{"id":41884,"date":"2021-07-21T16:00:42","date_gmt":"2021-07-21T16:00:42","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=94626"},"modified":"2021-07-21T16:00:42","modified_gmt":"2021-07-21T16:00:42","slug":"the-evolution-of-a-matrix-how-attck-for-containers-was-built","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/","title":{"rendered":"The evolution of a matrix: How ATT&amp;CK for Containers was built"},"content":{"rendered":"<p><em>Note: The content of this post is being released jointly with the Center for Threat-Informed Defense. It is co-authored with Chris Ante and Matthew Bajzek. The Center post can be found <a href=\"https:\/\/medium.com\/mitre-engenuity\/the-evolution-of-a-matrix-how-att-ck-for-containers-was-built-f5ca7fdbcb3f\">here<\/a>.<\/em><\/p>\n<p>As containers become a major part of many organizations\u2019 IT workloads, it becomes crucial to consider the unique security threats that target such environments when building security solutions. The first step in this process is understanding the relevant attack landscape.<\/p>\n<p>The <a href=\"https:\/\/attack.mitre.org\/\" target=\"_blank\" rel=\"noopener\">MITRE ATT&amp;CK\u00ae<\/a> team has received frequent questions from the community about if or when ATT&amp;CK would include coverage for adversary behavior in containers. Previous iterations of ATT&amp;CK have included references to containers (for example, <a href=\"https:\/\/attack.mitre.org\/techniques\/T1496\/\" target=\"_blank\" rel=\"noopener\">Resource Hijacking<\/a>) and some clearly container-relevant techniques (for example, <a href=\"https:\/\/attack.mitre.org\/techniques\/T1525\/\" target=\"_blank\" rel=\"noopener\">Implant Internal Image<\/a>), but the coverage was insufficient to provide network defenders a holistic view of how containers are being targeted in enterprise environments.<\/p>\n<h2>Addressing the need for a common framework for understanding container threats<\/h2>\n<p>Given clear community interest, inspiration from Microsoft\u2019s work on the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/04\/02\/attack-matrix-kubernetes\/\" target=\"_blank\" rel=\"noopener\">threat matrix for Kubernetes<\/a>, and the publication of research from other teams, the Center for Threat-Informed Defense <a href=\"https:\/\/medium.com\/mitre-engenuity\/help-shape-att-ck-for-containers-7fe4905623c5\" target=\"_blank\" rel=\"noopener\">launched an investigation<\/a> (sponsored by several Center members including Microsoft) that examined the viability of adding containers content to ATT&amp;CK. The purpose of the Container Techniques project was to investigate adversarial behavior in containerization technologies and determine whether there was enough open-source intelligence to warrant the creation of an ATT&amp;CK for Containers matrix, resulting in either new ATT&amp;CK content or a report on the state of in-the-wild Container-based tactics, techniques, and procedures (TTPs). The Center\u2019s research team quickly concluded that there was more than enough open-source intelligence to justify technique development, ultimately resulting in the new matrix.<\/p>\n<p>As of the <a href=\"https:\/\/medium.com\/mitre-attack\/attack-april-2021-release-39accaf23c81\" target=\"_blank\" rel=\"noopener\">ATT&amp;CK v9 release<\/a>, the <a href=\"https:\/\/attack.mitre.org\/matrices\/enterprise\/containers\" target=\"_blank\" rel=\"noopener\">ATT&amp;CK for Containers matrix<\/a> is officially available. More details about the Containers matrix can be found in <a href=\"https:\/\/medium.com\/mitre-engenuity\/att-ck-for-containers-now-available-4c2359654bf1\" target=\"_blank\" rel=\"noopener\">MITRE-Engenuity\u2019s announcement blog<\/a>. Some highlights of the new matrix include related software entries, procedure examples to help network defenders better understand new container-centric techniques, data sources to match the recent ATT&amp;CK data sources refactor, and many others.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-94647 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/ATTCK-for-Containers-matrix.png\" alt=\"A matrix of attack techniques related to containerization technologies, organized by stages of an attack.\" width=\"977\" height=\"604\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/ATTCK-for-Containers-matrix.png 977w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/ATTCK-for-Containers-matrix-300x185.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/ATTCK-for-Containers-matrix-768x475.png 768w\" sizes=\"auto, (max-width: 977px) 100vw, 977px\"><\/p>\n<p><em>Figure 1. ATT&amp;CK for Containers matrix.<\/em><\/p>\n<h2>Evolving the threat matrix<\/h2>\n<p>MITRE ATT&amp;CK has become the common vocabulary for describing real-world adversary behavior. ATT&amp;CK offers organizations a method to measure their defenses against threats that impact their environment and identify possible gaps. With ATT&amp;CK\u2019s approach of methodically outlining the possible threats, Microsoft built the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/04\/02\/attack-matrix-kubernetes\/\" target=\"_blank\" rel=\"noopener\">threat matrix for Kubernetes<\/a>, which was one of the first attempts to systematically map the attack surface of Kubernetes. An updated version of the matrix was released earlier in 2021.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone wp-image-94650 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/Threat-matrix-for-Kubernetes.png\" alt=\"A matrix of attack techniques specific to Kubernetes, organized by stages of an attack.