You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This document defines intentional, controlled vulnerabilities to evaluate the SOC's detection capabilities. Each vulnerability is mapped to OWASP Top 10, MITRE ATT&CK, and corresponding Wazuh detection rules.
1. Privilege Escalation (Admin Override)
Field
Value
OWASP
A01:2021 – Broken Access Control
MITRE Tactic
TA0004 – Privilege Escalation
MITRE Technique
T1078 – Valid Accounts
Mechanism
Header: X-Admin-Override: true
Endpoint
GET /admin/system_status
Detection Rule
100010 (Level 10)
Test Command
make test-privilege
2. SQL Injection
Field
Value
OWASP
A03:2021 – Injection
MITRE Tactic
TA0001 – Initial Access
MITRE Technique
T1190 – Exploit Public-Facing Application
Mechanism
Payload: 1' OR '1'='1
Endpoint
GET /items/{id}
Detection Rule
100005 (Level 12)
Test Command
make test-sqli
3. Brute Force Attack (API)
Field
Value
OWASP
A07:2021 – Identification and Authentication Failures