CAIM is the identity of EWQS’s offensive practice. Technical assessments to understand attack paths, verify controls and turn evidence into remediation priorities.
Offensive findings inform defensive improvements. Defensive evidence refines the next assessment.
TEACHING EXAMPLES · NO REAL DATA
Examples of how deliverables can be structured, using fictional information and no customer data. Findings for each engagement depend on the assessed environment and contracted scope.
Critical, High, Medium and Low are illustrative classifications for these scenarios. CVSS v4.0 requires an evidence-based vector and technical, threat and environmental context; business priority must also be assessed. No scores are calculated in these examples.
CriticalCAIM / EX-01 / CWE-862
Administrative operation without authorization
TEACHING EXAMPLES · NO REAL DATA
Precondition
Authenticated standard account; an administrative API operation is reachable; the server does not verify privileges.
Synthetic evidence — simulation
SIMULATION · test account: operator
POST /api/demo/admin/roles → 200
Fictional result: administrative privilege granted.
Business scenario
In this scenario, a low-privilege account could take over administrative functions and change controls protecting business operations.
Recommendation
Enforce server-side authorization for every sensitive operation, deny by default and validate role, resource and action. Audit privilege changes.
Two test accounts with separate resources; the API accepts an object identifier without checking ownership or organization.
Synthetic evidence — simulation
SIMULATION · session: account A
GET /api/demo/documents/doc-B → 200
Fictional body: a document belonging to account B.
Business scenario
Account isolation would fail, allowing unauthorized document access and disclosure of business information in the proposed scenario.
Recommendation
Enforce object-level authorization on the server and scope queries to the user and organization. Unpredictable identifiers do not replace authorization.
On an adversarial network, sending a session over HTTP could compromise an account. Feasibility depends on transport and effective protections.
Recommendation
Set Secure on session cookies, retain HttpOnly and choose SameSite for the workflow. Review HTTPS, proxy settings and HSTS adoption after assessing subdomains.
This information would assist technology reconnaissance. By itself, it does not demonstrate compromise or justify a higher severity.
Recommendation
Reduce production banners and detailed messages. Maintain a private inventory and update process; hiding versions does not fix vulnerable dependencies.
A deliverable for decisions. Another for implementation.
The executive summary explains exposure and impact. Technical material records scope, evidence, limitations, recommendations and validation conditions.
01Executive summary and contextual prioritization
02Technical record with handled evidence and limitations
03Remediation plan with owners to be agreed
04Retest and residual-risk record, when contracted
Start with the right scope.
Tell us which applications, controls or objectives need assessment. The proposal defines depth, deliverables and execution conditions.