271 defences6,772 crosswalks
D3FENDD3FEND defensive matrix
7 tactics · 271 defensive techniques · 6,772 defends_against crosswalks to MITRE ATT&CK. Authored by Adam Lundqvist.
ATT&CK coverage
0
1
2-3
4-5
6+
MODModel27 techniques
D3-AI
D3-AI Asset Inventory
Counters 119 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-CI
D3-CI Configuration Inventory
Counters 53 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-DI
D3-DI Data Inventory
Counters 29 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-AVE
D3-AVE Asset Vulnerability Enumeration
Counters 26 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-CIA
D3-CIA Container Image Analysis
Counters 26 ATT&CK techniques
Tactic: Model · Level: subtechnique · Click to inspect
D3-SWI
D3-SWI Software Inventory
Counters 25 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-AM
D3-AM Access Modeling
Counters 24 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-OAM
D3-OAM Operational Activity Mapping
Counters 24 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-NM
D3-NM Network Mapping
Counters 15 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-HCI
D3-HCI Hardware Component Inventory
Counters 11 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-NTPM
D3-NTPM Network Traffic Policy Mapping
Counters 8 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-ALLM
D3-ALLM Active Logical Link Mapping
Counters 7 ATT&CK techniques
Tactic: Model · Level: subtechnique · Click to inspect
D3-APLM
D3-APLM Active Physical Link Mapping
Counters 7 ATT&CK techniques
Tactic: Model · Level: subtechnique · Click to inspect
D3-DPLM
D3-DPLM Direct Physical Link Mapping
Counters 7 ATT&CK techniques
Tactic: Model · Level: subtechnique · Click to inspect
D3-LLM
D3-LLM Logical Link Mapping
Counters 7 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-NNI
D3-NNI Network Node Inventory
Counters 7 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-PLLM
D3-PLLM Passive Logical Link Mapping
Counters 7 ATT&CK techniques
Tactic: Model · Level: subtechnique · Click to inspect
D3-PLM
D3-PLM Physical Link Mapping
Counters 7 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-SYSM
D3-SYSM System Mapping
Counters 1 ATT&CK technique
Tactic: Model · Level: technique · Click to inspect
D3-SYSVA
D3-SYSVA System Vulnerability Assessment
Counters 1 ATT&CK technique
Tactic: Model · Level: technique · Click to inspect
D3-DEM
D3-DEM Data Exchange Mapping
Counters 0 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-NVA
D3-NVA Network Vulnerability Assessment
Counters 0 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-ODM
D3-ODM Operational Dependency Mapping
Counters 0 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-OM
D3-OM Organization Mapping
Counters 0 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-ORA
D3-ORA Operational Risk Assessment
Counters 0 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-SVCDM
D3-SVCDM Service Dependency Mapping
Counters 0 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
D3-SYSDM
D3-SYSDM System Dependency Mapping
Counters 0 ATT&CK techniques
Tactic: Model · Level: technique · Click to inspect
HARHarden55 techniques
D3-PH
D3-PH Platform Hardening
Counters 138 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-FE
D3-FE File Encryption
Counters 99 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-AA
D3-AA Agent Authentication
Counters 37 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-CH
D3-CH Credential Hardening
Counters 37 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-MFA
D3-MFA Multi-factor Authentication
Counters 36 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SU
D3-SU Software Update
Counters 25 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-TBA
D3-TBA Token-based Authentication
Counters 24 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-CDP
D3-CDP Change Default Password
Counters 20 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-CERO
D3-CERO Certificate Rotation
Counters 20 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-CRO
D3-CRO Credential Rotation
Counters 20 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-PWA
D3-PWA Password Authentication
Counters 20 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SPP
D3-SPP Strong Password Policy
Counters 20 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-OTP
D3-OTP One-time Password
Counters 19 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-PR
D3-PR Password Rotation
Counters 19 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-TB
D3-TB Token Binding
Counters 19 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-CBAN
D3-CBAN Certificate-based Authentication
Counters 18 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-BAN
D3-BAN Biometric Authentication
Counters 17 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-AH
D3-AH Application Hardening
Counters 16 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SCP
D3-SCP System Configuration Permissions
Counters 13 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-PSEP
D3-PSEP Process Segment Execution Prevention
Counters 12 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SAOR
D3-SAOR Segment Address Offset Randomization
Counters 12 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-EMH
D3-EMH Electromagnetic Radiation Hardening
Counters 11 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-RFS
D3-RFS RF Shielding
Counters 11 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-RH
D3-RH Radiation Hardening
Counters 11 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SFCV
D3-SFCV Stack Frame Canary Validation
Counters 5 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-ACH
D3-ACH Application Configuration Hardening
Counters 4 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-DRA
D3-DRA Disable Remote Access
Counters 4 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-DENCR
D3-DENCR Disk Encryption
Counters 2 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-BA
D3-BA Bootloader Authentication
