How MITRE ATT&CK's Seven Tactics Map to AWS CloudTrail Security Events
Security engineer Akira Nishikawa of Japan-based volunteer community Yamato Security presented on AWS threat detection at HITCON 2026, using open-source tools Suzaku and Senrigan. The presentation focused on mapping real-world AWS CloudTrail log events to seven key MITRE ATT&CK Enterprise Tactics, including Initial Access, Discovery, Credential Access, Persistence, Privilege Escalation, Defense Evasion, and Impact. Nishikawa noted that individual CloudTrail events often appear benign in isolation, making correlation across multiple events — or dedicated tooling — essential for accurate threat detection. The ATT&CK framework was chosen over the Cyber Kill Chain because it better suits cloud environments, excluding phases like Weaponization that are unobservable inside AWS. Findings are drawn from Nishikawa's own experience and research from organizations including Unit 42, Datadog Security Labs, Permiso, CrowdStrike, and Rapid7, covering only attacker behaviors confirmed in the wild.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in