MITRE ATT&CK · cloud matrix
Coverage isn't a number on a slide. It's a grid, tracked in the open.
Six full adversary emulations plus 43 atomic tests, mapped to the AWS ATT&CK surface. Every technique below is something our open-source repo can emulate today - nothing on this page you can't verify in the source. Each run ships the CloudTrail signature and the detection content that should catch it.
Campaign emulations
6
+ 43 atomic tests
MITRE techniques
49
unique IDs, 12 tactics
AWS services
27
exercised end-to-end
Source of truth
repo
verifiable on GitHub
rows = MITRE tactic · columns = emulation
TACTIC / EMULATION
DangerDev
AmberSquid
SCARLETEEL
SCARLETEEL2
CodeFinger
LUCR-3
Resource Dev
1tech
2tech
·
·
·
·
Initial Access
3tech
1tech
2tech
2tech
1tech
1tech
Execution
·
2tech
·
·
·
·
Persistence
2tech
3tech
·
1tech
·
4tech
Priv-Esc
1tech
·
·
·
·
·
Defense Evas.
3tech
3tech
1tech
1tech
·
5tech
Credential Acc.
·
·
2tech
3tech
·
3tech
Discovery
4tech
1tech
1tech
1tech
·
3tech
Lateral Mov.
1tech
·
·
·
·
2tech
Collection
1tech
·
1tech
·
1tech
3tech
Exfiltration
·
·
·
1tech
·
·
Impact
1tech
1tech
1tech
1tech
3tech
·
Techniques per tactic
3 or more
2
1
none in this emulation
number = techniques this emulation runs in that tactic
DangerDev
Phishing → broad cloud compromise 16 techT1566.002Spearphishing LinkINIT
T1199Trusted RelationshipINIT
T1098.003Additional Cloud RolesPRIVESC
T1526Cloud Service DiscoveryDISC
T1021.001Remote Services: RDPLATERAL
T1496Resource HijackingIMPACT
AmberSquid
Multi-service cryptomining 13 techT1059.009Cloud API executionEXEC
T1136.003Create Cloud AccountPERSIST
T1610Deploy ContainerEVASION
T1525Implant Internal ImagePERSIST
T1070Indicator RemovalEVASION
T1496Resource HijackingIMPACT
SCARLETEEL
Compute exploit → cloud theft 7 techT1190Exploit Public-Facing AppINIT
T1552.005Cloud Instance Metadata APICRED
T1552.001Credentials in FilesCRED
T1562.008Disable Cloud LogsEVASION
T1530Data from Cloud StorageCOLLECT
T1496Resource HijackingIMPACT
SCARLETEEL2
Evolved exploit + token theft 9 techT1190Exploit Public-Facing AppINIT
T1528Steal App Access TokenCRED
T1098.001Additional Cloud CredentialsPERSIST
T1562.008Disable Cloud LogsEVASION
T1048Exfil Over Alt ProtocolEXFIL
T1496Resource HijackingIMPACT
CodeFinger
S3 ransomware (SSE-C) 5 techT1078.004Valid Cloud AccountsINIT
T1530Data from Cloud StorageCOLLECT
T1486Data Encrypted for ImpactIMPACT
T1485Data DestructionIMPACT
T1490Inhibit System RecoveryIMPACT
LUCR-3
Identity-first (Scattered Spider) 19 techT1621MFA Request GenerationCRED
T1111MFA InterceptionCRED
T1098.005Device RegistrationPERSIST
T1555.006Cloud Secrets MgmtCRED
T1213.003Data from Code ReposCOLLECT
T1562.008Disable Cloud LogsEVASION
Atomic library
43 atomic tests for single-technique drills.
Full campaigns chain techniques end-to-end. Atomics isolate one technique at a time - fire a single API path, confirm one rule. 24 MITRE IDs across the catalogue, including four the campaign chains don't touch.
43atomic tests
24MITRE IDs
NEW TECHNIQUES - ATOMICS ONLY
T1537
Transfer Data to Cloud Account
Share AMIs, EBS / RDS snapshots and bucket policies to an external account - exfil via native AWS sharing.
T1552.007
Unsecured Credentials: Container API
Bulk-retrieve SSM Parameter Store SecureString values.
T1562.007
Disable / Modify Cloud Firewall
Open security-group port 22 to 0.0.0.0/0 to bypass network controls.
T1651
Cloud Administration Command
SSM SendCommand for agentless remote execution on instances.
AWS SERVICES EXERCISED
27
IAMSTSS3EC2VPCSES
Route 53GuardDutyCloudTrailLambda
Secrets ManagerAmplifyCodeCommitCodeBuild
SageMakerECS / FargateAuto ScalingCloudFormation
Image BuilderService QuotasSSMOrganizations
BedrockRDSIAM Roles Anywhere
Route 53 ResolverEC2 Instance Connect
Map the matrix against your AWS
Bring your CloudTrail or detection ruleset. We'll run a 30-minute readout, flag the techniques your current rules miss, and hand you a per-cell to-do list.