Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Arrow up icon
GO TO TOP
Cloud Security Handbook

You're reading from   Cloud Security Handbook Effectively secure cloud environments using AWS, Azure, and GCP

Arrow left icon
Product type Paperback
Published in Apr 2025
Publisher Packt
ISBN-13 9781836200017
Length 482 pages
Edition 2nd Edition
Arrow right icon
Author (1):
Arrow left icon
Eyal Estrin Eyal Estrin
Author Profile Icon Eyal Estrin
Eyal Estrin
Arrow right icon
View More author details
Toc

Table of Contents (24) Chapters Close

Preface 1. Part 1:Securing Infrastructure Cloud Services FREE CHAPTER
2. Chapter 1: Introduction to Cloud Security 3. Chapter 2: Securing Compute Services – Virtual Machines 4. Chapter 3: Securing Compute Services – Containers and Kubernetes 5. Chapter 4: Securing Compute Services – Serverless and FaaS 6. Chapter 5: Securing Storage Services 7. Chapter 6: Securing Networking Services – Part 1 8. Chapter 7: Securing Networking Services – Part 2 9. Chapter 8: Securing Generative AI Services 10. Part 2: Deep Dive into IAM, Auditing, and Encryption
11. Chapter 9: Effective Strategies for Implementing IAM Solutions 12. Chapter 10: Auditing and Threat Management in Cloud Environments 13. Chapter 11: Applying Encryption in Cloud Services 14. Part 3: Threat and Vendor Management
15. Chapter 12: Understanding Common Security Threats to Cloud Services 16. Chapter 13: Engaging with Cloud Providers 17. Part 4: Advanced Use of Cloud Services
18. Chapter 14: Managing Hybrid Clouds 19. Chapter 15: Managing Multi-Cloud Environments 20. Chapter 16: Implementing DevSecOps 21. Chapter 17: Security in Large-Scale Environments 22. Index 23. Other Books You May Enjoy

The MITRE ATT&CK framework

The MITRE ATT&CK framework is a knowledge base of hacking techniques. The cloud matrix of MITRE ATT&CK contains the following attack techniques:

  • Initial access
  • Execution
  • Persistence
  • Privilege escalation
  • Defense evasion
  • Credential access
  • Discovery
  • Lateral movement
  • Collection
  • Exfiltration
  • Impact

Understanding attack techniques allows us to understand the results of attacks. For example, using the abuse of credentials allows an attacker to gain persistent access to our system.

Another attack example is cloud object storage discovery, which may be used by an attacker to gain access to all objects inside a cloud storage instance.

Reviewing all attack techniques will allow us to understand which security controls we can implement to mitigate potential attacks in our cloud environment.

For more information, refer to the following resources:

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Modal Close icon
Modal Close icon