, guardrails, encryption, action-group Lambdas, and S3 data sources
- AI attack paths: public training data, public model artifacts, over-privileged notebooks, knowledge bases fed from public buckets, agents whose action groups run as admin
- Azure AI Foundry and Vertex AI supply chain: training data, artifacts, images, identities
- 10ET AI Workload Baseline compliance framework
- Customer-run prompt test CLI (10et-ai-test): verdicts linked to AI assets as findings and baseline controls
On the roadmap
Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.
More of the platform
Other modules — not a reprint of this page.
Code security
Agentless code-to-cloud security
Check Terraform, CloudFormation, ARM, and Kubernetes YAML against built-in pattern rules — in the console or on every pull request — then see the same risk classes on live AWS, Azure, GCP, Kubernetes, and other VPS.
CSPM
Cloud Security Posture Management
Misconfiguration and identity-risk checks across AWS, Azure, GCP, Kubernetes, and other VPS — AWS-first, re-checked on every scan you run or schedule.
CWPP
Cloud Workload Protection
Inventory VMs, Lambda functions, and hosts from the control plane, and look inside VM disks with opt-in, agentless DeepScan.
CIEM
Cloud Identity & Access
AWS IAM, Azure Entra ID and GCP service accounts: missing MFA, standing admins, and effective Azure permissions that can reach sensitive data.
Containers
Container & Kubernetes Security
EKS, AKS, and any Kubernetes API you connect, ECR scan-on-push, and public services in one queue — agentless by default, with an optional sensor for runtime evidence and deploy-time blocking.
Compliance
Cloud Compliance Monitoring
CIS, SOC 2, PCI DSS, HIPAA, ISO 27001, NIST CSF, FedRAMP, GDPR, DPDP, an AI workload baseline, and your own frameworks — mapped to live findings, with signed evidence packs for auditors.
Vulnerabilities
Cloud Vulnerability Management
ECR scan-on-push gaps from the control plane, plus package CVEs from opt-in DeepScan or the optional host sensor, prioritized by blast radius.