Skip to main content

Demo Contrast CVE Shield

Use this workflow to automatically download an application, instrument it, create an exploit, and clean up within minutes using the Agent Wizard. See CVE Shield detect a real vulnerability without instrumenting anything of your own.

You'll need an active CVE Shield account. Learn more about CVE Shield, Review Contrast CVE Shield states, trying Contrast for free, signing up for CVE Shield, and available CLI commands in NorthstarNorthstar.

Before you begin

Make sure you have everything you need before you start.

  • macOS or Linux with a UI and browser

  • Homebrew

  • Docker Engine

  • Docker Desktop (optional)

  • A Contrast account and the URL of your Contrast instance

  • A web browser on the same machine for signing in to Contrast

Run a CVE Shield demo

  1. In NorthstarNorthstar, select Try with a Demo App.

  2. Choose whether you want the demo to run automatically or guide you through each step manually.

  3. Run the CLI commands displayed in the wizard.

View the results of a guided demo

When you run the demo in guided mode, you can walk through the results of each step of the process.

  1. In NorthstarNorthstar, go to Explorer > CVEs.

  2. Search for CVE-2021-45046. You'll see its CVE Shield status, the affected library and version, and which of your environments it affects.

  3. Go to Observations to see an Exposed observation for CVE-2021-45046 that tells you that the vulnerable library code has been reached, but nothing malicious has happened yet.

  4. Following the exploit request, refresh Observations. A new entry appears with a result of Exploited for the CVE.

  5. Select that entry to open the individual observation, then look at the What happened? section to see exactly which request was intercepted.

  6. Refresh Explorer > CVEs. The CVE's status also updates to Exploited.