Skip to content
FlowScript templates

Security — Alert Triage Funnel

A detection-to-containment funnel for one quarter, with the threat model the detections were written from sitting beside it. Typed FlowScript for threat modelling. Keywords: threat model, STRIDE, risk matrix, security.

Template previewFlowScript
RISK MATRIX · STRIDEExternally reachable API surfaceLIKELIHOOD →IMPACT →1122334455CRTODELORESIDUAL RISK · RANKEDCI token exfiltrated from a build logL:1 · I:5 · info-disclosure5Malicious dependency introduced at build timeL:1 · I:5 · tampering5Credential stuffing against the admin consoleL:1 · I:4 · spoofing4Admin action taken with audit logging disabledL:1 · I:3 · repudiation3

Make it your own.

// A detection-to-containment funnel for one quarter, with the threat
// model the detections were written from sitting beside it. Every alert
// closed short of an incident is attributed to a reason, so the funnel
// narrows from 9 840 detections to 41 same-day containments with nothing
// unexplained in between.

threat_model perimeter {
  framework: "STRIDE"
  title: "Externally reachable API surface"
  scope: "Public API gateway, admin console, CI runners"
}

asset customer_data {
  name: "Customer records"
  value: "Regulated personal data; breach is notifiable within 72 hours"
  classification: "restricted"
}

asset build_pipeline {
  name: "CI build pipeline"
  value: "Signs and publishes every production artefact"
  classification: "confidential"
}

threat cred_stuffing {
  title: "Credential stuffing against the admin console"
  asset: customer_data
  category: "spoofing"
  likelihood: 5
  impact: 4
}

threat token_exfil {
  title: "CI token exfiltrated from a build log"
  asset: build_pipeline
  category: "info-disclosure"
  likelihood: 3
  impact: 5
}

threat dependency_swap {
  title: "Malicious dependency introduced at build time"
  asset: build_pipeline
  category: "tampering"
  likelihood: 2
  impact: 5
}

threat log_gap {
  title: "Admin action taken with audit logging disabled"
  asset: customer_data
  category: "repudiation"
  likelihood: 3
  impact: 3
}

control hardware_mfa {
  title: "Hardware MFA on every admin session"
  mitigates: [cred_stuffing]
  type: "preventive"
  coverage: 0.85
  owner: "IT security"
}

control log_scrub {
  title: "Secret scrubbing in the CI log shipper"
  mitigates: [token_exfil]
  type: "preventive"
  coverage: 0.7
  owner: "Platform"
}

control pinned_deps {
  title: "Pinned, checksum-verified dependencies"
  mitigates: [dependency_swap]
  type: "preventive"
  coverage: 0.8
  owner: "Platform"
}

control append_only_audit {
  title: "Append-only audit log the console cannot disable"
  mitigates: [log_gap, cred_stuffing]
  type: "detective"
  coverage: 0.9
  owner: "IT security"
}

// ── Triage, as accounted arithmetic.
cohort detections {
  n: 9840 source "SIEM export, Q2"
}

cohort deduplicated {
  n: 3112
  from: detections
  excluded: {
    correlated_into_open_case: 5981
    known_benign_signature: 747
  }
}

cohort analyst_triaged {
  n: 986
  from: deduplicated
  excluded: {
    auto_closed_by_playbook: 1904
    below_severity_threshold: 222
  }
}

cohort escalated {
  n: 214
  from: analyst_triaged
  excluded: {
    false_positive: 658
    expected_administrator_activity: 114
  }
}

cohort confirmed_incidents {
  n: 47
  from: escalated
  excluded: {
    no_evidence_of_compromise: 152
    duplicate_of_confirmed_incident: 15
  }
}

cohort contained_same_day {
  n: 41
  from: confirmed_incidents
  excluded: {
    contained_next_day: 5
    contained_after_72_hours: 1
  }
}

view risk: risk_matrix
view triage: consort(detections)