Skip to content
winfunc
Blue team & incident response

Contain faster, with the code already traced.

When an alert fires, winfunc ties it to the code path and open findings behind it, scopes the blast radius, and hands responders the fix, then replays the attack to prove it is closed.

What's included
  1. acme
  2. /Incidents
  3. /INC-0142
Contained
HighUnusual role use from billing-apiUTC · Sep 24
  1. 02:14AlertInstance role used from an outside address
    cloudtrail · AssumeRole · app-role
  2. 02:16TriageLinked to open finding WF-0877
    webhook preview SSRF · webhooks/preview.ts:61
  3. 02:21Scope3 metadata requests, 1 role, 0 objects read
    access logs · object-level trail
  4. 02:29ContainCredentials rotated, metadata hop limit set
    app-role · IMDSv2 required
  5. 02:47FixPatch opened for the URL allow-list
    PR #2519 · validated
  6. 03:05VerifyReplay of the attacker's request rejected
    400 · host not allowed
Record
Detected by
SIEM rule · purple team
Root cause
webhooks/preview.ts:61
Blast radius
1 role · no data read
Contained in
15m
Postmortem
Incident response · timelineIllustrative data
The problem

Responders start from logs. The cause lives in code.

An alert tells you something happened, not why it was possible. winfunc connects the activity to the vulnerable code path, the findings already on record, and the configuration that allowed it, so containment and the permanent fix happen in the same response.

Included

What winfunc covers.

  • Alert and incident triage tied to code paths and open findings
  • Scoping of the affected services, identities, and data
  • Containment steps and configuration hardening recommendations
  • Root cause traced to the line of code or the configuration that allowed it
  • Patches opened as pull requests, then the attack replayed to confirm the fix
  • Incident timeline and a postmortem draft for your records
  • Blue team reviews between incidents: hardening, logging, and detection coverage
Outcomes

What your team walks away with.

01

Cause, not just symptoms

Responders see the exploited path in the code and the configuration beside it, not only the anomalous log line.

02

Scope with evidence

Blast radius is established from access logs and code paths, so containment is proportionate and defensible.

03

Fixed and verified

The permanent fix ships as a reviewed pull request and the attacker's request is replayed until it fails.

04

Stronger between incidents

Hardening and detection reviews carry the lessons of each incident into the next quarter's defenses.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.

A voxel chessboard: a bone rook and a red knight, with the traced path between them lit green after the fix was verified