Skip to main content

Security ContentThreat Detection, Investigation, and Response for Public Cloud Guide

Microsoft Azure – MITRE ATT&CK Coverage by Use Case

Use Case

TTP Number

TTP Name

Abnormal Authentication & Access

TA0007

T1087.004

T1535

Discovery

Account Discovery: Cloud Account

Unused/Unsupported Cloud Regions

Privilege Escalation

TA0004

T1555

Privilege Escalation

Credentials from Password Stores

Cloud Data Protection

TA0009

T1530

T1580

Collection

Data from Cloud Storage Object

Cloud Infrastructure Discovery

Malware

TA0002

T1087.004

T1204.002

T1204.003

Execution

Account Discovery: Cloud Account

User Execution: Malicious File

User Execution: Malicious Image

Cryptomining

T1496

Resource Hijacking