Skip to content

Add SAF-T1506: Infrastructure Token Theft - #219

Open
mironovisa wants to merge 1 commit into
secure-agentic-framework:mainfrom
mironovisa:feat/SAF-T1506-infrastructure-token-theft
Open

mironovisa wants to merge 1 commit into
secure-agentic-framework:mainfrom
mironovisa:feat/SAF-T1506-infrastructure-token-theft

Conversation

@mironovisa

Copy link
Copy Markdown

Summary

  • document infrastructure token theft from logs, traces, proxies, crash dumps, and support exports
  • explain the separate client, MCP policy, and upstream credential boundaries
  • add detection guidance, incident response steps, and an experimental Sigma-compatible rule
  • map the technique to primary MCP, OAuth, OWASP, and MITRE sources

Validation

  • confirmed no open PR or issue currently targets SAF-T1506
  • parsed detection-rule.yml successfully as YAML
  • ran git diff --check
  • commit includes DCO sign-off

Signed-off-by: mironovisa <119300058+mironovisa@users.noreply.github.com>
@mironovisa

Copy link
Copy Markdown
Author

Hi — quick maintainer check on SAF-T1506. The contribution is scoped to infrastructure-token exposure through logs, traces, proxies, crash dumps, support exports, and persistent agent memory, with separate client, MCP-policy, and upstream-credential boundaries. DCO is passing and the PR is mergeable. Happy to revise the technique structure or evidence references if needed.

@Santoshkumarpuppala

Copy link
Copy Markdown

Heads up before this waits any longer on review: #182 (feat(SAFE-T1506): added [Infrastructure Token Theft]) is still open and targets the same technique ID with the same title. It predates this one — opened 2026-02-08, last touched 2026-03-07 — and techniques/SAF-T1506 doesn't exist on main, so neither has landed.

It also carries review feedback that probably applies here too: @bishnubista asked for a version history section on 2026-03-04, and left a review on 2026-03-07 with seven inline comments, three flagged critical, including a citation that doesn't support the claim attached to it.

Probably faster to reconcile the two than to wait for a maintainer to spot the collision — either fold your content into #182, or state in this PR why it supersedes it. The "confirmed no open PR or issue currently targets SAF-T1506" line in the description is the first thing a reviewer will check.

Context for the drive-by: I work on MCP tool-call policy enforcement — Norviq, https://norviq.dev / https://github.com/norviq-dev/norviq — and hit #182 while reading through the SAF-T15xx range.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants