CuraSec

tag: Framework · 1 items

2026-09-10 · Microsoft Security Blog · source ↗ #threat-modeling#cloud-security#framework
  • Engineer — Learn: A new ATT&CK-aligned taxonomy for cloud web app and serverless threats is worth reviewing to identify gaps in your current threat models and security controls, but requires no immediate system changes.
  • SOC/IR — Learn: Review the matrix to identify coverage gaps in existing detections for cloud web app attack techniques, and consider mapping current Sigma/KQL rules to the new framework over time.
  • Leader — Skip