Cybersecurity Analyst Skill
Purpose
Analyze events through the disciplinary lens of cybersecurity, applying rigorous security frameworks (CIA triad, defense-in-depth, zero-trust), threat modeling methodologies (STRIDE, PASTA, VAST), attack surface analysis, and industry standards (NIST, ISO 27001, MITRE ATT&CK) to understand security risks, identify vulnerabilities, assess threat actors and attack vectors, evaluate defensive controls, and recommend risk mitigation strategies.
When to Use This Skill
- Security Incident Analysis: Investigate breaches, data leaks, ransomware attacks, insider threats
- Vulnerability Assessment: Identify weaknesses in systems, applications, networks, processes
- Threat Modeling: Analyze potential attack vectors and threat actors for new systems or changes
- Security Architecture Review: Evaluate design decisions for security implications and gaps
- Risk Assessment: Quantify and prioritize security risks using frameworks like CVSS, FAIR
- Compliance Analysis: Assess adherence to security standards (SOC 2, PCI-DSS, HIPAA, GDPR)
- Incident Response Planning: Design detection, containment, eradication, and recovery strategies
- Security Posture Evaluation: Assess overall defensive capabilities and maturity
- Code Security Review: Identify security vulnerabilities in software implementations
Core Philosophy: Security Thinking
Cybersecurity analysis rests on fundamental principles:
Defense in Depth: No single security control is perfect. Layer multiple independent controls so compromise of one doesn't compromise the whole system.
Assume Breach: Modern security assumes attackers will penetrate perimeter defenses. Design systems to minimize damage and enable detection when (not if) breach occurs.
Least Privilege: Grant minimum access necessary for legitimate function. Every excess permission is an opportunity for exploitation.
Zero Trust: Never trust, always verify. Verify explicitly, use least privilege access, and assume breach regardless of network location.
Security by Design: Security cannot be bolted on afterward. It must be fundamental to architecture and implementation from the beginning.
CIA Triad: Security protects three properties—Confidentiality (only authorized access), Integrity (only authorized modification), Availability (accessible when needed).
Threat-Informed Defense: Base defensive priorities on understanding of actual threat actors, their capabilities, motivations, and tactics (threat intelligence).
Risk-Based Approach: Perfect security is impossible. Prioritize security investments based on risk (likelihood × impact) to maximize security per dollar spent.
Theoretical Foundations (Expandable)
Foundation 1: CIA Triad (Classic Security Model)
Components:
Confidentiality: Information accessible only to authorized entities
- Protection mechanisms: Encryption, access controls, authentication
- Threats: Eavesdropping, data theft, unauthorized disclosure
- Example violations: Data breach, password theft, insider leak
Integrity: Information modifiable only by authorized entities in authorized ways
- Protection mechanisms: Hashing, digital signatures, access controls, version control
- Threats: Tampering, unauthorized modification, malware
- Example violations: Database manipulation, man-in-the-middle attacks, ransomware encryption
Availability: Information and systems accessible when needed by authorized entities
- Protection mechanisms: Redundancy, backups, DDoS mitigation, incident response
- Threats: Denial of service, ransomware, system destruction
- Example violations: DDoS attacks, ransomware, infrastructure failures
Extensions:
- Authenticity: Verified identity of entities and origin of information
- Non-repudiation: Cannot deny taking action
- Accountability: Actions traceable to entities
Application: Every security analysis should identify which aspects of CIA triad are at risk and how controls protect each.
Sources:
Foundation 2: Defense in Depth (Layered Security)
Principle: Deploy multiple layers of security controls so compromise of one layer doesn't compromise entire system.
Historical Origin: Military defensive strategy—multiple concentric perimeter defenses
Security Layers:
- Physical: Facility access controls, locked server rooms
- Network: Firewalls, network segmentation, IDS/IPS
- Host: Endpoint protection, host firewalls, patch management
- Application: Input validation, secure coding, authentication
- Data: Encryption at rest and in transit, DLP, tokenization
- Human: Security awareness training, phishing simulation
Key Insight: Redundancy is not waste—it's resilience. Even if attacker bypasses firewall, they still face authentication, authorization, monitoring, encryption, and detection controls.
Application: Security architecture should have multiple independent defensive layers protecting critical assets.
Limitation: Can create complexity and false sense of security if layers are not maintained or are interdependent.
Sources:
Foundation 3: Zero Trust Architecture
Core Principle: "Never trust, always verify" regardless of network location
Contrast with Perimeter Model: Traditional security assumed internal network is trusted ("castle and moat"). Zero trust assumes no network location is trusted.
Key Tenets (NIST SP 800-207):
- Verify explicitly: Always authenticate and authorize based on all available data points
- Least privilege access: Limit user access with Just-In-Time and Just-Enough-Access
- Assume breach: Minimize blast radius and segment access; verify end-to-end encryption
Components:
- Identity-centric security: Identity becomes new perimeter
- Micro-segmentation: Network divided into small zones with separate controls
- Continuous verification: Authentication and authorization are continuous, not one-time
- Data-centric: Protect data itself, not just perimeter around it
Drivers:
- Cloud adoption (no clear perimeter)
- Remote work (users outside traditional perimeter)
- Sophisticated attacks (perimeter breaches common)
Application: Modern security architectures should be designed with zero trust principles, especially for cloud and hybrid environments.
Sources:
Foundation 4: Threat Modeling
Definition: Structured approach to identify and prioritize potential threats to a system
Purpose: Proactively identify security issues during design phase when fixes are cheapest
Benefits:
- Find vulnerabilities before implementation
- Prioritize security work
- Communicate risks to stakeholders
- Guide security testing
Common Methodologies:
STRIDE (Microsoft):
- Spoofing identity
- Tampering with data
- Repudiation
- Information disclosure
- Denial of service
- Elevation of privilege
PASTA (Process for Attack Simulation and Threat Analysis):
- Seven-stage risk-centric methodology
- Aligns business objectives with technical requirements
VAST (Visual, Agile, and Simple Threat modeling):
- Scalable for agile development
- Two types: application threat models and operational threat models
Application: Use threat modeling for new features, architecture changes, or security reviews.
Sources:
Foundation 5: MITRE ATT&CK Framework
Description: Knowledge base of adversary tactics and techniques based on real-world observations
Purpose: Understand how attackers operate to inform defense, detection, and threat hunting
Structure:
- Tactics: High-level goals (e.g., Initial Access, Execution, Persistence, Privilege Escalation)
- Techniques: Ways to achieve tactics (e.g., Phishing, Exploiting Public Applications)
- Sub-techniques: Specific implementations
- Procedures: Specific attacker behaviors
14 Tactics (Enterprise Matrix):
- Reconnaissance
- Resource Development
- Initial Access
- Execution
- Persistence
- Privilege Escalation
- Defense Evasion
- Credential Access
- Discovery
- Lateral Movement
- Collection
- Command and Control
- Exfiltration
- Impact
Application:
- Map defensive controls to ATT&CK techniques
- Identify detection gaps
- Threat intelligence sharing
- Red team/purple team exercises
Value: Common language for describing attacker behavior; basis for threat-informed defense
Sources:
Core Analytical Frameworks (Expandable)
Framework 1: Attack Surface Analysis
Definition: Identification and assessment of all points where unauthorized user could enter or extract data from system
Components:
Attack Surface Elements:
- Network attack surface: Exposed ports, services, protocols
- Software attack surface: Applications, APIs, web interfaces
- Human attack surface: Users, administrators, social engineering targets
- Physical attack surface: Facility access, hardware access
Attack Vectors: Methods attackers use to exploit attack surface
- Network-based: Port scanning, protocol exploits, man-in-the-middle
- Web-based: SQL injection, XSS, CSRF, authentication bypass
- Email-based: Phishing, malicious attachments, credential harvesting
- Physical: Theft, unauthorized access, evil maid attacks
- Social engineering: Pretexting, baiting, tailgating
Analysis Process:
- Enumerate: List all entry points and assets
- Classify: Categorize by type and criticality
- Assess: Evaluate exploitability and impact
- Prioritize: Rank by risk
- Reduce: Minimize unnecessary exposure
Metrics:
- Number of exposed services
- Number of internet-facing applications
- Number of privileged accounts
- Lines of code exposed to untrusted input
Application: Reducing attack surface is fundamental defensive strategy. Eliminate unnecessary exposure.
Sources:
Framework 2: Risk Assessment Frameworks
Purpose: Quantify and prioritize security risks to guide resource allocation
Common Frameworks:
CVSS (Common Vulnerability Scoring System):
- Standard for assessing vulnerability severity
- Score 0-10 based on exploitability, impact, scope
- Base score (intrinsic characteristics) + temporal + environmental scores
- Widely used but criticized for not capturing actual risk in specific contexts
FAIR (Factor Analysis of Information Risk):
- Quantitative risk framework
- Risk = Loss Event Frequency × Loss Magnitude
- Enables cost-benefit analysis of security investments
- More complex but provides dollar-denominated risk figures
NIST Risk Management Framework (RMF):
- Seven steps: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor
- Links security controls to risk management
- Used by U.S. federal agencies
Qualitative vs. Quantitative:
- Qualitative: High/Medium/Low risk ratings (simpler, faster, subjective)
- Quantitative: Numerical risk values (complex, objective, requires data)
Application: Risk assessment informs prioritization. Not all vulnerabilities are equally important—focus on highest risks.
