Adversary tactics and techniques for cloud — IaaS, SaaS and identity
MITRE ATT&CK (Cloud)
MITRE ATT&CK is a knowledge base of adversary tactics and techniques. Its Cloud matrices (IaaS, SaaS, and identity) map real-world attacker behavior such as initial access, persistence, privilege escalation, defense evasion, credential access, and exfiltration to concrete detections and mitigations.
By expressing cloud misconfigurations and detections in threat-informed terms, ATT&CK helps teams on AWS, Azure, GCP, and OCI prioritize the gaps attackers actually exploit. Cloudanix maps findings to ATT&CK techniques so security teams can reason about posture in the language of the adversary.