Step 1Collect the attack paths
From pentests, bounty reports and threat models.
ATALAIANine attack paths from your pentests and bounty. These are real. They worked.
OFFENSIVEThe IDOR on /redeem is the one we'd try again.
Leaves the room9 attack paths from pentests and bounty
Step 2Find the signal
Which log, event or metric would show each one.
SOCWhat would that look like in our logs?
ATALAIAOne user asking for offers owned by many others. But /redeem doesn't log the owner.
DEV LEADWe'll add the owner ID to the access log this sprint.
Leaves the roomSignal: user ≠ owner on /redeem
Step 3Write and test
Rules, then attack simulations that prove they fire.
ATALAIARule: one user, more than five foreign offer IDs in ten minutes.
OFFENSIVERunning the attack in staging now.
SOCAlert fired. Forty seconds.
Leaves the roomRule written, simulation fired
Step 4Tune with the SOC
Thresholds and runbooks the analysts agree with.
SOCSupport agents will trip it. They look up offers all day.
ATALAIAThen exclude the support role and keep it for everyone else. Here's the runbook.
Leaves the roomRunbook, threshold agreed
- SOC
- ATALAIA
- OFFENSIVE
- DEV LEAD