Sources:
Framework 3: Security Control Frameworks
Purpose: Structured set of security controls to achieve security objectives
Major Frameworks:
NIST Cybersecurity Framework:
- Five core functions: Identify, Protect, Detect, Respond, Recover
- Not prescriptive—flexible for different organizations
- Widely adopted across industries and internationally
NIST SP 800-53 (Security and Privacy Controls):
- Comprehensive catalog of security controls for federal systems
- 20 control families (Access Control, Incident Response, etc.)
- Detailed implementation guidance
CIS Controls (Center for Internet Security):
- 18 prioritized security controls
- Implementation groups (IG1, IG2, IG3) based on organizational maturity
- Actionable and measurable
ISO/IEC 27001:
- International standard for information security management systems
- 14 control domains, 114 controls
- Certification available
Application: Use frameworks to:
- Ensure comprehensive coverage
- Benchmark security posture
- Communicate with stakeholders
- Meet compliance requirements
Sources:
Framework 4: Incident Response Lifecycle
Definition: Structured approach to handling security incidents
Standard Model (NIST SP 800-61):
Phase 1: Preparation
- Establish IR capability, tools, playbooks
- Training and exercises
- Communication plans
Phase 2: Detection and Analysis
- Monitoring and alerting
- Incident classification and prioritization
- Initial investigation
- Scope determination
Phase 3: Containment, Eradication, and Recovery
- Containment: Stop spread (short-term and long-term)
- Eradication: Remove threat from environment
- Recovery: Restore systems to normal operation
Phase 4: Post-Incident Activity
- Lessons learned
- Evidence preservation
- Incident report
- Process improvement
Key Concepts:
- Playbooks: Predefined procedures for common incident types
- Indicators of Compromise (IoCs): Artifacts indicating malicious activity
- Chain of custody: Evidence handling procedures
- Communication: Internal and external stakeholders, legal, PR
Metrics:
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Mean Time to Contain (MTTC)
Application: Effective incident response minimizes damage, reduces recovery time, and captures learning.
Sources:
Framework 5: Secure Development Lifecycle (SDL)
Purpose: Integrate security into software development process
Microsoft SDL Phases:
- Training: Security training for developers
- Requirements: Define security requirements and privacy requirements
- Design: Threat modeling, attack surface reduction, defense in depth
- Implementation: Secure coding standards, code analysis tools
- Verification: Security testing (SAST, DAST, penetration testing)
- Release: Final security review, incident response plan
- Response: Execute incident response plan if vulnerability discovered
Key Practices:
- Static Analysis (SAST): Analyze source code for vulnerabilities
- Dynamic Analysis (DAST): Test running application
- Dependency Scanning: Check third-party libraries for known vulnerabilities
- Penetration Testing: Simulate real attacks
- Security Champions: Embed security expertise in development teams
OWASP SAMM (Software Assurance Maturity Model):
- Maturity model for secure software development
- Five business functions: Governance, Design, Implementation, Verification, Operations
- Three maturity levels for each function
Application: Security must be integrated throughout development lifecycle, not just at the end.
Sources:
Methodological Approaches (Expandable)
Method 1: Threat Intelligence Analysis
Purpose: Understand adversaries, their capabilities, tactics, and targets to inform defense
Types of Threat Intelligence:
Strategic: High-level trends for executives
- APT group activity and motivations
- Geopolitical cyber threats
- Industry-specific threat landscape
Operational: Campaign-level information for security operations
- Current attack campaigns
- Threat actor TTPs
- Malware families
Tactical: Technical indicators for immediate defense
- IP addresses, domains, file hashes
- YARA rules, Snort signatures
- CVEs being exploited
Analytical Process:
- Collection: Gather data from internal sources, threat feeds, OSINT, dark web
- Processing: Normalize, correlate, deduplicate
- Analysis: Contextualize, attribute, assess intent and capability
- Dissemination: Share with relevant teams in actionable format
- Feedback: Assess effectiveness and refine
Frameworks:
- Diamond Model: Adversary, Capability, Infrastructure, Victim
- Kill Chain: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → C2 → Actions on Objectives
- MITRE ATT&CK: Map observed techniques to ATT&CK matrix
Application: Threat intelligence enables proactive, threat-informed defense rather than generic security measures.
Sources:
Method 2: Penetration Testing
Definition: Authorized simulated attack to evaluate security of systems
Types:
Black Box: No prior knowledge (simulates external attacker)
Gray Box: Partial knowledge (simulates insider or compromised user)
White Box: Full knowledge (comprehensive security assessment)
Phases (Penetration Testing Execution Standard):
- Pre-engagement: Scope, rules of engagement, legal agreements
- Intelligence gathering: OSINT, network scanning, service enumeration
- Threat modeling: Identify potential attack vectors
- Vulnerability analysis: Identify exploitable weaknesses
- Exploitation: Attempt to exploit vulnerabilities
- Post-exploitation: Assess impact, lateral movement, privilege escalation
- Reporting: Document findings, demonstrate impact, provide remediation guidance
Specialized Types:
- Web application penetration testing: Focus on OWASP Top 10
- Network penetration testing: Internal and external network
- Social engineering: Phishing, vishing, physical intrusion
- Wireless penetration testing: WiFi security assessment
Red Team vs. Penetration Testing:
- Penetration testing: Find as many vulnerabilities as possible
- Red teaming: Goal-oriented (e.g., access specific data), simulates APT, tests detection and response
Application: Regular penetration testing validates effectiveness of controls and identifies gaps before attackers do.
Sources:
Method 3: Security Architecture Review
Purpose: Evaluate system design for security properties and identify architectural vulnerabilities
Review Dimensions:
Structural Analysis:
- Trust boundaries and data flows
- Authentication and authorization architecture
- Network segmentation and isolation
- Data classification and protection
Threat Modeling:
- Apply STRIDE or other methodology
- Identify attack trees
- Assess mitigations for identified threats
Control Assessment:
- Map controls to CIA triad
- Evaluate defense-in-depth layers
- Identify single points of failure
Compliance Review:
- Check against security frameworks (NIST, CIS, ISO)
- Regulatory requirements (PCI-DSS, HIPAA, SOC 2)
Technology Assessment:
- Cryptographic implementation
- Secure protocols
- Patch management approach
- Secret management
Analysis Questions:
- What are trust boundaries?
- Where does sensitive data flow?
- How is authentication/authorization enforced?
- What happens if component X is compromised?
- Are security assumptions documented and validated?
Outputs:
- Architecture diagrams with security annotations
- Threat model
- Risk assessment
- Remediation recommendations
Application: Architecture review during design phase prevents expensive security issues in production.
Method 4: Vulnerability Assessment and Management
Purpose: Systematically identify, classify, prioritize, and remediate security weaknesses
Process:
Phase 1: Discovery
- Asset inventory (what do we have?)
- Vulnerability scanning (automated tools)
- Manual security testing
- Code review (static analysis)
Phase 2: Assessment
- Classify vulnerabilities by type and severity
- Assess exploitability (is there exploit code? Is it being exploited?)
- Determine impact (what data/systems at risk?)
- Calculate risk score (CVSS, contextual factors)
Phase 3: Prioritization
- Rank by risk (likelihood × impact)
- Consider threat intelligence (is it being exploited in wild?)
- Business criticality of affected assets
- Remediation complexity
Phase 4: Remediation
- Patching (ideal)
- Configuration changes
- Compensating controls (if patching impossible)
- Accept risk (document and approve)
Phase 5: Verification
- Rescan to confirm remediation
- Update vulnerability database
- Track metrics (time to remediate, vulnerability density)
Challenges:
- Alert fatigue (too many findings)
- False positives
- Patching disruption
- Legacy systems
Best Practices:
- Risk-based prioritization (not just CVSS)
- SLA-based remediation (Critical: 7 days, High: 30 days, etc.)
- Automate where possible
- Track trends and metrics
Application: Continuous vulnerability management is essential hygiene. Can't fix what you don't know about.
Sources:
Method 5: Security Monitoring and Detection Engineering
Purpose: Design and operate capabilities to detect malicious activity
Components:
Data Sources:
- Network traffic (NetFlow, full packet capture)
- Endpoint logs (process creation, file access, registry changes)
- Authentication logs (logins, privilege escalation)
- Application logs (errors, transactions)
- Cloud APIs and audit logs
Detection Mechanisms:
Signature-based: Known malicious patterns (antivirus, IDS signatures)
- Pros: Low false positives, fast
- Cons: Only detects known threats
Anomaly-based: Deviations from baseline behavior
- Pros: Can detect novel attacks
- Cons: High false positives, requires tuning
Heuristic-based: Rules based on attacker behavior patterns
- Pros: Detects variations of known attacks
- Cons: Requires security expertise to create rules
Threat intelligence-based: Match against known IoCs
- Pros: Leverages collective knowledge
- Cons: Reactive (indicators discovered post-compromise)
Detection Development:
- Understand attacker technique (MITRE ATT&CK)
- Identify data sources that capture technique
- Develop detection logic
- Test against true positives and false positives
- Tune threshold and logic
- Document detection and response procedures
- Monitor effectiveness and iterate
SIEM and SOC:
- SIEM: Aggregate, correlate, and analyze security logs
- SOC: Security Operations Center—team that monitors alerts and responds to incidents
Metrics:
- Detection coverage (% of ATT&CK techniques covered)
- Alert volume and quality
- False positive rate
- Mean Time to Detect (MTTD)
Application: You can't respond to what you don't detect. Invest in detection capabilities aligned to threats you face.
Sources:
Analysis Rubric
What to Examine
Assets and Data:
- What sensitive data exists? (PII, credentials, trade secrets, financial data)
- Where is it stored, processed, transmitted?
- Who has access?
- What is business impact if compromised? (confidentiality, integrity, availability)
Attack Surface:
- What systems are exposed to internet?
- What are entry points for attackers?
- What authentication is required?
- What third-party dependencies exist?
Threat Actors:
- Who might target this? (Nation-states, cybercriminals, hacktivists, insiders)
- What are their capabilities and motivations?
- What TTPs do they typically use?
- What threat intelligence exists?
Vulnerabilities:
- Known software vulnerabilities (CVEs)?
- Configuration weaknesses?
- Architectural security flaws?
- Code-level vulnerabilities?
- Human vulnerabilities (phishing susceptibility)?
Existing Controls:
- What security controls are in place?
- Do they follow defense-in-depth principles?
- Are they properly configured and maintained?
- What detection and response capabilities exist?
Questions to Ask
Threat Questions:
- What could go wrong?
- What are most likely attack vectors?
- What threat actors might target this?
- What are their goals and capabilities?
- What historical incidents are relevant?
Vulnerability Questions:
- What weaknesses exist?
- How exploitable are they?
- What is impact if exploited?
- Are there known exploits or active exploitation?
- How quickly can vulnerabilities be remediated?
Control Questions:
- What protections are in place?
- How effective are they?
- What gaps exist in defensive coverage?
- Can controls be bypassed?
- How will malicious activity be detected?
Risk Questions:
- What is likelihood of compromise?
- What is potential impact?
- What is overall risk level?
- How does risk compare to organization's risk appetite?
- What risk treatment options exist? (mitigate, accept, transfer, avoid)
Compliance Questions:
- What regulations or standards apply?
- Are security requirements met?
- What evidence demonstrates compliance?
- What gaps exist?
Factors to Consider
Technical Factors:
- System architecture and design
- Technology stack and versions
- Configuration and hardening
- Cryptographic implementation
- Network topology and segmentation
Organizational Factors:
- Security maturity and culture
- Available resources and budget
- Risk tolerance
- Regulatory environment
- Business criticality
Threat Landscape:
- Current threat actor activity
- Emerging attack techniques
- Industry-specific threats
- Geopolitical factors
Operational Factors:
- Patch management processes
- Incident response capabilities
- Security monitoring and detection
- Security awareness and training
- Third-party risk management
Historical Parallels to Consider
- Similar security incidents
- Comparable vulnerability exploits
- Industry-specific attack patterns
- Lessons from major breaches
- Evolution of threat actor TTPs
Implications to Explore
Immediate Security Implications:
- Confidentiality: Data breach risk
- Integrity: Data tampering or corruption risk
- Availability: Service disruption risk
- Financial: Ransom, recovery costs, fines
Broader Implications:
- Reputation damage
- Legal and regulatory consequences
- Customer trust erosion
- Competitive disadvantage
- Systemic risk (if in critical infrastructure)
Strategic Implications:
- Security architecture changes needed
- Security program maturity gaps
- Resource allocation and prioritization
- Risk management approach
Step-by-Step Analysis Process
Step 1: Define Scope and Context
Actions:
- Clearly identify system, application, or event being analyzed
- Determine boundaries and interfaces
- Identify stakeholders and their security requirements
- Understand business context and criticality
- Gather relevant documentation (architecture diagrams, data flows, policies)
Outputs:
- Scope statement
- Asset inventory
- Stakeholder list
- Business context understanding
Step 2: Identify Assets and Data
Actions:
- List critical assets (systems, data, services)
- Classify data by sensitivity (public, internal, confidential, restricted)
- Map data flows (where data is created, stored, processed, transmitted, destroyed)
- Identify crown jewels (most valuable assets)
Outputs:
- Asset inventory with criticality ratings
- Data classification matrix
- Data flow diagrams
- Crown jewels list
Step 3: Analyze Attack Surface
Actions:
- Enumerate all entry points (APIs, web interfaces, network services, physical access)
- Identify trust boundaries (where untrusted input crosses into trusted zones)
- Map authentication and authorization points
- Identify dependencies (third-party services, libraries, suppliers)
Outputs:
- Attack surface map
- Trust boundary diagram
- Entry point inventory
- Dependency list
Step 4: Conduct Threat Modeling
Actions:
- Select threat modeling methodology (STRIDE, PASTA, etc.)
- Identify potential threat actors and their goals
- Enumerate potential attack vectors for each asset
- Create attack trees showing attack paths
- Map to MITRE ATT&CK techniques
Outputs:
- Threat model document
- Threat actor profiles
- Attack tree diagrams
- ATT&CK technique mapping
Step 5: Identify Vulnerabilities
Actions:
- Review known CVEs for technologies in use
- Analyze configuration against security benchmarks (CIS, STIGs)
- Review architecture for security design flaws
- Consider code-level vulnerabilities (if applicable)
- Assess human vulnerabilities (phishing susceptibility, privilege misuse)
Outputs:
- Vulnerability inventory
- CVSS scores or risk ratings
- Configuration gap analysis
- Architectural security issues
Step 6: Assess Existing Controls
Actions:
- Inventory security controls across all layers (network, host, application, data)
- Map controls to threats (which threats do controls mitigate?)
- Evaluate control effectiveness (properly configured? maintained? monitored?)
- Identify control gaps (threats without adequate mitigation)
- Assess detection and response capabilities
Outputs:
- Control inventory
- Threat-control mapping matrix
- Control effectiveness assessment
- Detection coverage gaps
Step 7: Analyze Risk
Actions:
- For each threat-vulnerability pair, estimate likelihood and impact
- Calculate risk scores (qualitative or quantitative)
- Prioritize risks
- Compare to organizational risk tolerance
- Consider risk interdependencies and cascading effects
Outputs:
- Risk register
- Risk heat map
- Prioritized risk list
- Risk acceptance recommendations
Step 8: Evaluate Detection and Response
Actions:
- Assess what malicious activities would be detected
- Evaluate MTTD (Mean Time to Detect) for various attack scenarios
- Review incident response plans and playbooks
- Assess incident response team capabilities
- Identify gaps in detection or response
Outputs:
- Detection coverage assessment
- MTTD estimates
- IR capability assessment
- Detection and response gaps
Step 9: Develop Remediation Recommendations
Actions:
- Propose mitigations for identified risks (preventive, detective, corrective)
- Prioritize by risk reduction and implementation effort
- Consider compensating controls where direct mitigation is impractical
- Estimate costs and implementation timelines
- Document risk acceptance for risks not mitigated
Outputs:
- Remediation roadmap
- Prioritized recommendation list
- Cost-benefit analysis
- Risk acceptance documentation
Step 10: Consider Compliance Requirements
Actions:
- Identify applicable regulations and standards
- Map controls to compliance requirements
- Document evidence of compliance
- Identify compliance gaps
- Recommend actions to achieve or maintain compliance
Outputs:
- Compliance matrix
- Gap analysis
- Evidence documentation
- Compliance remediation plan
Step 11: Synthesize and Report
Actions:
- Summarize key findings for different audiences (executives, technical teams, compliance)
- Provide clear risk assessment and recommendations
- Include metrics and KPIs
- Document assumptions and limitations
- Create action plan with owners and timelines
Outputs:
- Executive summary
- Technical findings report
- Remediation roadmap
- Compliance summary
Usage Examples
Example 1: Security Incident - Ransomware Attack
Event: Organization experiences ransomware attack; files encrypted, ransom note demands payment
Analysis:
Step 1 - Scope and Context:
- Affected systems: File servers, workstations, backups
- Business impact: Operations halted, data unavailable
- Critical: Understand ransomware variant, encryption scope, attacker access
Step 2 - Assets:
- Crown jewels: Customer database, financial records, intellectual property
- Status: Files encrypted, availability compromised
Step 3 - Attack Surface Analysis:
- Initial access vector: Likely phishing email or vulnerable RDP endpoint
- Lateral movement: SMB, credential theft
Step 4 - Threat Modeling (Post-Incident):
- Threat actor: Likely cybercriminal group (financial motivation)
- ATT&CK mapping:
- Initial Access: Phishing or Exploit Public-Facing Application
- Execution: User Execution or Exploitation for Client Execution
- Persistence: Registry Run Keys, Scheduled Tasks
- Privilege Escalation: Exploitation for Privilege Escalation
- Credential Access: Credential Dumping
- Lateral Movement: SMB/Windows Admin Shares
- Impact: Data Encrypted for Impact
Step 5 - Vulnerabilities:
- Phishing susceptibility (no email filtering, insufficient user training)
- Unpatched RDP vulnerabilities
- Weak passwords or credential reuse
- Inadequate network segmentation (ransomware spread easily)
- Backup vulnerabilities (backups also encrypted)
Step 6 - Control Assessment:
- Missing: Email security gateway, EDR, MFA
- Inadequate: Network segmentation, backup isolation, patch management
- Failed: Antivirus didn't detect ransomware
Step 7 - Risk Analysis:
- Impact: HIGH (business disruption, data loss, ransom demand, reputation damage)
- Likelihood: HIGH (demonstrated—incident occurred)
- Residual risk: CRITICAL (without improvements, repeat likely)
Step 8 - Detection and Response:
- Detection: Failed until encryption began (no EDR, limited logging)
- MTTD: Hours to days (too slow)
- Response: No playbook, uncoordinated response
- Gaps: No IR team, no communication plan, no legal/PR coordination
Step 9 - Recommendations (Prioritized):
Immediate (Hours to Days):
- Isolate affected systems (contain spread)
- Identify ransomware variant and check for decryption tools
- Engage incident response firm if no internal capability
- Do NOT pay ransom immediately (assess alternatives first)
- Notify legal, insurance, possibly law enforcement
Short-term (Days to Weeks):
- Restore from backups if available and uncompromised
- Deploy EDR on all endpoints
- Implement MFA for all remote access
- Conduct forensic investigation to determine root cause and scope
- Develop and test IR playbook
Medium-term (Weeks to Months):
- Network segmentation (prevent lateral movement)
- Email security gateway (block phishing)
- Privileged access management (limit credential theft)
- Security awareness training (reduce phishing success)
- Backup hardening (air-gapped or immutable backups)
Long-term (Months to Year):
- Security maturity assessment and roadmap
- 24/7 SOC or MDR service
- Penetration testing and red team exercises
- Comprehensive vulnerability management program
Step 10 - Compliance:
- Regulatory notification requirements (GDPR, state breach laws, etc.)
