Mitigant FAQs

We've compiled a list of common questions about our cloud security platform with clear and helpful answers to address your concerns.
Table of Contents
Understanding The Mitigant Platform
This is some text inside of a div block.
Getting Started - General FAQ
This is some text inside of a div block.
Cloud Attack Emulation (CAE) - Getting Started
This is some text inside of a div block.
Cloud Attack Emulation (CAE) - Safety Measures
This is some text inside of a div block.
Cloud Security Posture Management (CSPM)
This is some text inside of a div block.
Kubernetes Security Posture Management (KSPM)
This is some text inside of a div block.
Technical Capabilities - Platform Wide
This is some text inside of a div block.
Platform Capabilities - All Products
This is some text inside of a div block.
Use Cases & Benefits
This is some text inside of a div block.
Business & Pricing
This is some text inside of a div block.
Mitigant versus Breach & Attack Simulation
This is some text inside of a div block.
Mitigant versus CNAPPs
This is some text inside of a div block.
Security & Trust
This is some text inside of a div block.
Implementation & Operations
This is some text inside of a div block.
Advanced Topics
This is some text inside of a div block.
Bring Your Own Role (BYOR) - Deep Dive
This is some text inside of a div block.

Technical Capabilities - Platform Wide

Which cloud providers does the Mitigant Platform support?

‍

All Products (CSPM, KSPM, CAE):

  • Amazon Web Services (AWS)
  • Microsoft Azure
  • Google Cloud Platform (GCP)

‍

KSPM Additionally Supports:

  • Self-hosted Kubernetes clusters (any distribution)
  • Managed Kubernetes services (EKS, AKS, GKE)
  • OpenShift, Rancher, K3s, MicroK8s

‍

Multi-Cloud Capabilities:

  • Single platform for all cloud providers
  • Unified reporting and dashboards
  • Cross-cloud security policies
  • Consistent compliance framework

Learn more: Feature Release: Cloud Attack Emulation for Azure

‍

Does the Mitigant Platform require agents?

Mostly agentless architecture:

‍

CSPM:

  • API-based monitoring
  • No agents on VMs or containers
  • Read-only access via cloud provider APIs

‍

KSPM:

  • Uses a lightweight agent installed as an operator
  • Minimal resource consumption
  • No performance impact on workloads

‍

CAE:

  • API-driven attack execution
  • No software installation required
  • Works through cloud service interfaces

‍

Benefits of this architecture:

  • Faster deployment (minutes, not weeks)
  • Minimal maintenance overhead
  • No compatibility issues
  • Works equally well for ephemeral and persistent infrastructure
  • Reduced attack surface

How does the Mitigant Platform integrate with our SIEM?

The Mitigant Platform provides multiple integration options:

‍

Event Log Export (All Products):

  • Export security findings to your SIEM
  • CAE automatically retrieves attack telemetry
  • CSPM/KSPM export misconfiguration alerts
  • Standard formats (JSON, Syslog)

‍

Microsoft Sentinel Integration (CAE):

  • Deep integration with Microsoft Sentinel
  • Attack telemetry flows directly into Sentinel for analysis
  • Bi-directional integration for enhanced detection and response

Learn more: Ultimate Combo: Cloud Attack Emulation meets Microsoft Sentinel

‍

Sigma Rules (CAE):

  • For each attack, Mitigant provides corresponding Sigma rules
  • Standardized detection rules can be copied to any SIEM
  • Saves time for detection engineers
  • Helps remediate failed or misconfigured detection systems

Learn more: Cloud Attack Emulation & Detection Engineering: A Match Made in Heaven

‍

Notification Integrations (All Products):

  • Slack
  • Microsoft Teams
  • Jira
  • PagerDuty
  • Email
  • Webhooks for custom integrations

API Access (All Products):

  • RESTful API for programmatic access
  • Integration into CI/CD pipelines
  • Custom workflows and automation
  • Attack-as-Code support (CAE)

‍

What permissions does the Mitigant Platform need?

Mitigant follows the principle of least privilege, and requirements vary by product:

‍

CSPM Permissions (Read-Only):

  • Discover and inventory resources
  • View cloud configurations
  • Monitor for suspicious activities
  • Examples: ec2:Describe*, s3:GetBucketPolicy, iam:List*

‍

KSPM Permissions (Read-Only):

  • Access to Kubernetes API
  • Read cluster configurations
  • View pod and deployment specs
  • No write permissions required

‍

CAE Permissions (BYOR - Bring Your Own Role):

  • You define the permissions through BYOR
  • Controlled write permissions scoped to specific resources you authorize
  • You can restrict by tags, accounts, regions, services, or resource types
  • See the BYOR section below for detailed configuration options

‍

Customization Options (CAE with BYOR):

  • Restrict by resource tags: Only allow attacks on resources tagged test:true or environment:staging
  • Restrict by account: Provide access only to non-production AWS accounts or Azure subscriptions
  • Restrict by region: Limit operations to specific geographic regions
  • Restrict by service: Grant access only to specific cloud services (e.g., S3 and EC2, but not RDS)
  • Restrict by resource type: Allow access to VMs but not databases
  • Set budget limits: Use IAM conditions to enforce cost controls
  • Time-based restrictions: Implement time-of-day or maintenance window constraints

‍

Implementation:

  • Mitigant provides example IAM policies during onboarding
  • You can modify templates to match your security requirements
  • CloudFormation/Terraform templates include documented permissions
  • All required permissions are transparently listed-no hidden access

‍

This is some text inside of a div block.
This FAQ is regularly updated to reflect the latest platform capabilities and industry best practices.
Last Updated: July 2026

Expose Threats with AI-Powered Adversary Emulation

Safely run controlled cloud attacks and validate your real defensive capabilities in minutes. No credit card required.