Skip to content

Defensive security / ABEL

A.B.E.L.Strengthen controls.Reduce exposure.

ABEL is the identity of EWQS’s defensive practice. Technical guidance to turn risk scenarios into implementable controls, validation criteria and residual-risk decisions.

A.B.E.L. Blue Team: EWQS brand character in dark armor with blue lighting. Abel strengthens defense.
BLUE TEAMStrengthen defense.

ABEL / BLUE TEAM

What the engagement covers

Depth matched to your environment, with useful priorities for decision-makers and implementers.

Control reviews

Assessment of existing controls, gaps and suitability for agreed scenarios and priorities.

Practical hardening

Guidance on application, infrastructure and transport configuration, accounting for compatibility and safe changes.

IAM and authorization

Review of permissions, least privilege, account isolation and access policies for actions and resources.

SOC team guidance

Support for event analysis, detection hypothesis refinement and procedure preparation with the responsible team.

Contract-defined monitoring

Event sources, coverage, operating hours and responsibilities are defined in the proposal. No promise of a 24/7 SOC or guaranteed detection.

Validation and residual risk

Acceptance criteria, retest support and documentation of coverage gaps or risks requiring a decision.

From hypothesis to validated control

A context handover between offensive assessment and defensive improvement, with technical review and human accountability.

  1. Define

    Agree on scope, rules of engagement and business objectives.

  2. Assess

    Test hypotheses and review evidence with explicit limitations.

  3. Remediate

    Prioritize controls, owners and acceptance criteria.

  4. Retest

    Verify scoped fixes and record residual risk.

What one team discovers strengthens the other.

The defensive perspective

From recommendation to control

Offensive findings inform defensive improvements. Defensive evidence refines the next assessment.

TEACHING EXAMPLES · NO REAL DATA

Examples of how deliverables can be structured, using fictional information and no customer data. Findings for each engagement depend on the assessed environment and contracted scope.

Critical, High, Medium and Low are illustrative classifications for these scenarios. CVSS v4.0 requires an evidence-based vector and technical, threat and environmental context; business priority must also be assessed. No scores are calculated in these examples.

CriticalABEL / EX-01 / CWE-862

Administrative operation without authorization

TEACHING EXAMPLES · NO REAL DATA

Proposed control
Action-level authorization and least privilege
Practical mitigation
Centralize authorization policies; deny the operation to standard roles; require approval for sensitive changes and record actor, target and outcome without secrets.
Suggested owner
Backend lead and IAM owner.
Retest criterion
Standard accounts receive 403 with no state change; authorized accounts can perform only permitted actions. Test role revocation and review the audit record.
Residual risk
A compromised administrative account could still abuse legitimate access. Separation of duties, privilege reviews and alerts require their own validation.
View CAIM scenarioEX-01
HighABEL / EX-02 / CWE-639

Access to another account’s object

TEACHING EXAMPLES · NO REAL DATA

Proposed control
Account isolation and object-level authorization
Practical mitigation
Validate organization, owner and permission for reads and writes; apply query scoping and negative cross-account tests. Review export paths.
Suggested owner
Application team, architecture and data owner.
Retest criterion
Account A cannot read or change account B’s objects; test listings, direct access and exports. Denial responses disclose no protected content.
Residual risk
Other routes, caches or asynchronous tasks may retain isolation weaknesses. Retesting covers only the agreed resources.
View CAIM scenarioEX-02
MediumABEL / EX-03 / CWE-614

Session cookie missing the Secure attribute

TEACHING EXAMPLES · NO REAL DATA

Proposed control
Session and transport hardening
Practical mitigation
Configure Secure at the cookie issuer; validate TLS termination and proxy forwarding; remove insecure HTTP paths and plan HSTS with domain owners.
Suggested owner
Backend and platform/infrastructure teams.
Retest criterion
Authentication cookies include Secure during login and renewal; browsers do not send them over HTTP. Legitimate workflows still work and the HTTPS policy is verified.
Residual risk
Secure does not prevent every form of session theft. XSS, session expiration and revocation need separate assessments.
View CAIM scenarioEX-03
LowABEL / EX-04 / CWE-200

Detailed version in a public response

TEACHING EXAMPLES · NO REAL DATA

Proposed control
Information minimization and component management
Practical mitigation
Remove version information at the application or proxy; standardize public errors. Keep component versions in the internal inventory and review applicable updates.
Suggested owner
Platform and application owners.
Retest criterion
Normal and error responses do not disclose detailed versions at agreed points. Verify that internal support and diagnostics remain available.
Residual risk
Behavior-based fingerprinting may remain possible. Removing banners reduces information but does not replace updates or hardening.
View CAIM scenarioEX-04

EWQS / DELIVERABLES

A deliverable for decisions. Another for implementation.

The executive summary explains exposure and impact. Technical material records scope, evidence, limitations, recommendations and validation conditions.

  • Executive summary and contextual prioritization
  • Technical record with handled evidence and limitations
  • Remediation plan with owners to be agreed
  • Retest and residual-risk record, when contracted

Start with the right scope.

Tell us which applications, controls or objectives need assessment. The proposal defines depth, deliverables and execution conditions.

Discuss your project