Step 1Learn the stack
Languages, packages, clouds, vendors and exposed services.
ATALAIANode, Postgres, two clouds, nine vendors. That's the watch list.
APPSECAdd the partner SDK. It's in every build.
Leaves the roomWatch list: 212 packages, 2 clouds, 9 vendors
Step 2Watch what matters
Sources filtered to that stack, not the whole internet.
ATALAIAA zero-day this morning in an XML parser. It's on our list.
Leaves the roomSources filtered to the stack
Step 3Ask the right team
SOC: do we see it? AppSec: are we exposed? Offensive: can we test it?
ATALAIASOC: do we see exploit attempts?
SOCNothing in the gateway logs so far. Rule added.
ATALAIAAppSec: are we exposed?
APPSECThe partner callback parser uses it. Affected version.
ATALAIAOffensive: can you test it tonight?
OFFENSIVEOn staging, tonight.
Leaves the room3 questions, 3 teams
Step 4Report the answer
Affected or not, what we did, what's next.
OFFENSIVEThe exploit works on the old version, not on the patched one.
ATALAIAAffected, patched in six hours, monitored. One paragraph for leadership.
Leaves the roomAffected: yes, patched in 6 hours
- ATALAIA
- APPSEC
- SOC
- OFFENSIVE