Views:

A list of demo models to trigger Workbench alerts for your cloud account.

The following are a list of demonstration models used to test your XDR for Cloud - AWS VPC Flow Logs integration. Running the listed models creates an alert in the Workbench app.

Demo Model - Network connection to known suspicious IP address

Use these steps to trigger the detection model and create a Workbench alert.

Procedure

  1. Create a batch file with the following command.
    ping 5.135.115.193
  2. Sign in to the AWS account you want to use to test XDR for Cloud - VPC Flow Logs.
  3. Set up an EC2 instance.
  4. Connect to the EC2 instance and run the batch file.
  5. In the Trend Vision One console, go to XDR Threat InvestigationWorkbench to view the generated alert.