CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

OWASP’s subtractive security project measures the attack paths you erased

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3778

As cited

Copy frozen at (site build).

research

OWASP’s subtractive security project measures the attack paths you erased

The OWASP Subtractive Security Top 10 project, led by Christopher Frenz, identifies and measures attack paths that organizations should remove before they can be exploited. The initiative publishes nine lists and introduces the Path Erasure Rate engineering standard to help organizations eliminate unnecessary capabilities like service accounts, outbound routes, and scripting engines that attackers could leverage.

Why it matters: Security practitioners should adopt this framework to reduce their attack surface by removing unnecessary permissions and capabilities before adversaries can abuse them, complementing rather than replacing traditional detection-focused defenses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary