Our APT chains, your detection sources. Every step published and reproducible.
Each scenario is a Pulumi stack, a boto3 module, and a runnable chain. We publish the technique map, the CloudTrail it produces, and the detection rule that should catch it. Six full campaigns below, plus 43 atomic single-technique tests in the coverage matrix.
DangerDev - phishing to broad cloud compromise
Spearphishing and a trusted-relationship foothold escalate into new cloud roles, wide service discovery, RDP lateral movement and resource hijacking. The broadest of our chains - 16 techniques across nine tactics.
AmberSquid - multi-service cryptomining
Burst-provisions miners across Amplify, ECS Fargate, SageMaker, CodeBuild and Auto Scaling, then disables CloudTrail and deletes the trail. Hits the under-monitored services GuardDuty doesn't watch. This is the chain you can run live on the Run page.
SCARLETEEL - compute exploit to cloud theft
Exploits a public-facing compute workload, steals credentials from the instance metadata API and files, disables cloud logging, then sweeps cloud storage and runs miners. The original cloud-native data-theft chain.
SCARLETEEL2 - exploit plus token theft
The evolved variant: same exploit entry, but steals an application access token, mints additional cloud credentials, disables logging and exfiltrates over an alternative protocol to evade egress monitoring.
CodeFinger - S3 ransomware via SSE-C
Uses valid cloud credentials to re-encrypt S3 objects with an attacker-supplied SSE-C key, then sets a short lifecycle to destroy originals - inhibiting recovery. The data stays in place and is unreadable without the attacker's key.
LUCR-3 - identity-first intrusion
The Scattered Spider playbook: MFA fatigue and interception, device registration for persistence, secrets-manager raids, SaaS and code-repo collection, and cloud-log tampering. The broadest identity-driven chain - 19 techniques.
Have a chain we should ship next?
The catalogue is open. Open an RFC on GitHub or email admin@mayatrail.tech.