Security — Alert Triage Funnel
A detection-to-containment funnel for one quarter, with the threat model the detections were written from sitting beside it. Typed FlowScript for threat modelling. Keywords: threat model, STRIDE, risk matrix, security.
Make it your own.
// A detection-to-containment funnel for one quarter, with the threat
// model the detections were written from sitting beside it. Every alert
// closed short of an incident is attributed to a reason, so the funnel
// narrows from 9 840 detections to 41 same-day containments with nothing
// unexplained in between.
threat_model perimeter {
framework: "STRIDE"
title: "Externally reachable API surface"
scope: "Public API gateway, admin console, CI runners"
}
asset customer_data {
name: "Customer records"
value: "Regulated personal data; breach is notifiable within 72 hours"
classification: "restricted"
}
asset build_pipeline {
name: "CI build pipeline"
value: "Signs and publishes every production artefact"
classification: "confidential"
}
threat cred_stuffing {
title: "Credential stuffing against the admin console"
asset: customer_data
category: "spoofing"
likelihood: 5
impact: 4
}
threat token_exfil {
title: "CI token exfiltrated from a build log"
asset: build_pipeline
category: "info-disclosure"
likelihood: 3
impact: 5
}
threat dependency_swap {
title: "Malicious dependency introduced at build time"
asset: build_pipeline
category: "tampering"
likelihood: 2
impact: 5
}
threat log_gap {
title: "Admin action taken with audit logging disabled"
asset: customer_data
category: "repudiation"
likelihood: 3
impact: 3
}
control hardware_mfa {
title: "Hardware MFA on every admin session"
mitigates: [cred_stuffing]
type: "preventive"
coverage: 0.85
owner: "IT security"
}
control log_scrub {
title: "Secret scrubbing in the CI log shipper"
mitigates: [token_exfil]
type: "preventive"
coverage: 0.7
owner: "Platform"
}
control pinned_deps {
title: "Pinned, checksum-verified dependencies"
mitigates: [dependency_swap]
type: "preventive"
coverage: 0.8
owner: "Platform"
}
control append_only_audit {
title: "Append-only audit log the console cannot disable"
mitigates: [log_gap, cred_stuffing]
type: "detective"
coverage: 0.9
owner: "IT security"
}
// ── Triage, as accounted arithmetic.
cohort detections {
n: 9840 source "SIEM export, Q2"
}
cohort deduplicated {
n: 3112
from: detections
excluded: {
correlated_into_open_case: 5981
known_benign_signature: 747
}
}
cohort analyst_triaged {
n: 986
from: deduplicated
excluded: {
auto_closed_by_playbook: 1904
below_severity_threshold: 222
}
}
cohort escalated {
n: 214
from: analyst_triaged
excluded: {
false_positive: 658
expected_administrator_activity: 114
}
}
cohort confirmed_incidents {
n: 47
from: escalated
excluded: {
no_evidence_of_compromise: 152
duplicate_of_confirmed_incident: 15
}
}
cohort contained_same_day {
n: 41
from: confirmed_incidents
excluded: {
contained_next_day: 5
contained_after_72_hours: 1
}
}
view risk: risk_matrix
view triage: consort(detections)