FAQs

We've compiled a list of common questions about our cloud security platform with clear and helpful answers to address your concerns.
Table of Contents
Cloud Attack Emulation (CAE) - Getting Started
This is some text inside of a div block.
Cloud Attack Emulation (CAE) - Safety Measures
This is some text inside of a div block.
Cloud Security Posture Management (CSPM)
This is some text inside of a div block.
Kubernetes Security Posture Management (KSPM)
This is some text inside of a div block.
Technical Capabilities - Platform Wide
This is some text inside of a div block.
Platform Capabilities - All Products
This is some text inside of a div block.
Use Cases & Benefits
This is some text inside of a div block.
Business & Pricing
This is some text inside of a div block.
Security & Trust
This is some text inside of a div block.
Implementation & Operations
This is some text inside of a div block.
Advanced Topics
This is some text inside of a div block.
Bring Your Own Role (BYOR) - Deep Dive
This is some text inside of a div block.
Understanding The Mitigant Platform
This is some text inside of a div block.
Getting Started - General
This is some text inside of a div block.
Mitigant versus Breach & Attack Simulation
This is some text inside of a div block.
Mitigant versus CNAPPs
This is some text inside of a div block.

Mitigant versus CNAPPs

How is Mitigant different from standalone CSPM tools?

Standalone CSPM Tools:

  • Identify misconfigurations
  • Provide compliance dashboards
  • Alert on policy violations
  • Stop there (detection without validation)

‍

Mitigant Platform (CSPM + CAE with AEV):

  • Identify misconfigurations (CSPM)
  • Validate exploitability through Adversarial Exposure Validation (CAE)
  • Prove which issues are real vs. theoretical
  • Provide validated, evidence-based prioritization
  • Continuous red team validation

‍

Example:

  • Standalone CSPM: "S3 bucket is public" → You get an alert with a severity score
  • Mitigant AEV: "S3 bucket is public" (CSPM) → "We validated by checking 4 levels of access control (CAE)"

‍

The AEV Differentiator:

  • Most CSPM tools give you thousands of findings - Mitigant proves which ones attackers can actually exploit
  • Reduces alert fatigue by focusing on validated exposures
  • Provides evidence for remediation prioritization and business risk discussions

The integration of posture management with adversarial validation is the differentiator.

‍

How does this compare to vulnerability scanners?

Different Focus:

  • Vulnerability scanners: Software vulnerabilities (CVEs)
  • Mitigant CSPM: Cloud misconfigurations, IAM issues
  • Mitigant KSPM: Container/Kubernetes vulnerabilities and misconfigurations
  • Mitigant CAE: Detection gaps, response readiness

‍

Different Approach:

  • Vulnerability scanners: Passive scanning
  • Mitigant CAE: Active attack emulation

‍

Complementary Value:

  • Use both together
  • Vulnerability scanners find CVEs
  • Mitigant validates cloud-specific security and proves exploitability

‍

‍

Determinism Meets AI:

  • Predictable attack execution - CAL ensures attacks run exactly as defined, every time
  • AI-enhanced interpretation - intelligent analysis of deterministic results
  • No AI hallucinations in attack logic - attacks execute precisely, AI assists with understanding impact
  • The perfect balance: deterministic security testing with AI-powered insights

‍

Cloud-Native by Design:

  • Purpose-built for cloud - AWS, Azure, GCP, Kubernetes from day one
  • Understands cloud-specific attack patterns - not retrofitted from network pen testing tools
  • Multi-cloud attack chains - test attacks that pivot across cloud providers
  • 500 attacks mapped to MITRE ATT&CK and real threat actors

‍

Customer-Controlled Safety (BYOR):

  • You define the blast radius through your own IAM policies
  • No vendor lock-in or opaque permissions
  • Complete transparency - you see exactly what permissions are used
  • Revocable anytime - you control the security boundary, not us

‍

Modern Tech Stack Alignment:

  • Integrates with Detection-as-Code workflows - validate Sigma rules automatically
  • API-first architecture - trigger attacks from any system
  • Attack Builder - no-code visual interface for security teams without offensive expertise
  • Mitigant Threat Catalog - free, community-driven attack library

‍

Integrated Platform Approach:

  • Works with CSPM and KSPM - validate what posture management finds
  • Implements Gartner's CTEM framework - complete the full cycle from discovery to validation to mobilization
  • Unified view - see misconfigurations and their exploitability in one place
  • Single vendor, single platform - no integration complexity

‍

The combination of Cloud Attack Language for determinism, AI for intelligence, CTEM methodology alignment, and cloud-native design creates a platform aligned with how modern security teams actually work - not how pen testing worked 20 years ago.

Learn more: Cloud Attack Language
Learn more: AI-Powered Analysis
Learn more: Attack Builder

‍

Mitigant's AEV approach aligns with how cloud breaches actually happen - through misconfiguration exploitation, not traditional malware.

Learn more: Adversarial Exposure Validation
Learn more: AEV and CTEM

‍

‍

This is some text inside of a div block.

About Mitigant

‍

Mitigant is a German cybersecurity company pioneering cloud security validation through attack emulation and Security Chaos Engineering. Founded by researchers from Hasso Plattner Institute with over 20 years of combined cloud security experience, Mitigant provides an integrated security platform combining CSPM, KSPM, and Cloud Attack Emulation.

‍

The platform enables organizations of all sizes to proactively verify the readiness and resilience of their cloud-native infrastructures across AWS, Azure, and Kubernetes against potential cyber threats. By combining continuous posture management with attack validation based on MITRE ATT&CK and ATLAS frameworks, Mitigant helps detect and remediate security blind spots within cloud security strategies, tools, and teams.

‍

Contact Information

‍

Partnerships & Recognition

  • Strategic partner with German Federal Office for Information Security (BSI)
  • Selected for Google for Startups Growth Academy: AI for Cybersecurity
  • Member of Digital Hub Bonn
  • Strategic partnerships with GlobalDots, Future Spirits, Syself, and Fogbyte
This FAQ is regularly updated to reflect the latest platform capabilities and industry best practices.
Last Updated: July 2026

Übernehmen Sie die Kontrolle ĂŒber Ihre Cloud-Sicherheitslage

Übernehmen Sie in wenigen Minuten die Kontrolle ĂŒber Ihre Cloud-Sicherheit. Keine Kreditkarte erforderlich.