OWASP / OWASP/maswe

Define and Normalize Threats, Attacks and Impact (DRAFT ISSUE; WIP)

Open
#185 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
43
Forks
27
Avg merge
1d 17h
Merged PRs (30d)
4

Description

Define Threats, Attacks (align with CAPEC/MITRE) and Impact

https://capec.mitre.org/data/definitions/188.html

Example: https://attack.mitre.org/techniques/T1474/001/ (Supply Chain Compromise: Compromise Software Dependencies and Development Tools)

in MASWE-0041: Identifying vulnerable dependency versions in the app package and using public advisories or exploits.

Align impact labels to STRIDE: https://learn.microsoft.com/en-us/previous-versions/commerce-server/ee823878(v=cs.20)?redirectedfrom=MSDN

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with MASWE-0041 and review the linked CAPEC, MITRE ATT&CK, and STRIDE references. Define a consistent vocabulary and normalize threat, attack, and impact labels across the relevant MASWE content; done means the terms and labels are aligned and their usage is documented.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.