Analysis · Cross-reference
Framework Mapping
Mapping findings to shared vocabularies makes them comparable across teams and easier to prioritize against existing control programs.
These mappings demonstrate security-analysis reasoning on synthetic data. They are not a certification, a compliance attestation, or a formal assessment of any organization.
Full cross-reference
Every validated synthetic finding with its mappings.
| ID | Severity | Finding | OWASP Top 10 | CWE | MITRE ATT&CK | NIST CSF 2.0 |
|---|---|---|---|---|---|---|
| EH-001 | Critical | Broken access control in synthetic admin workflow | A01:2021 Broken Access Control | CWE-284 | T1078 Valid Accounts (conceptual) | PR.AA — Identity Management, Authentication and Access Control |
| EH-002 | High | Overly broad permissions assigned to synthetic test role | A01:2021 Broken Access Control | CWE-269 | T1098 Account Manipulation (conceptual) | PR.AA — Access permissions managed with least privilege |
| EH-003 | High | Overly permissive network path between synthetic application and data tiers | A05:2021 Security Misconfiguration | CWE-923 | T1210 Exploitation of Remote Services (conceptual) | PR.IR — Network segmentation and resilience |
| EH-004 | High | Insecure test upload validation on lab endpoint | A04:2021 Insecure Design | CWE-434 | — | PR.PS — Platform security and secure development practices |
| EH-005 | Medium | Missing rate-limit control on lab authentication endpoint | A07:2021 Identification and Authentication Failures | CWE-307 | T1110 Brute Force (conceptual) | DE.CM — Continuous monitoring of authentication activity |
| EH-006 | Medium | Weak session timeout policy on synthetic portal | A07:2021 Identification and Authentication Failures | CWE-613 | — | PR.AA — Authentication lifecycle management |
| EH-007 | Medium | Insecure default security headers on lab web tier | A05:2021 Security Misconfiguration | CWE-693 | — | PR.PS — Secure configuration baselines |
| EH-008 | Medium | Secrets represented in a synthetic configuration example | A05:2021 Security Misconfiguration | CWE-798 | T1552 Unsecured Credentials (conceptual) | PR.DS — Data-in-use and credential protection |
| EH-009 | Medium | Stale synthetic service account remains enabled | A01:2021 Broken Access Control | CWE-1108 | T1078.004 Valid Accounts: Cloud Accounts (conceptual) | ID.AM — Inventory of non-human identities |
| EH-010 | Low | Exposed version and banner information on lab gateway | A05:2021 Security Misconfiguration | CWE-200 | T1592 Gather Victim Host Information (conceptual) | PR.PS — Configuration hardening |
| EH-011 | Low | Verbose error messages reveal internal structure on lab API | A05:2021 Security Misconfiguration | CWE-209 | — | PR.PS — Secure defaults for error handling |
| EH-012 | Low | Insufficient logging of privileged actions in lab admin console | A09:2021 Security Logging and Monitoring Failures | CWE-778 | — | DE.AE — Adverse event analysis |
Grouped views
Where the synthetic findings concentrate by vocabulary.
OWASP Top 10 (2021)
A01:2021 Broken Access Control
EH-001 · EH-002 · EH-009
A04:2021 Insecure Design
EH-004
A05:2021 Security Misconfiguration
EH-003 · EH-007 · EH-008 · EH-010 · EH-011
A07:2021 Identification and Authentication Failures
EH-005 · EH-006
A09:2021 Security Logging and Monitoring Failures
EH-012
CWE
CWE-1108
EH-009
CWE-200
EH-010
CWE-209
EH-011
CWE-269
EH-002
CWE-284
EH-001
CWE-307
EH-005
CWE-434
EH-004
CWE-613
EH-006
CWE-693
EH-007
CWE-778
EH-012
CWE-798
EH-008
CWE-923
EH-003
MITRE ATT&CK (conceptual)
T1078 Valid Accounts (conceptual)
EH-001
T1078.004 Valid Accounts: Cloud Accounts (conceptual)
EH-009
T1098 Account Manipulation (conceptual)
EH-002
T1110 Brute Force (conceptual)
EH-005
T1210 Exploitation of Remote Services (conceptual)
EH-003
T1552 Unsecured Credentials (conceptual)
EH-008
T1592 Gather Victim Host Information (conceptual)
EH-010
Techniques are cited only where conceptually relevant to the synthetic finding. They describe adversary behaviour categories, not steps taken in this lab.
NIST CSF 2.0 functions
High-level alignment of engagement activity to CSF 2.0 functions.
GOVERN (GV)
Rules of engagement, authorization requirements, and named remediation ownership.
IDENTIFY (ID)
Attack-surface inventory, asset ownership, and non-human identity inventory (EH-009).
PROTECT (PR)
Access control, least privilege, secure configuration, segmentation, and secret protection (EH-001 to EH-011).
DETECT (DE)
Authentication-failure monitoring and privileged-action audit coverage (EH-005, EH-012).
RESPOND (RS)
Escalation path, stop conditions, and detection opportunities recorded per attack path.
RECOVER (RC)
Retest and closure decisions that confirm the environment returns to an assured state.