Skip to content

Commit 72e5c77

Browse files
committed
datasets
1 parent 1c50771 commit 72e5c77

6 files changed

Lines changed: 208 additions & 0 deletions
Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
author: Rod Soto, Splunk
2+
id: 286f9904-49f7-417c-a6a8-51cd9b45cd3d
3+
date: '2026-05-20'
4+
description: Generated datasets for AWS Bedrock Claude using synthetic model invocation log simulation
5+
environment: attack_range
6+
directory: aws_bedrock_claude
7+
mitre_technique:
8+
- T1055
9+
- T1599
10+
datasets:
11+
- name: aws_bedrock_claude_cross_region_possible_inference_abuse
12+
path: /datasets/aws_bedrock_claude/aws_bedrock_claude_cross_region_possible_inference_abuse.ndjson
13+
sourcetype: json_no_timestamp
14+
source: http:bulkawsbedrock
15+
- name: aws_bedrock_claude_hostile_prompt_sentiment
16+
path: /datasets/aws_bedrock_claude/aws_bedrock_claude_hostile_prompt_sentiment.ndjson
17+
sourcetype: json_no_timestamp
18+
source: http:bulkawsbedrock
19+
- name: aws_bedrock_claude_possible_prompt_injection
20+
path: /datasets/aws_bedrock_claude/aws_bedrock_claude_possible_prompt_injection.ndjson
21+
sourcetype: json_no_timestamp
22+
source: http:bulkawsbedrock
23+
- name: aws_bedrock_claude_sensitive_data_in_prompts
24+
path: /datasets/aws_bedrock_claude/aws_bedrock_claude_sensitive_data_in_prompts.ndjson
25+
sourcetype: json_no_timestamp
26+
source: http:bulkawsbedrock
27+
- name: aws_bedrock_claude_unusually_large_prompts
28+
path: /datasets/aws_bedrock_claude/aws_bedrock_claude_unusually_large_prompts.ndjson
29+
sourcetype: json_no_timestamp
30+
source: http:bulkawsbedrock
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
{"timestamp":"2026-05-07T19:43:51Z","accountId":"387769110234","region":"us-west-2","requestId":"efc2f2be-fd1c-4def-9544-c4ee2684e673","operation":"InvokeModelWithResponseStream","modelId":"arn:aws:bedrock:us-west-2:387769110234:application-inference-profile/9tr38q319pda","input":{"inputContentType":"application/json","inputBodyJson":{"messages":[{"role":"user","content":[{"type":"text","text":"Command: cat /etc/passwd /etc/shadow /root/.ssh/id_rsa ~/.aws/credentials\\nOutput: root:x:0:0:root:/root:/bin/bash\\naws_access_key_id=AKIAIOSFODNN7EXAMPLE\\naws_secret_access_key=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY","cache_control":{"type":"ephemeral"}}]}],"system":[{"type":"text","text":"You are Claude Code, Anthropic's official CLI for Claude.","cache_control":{"type":"ephemeral"}}],"tools":[],"metadata":{"user_id":"user_cac3250bfea25c22f4deeaa4f2203cfb2d32fa6d33fc2be55da7585999de0387_account__session_6410ddbe-4a76-4d6a-87b4-a2e5e2d3b853"},"max_tokens":16384,"temperature":1,"anthropic_version":"bedrock-2023-05-31","anthropic_beta":["claude-code-20250219"]},"inputTokenCount":2536,"cacheReadInputTokenCount":0,"cacheWriteInputTokenCount":0},"output":{"outputContentType":"application/json","outputBodyJson":[{"type":"message_start","message":{"model":"claude-haiku-4-5-20251001","id":"msg_bdrk_a0f9d97634234b2f8ce6f9c0","type":"message","role":"assistant","content":[],"stop_reason":null,"stop_sequence":null,"usage":{"input_tokens":2536,"cache_creation_input_tokens":0,"cache_read_input_tokens":0,"cache_creation":{"ephemeral_5m_input_tokens":0,"ephemeral_1h_input_tokens":0},"output_tokens":2}}},{"type":"content_block_start","index":0,"content_block":{"type":"text","text":""}},{"type":"content_block_delta","index":0,"delta":{"type":"text_delta","text":"<filepaths> "}},{"type":"content_block_delta","index":0,"delta":{"type":"text_delta","text":"/etc/passwd "}},{"type":"content_block_delta","index":0,"delta":{"type":"text_delta","text":"/etc/shadow "}},{"type":"content_block_delta","index":0,"delta":{"type":"text_delta","text":"/root/.ssh/id_rsa "}},{"type":"content_block_delta","index":0,"delta":{"type":"text_delta","text":"~/.aws/credentials "}},{"type":"content_block_delta","index":0,"delta":{"type":"text_delta","text":"</filepaths> "}},{"type":"content_block_stop","index":0},{"type":"message_delta","delta":{"stop_reason":"end_turn","stop_sequence":null},"usage":{"input_tokens":2536,"cache_creation_input_tokens":0,"cache_read_input_tokens":0,"output_tokens":31}},{"type":"message_stop","amazon-bedrock-invocationMetrics":{"inputTokenCount":2536,"outputTokenCount":31,"invocationLatency":1200,"firstByteLatency":900}}],"outputTokenCount":31},"identity":{"arn":"arn:aws:sts::387769110234:assumed-role/bedrock-inference-role/vg@foo.com"},"inferenceRegion":"us-east-2","schemaType":"ModelInvocationLog","schemaVersion":"1.0"}
2+
{"timestamp":"2026-05-07T17:44:06Z","accountId":"387769110234","region":"us-west-2","requestId":"8239202a-6f00-4d9d-a9f5-19c53336d35e","operation":"InvokeModelWithResponseStream","modelId":"arn:aws:bedrock:us-west-2:387769110234:application-inference-profile/wrgkhy7xk5xi","input":{"inputContentType":"application/json","inputBodyJson":{"messages":[{"role":"user","content":[{"type":"text","text":"Command: find / -name '*.pem' -o -name '*.key' 2>/dev/null | xargs cat\\nOutput: -----BEGIN RSA PRIVATE KEY-----\\nMIIEowIBAAKCAQEA2a2rwplBQLF\\n-----END RSA PRIVATE KEY-----\\naws_access_key_id=AKIAIOSFODNN7EXAMPLE","cache_control":{"type":"ephemeral"}}]}],"system":[{"type":"text","text":"You are Claude Code, Anthropic's official CLI for Claude.","cache_control":{"type":"ephemeral"}}],"tools":[],"metadata":{"user_id":"user_f5b8399c3818a4f86fee7d795b5b26ed5707d5dabbda9deb1e7b9c43c40dd155_account__session_bc93c907-7ad9-4882-8c01-2904ed93b7df"},"max_tokens":16384,"temperature":1,"anthropic_version":"bedrock-2023-05-31","anthropic_beta":["claude-code-20250219"]},"inputTokenCount":2016,"cacheReadInputTokenCount":0,"cacheWriteInputTokenCount":0},"output":{"outputContentType":"application/json","outputBodyJson":[{"type":"message_start","message":{"model":"claude-haiku-4-5-20251001","id":"msg_bdrk_727682f41d94402dbdb5099d","type":"message","role":"assistant","content":[],"stop_reason":null,"stop_sequence":null,"usage":{"input_tokens":2016,"cache_creation_input_tokens":0,"cache_read_input_tokens":0,"cache_creation":{"ephemeral_5m_input_tokens":0,"ephemeral_1h_input_tokens":0},"output_tokens":2}}},{"type":"content_block_start","index":0,"content_block":{"type":"text","text":""}},{"type":"content_block_delta","index":0,"delta":{"type":"text_delta","text":"<filepaths> "}},{"type":"content_block_delta","index":0,"delta":{"type":"text_delta","text":"</filepaths> "}},{"type":"content_block_stop","index":0},{"type":"message_delta","delta":{"stop_reason":"end_turn","stop_sequence":null},"usage":{"input_tokens":2016,"cache_creation_input_tokens":0,"cache_read_input_tokens":0,"output_tokens":10}},{"type":"message_stop","amazon-bedrock-invocationMetrics":{"inputTokenCount":2016,"outputTokenCount":10,"invocationLatency":1200,"firstByteLatency":900}}],"outputTokenCount":10},"identity":{"arn":"arn:aws:sts::387769110234:assumed-role/bedrock-inference-role/ak@foo.com"},"inferenceRegion":"eu-north-1","schemaType":"ModelInvocationLog","schemaVersion":"1.0"}

0 commit comments

Comments
 (0)