Security Researcher
Senior-grade security review guidelines anchored on canonical control frameworks: NIST CSF 2.0, CIS Controls v8, NIST SSDF, OWASP ASVS, OWASP Top 10, MITRE ATT&CK, SLSA, and OpenSSF Scorecard.
When to Use
- Security review or audit of code, architecture, or infrastructure
- Threat modeling sessions
- Reviewing PRs for security implications
- Assessing supply chain security
- Smart contract or ZK circuit security reviews
Frameworks Reference
| Framework |
Purpose |
| NIST CSF 2.0 |
Org-wide risk outcomes |
| CIS Controls v8 |
Practical enterprise controls |
| NIST SSDF SP 800-218 |
Secure development lifecycle |
| OWASP ASVS |
App security requirements |
| OWASP Top 10 (2025) |
Common web app failures |
| MITRE ATT&CK |
Adversary techniques mapping |
| SLSA + OpenSSF |
Supply chain integrity |
Non-Negotiables
Before any deep review, verify these fundamentals:
- Asset inventory - Systems, repos, secrets locations, dependencies, owners
- MFA everywhere - Hardware keys for admins, no shared accounts
- Patch management - Continuous vuln scanning (OS, containers, deps)
- Centralized logging - Auth, privilege changes, egress, CI/CD, key access
- Tested backups - Restore drills, immutable where possible
- Incident response - Runbooks, on-call, break-glass procedures
Review Methodology
1. Threat Model First
Use STRIDE categories:
- Spoofing - Can attacker impersonate?
- Tampering - Can data be modified?
- Repudiation - Can actions be denied?
- Information disclosure - Data leaks?
- Denial of service - Availability attacks?
- Elevation of privilege - Unauthorized access?
Document for each trust boundary:
- Auth strategy
- Data classification
- Rate limits
- Audit requirements
Assume compromise review:
- If one service key leaks, what's the blast radius?
- If one dependency is malicious, what stops it?
2. Identity & Access (Root Cause #1)
Broken access control is the most common vulnerability.
Check:
- Default-deny authorization (by resource, not just endpoint)
- Short-lived sessions, secure cookies, CSRF protection
- Separation: authentication ≠ authorization ≠ accounting
- Step-up auth for high-risk actions
- RBAC/ABAC with explicit admin boundaries
Protect against:
- Credential stuffing (rate limits, breached password checks)
- Account takeover (MFA, risky-login alerts)
- Session fixation/replay (rotation, binding, nonce/jti)
3. Secrets & Keys
- No secrets in git - Pre-receive hooks, CI secret detectors
- Dedicated KMS/HSM - Least privilege, rotate keys
- Environment separation - Dev/stage/prod with separate creds
- Short-lived credentials - OIDC to cloud, not static keys
- Track usage - Who/what accessed, from where, when
- Compromise playbook - Rotate, revoke, invalidate, postmortem
4. Cryptography
- Use modern primitives (AEAD, not raw AES modes)
- Never roll your own crypto
- CSPRNG for randomness (no time-based seeds)
- Unique nonces where required
- Constant-time ops for secret-dependent paths
- Domain separation for hashes
- Passwords: argon2/bcrypt/scrypt, per-user salt
5. Input Handling & Injection
- Strict allowlists, schema validation at boundaries
- Parameterized queries (no string concatenation)
- Contextual output encoding (HTML/JS/URL)
- SSRF prevention: egress allowlists, metadata IP blocks
- Deserialization: avoid unsafe deserializers, type allowlists
- File uploads: content-type defense, store outside web root
6. Infrastructure
- Asset inventory + secure baseline (golden images)
- Patch SLAs with emergency path
- Network segmentation (prod ≠ CI/CD ≠ corp)
- mTLS for service-to-service
- Rate limits, quotas, circuit breakers
- No public admin panels (VPN + MFA + IP allowlists)
7. CI/CD & Supply Chain
Protect the build pipeline like prod:
- Least privilege runners
- Secrets only in protected contexts
- Reviews for workflow changes
Dependencies:
- Pin versions, verify integrity, monitor CVEs
- Remove abandoned libs
Supply chain:
- Signed build provenance
- OpenSSF Scorecard checks
- SLSA levels adoption
8. Detection & Response
Log with context:
- Auth events, privilege changes, key access
- Config changes, CI/CD events, unusual egress
Protect logs:
- Append-only/immutable, restricted access
Alerting:
- Brute force, impossible travel, new admin grants
- Anomalous token use
Readiness:
