ABEL is the identity of EWQS’s defensive practice. Technical guidance to turn risk scenarios into implementable controls, validation criteria and residual-risk decisions.
Offensive findings inform defensive improvements. Defensive evidence refines the next assessment.
TEACHING EXAMPLES · NO REAL DATA
Examples of how deliverables can be structured, using fictional information and no customer data. Findings for each engagement depend on the assessed environment and contracted scope.
Critical, High, Medium and Low are illustrative classifications for these scenarios. CVSS v4.0 requires an evidence-based vector and technical, threat and environmental context; business priority must also be assessed. No scores are calculated in these examples.
CriticalABEL / EX-01 / CWE-862
Administrative operation without authorization
TEACHING EXAMPLES · NO REAL DATA
Proposed control
Action-level authorization and least privilege
Practical mitigation
Centralize authorization policies; deny the operation to standard roles; require approval for sensitive changes and record actor, target and outcome without secrets.
Suggested owner
Backend lead and IAM owner.
Retest criterion
Standard accounts receive 403 with no state change; authorized accounts can perform only permitted actions. Test role revocation and review the audit record.
Residual risk
A compromised administrative account could still abuse legitimate access. Separation of duties, privilege reviews and alerts require their own validation.
Configure Secure at the cookie issuer; validate TLS termination and proxy forwarding; remove insecure HTTP paths and plan HSTS with domain owners.
Suggested owner
Backend and platform/infrastructure teams.
Retest criterion
Authentication cookies include Secure during login and renewal; browsers do not send them over HTTP. Legitimate workflows still work and the HTTPS policy is verified.
Residual risk
Secure does not prevent every form of session theft. XSS, session expiration and revocation need separate assessments.
Remove version information at the application or proxy; standardize public errors. Keep component versions in the internal inventory and review applicable updates.
Suggested owner
Platform and application owners.
Retest criterion
Normal and error responses do not disclose detailed versions at agreed points. Verify that internal support and diagnostics remain available.
Residual risk
Behavior-based fingerprinting may remain possible. Removing banners reduces information but does not replace updates or hardening.
A deliverable for decisions. Another for implementation.
The executive summary explains exposure and impact. Technical material records scope, evidence, limitations, recommendations and validation conditions.
01Executive summary and contextual prioritization
02Technical record with handled evidence and limitations
03Remediation plan with owners to be agreed
04Retest and residual-risk record, when contracted
Start with the right scope.
Tell us which applications, controls or objectives need assessment. The proposal defines depth, deliverables and execution conditions.