Database / WarehouseThreatsVersion:DEV (latest)Download file from GitHubIDTitleDescriptionExternal MappingsCapability MappingsControl MappingsCCC.DataWar.TH01Unauthorized Public Access to DatasetsDatasets may be unintentionally made publicly accessible, either at the dataset level or via IAM policies, allowing unauthorized users to read or modify sensitive data, leading to data breaches and compliance violations.110CCC.DataWar.TH02Data Exfiltration via Unauthorized ViewsAttackers may create or exploit unauthorized views to access sensitive data without proper permissions, leading to data leakage.110CCC.DataWar.TH03Exposure of Sensitive Data through Inadequate Column-Level SecurityLack of proper column-level security can lead to unauthorized users accessing sensitive data fields, resulting in data breaches.110ImportsIDRemarksCCC.Core.TH01Access Control is MisconfiguredCCC.Core.TH02Data is intercepted in transitCCC.Core.TH03Deployment region network is untrustedCCC.Core.TH04Data is replicated to untrusted or external locationsCCC.Core.TH05Data is corrupted during replicationCCC.Core.TH06Data is lost or corruptedCCC.Core.TH07Logs are Tampered With or DeletedCCC.Core.TH08Cost Management Data is ManipulatedCCC.Core.TH09Logs or Monitoring Data are Read by Unauthorized UsersCCC.Core.TH10Alerts are InterceptedCCC.Core.TH11Event Notifications are Incorrectly TriggeredCCC.Core.TH12Resource constraints are exhaustedCCC.Core.TH13Resource Tags Are ManipulatedCCC.Core.TH14Older Resource Versions Are ExploitedCCC.Core.TH15Automated Enumeration and Reconnaissance by Non-Human Entities