\" width=\"1617\" height=\"759\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/Threat-matrix-for-Kubernetes.png 1617w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/Threat-matrix-for-Kubernetes-300x141.png 300w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/Threat-matrix-for-Kubernetes-1024x481.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/Threat-matrix-for-Kubernetes-768x360.png 768w, https:\/\/www.microsoft.com\/security\/blog\/uploads\/securityprod\/2021\/07\/Threat-matrix-for-Kubernetes-1536x721.png 1536w\" sizes=\"auto, (max-width: 1617px) 100vw, 1617px\"><\/p>\n<p><em>Figure 2: Threat matrix for Kubernetes.<\/em><\/p>\n<p>Microsoft took part in the Center\u2019s project and contributed knowledge that the company gained in the field of container security. Microsoft\u2019s unparalleled visibility into threats helps to identify real-world attacks against containerized workloads and provide information about tactics and techniques used in those attacks. One example of such an attack is a <a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/detect-largescale-cryptocurrency-mining-attack-against-kubernetes-clusters\/\" target=\"_blank\" rel=\"noopener\">cryptocurrency mining campaign<\/a> that targeted Kubernetes. In this incident, Microsoft saw evidence of the following techniques from the Microsoft threat matrix:<\/p>\n<ul>\n<li>Exposed sensitive interfaces<\/li>\n<li>New container<\/li>\n<li>Pod\/container name similarity<\/li>\n<li>List Kubernetes secrets<\/li>\n<li>Access Kubernetes API server<\/li>\n<li>Resource Hijacking<\/li>\n<\/ul>\n<p>The techniques that went into ATT&amp;CK for Containers are different from those in the Microsoft threat matrix. As described in a <a href=\"https:\/\/medium.com\/mitre-engenuity\/update-help-shape-att-ck-for-containers-bfcd24515df5\" target=\"_blank\" rel=\"noopener\">blog post<\/a> by the Center, it was preferable to use an existing ATT&amp;CK technique rather than create a new one when possible. Therefore, several techniques from the threat matrix were mapped into existing Enterprise ATT&amp;CK techniques. For example, in the techniques listed above, \u201cExposed sensitive interfaces\u201d from the threat matrix is equivalent to ATT&amp;CK\u2019s \u201cExternal Remote Services.\u201d<\/p>\n<p>The Center\u2019s process for leveraging Microsoft\u2019s Kubernetes threat matrix was as follows:<\/p>\n<ul>\n<li>Cross-referencing threat intelligence with the techniques in the Kubernetes threat matrix.<\/li>\n<li>Determining whether techniques with sufficient intelligence backing were already covered by existing Enterprise ATT&amp;CK techniques, or whether they justified the creation of one or more new techniques or sub-techniques.<\/li>\n<\/ul>\n<p>Considering Microsoft\u2019s tactics mapping for specific techniques and how they fit within ATT&amp;CK\u2019s Enterprise, Cloud, and Containers matrix scoping, as in the case of multiple forms of \u201clateral movement,\u201d the Center instead identified pivots from one ATT&amp;CK platform matrix to another (for example, Containers to Cloud).<\/p>\n<p>The following are examples of techniques from Microsoft\u2019s matrix that were re-scoped to fit into existing Enterprise ATT&amp;CK techniques:<\/p>\n<figure class=\"wp-block-table\"> <\/figure>\n<p>Meanwhile, the following are examples of techniques from the Microsoft threat matrix that were re-scoped based on the Center\u2019s platform decisions and additional open-source intelligence, with additional detail on each technique\/sub-technique available in its description within ATT&amp;CK for Containers:<\/p>\n<figure class=\"wp-block-table\"> <\/figure>\n<p>Not all the techniques and tactics that appear in the Microsoft threat matrix went into the new ATT&amp;CK matrix. ATT&amp;CK focuses on real-world techniques that are seen in the wild. In contrast, many of the techniques in the threat matrix were observed during research work and not necessarily as part of an active attack. For example, \u201cCoreDNS poisoning\u201d from the <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/23\/secure-containerized-environments-with-updated-threat-matrix-for-kubernetes\/\" target=\"_blank\" rel=\"noopener\">updated matrix<\/a> is a possible attack vector but hasn\u2019t been seen in the wild yet.<\/p>\n<h2>ATT&amp;CK is dynamic<\/h2>\n<p>ATT&amp;CK for Containers is by no means finished, and we look forward to future additions based on new intelligence and further community contributions. Before the public release of ATT&amp;CK for Containers, Microsoft released an updated version of the threat matrix for Kubernetes, which speaks to the fast-paced evolution of this technology space and the need to keep up with new adversary behaviors.<\/p>\n<p>The next step for the ATT&amp;CK team is to assess the new content in Microsoft\u2019s matrix and consider it for potential future inclusion in ATT&amp;CK based on the factors described above. Microsoft and the ATT&amp;CK team will continue to collaborate to ensure that container techniques coverage in ATT&amp;CK is up-to-date and can continue to serve the need of the community.