SCARP
CS-1042
Illustrative — not customer data
Report date: 30 August 2026
Prepared for: illustrative B2B SaaS attack surface
Change-set review
CS-1042: Admin takeover
4 paths · 9 evidence entries · Owner Platform engineering
Decision
Require MFA and trusted network access
Cuts the three sign-in routes that share the workforce identity policy.
- Owner
- Platform engineering
- Effort / disruption
- 1–2 days · Medium
- Confidence
- 86% illustrative
Projected
4
paths expected removed
Realized
3
paths confirmed removed
Remaining
1
path still reachable after re-check
Still reachable after re-check
staging-admin.example still reaches the customer administration plane: it authenticates against separate local credentials, outside the identity policy the change tightened.
Change-set comparison
The selected fix is shown alongside the counterfactual so its projected and realized reach are explicit.
Illustrative alternatives
Selected change
Require MFA and trusted network access
- Owner
- Platform engineering
- Effort
- 1–2 days
- Disruption
- Medium
- Expected paths removed
- 4
- Realized paths removed
- 3
Counterfactual
Retire the legacy administration endpoint
- Owner
- Application engineering
- Effort
- 1–2 sprints
- Disruption
- High
- Expected paths removed
- 2
- Realized paths removed
- 2
Audit closure line · 30 August 2026
Change set CS-1042, owned by Platform engineering, was reviewed under the 48 hours SLA. Observation obs_31bc and closure closure_9cd2 tie the projected 4-path reduction to 3 paths confirmed removed; verification: Direct-origin denial, gateway authentication, and alternate-host reachability.
Evidence register
Illustrative data — not customer output.
| Stage | Entity | Detail | Evidence | Source | Confidence | Freshness |
|---|---|---|---|---|---|---|
| entry | Public internet | Unauthenticated route | observed | Passive external observation | 98% | 12 min ago |
| entry | Credential spray | Known admin usernames | inferred | Reachability correlation | 82% | 12 min ago |
| exposure | admin-legacy.example | Public legacy admin panel | observed | Passive external observation | 98% | 12 min ago |
| exposure | Workforce identity | Single-factor fallback | validated | Operator-authorized validation | 96% | 8 min ago |
| exposure | staging-admin.example | Administration host with separate local credentials | observed | Passive external observation | 98% | 12 min ago |
| control | Weak access policy | No MFA or network restriction | validated | Operator-authorized validation | 96% | 8 min ago |
| asset | Customer administration plane | Privileged customer configuration | inferred | Reachability correlation | 82% | 12 min ago |
| asset | Reporting workspace | Customer evidence exports | inferred | Reachability correlation | 82% | 12 min ago |
| impact | Administrative takeover | Customer data and configuration access | inferred | Reachability correlation | 82% | 12 min ago |