I’m assembling a reusable threat-modeling package for multi-account AWS and Azure and need resources that connect reference architectures to concrete mitigations. Ideally: Terraform/OpenTofu modules with OPA/Rego policy gates, AWS SCP/Azure Policy baselines, and mappings to MITRE ATT&CK (cloud); in October I validated a 12-control playbook tying GuardDuty and Sentinel alerts to lateral-movement paths. What kits or repos have held up in design reviews?