<\/p>\n<p>With the completion of this Center project, ATT&amp;CK for Containers will be maintained by the ATT&amp;CK team, who would love your continuous feedback and contribution! Let the team know what you think, what could be improved, and most importantly what you see adversaries doing in the wild related to containers. Feel free to send an email at any time to <a href=\"mailto:attack@mitre.org\" target=\"_blank\" rel=\"noopener\">attack@mitre.org<\/a>. If you have ideas for other research and development projects that the Center should consider, please send an email to <a href=\"mailto:ctid@mitre-engenuity.org\" target=\"_blank\" rel=\"noopener\">ctid@mitre-engenuity.org<\/a>.<\/p>\n<h2>Learn more<\/h2>\n<p>To learn how Microsoft can help you protect containers and relevant technologies today, read about <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/security\/endpoint-defender\" target=\"_blank\" rel=\"noopener\">Microsoft Defender for Endpoint<\/a> and <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-defender\/\" target=\"_blank\" rel=\"noopener\">Azure Defender<\/a>.<\/p>\n<p>To learn more about Microsoft Security solutions,&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\" target=\"_blank\" rel=\"noopener\">visit our&nbsp;website<\/a>.&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us at&nbsp;<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener\">@MSFTSecurity<\/a>&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/07\/21\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As containers become a major part of many organizations\u2019 IT workloads, it becomes crucial to consider the unique security threats that target such environments when building security solutions. The first step in this process is understanding the relevant attack landscape.<br \/>\nThe post The evolution of a matrix: How ATT&#038;CK for Containers was built appeared first on Microsoft Security Blog. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":41885,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[9351,347,9177,7221],"class_list":["post-41884","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-attck-for-containers","tag-cybersecurity","tag-integrated-threat-protection","tag-microsoft-security-intelligence"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>The evolution of a matrix: How ATT&amp;CK for Containers was built 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The evolution of a matrix: How ATT&amp;CK for Containers was built 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-21T16:00:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png\" \/>\n\t<meta property=\"og:image:width\" content=\"977\" \/>\n\t<meta property=\"og:image:height\" content=\"604\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"The evolution of a matrix: How ATT&amp;CK for Containers was built\",\"datePublished\":\"2021-07-21T16:00:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/\"},\"wordCount\":1199,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png\",\"keywords\":[\"ATT&amp;CK for Containers\",\"Cybersecurity\",\"Integrated Threat Protection\",\"Microsoft security intelligence\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/\",\"name\":\"The evolution of a matrix: How ATT&amp;CK for Containers was built 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png\",\"datePublished\":\"2021-07-21T16:00:42+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png\",\"width\":977,\"height\":604},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ATT&amp;CK for Containers\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/attck-for-containers\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"The evolution of a matrix: How ATT&amp;CK for Containers was built\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The evolution of a matrix: How ATT&amp;CK for Containers was built 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/","og_locale":"en_US","og_type":"article","og_title":"The evolution of a matrix: How ATT&amp;CK for Containers was built 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-07-21T16:00:42+00:00","og_image":[{"width":977,"height":604,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"The evolution of a matrix: How ATT&amp;CK for Containers was built","datePublished":"2021-07-21T16:00:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/"},"wordCount":1199,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png","keywords":["ATT&amp;CK for Containers","Cybersecurity","Integrated Threat Protection","Microsoft security intelligence"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/","url":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/","name":"The evolution of a matrix: How ATT&amp;CK for Containers was built 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png","datePublished":"2021-07-21T16:00:42+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/the-evolution-of-a-matrix-how-attck-for-containers-was-built.png","width":977,"height":604},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/the-evolution-of-a-matrix-how-attck-for-containers-was-built\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"ATT&amp;CK for Containers","item":"https:\/\/www.threatshub.org\/blog\/tag\/attck-for-containers\/"},{"@type":"ListItem","position":3,"name":"The evolution of a matrix: How ATT&amp;CK for Containers was built"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=41884"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41884\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/41885"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=41884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=41884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=41884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}