Threat Matrix: Mapping Threats Across Cloud Web Applications
Microsoft, Wednesday, September 9th, 2026
A MITRE ATT&CK-aligned matrix covering eleven tactics against cloud-hosted web apps and serverless platforms.
Microsoft published a MITRE ATT&CK-aligned threat matrix documenting attack techniques against cloud-hosted web applications and serverless platforms.
It spans eleven tactics from resource development through impact, covering application code, container registries, deployment pipelines and workload identities.
The inclusion of pipelines and workload identity is what distinguishes it from general cloud matrices, since those are where modern application compromise typically begins.
Defensive priorities called out are multifactor authentication, least-privilege access and source repository protection. A useful reference for structuring threat modeling of cloud applications.