Glossary
MITRE ATT&CK
A public knowledge base of adversary tactics and techniques; its cloud (IaaS) matrix gives shared ids such as T1078.004 or T1562.008 for AWS attack behaviour.
MITRE ATT&CK is a publicly available knowledge base of adversary tactics (the goal, such as persistence or exfiltration) and techniques (how it is achieved), each with a stable identifier. Its IaaS matrix covers cloud behaviour: T1078.004 valid cloud accounts, T1098.001 additional cloud credentials, T1562.008 disabling cloud logs, T1530 data from cloud storage, T1496 resource hijacking.
Mapping findings to ATT&CK makes reports comparable and shows coverage gaps. The analyzer tags every detection with its techniques; see CloudTrail events mapped to MITRE ATT&CK.
Reference: ATT&CK IaaS matrix.