Microsoft published the Cloud Web Applications Threat Matrix. It maps attack techniques against cloud-hosted web applications and serverless platforms using the MITRE ATT&CK framework, a public catalog of attacker tactics and techniques. The matrix covers services such as Azure App Service, AWS Lambda, and Google Cloud Run. It follows earlier Microsoft matrices for Kubernetes and cloud storage. If you manage Azure subscriptions or review cloud deployments, the matrix gives you a structured checklist for visibility, hardening, and incident response gaps.
Source