
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
This repository is a collection of browser and identity attack techniques covering SaaS apps, browser-based attacks, identity providers, and phishing. It is intended to be a resource for security researchers, red/blue teams, and penetration testers to learn about and share these attack techniques.
Name change notice: This project was previously known as the SaaS Attacks Matrix. We've renamed it to the Browser & Identity Attacks Matrix to better reflect its expanding scope — including browser-based attack techniques (like malicious extensions and phishing) and identity-layer attacks that don't fit neatly under the "SaaS" label. All existing links and references to this repo continue to work; only the name has changed.
Quick note: we wanted to start sharing as early as possible, so this is very much a work in progress. Hopefully there is enough to see the shape of things to come, but no doubt there are gaps - we'll be filling them in over the coming weeks and months. If you can help fill in some references, add examples, or point us to missing techniques - please open an issue (or even a PR)! We'll be very sure to credit you.
For more information on the background to this project, check the following blog post
The Microsoft BlueHat 2023 "The new SaaS cyber kill chain" presentation that covers a lot of this research can be found below:
BlueHat - The new SaaS cyber kill chain
For a podcast covering this topic, checkout the DCP Podcast by SpectreOps below:
We’ve taken inspiration from the MITRE ATT&CK framework (certainly intended as the sincerest form of flattery), but wanted to make a conscious break away from the endpoint-focused ATT&CK techniques and instead focus on techniques targeting browsers, identity systems, and SaaS applications. In fact, none of these techniques touch endpoints or customer networks - so we’re calling them networkless attacks.