By Rodman Ramezanian - Enterprise Cloud Security Advisor, Skyhigh Security
June 3, 2022 3 Minute Read
As the ancient military strategist, Sun Tzu, famously said: “If you know the enemy and know yourself, you need not fear the result of a hundred battles.”
Skyhigh Cloud Access Security Broker (CASB), the multi-cloud security platform for enterprises, includes MITRE ATT&CK into the workflow for SOC analysts to investigate cloud threats and security managers to defend against future attacks with precision.
Most enterprises use over 1,500 cloud services, generating millions of events, from login, to file share, to download and an infinite number of actions meant for productivity yet exploited by adversaries. Until now, hunting for adversary activity within that haystack has been an arduous effort, with so much noise that many data breaches have gone unnoticed until it is too late.
Skyhigh Security Service Edge (SSE), which includes Skyhigh CASB, takes a multi-layered approach to cloud threat investigation that can speed your time to detect adversary activity in your cloud services, identify gaps, and implement targeted changes to your policy and configuration.
First, the haystack of events is processed continuously against a baseline of known good behavior by User and Entity Behavior Analytics (UEBA) to identify the anomalies and actual threats in your environment, assessing behavior across multiple services and accounts.
This takes your investigation process down to a manageable quantity of incidents. With this release, those incidents are now in the same language as the rest of the SOC – MITRE ATT&CK. Each cloud security incident is mapped to ATT&CK tactics and techniques, showing you adversary activity currently being executed in your environment.
Multi-cloud MITRE ATT&CK view of adversary activity in Skyhigh Cloud Access Security Broker (CASB)
You have three views within Skyhigh CASB:
Multiple teams in your organization benefit from this addition to Skyhigh Security Service Edge (SSE):
Many SecOps teams leverage repeatable processes and frameworks such as ATT&CK to mitigate risk and respond to threats to their endpoints and networks, but so far cloud threats and vulnerabilities have presented an unfamiliar paradigm. By translating cloud threats and vulnerabilities into the common language of ATT&CK, Skyhigh CASB allows security teams to extend their processes and runbooks to the cloud, understand and pre-emptively respond to cloud vulnerabilities and improve enterprise security.
Learn more about Skyhigh SSE.
Back to BlogsThyaga Vasudevan April 3, 2025
Sarang Warudkar and Hari Prasad Mariswamy March 13, 2025
Sarang Warudkar March 4, 2025
Rodman Ramezanian February 24, 2025
Hari Prasad Mariswamy February 20, 2025