diff --git a/cloud_resources/omar_saas_attack_example.json b/cloud_resources/omar_saas_attack_example.json new file mode 100644 index 0000000..de70863 --- /dev/null +++ b/cloud_resources/omar_saas_attack_example.json @@ -0,0 +1,1237 @@ +{ + "name": "Omar's SaaS", + "versions": { + "attack": "15", + "navigator": "5.0.0", + "layer": "4.5" + }, + "domain": "enterprise-attack", + "description": "MITRE ATT&CK TTPs for SaaS implementations", + "filters": { + "platforms": [ + "SaaS", + "Office 365", + "Google Workspace" + ] + }, + "sorting": 0, + "layout": { + "layout": "side", + "aggregateFunction": "average", + "showID": false, + "showName": true, + "showAggregateScores": false, + "countUnscored": false, + "expandedSubtechniques": "all" + }, + "hideDisabled": false, + "techniques": [ + { + "techniqueID": "T1037", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1037", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1557", + "tactic": "credential-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1557", + "tactic": "collection", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1583", + "tactic": "resource-development", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1592", + "tactic": "reconnaissance", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1003", + "tactic": "credential-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1602", + "tactic": "collection", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1543", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1543", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1578", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1069", + "tactic": "discovery", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1114", + "tactic": "collection", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1561", + "tactic": "impact", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1547", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1547", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1600", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1564", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1137", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1071", + "tactic": "command-and-control", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1053", + "tactic": "execution", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1053", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1053", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1562", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1195", + "tactic": "initial-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1558", + "tactic": "credential-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1555", + "tactic": "credential-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1567", + "tactic": "exfiltration", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1036", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1552", + "tactic": "credential-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1055", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1055", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1205", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1205", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1205", + "tactic": "command-and-control", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1218", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1550", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1550", + "tactic": "lateral-movement", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1011", + "tactic": "exfiltration", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1589", + "tactic": "reconnaissance", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1560", + "tactic": "collection", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1021", + "tactic": "lateral-movement", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1596", + "tactic": "reconnaissance", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1491", + "tactic": "impact", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1563", + "tactic": "lateral-movement", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1222", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1595", + "tactic": "reconnaissance", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1548", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1548", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1016", + "tactic": "discovery", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1087", + "tactic": "discovery", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1090", + "tactic": "command-and-control", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1059", + "tactic": "execution", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1020", + "tactic": "exfiltration", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1070", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1568", + "tactic": "command-and-control", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1074", + "tactic": "collection", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1584", + "tactic": "resource-development", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1542", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1542", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1586", + "tactic": "resource-development", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1497", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1497", + "tactic": "discovery", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1102", + "tactic": "command-and-control", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1608", + "tactic": "resource-development", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1480", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1204", + "tactic": "execution", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1591", + "tactic": "reconnaissance", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1606", + "tactic": "credential-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1590", + "tactic": "reconnaissance", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1593", + "tactic": "reconnaissance", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1098", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1098", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1048", + "tactic": "exfiltration", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1597", + "tactic": "reconnaissance", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1566", + "tactic": "initial-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1110", + "tactic": "credential-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1565", + "tactic": "impact", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