Performing Security Headers Audit
Overview
Cybersecurity skill for performing security headers audit. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"performing security headers audit"
"Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie "
During authorized web application security assessments as a standard configuration review
When evaluating browser-level protections against XSS, clickjacking, and data leakage
For compliance assessments requiring security header implementation (PCI DSS, SOC 2)
When performing initial reconnaissance to identify easy-win security improvements
During CI/CD pipeline security gate checks for new deployments
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Authorization: Written scope for the target application (header review is low-risk)
- curl: For fetching response headers from target endpoints
- SecurityHeaders.com: Online scanner for quick header assessment
- Mozilla Observatory: Mozilla's web security testing tool
- Burp Suite: For comprehensive header analysis across multiple pages
- Browser DevTools: For examining headers and CSP violations in real-time
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for security headers audit operations.
- Prepare Environment — Set up tools, access, and data sources required for security headers audit.
- Execute Core Workflow — Perform the security headers audit operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Reconnaissance — Gather target information, identify attack surface, enumerate services
- Analysis/Exploitation — Execute the technique, analyze results, document findings
- Reporting — Document IOCs, write findings, provide remediation recommendations
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-security-headers-audit3description: Use when auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections. Use when working with performing security headers audit.4license: Apache-2.05---67# Performing Security Headers Audit89## Overview1011Cybersecurity skill for performing security headers audit. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "performing security headers audit"16- "Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie "171819- During authorized web application security assessments as a standard configuration review20- When evaluating browser-level protections against XSS, clickjacking, and data leakage21- For compliance assessments requiring security header implementation (PCI DSS, SOC 2)22- When performing initial reconnaissance to identify easy-win security improvements23- During CI/CD pipeline security gate checks for new deployments242526## When NOT to Use2728- When you lack proper authorization for testing29- For production systems without change management30- When the task requires legal or compliance expertise beyond technical scope313233## Prerequisites3435- **Authorization**: Written scope for the target application (header review is low-risk)36- **curl**: For fetching response headers from target endpoints37- **SecurityHeaders.com**: Online scanner for quick header assessment38- **Mozilla Observatory**: Mozilla's web security testing tool39- **Burp Suite**: For comprehensive header analysis across multiple pages40- **Browser DevTools**: For examining headers and CSP violations in real-time4142## Workflow4344```python45# Example: IOC detection46import re4748IOC_PATTERNS = {49 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",50 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",51 "hash_md5": r"\b[a-f0-9]{32}\b",52 "hash_sha256": r"\b[a-f0-9]{64}\b",53}5455def extract_iocs(text: str) -> dict:56 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}57```58591. **Plan Operations** — Define objectives, scope, and success criteria for security headers audit operations.602. **Prepare Environment** — Set up tools, access, and data sources required for security headers audit.613. **Execute Core Workflow** — Perform the security headers audit operations following established procedures.624. **Validate Results** — Verify that results meet quality standards and objectives.635. **Report Findings** — Document results, observations, and recommendations.646. **Follow Up** — Track remediation actions and verify fixes where applicable.6566## Tools6768- **Analysis Platform** — Data processing and visualization69- **Collaboration Tools** — Team coordination and knowledge sharing707172## Process73741. **Reconnaissance** — Gather target information, identify attack surface, enumerate services751. **Analysis/Exploitation** — Execute the technique, analyze results, document findings761. **Reporting** — Document IOCs, write findings, provide remediation recommendations7778## Verification7980- [ ] All security headers audit procedures executed completely and documented81- [ ] Findings validated against multiple data sources82- [ ] False positives identified and filtered83- [ ] Results documented with evidence and timestamps84- [ ] Recommendations provided with risk-based prioritization8586## Anti-Rationalization Table8788| Rationalization | Reality |89|---|---|90| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |91| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |92| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |