CATALOGUE· APT chains · cloud techniques· shipped from the repo
open source
Attack catalogue

Our APT chains, your detection sources. Every step published and reproducible.

Each scenario is a Pulumi stack, a boto3 module, and a runnable chain. We publish the technique map, the CloudTrail it produces, and the detection rule that should catch it. Six full campaigns below, plus 43 atomic single-technique tests in the coverage matrix.

Filter sort · severity ▾
§01
Critical
DangerDevUNC-attributed

DangerDev - phishing to broad cloud compromise

Spearphishing and a trusted-relationship foothold escalate into new cloud roles, wide service discovery, RDP lateral movement and resource hijacking. The broadest of our chains - 16 techniques across nine tactics.

T1566.002 T1098.003 T1526 T1496
1Spearphishing link T1566.002
2Add cloud roles iam:CreateRole · AttachRolePolicy
3Resource hijack run compute · T1496
§02
Critical
AmberSquidSysdig, 2023

AmberSquid - multi-service cryptomining

Burst-provisions miners across Amplify, ECS Fargate, SageMaker, CodeBuild and Auto Scaling, then disables CloudTrail and deletes the trail. Hits the under-monitored services GuardDuty doesn't watch. This is the chain you can run live on the Run page.

T1059.009 T1496 T1610 T1070
1Create roles & assume iam:CreateRole · sts:AssumeRole
2Burst-provision miners amplify · sagemaker · ecs
3Disable CloudTrail cloudtrail:StopLogging
§03
High
SCARLETEELSysdig, 2023

SCARLETEEL - compute exploit to cloud theft

Exploits a public-facing compute workload, steals credentials from the instance metadata API and files, disables cloud logging, then sweeps cloud storage and runs miners. The original cloud-native data-theft chain.

T1190 T1552.005 T1562.008 T1530
1Exploit public app T1190
2Steal creds via IMDS 169.254.169.254
3Disable logs, sweep S3 cloudtrail off · s3:GetObject
§04
High
SCARLETEEL2evolved variant

SCARLETEEL2 - exploit plus token theft

The evolved variant: same exploit entry, but steals an application access token, mints additional cloud credentials, disables logging and exfiltrates over an alternative protocol to evade egress monitoring.

T1528 T1048 T1098.001 T1562.008
1Exploit + steal token T1190 · T1528
2Mint cloud creds T1098.001
3Exfil over alt protocol T1048
§05
Medium
CodeFinger2025

CodeFinger - S3 ransomware via SSE-C

Uses valid cloud credentials to re-encrypt S3 objects with an attacker-supplied SSE-C key, then sets a short lifecycle to destroy originals - inhibiting recovery. The data stays in place and is unreadable without the attacker's key.

T1486 T1490 T1485 T1530
1Valid cloud creds T1078.004
2Re-encrypt with SSE-C s3:CopyObject · customer key
3Inhibit recovery lifecycle expiry · T1490
§06
High
LUCR-3Scattered Spider

LUCR-3 - identity-first intrusion

The Scattered Spider playbook: MFA fatigue and interception, device registration for persistence, secrets-manager raids, SaaS and code-repo collection, and cloud-log tampering. The broadest identity-driven chain - 19 techniques.

T1621 T1111 T1098.005 T1555.006
1MFA fatigue / intercept T1621 · T1111
2Register device, raid secrets T1098.005 · T1555.006
3Collect & tamper logs code repos · T1562.008

Have a chain we should ship next?

The catalogue is open. Open an RFC on GitHub or email admin@mayatrail.tech.

Open an RFC