Skip to content

TheCloud.Events

The cloud security
event catalog

262 audit events across AWS, Azure, and GCP, mapped to MITRE ATT&CK — what each one means, how adversaries use it, and how to read it in the log.

aws 144 azure 79 gcp 39 12 tactics

cloudtrail event of the day
{
  "eventSource": "lambda.amazonaws.com",
  "eventName": "AddPermission20150331v2",
  "userIdentity": { "type": "IAMUser", "userName": "draco" },
  "sourceIPAddress": "203.0.113.66"
}
  1. 01 Initial Access 7
  2. 02 Execution 20
  3. 03 Persistence 79
  4. 04 Privilege Escalation 67
  5. 05 Stealth 16
  6. 06 Defense Impairment 75
  7. 07 Credential Access 26
  8. 08 Discovery 3
  9. 09 Lateral Movement 19
  10. 10 Collection 25
  11. 11 Exfiltration 24
  12. 12 Impact 37