Skip to content

Analysis · Cross-reference

Framework Mapping

Mapping findings to shared vocabularies makes them comparable across teams and easier to prioritize against existing control programs.

These mappings demonstrate security-analysis reasoning on synthetic data. They are not a certification, a compliance attestation, or a formal assessment of any organization.

Full cross-reference

Every validated synthetic finding with its mappings.

Findings mapped to OWASP, CWE, MITRE ATT&CK, and NIST CSF 2.0
IDSeverityFindingOWASP Top 10CWEMITRE ATT&CKNIST CSF 2.0
EH-001CriticalBroken access control in synthetic admin workflowA01:2021 Broken Access ControlCWE-284T1078 Valid Accounts (conceptual)PR.AA — Identity Management, Authentication and Access Control
EH-002HighOverly broad permissions assigned to synthetic test roleA01:2021 Broken Access ControlCWE-269T1098 Account Manipulation (conceptual)PR.AA — Access permissions managed with least privilege
EH-003HighOverly permissive network path between synthetic application and data tiersA05:2021 Security MisconfigurationCWE-923T1210 Exploitation of Remote Services (conceptual)PR.IR — Network segmentation and resilience
EH-004HighInsecure test upload validation on lab endpointA04:2021 Insecure DesignCWE-434PR.PS — Platform security and secure development practices
EH-005MediumMissing rate-limit control on lab authentication endpointA07:2021 Identification and Authentication FailuresCWE-307T1110 Brute Force (conceptual)DE.CM — Continuous monitoring of authentication activity
EH-006MediumWeak session timeout policy on synthetic portalA07:2021 Identification and Authentication FailuresCWE-613PR.AA — Authentication lifecycle management
EH-007MediumInsecure default security headers on lab web tierA05:2021 Security MisconfigurationCWE-693PR.PS — Secure configuration baselines
EH-008MediumSecrets represented in a synthetic configuration exampleA05:2021 Security MisconfigurationCWE-798T1552 Unsecured Credentials (conceptual)PR.DS — Data-in-use and credential protection
EH-009MediumStale synthetic service account remains enabledA01:2021 Broken Access ControlCWE-1108T1078.004 Valid Accounts: Cloud Accounts (conceptual)ID.AM — Inventory of non-human identities
EH-010LowExposed version and banner information on lab gatewayA05:2021 Security MisconfigurationCWE-200T1592 Gather Victim Host Information (conceptual)PR.PS — Configuration hardening
EH-011LowVerbose error messages reveal internal structure on lab APIA05:2021 Security MisconfigurationCWE-209PR.PS — Secure defaults for error handling
EH-012LowInsufficient logging of privileged actions in lab admin consoleA09:2021 Security Logging and Monitoring FailuresCWE-778DE.AE — Adverse event analysis

Grouped views

Where the synthetic findings concentrate by vocabulary.

OWASP Top 10 (2021)

  • A01:2021 Broken Access Control

    EH-001 · EH-002 · EH-009

  • A04:2021 Insecure Design

    EH-004

  • A05:2021 Security Misconfiguration

    EH-003 · EH-007 · EH-008 · EH-010 · EH-011

  • A07:2021 Identification and Authentication Failures

    EH-005 · EH-006

  • A09:2021 Security Logging and Monitoring Failures

    EH-012

CWE

  • CWE-1108

    EH-009

  • CWE-200

    EH-010

  • CWE-209

    EH-011

  • CWE-269

    EH-002

  • CWE-284

    EH-001

  • CWE-307

    EH-005

  • CWE-434

    EH-004

  • CWE-613

    EH-006

  • CWE-693

    EH-007

  • CWE-778

    EH-012

  • CWE-798

    EH-008

  • CWE-923

    EH-003

MITRE ATT&CK (conceptual)

  • T1078 Valid Accounts (conceptual)

    EH-001

  • T1078.004 Valid Accounts: Cloud Accounts (conceptual)

    EH-009

  • T1098 Account Manipulation (conceptual)

    EH-002

  • T1110 Brute Force (conceptual)

    EH-005

  • T1210 Exploitation of Remote Services (conceptual)

    EH-003

  • T1552 Unsecured Credentials (conceptual)

    EH-008

  • T1592 Gather Victim Host Information (conceptual)

    EH-010

Techniques are cited only where conceptually relevant to the synthetic finding. They describe adversary behaviour categories, not steps taken in this lab.

NIST CSF 2.0 functions

High-level alignment of engagement activity to CSF 2.0 functions.

GOVERN (GV)

Rules of engagement, authorization requirements, and named remediation ownership.

IDENTIFY (ID)

Attack-surface inventory, asset ownership, and non-human identity inventory (EH-009).

PROTECT (PR)

Access control, least privilege, secure configuration, segmentation, and secret protection (EH-001 to EH-011).

DETECT (DE)

Authentication-failure monitoring and privileged-action audit coverage (EH-005, EH-012).

RESPOND (RS)

Escalation path, stop conditions, and detection opportunities recorded per attack path.

RECOVER (RC)

Retest and closure decisions that confirm the environment returns to an assured state.