#frameworks

3 posts · Last used 14d

---------------- 📚 Frameworks =================== Microsoft has introduced the Cloud Web Applications Threat Matrix, a new framework designed to help defenders understand, prioritize, and mitigate threats targeting cloud-hosted web applications and serverless platforms. Context and Scope As organizations increasingly migrate web applications to cloud environments and adopt serverless architectures, traditional threat modeling approaches often fall short. The attack surface differs significantly from on-premises hosting, requiring tailored defensive methodologies. Microsoft's new matrix directly addresses this gap by providing a structured taxonomy of threats specific to these modern cloud infrastructures. Methodology The Cloud Web Applications Threat Matrix is aligned with the MITRE ATT&CK framework. This alignment ensures that security teams can integrate the new threat mappings into existing detection and response workflows. By using familiar tactics, techniques, and procedures (TTPs), defenders can map adversarial behavior directly to mitigation strategies. Key Features • Threat Mapping: Categorizes specific threats against cloud web apps. • Serverless Focus: Explicitly includes threats relevant to serverless computing platforms. • Prioritization: Helps security teams rank threats based on framework guidance. • Actionable Mitigation: Pairs identified threats with defensive measures. Technical Implementation Defenders can use the matrix to evaluate their current security posture against documented adversary techniques. The framework serves as a reference point for configuring cloud security posture management (CSPM) tools and web application firewalls (WAFs). Security teams should cross-reference events in their SIEM with the techniques listed in the matrix to identify active exploitation patterns. Limitations As a foundational framework, the matrix provides a structured approach but requires manual integration into existing security operations. Specific detection rules and automated responses must be developed by the internal team based on the framework's guidelines. 🔹 cloudsecurity #frameworks #microsoft #mitre #serverless 🔗 Source: https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/
0
0
0
0
Tideways supports Yii3! PHP keeps evolving, and Yii3 is a new addition to the ecosystem. After years of development, Yii3 has been released as a modern, modular framework for building APIs and web applications. Tideways supports Yii3 out of the box. With automatic instrumentation, profiling, monitoring, and exception tracking work without requiring any code changes. Looking forward to seeing what the community builds with Yii3. https://tideways.com/profiler/blog/changelog/yii3-support#PHP #Yii #Yii3 #Frameworks #APM
3
0
2
0
You've seen all posts