Dexfense

Know your attack surface.Build your defense.

Map your system architecture to MITRE ATT&CK® and get a prioritised, exportable security defense plan — in minutes.

MITRE ATT&CK® mapped 70+ components covered NIST CSF 2.0 Gap Analysis Exportable PDF reports
70+ Security Components
200+ ATT&CK® Techniques
NIST CSF 2.0 Aligned
Free to Use
HomeCommunity LibraryAWS Serverless Application

AWS Serverless Application

Dexfense Reviewed

Cloud-native application on AWS Lambda, API Gateway, Aurora/DynamoDB, S3 and CloudWatch with a GitOps CI/CD pipeline.

Cloud & SaaSEnterprise
15 components·By Dexfense·v1.0 · July 2026

Overview

Covers a serverless-first application on AWS using Lambda for compute, API Gateway for HTTP routing, Aurora/RDS for relational data, DynamoDB for high-throughput NoSQL storage, S3 for object storage, Cognito for authentication and MFA, AWS WAF for web protection, CloudWatch and CloudTrail for observability and audit, and a CI/CD pipeline. All compute runs inside a VPC with network segmentation; IAM roles follow least privilege throughout.

Intended for

Cloud architects, DevSecOps teams and security engineers working with AWS serverless workloads.

Architecture Assumptions

This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.

  • All compute is serverless; no persistent EC2 instances in the production path
  • IAM roles and resource policies follow the principle of least privilege
  • VPC isolates database and compute tiers; NAT Gateway controls outbound traffic
  • CloudTrail is enabled across all AWS regions in the account
  • Container images are scanned for CVEs before deployment to ECR

Out of Scope

  • Multi-account AWS Organisation structure and SCPs are not modelled
  • AWS Bedrock and AI/ML services are not included in this template
  • Data residency and cross-region replication are not assessed

Architecture Components15 components selected

Cloud

AWS Infrastructure

Amazon Web Services infrastructure

Serverless

Serverless compute functions

Web & APIs

API Services

API endpoints for application integration

Containers

Containers

Containerized applications and services

Databases

SQL Databases

Relational databases holding structured data

NoSQL Databases

Non-relational databases for unstructured data

Storage

Cloud Storage

Cloud-based object or file storage

Backup Systems

Data backup and recovery systems

Auth & IAM

OAuth/OIDC

Open authorization and identity protocols

Multi-Factor Auth

Additional authentication verification layer

Network

WAF

Web Application Firewall

Load Balancers

Traffic distribution systems

DNS Services

Domain name resolution services

Monitoring

Logging Systems

Centralized log collection and management

DevOps

CI/CD Pipeline

Continuous Integration/Continuous Deployment pipeline

Security Preview

Based on this architecture's component selection

Indicative Risk Score

58/100

13 techniques identified

2 Critical · 3 High

Top Attack Techniques

  • CriticalT1068Exploitation for Privilege Escalation
  • CriticalT1486Data Encrypted for Impact
  • HighT1190Exploit Public-Facing Application
  • HighT1574Hijack Execution Flow
  • HighT1072Software Deployment Tools

Top Recommended Controls

  • 1Implement Web Application Firewall (WAF) and regular security testing
  • 2Adopt container security best practices including least privilege access and network policies
  • 3Implement comprehensive cloud security posture management

The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.

Use This ArchitectureRemix This Architecture

Remix copies the components so you can add or remove items before generating your assessment.

Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.

Back to Community Library