Skip to content

Initial Access

The initial access tactic consists of techniques that are used for gaining access to cloud web applications and serverless environments. This access can be achieved through compromised credentials, vulnerable applications, misconfigured interfaces, or by exploiting connected resources.

ID Name
MS-TA7002 Application vulnerability
MS-TA7003 Code injection in connected repository
MS-TA7004 Compromised image in registry
MS-TA7005 Exposed/misconfigured admin interfaces
MS-TA7006 Serverless trigger injection
MS-TA7007 Using deployment credentials
MS-TA7008 Valid cloud accounts