☁️AWS detections
Clankerusecase tracks 112 detection use cases covering the AWS attack surface across 65 MITRE ATT&CK techniques.
Detections targeting AWS infrastructure — CloudTrail, IAM, S3, EC2, Lambda, KMS, GuardDuty.
112Use cases
65Techniques
13Articles
5Kill-chain phases
Top techniques on AWS (25)
T1078.004Cloud Accounts17T1078Valid Accounts11T1586.003Cloud Accounts11T1098Account Manipulation9T1537Transfer Data to Cloud Account8T1562.008T1562.0087T1535Unused/Unsupported Cloud Regions7T1136.003Cloud Account5T1530Data from Cloud Storage5T1580Cloud Infrastructure Discovery5T1110Brute Force4T1485Data Destruction4T1562.001T1562.0014T1190Exploit Public-Facing Application4T1071.001Web Protocols4T1550.001Application Access Token3T1550Use Alternate Authentication Material3T1531Account Access Removal3T1195.002Compromise Software Supply Chain3T1204.003Malicious Image3T1110.003Password Spraying3T1110.004Credential Stuffing3T1199Trusted Relationship2T1685.002Disable or Modify Cloud Log2T1621Multi-Factor Authentication Request Generation2