Skip to main content10ETLabsRequest demo

AI security

AI workload security

See how an attacker reaches your models — not just a list of AI misconfigurations.

10ETLabs reads AI services the same way it reads buckets and clusters: a read-only API inventory. It then links each model to the buckets it trains on and loads weights from, and to the IAM role it runs as, and links each Bedrock agent to its knowledge bases, their S3 data sources, and the Lambda functions its action groups call. That turns single findings into attack paths: an internet-facing notebook whose role is account admin, a public bucket feeding a fine-tuned model or an agent’s knowledge base, an agent whose action-group Lambda runs as admin, SageMaker data capture (recorded inference requests and responses) written to a public bucket. For prompt-level risks, the open-source 10et-ai-test CLI runs prompt-injection, leakage and tool-abuse tests that you run yourself, on your machine or in CI with your own credentials. 10ETLabs never calls your models; you can upload just the pass/fail verdicts to see them next to the asset.

Security analyst reviewing an AI attack-path graph on a workstation

AI security

SageMaker, Bedrock, Azure AI Foundry and Vertex AI linked to the buckets they train on, the images they serve and the identities they run as.

See it work

Two more paths to a model, hop by hop

Each hop is a setting we read from SageMaker, S3, or IAM. The path exists only when every hop does.

AI attack paths · SageMaker

01Public artifact bucket

The bucket holding model artifacts is public, per its bucket policy or ACL.

Illustrative resource names. Paths today cover AWS SageMaker, Bedrock custom models, agents and knowledge bases, and Lambda URLs with no auth; Azure ML and AI Foundry endpoints, models, training jobs, data connections and compute instances; and Vertex AI models, training and tuning jobs, Vector Search, RAG corpora, Agent Engine and Workbench.

What you get

AI service inventory

SageMaker notebooks and endpoints, Bedrock custom models, agents, and knowledge bases; Azure OpenAI and AI Services deployments, AI Foundry hubs and projects, Azure ML online endpoints, models, jobs and compute instances, AI Search; Vertex AI endpoints, models, datasets, training and tuning jobs, Vector Search, feature stores, RAG corpora, Agent Engine, and Workbench land in the AI category with the rest of the estate.

Public path checks

Direct internet or public IPs on notebooks and Workbench, endpoints reachable from the internet, key-based auth on Azure AI accounts, deployments with content filtering off, and registries with anonymous pull become findings in the AI category.

AI attack paths

Every path is built from evidence we collected — a real link between the model, its bucket, and its role. If we could not read a hop, there is no path.

Prompt tests you run

The 10et-ai-test CLI tests OpenAI-compatible APIs, Azure OpenAI, Bedrock models and agents, Vertex AI and your own HTTP apps for prompt injection, system-prompt and data leakage, jailbreaks, tool abuse, unsafe output and runaway token use (OWASP LLM Top 10), with canaries instead of harmful content. It runs where your credentials are; only verdicts are uploaded, and only if you choose.

Honest scope

We read configuration, never prompts or weights, and never invoke your models. On-demand Bedrock calls leave no control-plane trace, so Bedrock region checks run only where custom models, provisioned throughput, guardrails, or logging exist. Agents and knowledge bases are read wherever Bedrock Agents is offered.

In this module

  1. Step 1

    Inventory the model plane

    SageMaker, Bedrock, Azure AI Foundry, Azure OpenAI, Azure ML and Vertex AI models, endpoints, jobs, notebooks, and agents land in category AI.

  2. Step 2

    Link the supply chain

    Models are joined to their training data and artifact buckets or containers, the jobs that produced them, their serving images, and the role, managed identity or service account they run as; agents and indexes to their retrieval sources. Exposed links become AI attack paths.

  3. Step 3

    Open AI inventory

    Triage under the same RBAC as any finding. Prompts and weights are not collected.

In this release

  • SageMaker notebook, endpoint, and model inventory
  • Bedrock custom models, guardrails, and invocation logging
  • Bedrock agents and knowledge bases: roles, guardrails, encryption, action-group Lambdas, and S3 data sources
  • AI attack paths: public training data, public model artifacts, over-privileged notebooks, knowledge bases fed from public buckets, agents whose action groups run as admin
  • Azure AI Foundry and Vertex AI supply chain: training data, artifacts, images, identities
  • 10ET AI Workload Baseline compliance framework
  • Customer-run prompt test CLI (10et-ai-test): verdicts linked to AI assets as findings and baseline controls
Request a demo

On the roadmap

    Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.

    More of the platform

    Other modules — not a reprint of this page.