Skip to content

This tool is not affiliated with, endorsed by or sponsored by Amazon Web Services, Inc. or Amazon.com, Inc. AWS, Amazon Web Services, CloudTrail and GuardDuty are trademarks of Amazon.com, Inc. or its affiliates. Other names are trademarks of their respective owners.

Glossary

MITRE ATT&CK

A public knowledge base of adversary tactics and techniques; its cloud (IaaS) matrix gives shared ids such as T1078.004 or T1562.008 for AWS attack behaviour.

MITRE ATT&CK is a publicly available knowledge base of adversary tactics (the goal, such as persistence or exfiltration) and techniques (how it is achieved), each with a stable identifier. Its IaaS matrix covers cloud behaviour: T1078.004 valid cloud accounts, T1098.001 additional cloud credentials, T1562.008 disabling cloud logs, T1530 data from cloud storage, T1496 resource hijacking.

Mapping findings to ATT&CK makes reports comparable and shows coverage gaps. The analyzer tags every detection with its techniques; see CloudTrail events mapped to MITRE ATT&CK.

Reference: ATT&CK IaaS matrix.

This tool is not affiliated with, endorsed by or sponsored by Amazon Web Services, Inc. or Amazon.com, Inc. AWS, Amazon Web Services, CloudTrail and GuardDuty are trademarks of Amazon.com, Inc. or its affiliates. Other names are trademarks of their respective owners.