- Cyber insurance claim
- Document incident for auditors
Step 11 - Synthesis:
- Root cause: Combination of phishing/RDP exploit + inadequate detection + weak segmentation + backup vulnerabilities
- Key lesson: Defense-in-depth failures—multiple control failures allowed attack to succeed
- Priority: Immediate containment and recovery, then build detective and preventive controls
- Cost: Ransom demand + downtime + recovery + remediation + reputation damage (potentially millions)
Example 2: Vulnerability Assessment - New Web Application Launch
Event: Organization planning to launch customer-facing web application; pre-launch security review requested
Analysis:
Step 1 - Scope:
- Application: E-commerce web application
- Users: External customers
- Data: PII, payment information, order history
- Criticality: HIGH (revenue-generating, customer trust)
Step 2 - Assets:
- Customer PII and payment data (confidentiality, integrity critical)
- Inventory and pricing data (integrity, availability critical)
- Application availability (revenue impact)
Step 3 - Attack Surface:
- Web interface (public-facing)
- APIs (mobile app, third-party integrations)
- Admin portal (internal users)
- Payment processor integration
- Third-party libraries and dependencies
Step 4 - Threat Modeling (STRIDE):
Spoofing:
- Threat: Attacker impersonates user or admin
- Mitigations: Strong authentication, MFA, session management
Tampering:
- Threat: Attacker modifies prices, orders, or user data
- Mitigations: Input validation, authorization checks, integrity controls
Repudiation:
- Threat: User denies placing order
- Mitigations: Audit logging, transaction signing
Information Disclosure:
- Threat: Attacker accesses other users' PII or payment info
- Mitigations: Authorization checks, encryption, secure session management
Denial of Service:
- Threat: Attacker overwhelms application
- Mitigations: Rate limiting, DDoS protection, scalable infrastructure
Elevation of Privilege:
- Threat: User gains admin access
- Mitigations: Least privilege, secure authorization, privilege separation
Step 5 - Vulnerabilities (OWASP Top 10 Analysis):
- Broken Access Control: Check for IDOR vulnerabilities, horizontal/vertical privilege escalation
- Cryptographic Failures: Verify encryption at rest and in transit, key management
- Injection: Test for SQL injection, XSS, command injection
- Insecure Design: Review for security design flaws, threat model gaps
- Security Misconfiguration: Check for default credentials, unnecessary features, verbose errors
- Vulnerable Components: Scan dependencies for known CVEs
- Authentication Failures: Test password policy, session management, MFA
- Software/Data Integrity: Verify supply chain security, unsigned updates
- Logging Failures: Ensure security events logged, log tampering prevention
- SSRF: Test for server-side request forgery vulnerabilities
Step 6 - Control Assessment:
Positive Findings:
- TLS 1.3 for all connections
- Passwords hashed with bcrypt
- Input validation framework in use
- Dependency scanning
…(truncated)
1---2name: cybersecurity-analyst3description: Analyzes events through cybersecurity lens using threat modeling, attack surface analysis, defense-in-depth, zero-trust architecture, and risk-based frameworks (CIA triad, STRIDE, MITRE ATT&CK). Provides insights on vulnerabilities, attack vectors, defense strategies, incident response, and security posture. Use when: Security incidents, vulnerability assessments, threat analysis, security architecture, compliance. Evaluates: Confidentiality, integrity, availability, threat actors, attack patterns, controls, residual risk.4---5
6# Cybersecurity Analyst Skill
7
8## Purpose
9
10Analyze events through the disciplinary lens of cybersecurity, applying rigorous security frameworks (CIA triad, defense-in-depth, zero-trust), threat modeling methodologies (STRIDE, PASTA, VAST), attack surface analysis, and industry standards (NIST, ISO 27001, MITRE ATT&CK) to understand security risks, identify vulnerabilities, assess threat actors and attack vectors, evaluate defensive controls, and recommend risk mitigation strategies.
11
12## When to Use This Skill
13
14- **Security Incident Analysis**: Investigate breaches, data leaks, ransomware attacks, insider threats
15- **Vulnerability Assessment**: Identify weaknesses in systems, applications, networks, processes
16- **Threat Modeling**: Analyze potential attack vectors and threat actors for new systems or changes
17- **Security Architecture Review**: Evaluate design decisions for security implications and gaps
18- **Risk Assessment**: Quantify and prioritize security risks using frameworks like CVSS, FAIR
19- **Compliance Analysis**: Assess adherence to security standards (SOC 2, PCI-DSS, HIPAA, GDPR)
20- **Incident Response Planning**: Design detection, containment, eradication, and recovery strategies
21- **Security Posture Evaluation**: Assess overall defensive capabilities and maturity
22- **Code Security Review**: Identify security vulnerabilities in software implementations
23
24## Core Philosophy: Security Thinking
25
26Cybersecurity analysis rests on fundamental principles:
27
28**Defense in Depth**: No single security control is perfect. Layer multiple independent controls so compromise of one doesn't compromise the whole system.
29
30**Assume Breach**: Modern security assumes attackers will penetrate perimeter defenses. Design systems to minimize damage and enable detection when (not if) breach occurs.
31
32**Least Privilege**: Grant minimum access necessary for legitimate function. Every excess permission is an opportunity for exploitation.
33
34**Zero Trust**: Never trust, always verify. Verify explicitly, use least privilege access, and assume breach regardless of network location.
35
36**Security by Design**: Security cannot be bolted on afterward. It must be fundamental to architecture and implementation from the beginning.
37
38**CIA Triad**: Security protects three properties—Confidentiality (only authorized access), Integrity (only authorized modification), Availability (accessible when needed).
39
40**Threat-Informed Defense**: Base defensive priorities on understanding of actual threat actors, their capabilities, motivations, and tactics (threat intelligence).
41
42**Risk-Based Approach**: Perfect security is impossible. Prioritize security investments based on risk (likelihood × impact) to maximize security per dollar spent.
43
44---
45
46## Theoretical Foundations (Expandable)
47
48### Foundation 1: CIA Triad (Classic Security Model)
49
50**Components**:
51
52**Confidentiality**: Information accessible only to authorized entities
53
54- Protection mechanisms: Encryption, access controls, authentication
55- Threats: Eavesdropping, data theft, unauthorized disclosure
56- Example violations: Data breach, password theft, insider leak
57
58**Integrity**: Information modifiable only by authorized entities in authorized ways
59
60- Protection mechanisms: Hashing, digital signatures, access controls, version control
61- Threats: Tampering, unauthorized modification, malware
62- Example violations: Database manipulation, man-in-the-middle attacks, ransomware encryption
63
64**Availability**: Information and systems accessible when needed by authorized entities
65
66- Protection mechanisms: Redundancy, backups, DDoS mitigation, incident response
67- Threats: Denial of service, ransomware, system destruction
68- Example violations: DDoS attacks, ransomware, infrastructure failures
69
70**Extensions**:
71
72- **Authenticity**: Verified identity of entities and origin of information
73- **Non-repudiation**: Cannot deny taking action
74- **Accountability**: Actions traceable to entities
75
76**Application**: Every security analysis should identify which aspects of CIA triad are at risk and how controls protect each.
77
78**Sources**:
79
80- [CIA Triad - Wikipedia](https://en.wikipedia.org/wiki/Information_security#Key_concepts)
81- [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework)
82
83### Foundation 2: Defense in Depth (Layered Security)
84
85**Principle**: Deploy multiple layers of security controls so compromise of one layer doesn't compromise entire system.
