Corvus
RED×BLUE

Threat Playbook

Adversary vectors paired with the defensive controls that close them. Read top-to-bottom — engagements are sorted by severity. Baseline controls below apply across the surface.

2
Severe
4
Moderate
1
Low
1
Baseline

Severe · Act Now

2 engagements

Moderate · Plan Mitigation

4 engagements

Low · Monitor

1 engagement

Baseline · Surface-Wide

1 control
B-08Baseline

Continuous bug-bounty maturation (already live on HackerOne) + scope expansion

The active HackerOne program (DNS TXT confirms; ent_002) is already an asset. Maintenance work: expand scope to include the LE-portal API surface and any partner-facing federation endpoints; tier rewards to bring more capable researchers; publish a clear safe-harbor / vulnerability-disclosure policy. Baseline control orthogonal to the specific R-vectors above.