- Tabletop exercises, forensic snapshots, kill switches
- Post-incident RCA, patch bug classes
9. Verification
- Code review with security checklists
- SAST + dependency + secret scanning in CI
- DAST for critical surfaces
- Fuzzers on parsers, codecs, serialization
- Abuse case testing (rate limits, replay, permission boundaries)
- External audits for high-risk components
- Bug bounty when mature
Blockchain/Smart Contract Specifics
Protocol & Contracts
- Invariant-first design - Define safety properties, check continuously
- Upgradeability - Timelocks, emergency pause, clear admin key story
- Oracle/bridge threats - Assume counterpart compromise, minimize trust
- Economic attacks - MEV, sandwiching, griefing, liquidity manipulation
- Replay protection - Chain-id, contract address, nonce, EIP-712
- Key custody - Multisig, HSM, threshold signing
ZK Circuits/Provers
- Soundness - Constraints fully bind witness, no unchecked values
- Transcript binding - All public inputs in Fiat-Shamir transcript
- Range/overflow - Explicit range constraints, no wrap assumptions
- Challenges - Derive from transcript, never external mutable sources
- Trusted setup - Ceremony hygiene, reproducible parameters
- Side-channels - Constant-time for secrets, isolate prover infra
Operationalization
- Pick baselines: CIS v8 + NIST SSDF + OWASP ASVS
- Map to ATT&CK: What you can't detect, redesign
- Supply chain: SLSA + Scorecard for repos
- Loop: Threat model → Controls → Test → Monitor → Drills
Output Format
When conducting a review, structure findings as:
## Finding: [Title]
**Severity**: Critical / High / Medium / Low / Info
**Category**: [STRIDE category or framework reference]
**Location**: [File:line or component]
### Description
[What's wrong]
### Impact
[What could happen]
### Recommendation
[How to fix]
### References
[Framework links, CVE, etc.]
See references/ for detailed checklists by domain.
1---2name: security-audit-53description: Security review or audit of code, architecture, or infrastructure - Threat modeling sessions - Reviewing PRs for security implications4---5
6# Security Researcher
7
8Senior-grade security review guidelines anchored on canonical control frameworks: NIST CSF 2.0, CIS Controls v8, NIST SSDF, OWASP ASVS, OWASP Top 10, MITRE ATT&CK, SLSA, and OpenSSF Scorecard.
9
10## When to Use
11
12- Security review or audit of code, architecture, or infrastructure
13- Threat modeling sessions
14- Reviewing PRs for security implications
15- Assessing supply chain security
16- Smart contract or ZK circuit security reviews
17
18## Frameworks Reference
19
20| Framework | Purpose |
21| -------------------- | ----------------------------- |
22| NIST CSF 2.0 | Org-wide risk outcomes |
23| CIS Controls v8 | Practical enterprise controls |
24| NIST SSDF SP 800-218 | Secure development lifecycle |
25| OWASP ASVS | App security requirements |
26| OWASP Top 10 (2025) | Common web app failures |
27| MITRE ATT&CK | Adversary techniques mapping |
28| SLSA + OpenSSF | Supply chain integrity |
29
30## Non-Negotiables
31
32Before any deep review, verify these fundamentals:
33
341. **Asset inventory** - Systems, repos, secrets locations, dependencies, owners
352. **MFA everywhere** - Hardware keys for admins, no shared accounts
363. **Patch management** - Continuous vuln scanning (OS, containers, deps)
374. **Centralized logging** - Auth, privilege changes, egress, CI/CD, key access
385. **Tested backups** - Restore drills, immutable where possible
396. **Incident response** - Runbooks, on-call, break-glass procedures
40
41## Review Methodology
42
43### 1. Threat Model First
44
45Use STRIDE categories:
46
47- **S**poofing - Can attacker impersonate?
48- **T**ampering - Can data be modified?
49- **R**epudiation - Can actions be denied?
50- **I**nformation disclosure - Data leaks?
51- **D**enial of service - Availability attacks?
52- **E**levation of privilege - Unauthorized access?
53
54Document for each trust boundary:
55
56- Auth strategy
57- Data classification
58- Rate limits
59- Audit requirements
60
61**Assume compromise review:**
62
63- If one service key leaks, what's the blast radius?
64- If one dependency is malicious, what stops it?
65
66### 2. Identity & Access (Root Cause #1)
67
68Broken access control is the most common vulnerability.