86
87**Historical Origin**: Military defensive strategy—multiple concentric perimeter defenses
88
89**Security Layers**:
90
911. **Physical**: Facility access controls, locked server rooms
922. **Network**: Firewalls, network segmentation, IDS/IPS
933. **Host**: Endpoint protection, host firewalls, patch management
944. **Application**: Input validation, secure coding, authentication
955. **Data**: Encryption at rest and in transit, DLP, tokenization
966. **Human**: Security awareness training, phishing simulation
97
98**Key Insight**: Redundancy is not waste—it's resilience. Even if attacker bypasses firewall, they still face authentication, authorization, monitoring, encryption, and detection controls.
99
100**Application**: Security architecture should have multiple independent defensive layers protecting critical assets.
101
102**Limitation**: Can create complexity and false sense of security if layers are not maintained or are interdependent.
103
104**Sources**:
105
106- [Defense in Depth - NSA](https://www.nsa.gov/Press-Room/Cybersecurity-Advisories-Guidance/)
107- [Layered Security - CISA](https://www.cisa.gov/topics/cybersecurity-best-practices)
108
109### Foundation 3: Zero Trust Architecture
110
111**Core Principle**: "Never trust, always verify" regardless of network location
112
113**Contrast with Perimeter Model**: Traditional security assumed internal network is trusted ("castle and moat"). Zero trust assumes no network location is trusted.
114
115**Key Tenets** (NIST SP 800-207):
116
1171. **Verify explicitly**: Always authenticate and authorize based on all available data points
1182. **Least privilege access**: Limit user access with Just-In-Time and Just-Enough-Access
1193. **Assume breach**: Minimize blast radius and segment access; verify end-to-end encryption
120
121**Components**:
122
123- **Identity-centric security**: Identity becomes new perimeter
124- **Micro-segmentation**: Network divided into small zones with separate controls
125- **Continuous verification**: Authentication and authorization are continuous, not one-time
126- **Data-centric**: Protect data itself, not just perimeter around it
127
128**Drivers**:
129
130- Cloud adoption (no clear perimeter)
131- Remote work (users outside traditional perimeter)
132- Sophisticated attacks (perimeter breaches common)
133
134**Application**: Modern security architectures should be designed with zero trust principles, especially for cloud and hybrid environments.
135
136**Sources**:
137
138- [NIST SP 800-207: Zero Trust Architecture](https://csrc.nist.gov/publications/detail/sp/800-207/final)
139- [Zero Trust - Microsoft Security](https://www.microsoft.com/en-us/security/business/zero-trust)
140
141### Foundation 4: Threat Modeling
142
143**Definition**: Structured approach to identify and prioritize potential threats to a system
144
145**Purpose**: Proactively identify security issues during design phase when fixes are cheapest
146
147**Benefits**:
148
149- Find vulnerabilities before implementation
150- Prioritize security work
151- Communicate risks to stakeholders
152- Guide security testing
153
154**Common Methodologies**:
155
156**STRIDE** (Microsoft):
157
158- **S**poofing identity
159- **T**ampering with data
160- **R**epudiation
161- **I**nformation disclosure
162- **D**enial of service
163- **E**levation of privilege
164
165**PASTA** (Process for Attack Simulation and Threat Analysis):
166
167- Seven-stage risk-centric methodology
168- Aligns business objectives with technical requirements
169
170**VAST** (Visual, Agile, and Simple Threat modeling):
171
172- Scalable for agile development
173- Two types: application threat models and operational threat models
174
175**Application**: Use threat modeling for new features, architecture changes, or security reviews.
176
177**Sources**:
178
179- [Threat Modeling - OWASP](https://owasp.org/www-community/Threat_Modeling)
180- [STRIDE Threat Model - Microsoft](https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool-threats)
181
182### Foundation 5: MITRE ATT&CK Framework
183
184**Description**: Knowledge base of adversary tactics and techniques based on real-world observations
185
186**Purpose**: Understand how attackers operate to inform defense, detection, and threat hunting
187
188**Structure**:
189
190- **Tactics**: High-level goals (e.g., Initial Access, Execution, Persistence, Privilege Escalation)
191- **Techniques**: Ways to achieve tactics (e.g., Phishing, Exploiting Public Applications)
192- **Sub-techniques**: Specific implementations
193- **Procedures**: Specific attacker behaviors
194
195**14 Tactics** (Enterprise Matrix):
196
1971. Reconnaissance
1982. Resource Development
1993. Initial Access
2004. Execution
2015. Persistence
2026. Privilege Escalation
2037. Defense Evasion
2048. Credential Access
2059. Discovery
20610. Lateral Movement
20711. Collection
20812. Command and Control
20913. Exfiltration
21014. Impact
211
212**Application**:
213
214- Map defensive controls to ATT&CK techniques
215- Identify detection gaps
216- Threat intelligence sharing
217- Red team/purple team exercises
218
219**Value**: Common language for describing attacker behavior; basis for threat-informed defense
220
221**Sources**:
222
223- [MITRE ATT&CK](https://attack.mitre.org/)
224- [ATT&CK Navigator](https://mitre-attack.github.io/attack-navigator/)
225
226---
227
228## Core Analytical Frameworks (Expandable)
229
230### Framework 1: Attack Surface Analysis
231
232**Definition**: Identification and assessment of all points where unauthorized user could enter or extract data from system
233
234**Components**:
235
236**Attack Surface Elements**:
237
238- **Network attack surface**: Exposed ports, services, protocols
239- **Software attack surface**: Applications, APIs, web interfaces
240- **Human attack surface**: Users, administrators, social engineering targets
241- **Physical attack surface**: Facility access, hardware access
242
243**Attack Vectors**: Methods attackers use to exploit attack surface
244
245- Network-based: Port scanning, protocol exploits, man-in-the-middle
246- Web-based: SQL injection, XSS, CSRF, authentication bypass
247- Email-based: Phishing, malicious attachments, credential harvesting
248- Physical: Theft, unauthorized access, evil maid attacks
249- Social engineering: Pretexting, baiting, tailgating
250
251**Analysis Process**:
252
2531. **Enumerate**: List all entry points and assets
2542. **Classify**: Categorize by type and criticality
2553. **Assess**: Evaluate exploitability and impact
2564. **Prioritize**: Rank by risk
2575. **Reduce**: Minimize unnecessary exposure
258
259**Metrics**:
260
261- Number of exposed services
262- Number of internet-facing applications
263- Number of privileged accounts
264- Lines of code exposed to untrusted input
265
266**Application**: Reducing attack surface is fundamental defensive strategy. Eliminate unnecessary exposure.
267
268**Sources**:
269
270- [Attack Surface Analysis - OWASP](https://owasp.org/www-community/Attack_Surface_Analysis_Cheat_Sheet)
271- [Reducing Attack Surface - Microsoft](https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules)
272
273### Framework 2: Risk Assessment Frameworks
274
275**Purpose**: Quantify and prioritize security risks to guide resource allocation
276
277**Common Frameworks**:
278
279**CVSS** (Common Vulnerability Scoring System):
280
281- Standard for assessing vulnerability severity
282- Score 0-10 based on exploitability, impact, scope
283- Base score (intrinsic characteristics) + temporal + environmental scores
284- Widely used but criticized for not capturing actual risk in specific contexts
285
286**FAIR** (Factor Analysis of Information Risk):
287
288- Quantitative risk framework
289- Risk = Loss Event Frequency × Loss Magnitude
290- Enables cost-benefit analysis of security investments
291- More complex but provides dollar-denominated risk figures
292
293**NIST Risk Management Framework** (RMF):
294
295- Seven steps: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor
296- Links security controls to risk management
297- Used by U.S. federal agencies
298
299**Qualitative vs. Quantitative**:
300
301- **Qualitative**: High/Medium/Low risk ratings (simpler, faster, subjective)
302- **Quantitative**: Numerical risk values (complex, objective, requires data)
303
304**Application**: Risk assessment informs prioritization. Not all vulnerabilities are equally important—focus on highest risks.
305
306**Sources**:
307
308- [CVSS](https://www.first.org/cvss/)
309- [FAIR Institute](https://www.fairinstitute.org/)
310- [NIST RMF](https://csrc.nist.gov/projects/risk-management)
311
312### Framework 3: Security Control Frameworks
313
314**Purpose**: Structured set of security controls to achieve security objectives
315
316**Major Frameworks**:
317
318**NIST Cybersecurity Framework**:
319
320- Five core functions: Identify, Protect, Detect, Respond, Recover
321- Not prescriptive—flexible for different organizations
322- Widely adopted across industries and internationally
323
324**NIST SP 800-53** (Security and Privacy Controls):
325
326- Comprehensive catalog of security controls for federal systems
327- 20 control families (Access Control, Incident Response, etc.)
328- Detailed implementation guidance
329
330**CIS Controls** (Center for Internet Security):
331
332- 18 prioritized security controls
333- Implementation groups (IG1, IG2, IG3) based on organizational maturity
334- Actionable and measurable
335
336**ISO/IEC 27001**:
337
338- International standard for information security management systems
339- 14 control domains, 114 controls
340- Certification available
341
342**Application**: Use frameworks to:
343
344- Ensure comprehensive coverage
345- Benchmark security posture
346- Communicate with stakeholders
347- Meet compliance requirements
348
349**Sources**:
350
351- [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework)
352- [CIS Controls](https://www.cisecurity.org/controls)
353- [ISO 27001](https://www.iso.org/isoiec-27001-information-security.html)
354
355### Framework 4: Incident Response Lifecycle
356
357**Definition**: Structured approach to handling security incidents
358
359**Standard Model** (NIST SP 800-61):
360
361**Phase 1: Preparation**
362
363- Establish IR capability, tools, playbooks
364- Training and exercises
365- Communication plans
366
367**Phase 2: Detection and Analysis**
368
369- Monitoring and alerting
370- Incident classification and prioritization
371- Initial investigation
372- Scope determination
373
374**Phase 3: Containment, Eradication, and Recovery**
375
376- **Containment**: Stop spread (short-term and long-term)
377- **Eradication**: Remove threat from environment
378- **Recovery**: Restore systems to normal operation
379
380**Phase 4: Post-Incident Activity**
381
382- Lessons learned
383- Evidence preservation
384- Incident report
385- Process improvement
386
387**Key Concepts**:
388
389- **Playbooks**: Predefined procedures for common incident types
390- **Indicators of Compromise** (IoCs): Artifacts indicating malicious activity
391- **Chain of custody**: Evidence handling procedures
392- **Communication**: Internal and external stakeholders, legal, PR
393
394**Metrics**:
395
396- Mean Time to Detect (MTTD)
397- Mean Time to Respond (MTTR)
398- Mean Time to Contain (MTTC)
399
400**Application**: Effective incident response minimizes damage, reduces recovery time, and captures learning.
401
402**Sources**:
403
404- [NIST SP 800-61: Computer Security Incident Handling Guide](https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final)
405- [SANS Incident Response](https://www.sans.org/incident-response/)
406
407### Framework 5: Secure Development Lifecycle (SDL)
408
409**Purpose**: Integrate security into software development process
410
411**Microsoft SDL Phases**:
412
4131. **Training**: Security training for developers
4142. **Requirements**: Define security requirements and privacy requirements
4153. **Design**: Threat modeling, attack surface reduction, defense in depth
4164. **Implementation**: Secure coding standards, code analysis tools
4175. **Verification**: Security testing (SAST, DAST, penetration testing)
4186. **Release**: Final security review, incident response plan
4197. **Response**: Execute incident response plan if vulnerability discovered
420
421**Key Practices**:
422
423- **Static Analysis (SAST)**: Analyze source code for vulnerabilities
424- **Dynamic Analysis (DAST)**: Test running application
425- **Dependency Scanning**: Check third-party libraries for known vulnerabilities
426- **Penetration Testing**: Simulate real attacks
427- **Security Champions**: Embed security expertise in development teams
428
429**OWASP SAMM** (Software Assurance Maturity Model):
430
431- Maturity model for secure software development
432- Five business functions: Governance, Design, Implementation, Verification, Operations
433- Three maturity levels for each function
434
435**Application**: Security must be integrated throughout development lifecycle, not just at the end.
436
437**Sources**:
438
439- [Microsoft SDL](https://www.microsoft.com/en-us/securityengineering/sdl)
440- [OWASP SAMM](https://owaspsamm.org/)
441
442---
443
444## Methodological Approaches (Expandable)
445
446### Method 1: Threat Intelligence Analysis
447
448**Purpose**: Understand adversaries, their capabilities, tactics, and targets to inform defense
449
450**Types of Threat Intelligence**:
451
452**Strategic**: High-level trends for executives
453
454- APT group activity and motivations
455- Geopolitical cyber threats
456- Industry-specific threat landscape
457
458**Operational**: Campaign-level information for security operations
459
460- Current attack campaigns
461- Threat actor TTPs
462- Malware families
463
464**Tactical**: Technical indicators for immediate defense
465
466- IP addresses, domains, file hashes
467- YARA rules, Snort signatures
468- CVEs being exploited
469
470**Analytical Process**:
471
4721. **Collection**: Gather data from internal sources, threat feeds, OSINT, dark web
4732. **Processing**: Normalize, correlate, deduplicate
4743. **Analysis**: Contextualize, attribute, assess intent and capability
4754. **Dissemination**: Share with relevant teams in actionable format
4765. **Feedback**: Assess effectiveness and refine
477
478**Frameworks**:
479
480- **Diamond Model**: Adversary, Capability, Infrastructure, Victim
481- **Kill Chain**: Reconnaissance → Weaponization → Delivery → Exploitation → Installation → C2 → Actions on Objectives
482- **MITRE ATT&CK**: Map observed techniques to ATT&CK matrix
483
484**Application**: Threat intelligence enables proactive, threat-informed defense rather than generic security measures.
485
486**Sources**:
487
488- [CISA Threat Intelligence](https://www.cisa.gov/topics/cyber-threats-and-advisories)
489- [Threat Intelligence - SANS](https://www.sans.org/cyber-security-courses/cyber-threat-intelligence/)
490
491### Method 2: Penetration Testing
492
493**Definition**: Authorized simulated attack to evaluate security of systems
494
495**Types**:
496
497**Black Box**: No prior knowledge (simulates external attacker)
498
499**Gray Box**: Partial knowledge (simulates insider or compromised user)
500
501**White Box**: Full knowledge (comprehensive security assessment)
502
503**Phases** (Penetration Testing Execution Standard):
504
5051. **Pre-engagement**: Scope, rules of engagement, legal agreements
5062. **Intelligence gathering**: OSINT, network scanning, service enumeration
5073. **Threat modeling**: Identify potential attack vectors
5084. **Vulnerability analysis**: Identify exploitable weaknesses
5095. **Exploitation**: Attempt to exploit vulnerabilities
5106. **Post-exploitation**: Assess impact, lateral movement, privilege escalation
5117. **Reporting**: Document findings, demonstrate impact, provide remediation guidance
512
513**Specialized Types**:
514
515- **Web application penetration testing**: Focus on OWASP Top 10
516- **Network penetration testing**: Internal and external network
517- **Social engineering**: Phishing, vishing, physical intrusion
518- **Wireless penetration testing**: WiFi security assessment
519
520**Red Team vs. Penetration Testing**:
521
522- **Penetration testing**: Find as many vulnerabilities as possible
523- **Red teaming**: Goal-oriented (e.g., access specific data), simulates APT, tests detection and response
524
525**Application**: Regular penetration testing validates effectiveness of controls and identifies gaps before attackers do.
526
527**Sources**:
528
529- [Penetration Testing Execution Standard](http://www.pentest-standard.org/)
530- [OWASP Testing Guide](https://owasp.org/www-project-web-security-testing-guide/)
531
532### Method 3: Security Architecture Review
533
534**Purpose**: Evaluate system design for security properties and identify architectural vulnerabilities
535
536**Review Dimensions**:
537
538**Structural Analysis**:
539
540- Trust boundaries and data flows
541- Authentication and authorization architecture
542- Network segmentation and isolation
543- Data classification and protection
544
545**Threat Modeling**:
546
547- Apply STRIDE or other methodology
548- Identify attack trees
549- Assess mitigations for identified threats
550
551**Control Assessment**:
552
553- Map controls to CIA triad
554- Evaluate defense-in-depth layers
555- Identify single points of failure
556
557**Compliance Review**:
558
559- Check against security frameworks (NIST, CIS, ISO)
560- Regulatory requirements (PCI-DSS, HIPAA, SOC 2)
561
562**Technology Assessment**:
563
564- Cryptographic implementation
565- Secure protocols
566- Patch management approach
567- Secret management
568
569**Analysis Questions**:
570
571- What are trust boundaries?
572- Where does sensitive data flow?
573- How is authentication/authorization enforced?
574- What happens if component X is compromised?
575- Are security assumptions documented and validated?
576
577**Outputs**:
578
579- Architecture diagrams with security annotations
580- Threat model
581- Risk assessment
582- Remediation recommendations
583
584**Application**: Architecture review during design phase prevents expensive security issues in production.
585
586### Method 4: Vulnerability Assessment and Management
587
588**Purpose**: Systematically identify, classify, prioritize, and remediate security weaknesses
589
590**Process**:
591
592**Phase 1: Discovery**
593
594- Asset inventory (what do we have?)
595- Vulnerability scanning (automated tools)
596- Manual security testing
597- Code review (static analysis)
598
599**Phase 2: Assessment**
600
601- Classify vulnerabilities by type and severity
602- Assess exploitability (is there exploit code? Is it being exploited?)
603- Determine impact (what data/systems at risk?)
604- Calculate risk score (CVSS, contextual factors)
605
606**Phase 3: Prioritization**
607
608- Rank by risk (likelihood × impact)
609- Consider threat intelligence (is it being exploited in wild?)
610- Business criticality of affected assets
611- Remediation complexity
612
613**Phase 4: Remediation**
614
615- Patching (ideal)
616- Configuration changes
617- Compensating controls (if patching impossible)
618- Accept risk (document and approve)
619
620**Phase 5: Verification**
621
622- Rescan to confirm remediation
623- Update vulnerability database
624- Track metrics (time to remediate, vulnerability density)
625
626**Challenges**:
627
628- Alert fatigue (too many findings)
629- False positives
630- Patching disruption
631- Legacy systems
632
633**Best Practices**:
634
635- Risk-based prioritization (not just CVSS)
636- SLA-based remediation (Critical: 7 days, High: 30 days, etc.)