1559", + "tactic": "execution", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1001", + "tactic": "command-and-control", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1601", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1574", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1574", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1574", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1078", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1078", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1078", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1078", + "tactic": "initial-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1027", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1546", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1546", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1599", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1553", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1573", + "tactic": "command-and-control", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1056", + "tactic": "collection", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1056", + "tactic": "credential-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1499", + "tactic": "impact", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1614", + "tactic": "discovery", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1132", + "tactic": "command-and-control", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1598", + "tactic": "reconnaissance", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1585", + "tactic": "resource-development", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1588", + "tactic": "resource-development", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1569", + "tactic": "execution", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1213", + "tactic": "collection", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1505", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1498", + "tactic": "impact", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1134", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1134", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1136", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1518", + "tactic": "discovery", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1052", + "tactic": "exfiltration", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1484", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1484", + "tactic": "privilege-escalation", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1587", + "tactic": "resource-development", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1556", + "tactic": "credential-access", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1556", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1556", + "tactic": "persistence", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1216", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + }, + { + "techniqueID": "T1127", + "tactic": "defense-evasion", + "color": "", + "comment": "", + "enabled": true, + "metadata": [], + "links": [], + "showSubtechniques": true + } + ], + "gradient": { + "colors": [ + "#ff6666ff", + "#ffe766ff", + "#8ec843ff" + ], + "minValue": 0, + "maxValue": 100 + }, + "legendItems": [], + "metadata": [], + "links": [], + "showTacticRowBackground": false, + "tacticRowBackground": "#dddddd", + "selectTechniquesAcrossTactics": true, + "selectSubtechniquesWithParent": false, + "selectVisibleTechniques": false +} \ No newline at end of file diff --git a/cloud_resources/omar_saas_attack_example.svg b/cloud_resources/omar_saas_attack_example.svg new file mode 100644 index 0000000..adcb0a4 --- /dev/null +++ b/cloud_resources/omar_saas_attack_example.svg @@ -0,0 +1,2 @@ + +aboutOmar's SaaSMITRE ATT&CK TTPs for SaaS implementationsplatformsSaaS, Office 365, Google WorkspaceDrive-byCompromisePhishingTrustedRelationshipValidAccountsSpearphishingLinkSpearphishingVoiceCloudAccountsDefaultAccountsInitialAccessCommandand ScriptingInterpreterServerlessExecutionSoftwareDeploymentToolsCloudAPIExecutionAccountManipulationCreateAccountEvent TriggeredExecutionModifyAuthenticationProcessOfficeApplicationStartupValidAccountsAdditionalCloudCredentialsAdditionalCloud RolesAdditionalEmail DelegatePermissionsDeviceRegistrationCloudAccountConditionalAccessPoliciesHybridIdentityMulti-FactorAuthenticationAdd-insOfficeTemplateMacrosOfficeTestOutlookFormsOutlookHome PageOutlookRulesCloudAccountsDefaultAccountsPersistenceAbuse ElevationControlMechanismAccountManipulationDomain orTenant PolicyModificationEvent TriggeredExecutionValidAccountsTemporaryElevatedCloud AccessAdditionalCloudCredentialsAdditionalCloud RolesAdditionalEmail DelegatePermissionsDeviceRegistrationTrustModificationCloudAccountsDefaultAccountsPrivilegeEscalationAbuse ElevationControlMechanismDomain orTenant PolicyModificationExploitationforDefense EvasionHideArtifactsImpairDefensesImpersonationIndicatorRemovalModifyAuthenticationProcessUse AlternateAuthenticationMaterialValidAccountsTemporaryElevatedCloud AccessTrustModificationEmailHiding RulesDisableor ModifyCloud LogsClearMailbox DataConditionalAccessPoliciesHybridIdentityMulti-FactorAuthenticationApplicationAccess TokenWeb SessionCookieCloudAccountsDefaultAccountsDefenseEvasionBruteForceForge WebCredentialsModifyAuthenticationProcessMulti-FactorAuthenticationRequest GenerationStealApplicationAccess TokenSteal WebSession CookieUnsecuredCredentialsCredentialStuffingPasswordCrackingPasswordGuessingPasswordSprayingSAMLTokensWebCookiesConditionalAccessPoliciesHybridIdentityMulti-FactorAuthenticationChatMessagesCredentialAccessAccountDiscoveryCloud ServiceDashboardCloud ServiceDiscoveryPermissionGroupsDiscoveryCloudAccountEmailAccountCloudGroupsDiscoveryInternalSpearphishingSoftwareDeploymentToolsTaint SharedContentUse AlternateAuthenticationMaterialApplicationAccess TokenWeb SessionCookieLateralMovementAutomatedCollectionData fromCloud StorageData fromInformationRepositoriesEmailCollectionCodeRepositoriesConfluenceSharepointEmailForwardingRuleRemote EmailCollectionCollectionExfiltrationOver AlternativeProtocolExfiltrationOverWeb ServiceTransferData toCloud AccountExfiltrationOver WebhookExfiltrationAccountAccess RemovalEndpoint Denialof ServiceFinancialTheftNetwork Denialof ServiceApplicationExhaustionFloodApplicationor SystemExploitationServiceExhaustionFloodDirectNetworkFloodReflectionAmplificationImpact \ No newline at end of file diff --git a/cloud_resources/omar_saas_attack_example.xlsx b/cloud_resources/omar_saas_attack_example.xlsx new file mode 100644 index 0000000..4314e31 Binary files /dev/null and b/cloud_resources/omar_saas_attack_example.xlsx differ