69
70Check:
71
72- Default-deny authorization (by resource, not just endpoint)
73- Short-lived sessions, secure cookies, CSRF protection
74- Separation: authentication ≠ authorization ≠ accounting
75- Step-up auth for high-risk actions
76- RBAC/ABAC with explicit admin boundaries
77
78Protect against:
79
80- Credential stuffing (rate limits, breached password checks)
81- Account takeover (MFA, risky-login alerts)
82- Session fixation/replay (rotation, binding, nonce/jti)
83
84### 3. Secrets & Keys
85
86- **No secrets in git** - Pre-receive hooks, CI secret detectors
87- **Dedicated KMS/HSM** - Least privilege, rotate keys
88- **Environment separation** - Dev/stage/prod with separate creds
89- **Short-lived credentials** - OIDC to cloud, not static keys
90- **Track usage** - Who/what accessed, from where, when
91- **Compromise playbook** - Rotate, revoke, invalidate, postmortem
92
93### 4. Cryptography
94
95- Use modern primitives (AEAD, not raw AES modes)
96- Never roll your own crypto
97- CSPRNG for randomness (no time-based seeds)
98- Unique nonces where required
99- Constant-time ops for secret-dependent paths
100- Domain separation for hashes
101- Passwords: argon2/bcrypt/scrypt, per-user salt
102
103### 5. Input Handling & Injection
104
105- Strict allowlists, schema validation at boundaries
106- Parameterized queries (no string concatenation)
107- Contextual output encoding (HTML/JS/URL)
108- SSRF prevention: egress allowlists, metadata IP blocks
109- Deserialization: avoid unsafe deserializers, type allowlists
110- File uploads: content-type defense, store outside web root
111
112### 6. Infrastructure
113
114- Asset inventory + secure baseline (golden images)
115- Patch SLAs with emergency path
116- Network segmentation (prod ≠ CI/CD ≠ corp)
117- mTLS for service-to-service
118- Rate limits, quotas, circuit breakers
119- No public admin panels (VPN + MFA + IP allowlists)
120
121### 7. CI/CD & Supply Chain
122
123Protect the build pipeline like prod:
124
125- Least privilege runners
126- Secrets only in protected contexts
127- Reviews for workflow changes
128
129Dependencies:
130
131- Pin versions, verify integrity, monitor CVEs
132- Remove abandoned libs
133
134Supply chain:
135
136- Signed build provenance
137- OpenSSF Scorecard checks
138- SLSA levels adoption
139
140### 8. Detection & Response
141
142Log with context:
143
144- Auth events, privilege changes, key access
145- Config changes, CI/CD events, unusual egress
146
147Protect logs:
148
149- Append-only/immutable, restricted access
150
151Alerting:
152
153- Brute force, impossible travel, new admin grants
154- Anomalous token use
155
156Readiness:
157
158- Tabletop exercises, forensic snapshots, kill switches
159- Post-incident RCA, patch bug classes
160
161### 9. Verification
162
163- Code review with security checklists
164- SAST + dependency + secret scanning in CI
165- DAST for critical surfaces
166- Fuzzers on parsers, codecs, serialization
167- Abuse case testing (rate limits, replay, permission boundaries)
168- External audits for high-risk components
169- Bug bounty when mature
170
171## Blockchain/Smart Contract Specifics
172
173### Protocol & Contracts
174
175- **Invariant-first design** - Define safety properties, check continuously
176- **Upgradeability** - Timelocks, emergency pause, clear admin key story
177- **Oracle/bridge threats** - Assume counterpart compromise, minimize trust
178- **Economic attacks** - MEV, sandwiching, griefing, liquidity manipulation
179- **Replay protection** - Chain-id, contract address, nonce, EIP-712
180- **Key custody** - Multisig, HSM, threshold signing
181
182### ZK Circuits/Provers
183
184- **Soundness** - Constraints fully bind witness, no unchecked values
185- **Transcript binding** - All public inputs in Fiat-Shamir transcript
186- **Range/overflow** - Explicit range constraints, no wrap assumptions
187- **Challenges** - Derive from transcript, never external mutable sources
188- **Trusted setup** - Ceremony hygiene, reproducible parameters
189- **Side-channels** - Constant-time for secrets, isolate prover infra
190
191## Operationalization
192
1931. **Pick baselines**: CIS v8 + NIST SSDF + OWASP ASVS
1942. **Map to ATT&CK**: What you can't detect, redesign
1953. **Supply chain**: SLSA + Scorecard for repos
1964. **Loop**: Threat model → Controls → Test → Monitor → Drills
197
198## Output Format
199
200When conducting a review, structure findings as:
201
202```text
203## Finding: [Title]
204**Severity**: Critical / High / Medium / Low / Info
205**Category**: [STRIDE category or framework reference]
206**Location**: [File:line or component]
207
208### Description
209[What's wrong]
210
211### Impact
212[What could happen]
213
214### Recommendation
215[How to fix]
216
217### References
218[Framework links, CVE, etc.]
219```
220
221See `references/` for detailed checklists by domain.