637- Automate where possible
638- Track trends and metrics
639
640**Application**: Continuous vulnerability management is essential hygiene. Can't fix what you don't know about.
641
642**Sources**:
643
644- [NIST SP 800-40: Patch and Vulnerability Management](https://csrc.nist.gov/publications/detail/sp/800-40/rev-4/final)
645
646### Method 5: Security Monitoring and Detection Engineering
647
648**Purpose**: Design and operate capabilities to detect malicious activity
649
650**Components**:
651
652**Data Sources**:
653
654- Network traffic (NetFlow, full packet capture)
655- Endpoint logs (process creation, file access, registry changes)
656- Authentication logs (logins, privilege escalation)
657- Application logs (errors, transactions)
658- Cloud APIs and audit logs
659
660**Detection Mechanisms**:
661
662**Signature-based**: Known malicious patterns (antivirus, IDS signatures)
663
664- Pros: Low false positives, fast
665- Cons: Only detects known threats
666
667**Anomaly-based**: Deviations from baseline behavior
668
669- Pros: Can detect novel attacks
670- Cons: High false positives, requires tuning
671
672**Heuristic-based**: Rules based on attacker behavior patterns
673
674- Pros: Detects variations of known attacks
675- Cons: Requires security expertise to create rules
676
677**Threat intelligence-based**: Match against known IoCs
678
679- Pros: Leverages collective knowledge
680- Cons: Reactive (indicators discovered post-compromise)
681
682**Detection Development**:
683
6841. Understand attacker technique (MITRE ATT&CK)
6852. Identify data sources that capture technique
6863. Develop detection logic
6874. Test against true positives and false positives
6885. Tune threshold and logic
6896. Document detection and response procedures
6907. Monitor effectiveness and iterate
691
692**SIEM and SOC**:
693
694- **SIEM**: Aggregate, correlate, and analyze security logs
695- **SOC**: Security Operations Center—team that monitors alerts and responds to incidents
696
697**Metrics**:
698
699- Detection coverage (% of ATT&CK techniques covered)
700- Alert volume and quality
701- False positive rate
702- Mean Time to Detect (MTTD)
703
704**Application**: You can't respond to what you don't detect. Invest in detection capabilities aligned to threats you face.
705
706**Sources**:
707
708- [Detection Engineering - Splunk](https://www.splunk.com/en_us/blog/learn/detection-engineering.html)
709- [Sigma Rules](https://github.com/SigmaHQ/sigma)
710
711---
712
713## Analysis Rubric
714
715### What to Examine
716
717**Assets and Data**:
718
719- What sensitive data exists? (PII, credentials, trade secrets, financial data)
720- Where is it stored, processed, transmitted?
721- Who has access?
722- What is business impact if compromised? (confidentiality, integrity, availability)
723
724**Attack Surface**:
725
726- What systems are exposed to internet?
727- What are entry points for attackers?
728- What authentication is required?
729- What third-party dependencies exist?
730
731**Threat Actors**:
732
733- Who might target this? (Nation-states, cybercriminals, hacktivists, insiders)
734- What are their capabilities and motivations?
735- What TTPs do they typically use?
736- What threat intelligence exists?
737
738**Vulnerabilities**:
739
740- Known software vulnerabilities (CVEs)?
741- Configuration weaknesses?
742- Architectural security flaws?
743- Code-level vulnerabilities?
744- Human vulnerabilities (phishing susceptibility)?
745
746**Existing Controls**:
747
748- What security controls are in place?
749- Do they follow defense-in-depth principles?
750- Are they properly configured and maintained?
751- What detection and response capabilities exist?
752
753### Questions to Ask
754
755**Threat Questions**:
756
757- What could go wrong?
758- What are most likely attack vectors?
759- What threat actors might target this?
760- What are their goals and capabilities?
761- What historical incidents are relevant?
762
763**Vulnerability Questions**:
764
765- What weaknesses exist?
766- How exploitable are they?
767- What is impact if exploited?
768- Are there known exploits or active exploitation?
769- How quickly can vulnerabilities be remediated?
770
771**Control Questions**:
772
773- What protections are in place?
774- How effective are they?
775- What gaps exist in defensive coverage?
776- Can controls be bypassed?
777- How will malicious activity be detected?
778
779**Risk Questions**:
780
781- What is likelihood of compromise?
782- What is potential impact?
783- What is overall risk level?
784- How does risk compare to organization's risk appetite?
785- What risk treatment options exist? (mitigate, accept, transfer, avoid)
786
787**Compliance Questions**:
788
789- What regulations or standards apply?
790- Are security requirements met?
791- What evidence demonstrates compliance?
792- What gaps exist?
793
794### Factors to Consider
795
796**Technical Factors**:
797
798- System architecture and design
799- Technology stack and versions
800- Configuration and hardening
801- Cryptographic implementation
802- Network topology and segmentation
803
804**Organizational Factors**:
805
806- Security maturity and culture
807- Available resources and budget
808- Risk tolerance
809- Regulatory environment
810- Business criticality
811
812**Threat Landscape**:
813
814- Current threat actor activity
815- Emerging attack techniques
816- Industry-specific threats
817- Geopolitical factors
818
819**Operational Factors**:
820
821- Patch management processes
822- Incident response capabilities
823- Security monitoring and detection
824- Security awareness and training
825- Third-party risk management
826
827### Historical Parallels to Consider
828
829- Similar security incidents
830- Comparable vulnerability exploits
831- Industry-specific attack patterns
832- Lessons from major breaches
833- Evolution of threat actor TTPs
834
835### Implications to Explore
836
837**Immediate Security Implications**:
838
839- Confidentiality: Data breach risk
840- Integrity: Data tampering or corruption risk
841- Availability: Service disruption risk
842- Financial: Ransom, recovery costs, fines
843
844**Broader Implications**:
845
846- Reputation damage
847- Legal and regulatory consequences
848- Customer trust erosion
849- Competitive disadvantage
850- Systemic risk (if in critical infrastructure)
851
852**Strategic Implications**:
853
854- Security architecture changes needed
855- Security program maturity gaps
856- Resource allocation and prioritization
857- Risk management approach
858
859---
860
861## Step-by-Step Analysis Process
862
863### Step 1: Define Scope and Context
864
865**Actions**:
866
867- Clearly identify system, application, or event being analyzed
868- Determine boundaries and interfaces
869- Identify stakeholders and their security requirements
870- Understand business context and criticality
871- Gather relevant documentation (architecture diagrams, data flows, policies)
872
873**Outputs**:
874
875- Scope statement
876- Asset inventory
877- Stakeholder list
878- Business context understanding
879
880### Step 2: Identify Assets and Data
881
882**Actions**:
883
884- List critical assets (systems, data, services)
885- Classify data by sensitivity (public, internal, confidential, restricted)
886- Map data flows (where data is created, stored, processed, transmitted, destroyed)
887- Identify crown jewels (most valuable assets)
888
889**Outputs**:
890
891- Asset inventory with criticality ratings
892- Data classification matrix
893- Data flow diagrams
894- Crown jewels list
895
896### Step 3: Analyze Attack Surface
897
898**Actions**:
899
900- Enumerate all entry points (APIs, web interfaces, network services, physical access)
901- Identify trust boundaries (where untrusted input crosses into trusted zones)
902- Map authentication and authorization points
903- Identify dependencies (third-party services, libraries, suppliers)
904
905**Outputs**:
906
907- Attack surface map
908- Trust boundary diagram
909- Entry point inventory
910- Dependency list
911
912### Step 4: Conduct Threat Modeling
913
914**Actions**:
915
916- Select threat modeling methodology (STRIDE, PASTA, etc.)
917- Identify potential threat actors and their goals
918- Enumerate potential attack vectors for each asset
919- Create attack trees showing attack paths
920- Map to MITRE ATT&CK techniques
921
922**Outputs**:
923
924- Threat model document
925- Threat actor profiles
926- Attack tree diagrams
927- ATT&CK technique mapping
928
929### Step 5: Identify Vulnerabilities
930
931**Actions**:
932
933- Review known CVEs for technologies in use
934- Analyze configuration against security benchmarks (CIS, STIGs)
935- Review architecture for security design flaws
936- Consider code-level vulnerabilities (if applicable)
937- Assess human vulnerabilities (phishing susceptibility, privilege misuse)
938
939**Outputs**:
940
941- Vulnerability inventory
942- CVSS scores or risk ratings
943- Configuration gap analysis
944- Architectural security issues
945
946### Step 6: Assess Existing Controls
947
948**Actions**:
949
950- Inventory security controls across all layers (network, host, application, data)
951- Map controls to threats (which threats do controls mitigate?)
952- Evaluate control effectiveness (properly configured? maintained? monitored?)
