Build1 distinct publisher3 min readUpdated
A Yamato Security engineer maps CloudTrail events to seven ATT&CK tactics and drops techniques nobody has observed. The pruning is the useful part, and it will date fast.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Pruning is the load-bearing decision in this document, and it is also the one that takes on debt. Nishikawa says he left out events that are theoretically possible but have not been observed in the wild [5], and that the list comes from his own experience plus published research from Unit 42, Datadog Security Labs, Permiso, CrowdStrike and Rapid7 [4]. The coverage boundary of the shortlist is therefore the publication boundary of five vendors' write-ups. That is a far better boundary than "every API CloudTrail can emit", and it is a worse one than it looks on the day a technique gets used and not written up.
There is a tension inside the same article worth pulling on. He calls `GetCallerIdentity` the strongest indicator for this phase, alongside `iam:GetUser` and `iam:ListAccountAliases` [17], citing Unit 42's JavaGhost research, which found many threat actors make it their first API call after compromising AWS credentials in order to learn the account ID and user ID [16]. Elsewhere he writes that isolated events often look completely normal, and that you need a tool such as Suzaku, or correlation across several events, before concluding anything [18]. Both hold at once: high prior of attacker use, high base rate of benign use. Operationally that makes `GetCallerIdentity` a sequence opener rather than an alert. Fire a single-event rule on it and you have rebuilt the alert volume the article opens by complaining about [20].
The taxonomy argument matters more than taxonomy arguments usually do. T1078.004 spans four tactics, Initial Access, Persistence, Privilege Escalation and Defense Evasion [12]; he assigns it to Initial Access on the strength of that observed first call [13]. SigmaHQ places the same activity under T1087, which he declines to call wrong, distinguishing T1078 as the moment stolen credentials are used from T1087 as enumeration of account information [14][15]. Since GuardDuty finding names lead with the tactic string [8], and since he ranks urgency by tactic, with one Defense Evasion event outranking one Discovery event because it implies the attacker is already deep in [9], the bucket a rule lands in is what decides whether anyone gets paged.
The number nobody printed: half the Enterprise matrix is set aside, seven tactics of fourteen [6][7]. The stated reason for preferring ATT&CK to the Kill Chain is the same logic, since Weaponization cannot be observed inside a cloud environment at all [10]. And AWS entry is usually credential-shaped rather than mail-shaped, keys committed to GitHub by accident or lifted through SSRF [11], which is why the first tactic in this mapping begins at credential use rather than delivery. The framework here is being selected for what a log can actually show, and the honest caveat attached is that finding this before the incident remains much harder than reconstructing it afterwards [19].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
MITRE ATT&CK Enterprise contains 14 tactics in total, but the author identifies seven as particularly important when operating an AWS environment.
Akira Nishikawa, a security engineer and one of the developers behind the open-source tools Suzaku and Senrigan, presented on threat detection in AWS using those tools at HITCON 2026 as a member of the Yamato Security community.
Yamato Security is a Japan-based, volunteer-run security community; 'Yamato' is an ancient name for Japan.
The article summarises the events that occur in an AWS environment and are recorded in AWS CloudTrail at each stage of the MITRE ATT&CK Enterprise tactics covered in the presentation.
The mapping is based on the author's own experience along with research and blog posts published by Unit 42, Datadog Security Labs, Permiso, CrowdStrike and Rapid7.
The author states he intentionally omitted events that are theoretically possible but have not been observed in the wild, and asks readers to keep that limitation in mind.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One attributed practitioner account leaning on uncited vendor research
The technical substance is specific and checkable in kind - named APIs, technique IDs, GuardDuty naming convention, concrete vendor findings - and the author states his sourcing and his exclusion rule up front. But the cluster holds exactly one item from a developer blogging platform; the Unit 42, Datadog Security Labs, Permiso, CrowdStrike and Rapid7 material is referenced rather than supplied, the seven retained tactics are the author's judgement, and the seven discarded ones are never listed, so the central pruning claim cannot be verified from what is here.
No usage data
The only observable event is the author's own conference presentation and its written companion. Nothing in the supplied material shows any organisation running this mapping, any deployment or download figures for Suzaku or Senrigan, or any detection rules shipped on the basis of the shortlist, so adoption cannot be scored without inventing facts.
Slightly understated relative to its own content
The article's rhetoric runs below its substance. It volunteers its scope limit (unobserved techniques omitted), concedes the competing SigmaHQ T1087 classification without asserting the other side is wrong, undercuts its own strongest indicator by reporting that JavaGhost may have deliberately avoided GetCallerIdentity, and states plainly that proactive detection is much harder than post-incident investigation. Against that, it is promotional to the extent that the recommended correlation path routes through a tool the author builds, which keeps the gap close to aligned rather than clearly negative.
Disclosed tool-author interest, non-commercial framing
The author is a developer of Suzaku and Senrigan and names Suzaku as a way to get the correlation the article says is required, and the piece is the companion to his own HITCON 2026 talk - a clear interest in the recommended remedy. The interest is disclosed in the first line, the tools are open source, the community is described as volunteer-run, and no pricing, vendor or sponsorship relationship appears in the material, which caps the score in the middle band.
Moderate: internally coherent, externally unverified
Confidence is limited by single-source dependence and absent adoption data, and lifted by the article's specificity, explicit sourcing, disclosed authorship interest and willingness to surface contradictions to its own thesis. Claims about what the author asserts are solid; claims about whether the seven-tactic shortlist is the right one for AWS operators generally remain unconfirmed.
build
CrowdStrike's own triage numbers make AI auto-close a calibration contract, not a headcount cut1 distinct publisher
security
Talos tells the story instead of the matrix, and BEC's new economics fall out1 distinct publisher
build
GuardDuty says exfiltration and the patch is four hours out: revoke the sessions first1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 24, 2026