Threat matrix: Mapping threats across cloud web applications
Brief
In this article
- Overview
- Technique Catalog
- Privilege Escalation
- Mitigation and protection guidance
- References
- Learn more
Microsoft introduces the cloud web applications threat matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.
Cloud-hosted web applications and serverless platforms create attack paths that can cross application code, managed runtimes, workload identities, deployment pipelines, and connected cloud resources. Investigating the application and underlying cloud platform separately can leave gaps in how defenders understand those paths.
Microsoft developed the Cloud web applications threat matrix to organize relevant techniques using MITRE ATT&CK tactics.