953- Identify control gaps (threats without adequate mitigation)
954- Assess detection and response capabilities
955
956**Outputs**:
957
958- Control inventory
959- Threat-control mapping matrix
960- Control effectiveness assessment
961- Detection coverage gaps
962
963### Step 7: Analyze Risk
964
965**Actions**:
966
967- For each threat-vulnerability pair, estimate likelihood and impact
968- Calculate risk scores (qualitative or quantitative)
969- Prioritize risks
970- Compare to organizational risk tolerance
971- Consider risk interdependencies and cascading effects
972
973**Outputs**:
974
975- Risk register
976- Risk heat map
977- Prioritized risk list
978- Risk acceptance recommendations
979
980### Step 8: Evaluate Detection and Response
981
982**Actions**:
983
984- Assess what malicious activities would be detected
985- Evaluate MTTD (Mean Time to Detect) for various attack scenarios
986- Review incident response plans and playbooks
987- Assess incident response team capabilities
988- Identify gaps in detection or response
989
990**Outputs**:
991
992- Detection coverage assessment
993- MTTD estimates
994- IR capability assessment
995- Detection and response gaps
996
997### Step 9: Develop Remediation Recommendations
998
999**Actions**:
1000
1001- Propose mitigations for identified risks (preventive, detective, corrective)
1002- Prioritize by risk reduction and implementation effort
1003- Consider compensating controls where direct mitigation is impractical
1004- Estimate costs and implementation timelines
1005- Document risk acceptance for risks not mitigated
1006
1007**Outputs**:
1008
1009- Remediation roadmap
1010- Prioritized recommendation list
1011- Cost-benefit analysis
1012- Risk acceptance documentation
1013
1014### Step 10: Consider Compliance Requirements
1015
1016**Actions**:
1017
1018- Identify applicable regulations and standards
1019- Map controls to compliance requirements
1020- Document evidence of compliance
1021- Identify compliance gaps
1022- Recommend actions to achieve or maintain compliance
1023
1024**Outputs**:
1025
1026- Compliance matrix
1027- Gap analysis
1028- Evidence documentation
1029- Compliance remediation plan
1030
1031### Step 11: Synthesize and Report
1032
1033**Actions**:
1034
1035- Summarize key findings for different audiences (executives, technical teams, compliance)
1036- Provide clear risk assessment and recommendations
1037- Include metrics and KPIs
1038- Document assumptions and limitations
1039- Create action plan with owners and timelines
1040
1041**Outputs**:
1042
1043- Executive summary
1044- Technical findings report
1045- Remediation roadmap
1046- Compliance summary
1047
1048---
1049
1050## Usage Examples
1051
1052### Example 1: Security Incident - Ransomware Attack
1053
1054**Event**: Organization experiences ransomware attack; files encrypted, ransom note demands payment
1055
1056**Analysis**:
1057
1058**Step 1 - Scope and Context**:
1059
1060- Affected systems: File servers, workstations, backups
1061- Business impact: Operations halted, data unavailable
1062- Critical: Understand ransomware variant, encryption scope, attacker access
1063
1064**Step 2 - Assets**:
1065
1066- Crown jewels: Customer database, financial records, intellectual property
1067- Status: Files encrypted, availability compromised
1068
1069**Step 3 - Attack Surface Analysis**:
1070
1071- Initial access vector: Likely phishing email or vulnerable RDP endpoint
1072- Lateral movement: SMB, credential theft
1073
1074**Step 4 - Threat Modeling (Post-Incident)**:
1075
1076- Threat actor: Likely cybercriminal group (financial motivation)
1077- ATT&CK mapping:
1078 - Initial Access: Phishing or Exploit Public-Facing Application
1079 - Execution: User Execution or Exploitation for Client Execution
1080 - Persistence: Registry Run Keys, Scheduled Tasks
1081 - Privilege Escalation: Exploitation for Privilege Escalation
1082 - Credential Access: Credential Dumping
1083 - Lateral Movement: SMB/Windows Admin Shares
1084 - Impact: Data Encrypted for Impact
1085
1086**Step 5 - Vulnerabilities**:
1087
1088- Phishing susceptibility (no email filtering, insufficient user training)
1089- Unpatched RDP vulnerabilities
1090- Weak passwords or credential reuse
1091- Inadequate network segmentation (ransomware spread easily)
1092- Backup vulnerabilities (backups also encrypted)
1093
1094**Step 6 - Control Assessment**:
1095
1096- Missing: Email security gateway, EDR, MFA
1097- Inadequate: Network segmentation, backup isolation, patch management
1098- Failed: Antivirus didn't detect ransomware
1099
1100**Step 7 - Risk Analysis**:
1101
1102- Impact: HIGH (business disruption, data loss, ransom demand, reputation damage)
1103- Likelihood: HIGH (demonstrated—incident occurred)
1104- Residual risk: CRITICAL (without improvements, repeat likely)
1105
1106**Step 8 - Detection and Response**:
1107
1108- Detection: Failed until encryption began (no EDR, limited logging)
1109- MTTD: Hours to days (too slow)
1110- Response: No playbook, uncoordinated response
1111- Gaps: No IR team, no communication plan, no legal/PR coordination
1112
1113**Step 9 - Recommendations (Prioritized)**:
1114
1115_Immediate (Hours to Days)_:
1116
11171. Isolate affected systems (contain spread)
11182. Identify ransomware variant and check for decryption tools
11193. Engage incident response firm if no internal capability
11204. Do NOT pay ransom immediately (assess alternatives first)
11215. Notify legal, insurance, possibly law enforcement
1122
1123_Short-term (Days to Weeks)_:
1124
11251. Restore from backups if available and uncompromised
11262. Deploy EDR on all endpoints
11273. Implement MFA for all remote access
11284. Conduct forensic investigation to determine root cause and scope
11295. Develop and test IR playbook
1130
1131_Medium-term (Weeks to Months)_:
1132
11331. Network segmentation (prevent lateral movement)
11342. Email security gateway (block phishing)
11353. Privileged access management (limit credential theft)
11364. Security awareness training (reduce phishing success)
11375. Backup hardening (air-gapped or immutable backups)
1138
1139_Long-term (Months to Year)_:
1140
11411. Security maturity assessment and roadmap
11422. 24/7 SOC or MDR service
11433. Penetration testing and red team exercises
11444. Comprehensive vulnerability management program
1145
1146**Step 10 - Compliance**:
1147
1148- Regulatory notification requirements (GDPR, state breach laws, etc.)
1149- Cyber insurance claim
1150- Document incident for auditors
1151
1152**Step 11 - Synthesis**:
1153
1154- Root cause: Combination of phishing/RDP exploit + inadequate detection + weak segmentation + backup vulnerabilities
1155- Key lesson: Defense-in-depth failures—multiple control failures allowed attack to succeed
1156- Priority: Immediate containment and recovery, then build detective and preventive controls
1157- Cost: Ransom demand + downtime + recovery + remediation + reputation damage (potentially millions)
1158
1159### Example 2: Vulnerability Assessment - New Web Application Launch
1160
1161**Event**: Organization planning to launch customer-facing web application; pre-launch security review requested
1162
1163**Analysis**:
1164
1165**Step 1 - Scope**:
1166
1167- Application: E-commerce web application
1168- Users: External customers
1169- Data: PII, payment information, order history
1170- Criticality: HIGH (revenue-generating, customer trust)
1171
1172**Step 2 - Assets**:
1173
1174- Customer PII and payment data (confidentiality, integrity critical)
1175- Inventory and pricing data (integrity, availability critical)
1176- Application availability (revenue impact)
1177
1178**Step 3 - Attack Surface**:
1179
1180- Web interface (public-facing)
1181- APIs (mobile app, third-party integrations)
1182- Admin portal (internal users)
1183- Payment processor integration
1184- Third-party libraries and dependencies
1185
1186**Step 4 - Threat Modeling (STRIDE)**:
1187
1188**Spoofing**:
1189
1190- Threat: Attacker impersonates user or admin
1191- Mitigations: Strong authentication, MFA, session management
1192
1193**Tampering**:
1194
1195- Threat: Attacker modifies prices, orders, or user data
1196- Mitigations: Input validation, authorization checks, integrity controls
1197
1198**Repudiation**:
1199
1200- Threat: User denies placing order
1201- Mitigations: Audit logging, transaction signing
1202
1203**Information Disclosure**:
1204
1205- Threat: Attacker accesses other users' PII or payment info
1206- Mitigations: Authorization checks, encryption, secure session management
1207
1208**Denial of Service**:
1209
1210- Threat: Attacker overwhelms application
1211- Mitigations: Rate limiting, DDoS protection, scalable infrastructure
1212
1213**Elevation of Privilege**:
1214
1215- Threat: User gains admin access
1216- Mitigations: Least privilege, secure authorization, privilege separation
1217
1218**Step 5 - Vulnerabilities (OWASP Top 10 Analysis)**:
1219
12201. **Broken Access Control**: Check for IDOR vulnerabilities, horizontal/vertical privilege escalation
12212. **Cryptographic Failures**: Verify encryption at rest and in transit, key management
12223. **Injection**: Test for SQL injection, XSS, command injection
12234. **Insecure Design**: Review for security design flaws, threat model gaps
12245. **Security Misconfiguration**: Check for default credentials, unnecessary features, verbose errors
12256. **Vulnerable Components**: Scan dependencies for known CVEs
12267. **Authentication Failures**: Test password policy, session management, MFA
12278. **Software/Data Integrity**: Verify supply chain security, unsigned updates
12289. **Logging Failures**: Ensure security events logged, log tampering prevention
122910. **SSRF**: Test for server-side request forgery vulnerabilities
1230
1231**Step 6 - Control Assessment**:
1232
1233_Positive Findings_:
1234
1235- TLS 1.3 for all connections
1236- Passwords hashed with bcrypt
1237- Input validation framework in use
1238- Dependency scanning
1239
1240…(truncated)