As cited
Copy frozen at (site build).
research
OWASP’s subtractive security project measures the attack paths you erased
The OWASP Subtractive Security Top 10 project, led by Christopher Frenz, identifies and measures attack paths that organizations should remove before they can be exploited. The initiative publishes nine lists and introduces the Path Erasure Rate engineering standard to help organizations eliminate unnecessary capabilities like service accounts, outbound routes, and scripting engines that attackers could leverage.
Why it matters: Security practitioners should adopt this framework to reduce their attack surface by removing unnecessary permissions and capabilities before adversaries can abuse them, complementing rather than replacing traditional detection-focused defenses.
- Source published
- First seen by Cybersecurity Tracker