ThinkCNAP.org

Maturity Assessment & Attack Simulation

Assess · Simulate · Improve

Measure the security maturity of your cloud native applications, turn the gaps into a roadmap aligned with business goals, and prove your threat detection works with real attack scenarios running inside your Kubernetes clusters.

Why ThinkCNAP

Know where you stand. Plan where to go. Prove it works.

ThinkCNAP helps security and platform teams assess the maturity of their cloud native applications and build an improvement roadmap connected to business goals. On top of that, you can launch real-world attack scenarios to validate how well your existing threat detection controls actually perform, by deploying the attack-simulation container to Kubernetes.

Assess maturity

Score every security measure from 0 to 5 across AWS, Kubernetes and AI workloads, and see your posture per domain at a glance.

Build a business-aligned roadmap

Set initial, present and desired maturity, weigh each measure by impact and effort, and prioritize the work that matters most to the business.

Validate detection

Deploy the attack-simulation container to Kubernetes and run real MITRE ATT&CK scenarios to verify your detection and response controls.

Core features

One platform from assessment to proof

Maturity Assessment

AWS, Kubernetes & AI security maturity

Assess your environment against measures mapped to the AWS Well-Architected Security Pillar. Every measure gets an impact, an effort and three maturity levels, so the gap between today and your target is always visible.

  • Radar overview of Initial, Present and Desired maturity across 7 domains
  • Impact and effort per measure to prioritize a realistic roadmap
  • Measures linked to MITRE ATT&CK techniques with exploitation examples
app.thinkcnap.org · Maturity Assessment · AWS
ThinkCNAP AWS maturity assessment: radar chart and per-domain scores
AWS maturity assessment screenshot
app.thinkcnap.org · Attack Simulation · Report
ThinkCNAP attack simulation report with MITRE ATT&CK techniques executed in Kubernetes and AWS
Attack simulation screenshot
Attack Simulation

Real attack scenarios, inside your cluster

Attack Simulation is a containerized security testing tool that automates MITRE ATT&CK techniques to validate your detection capabilities and response coverage. It runs as a Kubernetes Job, on demand, against AWS and Kubernetes targets.

  • Install with Helm; configure and download values.yaml from the app
  • Simulates IAM abuse and Kubernetes techniques mapped to MITRE ATT&CK
  • Results are exported back to your ThinkCNAP account as a report
AI-Assisted Assessment

Let an AI agent run the assessment

Connect an AI agent to ThinkCNAP with your API token and let it assess maturity for you. The agent inspects your AWS environment against each measure and records the results in your assessment, so you spend your time reviewing findings instead of collecting evidence.

  • Reads the measures and your current scores through the API
  • Checks your AWS accounts and sets present and desired maturity with a short finding
  • Repeatable: rerun it after changes to keep the assessment up to date
GET /api/integrations/get-user-aws-maturity
POST /api/integrations/update-measure
AI agent · ThinkCNAP API
An AI agent assessing AWS security measures and updating maturity scores through the ThinkCNAP API
AI agent and API screenshot

How it works

Assess · Simulate · Improve

  1. 1

    Assess

    Sign up, choose AWS, Kubernetes or AI, and score each measure's impact, effort and initial, present and desired maturity.

  2. 2

    Simulate

    Deploy the attack-simulation Helm chart to your Kubernetes cluster and run real-world attack techniques.

    helm repo add aliaksxssv https://aliaksxssv.github.io/attack-simulation/
  3. 3

    Improve

    Review the simulation report against your detections, close the gaps on your roadmap and track progress from present to desired maturity.

Coverage

7 security domains, mapped to MITRE ATT&CK

Domains follow the AWS Well-Architected Framework Security Pillar. Measures are linked to the MITRE ATT&CK techniques they defend against, with exploitation examples, so every control has a clear "why".

SEC01Security Foundations
SEC02Identity & Access Management
SEC03Detection
SEC04Infrastructure Protection
SEC05Data Protection
SEC06Incident Response
SEC07Application Security
ATT&CKTechnique links & exploitation examples

Start your assessment

Free to sign up. Assess your cloud native security in minutes and build the roadmap to where you want to be.