AI + cloud security case study

Cloud Threat Landscape Platform

A cloud-security intelligence platform that correlates resource-level findings with current threat actors, campaigns, vulnerabilities, and MITRE ATT&CK techniques so teams can focus on the exposures that matter most.

24 hoursAutomated refresh cycle
4 viewsDecision-focused analysis
Next.js + FastAPIProduct and API
PostgreSQLNormalized evidence model

Problem

Cloud-security findings and external threat intelligence answer different questions. Wiz and Steampipe show weaknesses in the current environment, while MITRE ATT&CK, Anomali, vulnerability intelligence, and campaign reporting describe how adversaries operate. When these sources remain separate, security and platform teams must repeatedly gather findings, translate them into techniques, research relevant actors, and decide where to focus.

The goal was to turn that fragmented research into a current, cloud-specific view of which attacker behaviors align with real resource-level exposure and what teams should examine first.

What I built

I built a Next.js and FastAPI application backed by PostgreSQL that combines cloud trust-model data with external threat intelligence. Scheduled Python ingestion pipelines refresh the source data and analytical views every 24 hours.

The platform does not use AI to invent findings or determine whether a vulnerability exists. Deterministic correlation identifies the relevant environments, resources, findings, techniques, actors, and campaigns. AI converts that selected evidence into readable narratives with citations and links back to the supporting TTP and cloud-finding data.

Data architecture

  • Steampipe supplies queryable cloud inventory, configuration, and control findings.
  • Wiz supplies resource-level cloud vulnerabilities, security findings, and relevant campaign intelligence.
  • MITRE ATT&CK provides the common technique and tactic vocabulary used to connect cloud weaknesses with adversary behavior.
  • Anomali and other curated intelligence sources contribute threat-actor, campaign, behavior, and current vulnerability context.
  • Python ingestion jobs validate and normalize source records into PostgreSQL while retaining source identifiers, timestamps, and evidence links.
  • FastAPI exposes the normalized and derived views to the Next.js product experience.

Keeping source attribution allows a consumer to move from a score or narrative back to the underlying cloud finding and threat-intelligence evidence.

Data and analysis architectureCloud evidence to prioritized threat context
Evidence sources
SteampipeInventory · configuration · controls
WizResource findings · vulnerabilities
MITRE ATT&CKTactics · techniques · behaviors
Anomali + curated intelActors · campaigns · current context
Daily ingestion
Scheduled Python pipelinesValidate · normalize · resolve entities · preserve provenance
Evidence model and API
PostgreSQLCloud findings · TTP mappings · actors · campaigns · history
FastAPINormalized evidence · derived views · source links
Analysis
Deterministic correlationPosture scoring · TTP mapping · resource relationships
Grounded AINarrates selected evidence · preserves citations
Next.js decision views
Cloud postureTechnique exposure
Modeled pathsResource-level hypotheses
Campaign exposureBehavior overlap
Attacker scenariosPriority validation

Deterministic analysis selects the evidence. AI explains that evidence; it does not create findings or confirm exploitation.

Analytical model

The cloud posture score is an explainable exposure indicator based on the number of vulnerabilities and security findings observed for an environment across Steampipe and Wiz. Findings are mapped to MITRE ATT&CK techniques, creating a shared representation between the current cloud environment and external attacker behavior.

The score is used to focus investigation rather than claim a precise probability of compromise. Resource-level Wiz and Steampipe evidence provides the concrete environment context needed to determine whether a modeled path is plausible.

Four decision views

Cloud posture

The posture view scores MITRE ATT&CK techniques against the current cloud trust model. Teams can see where findings accumulate, which techniques those weaknesses may enable, and the source evidence behind each score.

Modeled attack paths

The platform identifies lower-scoring cloud environments and examines their actual resource-level findings and relationships. It combines that evidence with current attacker behaviors and techniques, then uses AI to produce a cited narrative describing a plausible route through the exposed environment. These are presented as evidence-backed modeled paths rather than proof that an attack occurred.

Campaign exposure

The campaigns view extracts the MITRE techniques associated with a known campaign, compares them with the organization's cloud posture and affected resources, and explains where the campaign's behaviors overlap with observed exposure. The narrative links back to both the campaign intelligence and the supporting cloud findings.

Attacker scenarios

The scenario view examines ten currently relevant threat actors and asks how their observed techniques would intersect with today's cloud environment. It highlights the resources and technique gaps that would provide the most plausible opportunities, giving teams a focused starting point for validation and hardening.

Grounded AI design

  • Scoring, source selection, technique mapping, and resource correlation happen before narrative generation.
  • Prompts receive only the selected trust-model findings and threat-intelligence evidence for the scenario being analyzed.
  • Generated narratives cite and link the MITRE techniques and Wiz or Steampipe findings used as evidence.
  • The user can inspect the source data rather than treating the narrative as an unsupported conclusion.
  • AI output is positioned as decision support for investigation and prioritization, not confirmation of exploitation.

Refresh and feedback loop

Independent ingestion pipelines refresh cloud posture and threat-intelligence data once every 24 hours. The product displays the refreshed analytical views after correlation and narrative generation complete. When a team fixes a cloud vulnerability or configuration issue, the next Wiz or Steampipe refresh incorporates that change and recalculates the affected posture, paths, campaigns, and scenarios.

The current platform deliberately stops at decision support: remediation is completed through the owning cloud and engineering workflows rather than being executed automatically from the threat application.

Design tradeoffs

A finding-count-based posture score is transparent and easy to explain, but it is an exposure indicator rather than a complete risk model. Larger environments may naturally produce more findings, and raw counts do not fully express exploitability, asset criticality, or blast radius. Those dimensions can be introduced later without obscuring the evidence behind the current score.

A 24-hour refresh provides predictable, comparable daily views but is not a real-time detection system. Source timestamps and evidence links are therefore essential, particularly when consumers investigate fast-moving vulnerabilities or campaigns.

Impact

The platform moves teams from source-by-source investigation to a prioritized review of already-correlated evidence. Instead of separately collecting cloud findings, translating them into MITRE techniques, researching actors and campaigns, and writing an exposure summary, consumers begin with four current views that connect the relevant resource, weakness, behavior, and source evidence.

This reduces investigation preparation and context-switching without relying on an unverified time-savings percentage. More importantly, it helps teams spend their limited focus time validating and fixing the cloud exposures most aligned with current adversary behavior.

← Back to projects