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-CP
D3-CP Certificate Pinning
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-CS
D3-CS Credential Scrubbing
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-DLV
D3-DLV Domain Logic Validation
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-HBWP
D3-HBWP Hardware-based Write Protection
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-SCH
D3-SCH Source Code Hardening
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-TL
D3-TL Trusted Library
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-VI
D3-VI Variable Initialization
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-BMA
D3-BMA Bus Message Authentication
Counters 0 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-CFI
D3-CFI Control Flow Integrity
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-DCE
D3-DCE Dead Code Elimination
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-DLIC
D3-DLIC Driver Load Integrity Checking
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-EHPV
D3-EHPV Exception Handler Pointer Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-IRV
D3-IRV Integer Range Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-MAN
D3-MAN Message Authentication
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-MBSV
D3-MBSV Memory Block Start Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-MENCR
D3-MENCR Message Encryption
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-MH
D3-MH Message Hardening
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-NPC
D3-NPC Null Pointer Checking
Counters 0 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-OLV
D3-OLV Operational Logic Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: subtechnique · Click to inspect
D3-PAN
D3-PAN Pointer Authentication
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-PEH
D3-PEH Physical Enclosure Hardening
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-PV
D3-PV Pointer Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-RN
D3-RN Reference Nullification
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-TAAN
D3-TAAN Transfer Agent Authentication
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-TBI
D3-TBI TPM Boot Integrity
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-VTV
D3-VTV Variable Type Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
DETDetect90 techniques
D3-PM
D3-PM Platform Monitoring
Counters 138 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FA
D3-FA File Analysis
Counters 99 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FCOA
D3-FCOA File Content Analysis
Counters 99 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FCR
D3-FCR File Content Rules
Counters 99 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-FH
D3-FH File Hashing
Counters 99 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FIM
D3-FIM File Integrity Monitoring
Counters 99 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-UBA
D3-UBA User Behavior Analysis
Counters 95 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-NTA
D3-NTA Network Traffic Analysis
Counters 74 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-APCA
D3-APCA Application Protocol Command Analysis
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-CSPP
D3-CSPP Client-server Payload Profiling
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-NTCD
D3-NTCD Network Traffic Community Deviation
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-NTSA
D3-NTSA Network Traffic Signature Analysis
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PHDURA
D3-PHDURA Per Host Download-Upload Ratio Analysis
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PMAD
D3-PMAD Protocol Metadata Anomaly Detection
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-RTSD
D3-RTSD Remote Terminal Session Detection
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-UGLPA
D3-UGLPA User Geolocation Logon Pattern Analysis
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PA
D3-PA Process Analysis
Counters 59 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-OSM
D3-OSM Operating System Monitoring
Counters 43 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SCA
D3-SCA System Call Analysis
Counters 40 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-DA
D3-DA Dynamic Analysis
Counters 38 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-EFA
D3-EFA Emulated File Analysis
Counters 38 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PSA
D3-PSA Process Spawn Analysis
Counters 36 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-RPA
D3-RPA Relay Pattern Analysis
Counters 31 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-CCSA
D3-CCSA Credential Compromise Scope Analysis
Counters 19 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SBV
D3-SBV Service Binary Verification
Counters 16 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-SFA
D3-SFA System File Analysis
Counters 16 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-CAA
D3-CAA Connection Attempt Analysis
Counters 15 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-AEM
D3-AEM Application Exception Monitoring
Counters 14 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-APM
D3-APM Application Performance Monitoring
Counters 14 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PLA
D3-PLA Process Lineage Analysis
Counters 14 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-PSMD
D3-PSMD Process Self-Modification Detection
Counters 14 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-OPM
D3-OPM Operational Process Monitoring
Counters 13 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-ANAA
D3-ANAA Administrative Network Activity Analysis
Counters 8 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-EHB
D3-EHB Endpoint Health Beacon
Counters 7 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-HD
D3-HD Homoglyph Detection
Counters 7 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-ID
D3-ID Identifier Analysis
Counters 7 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-MBT
D3-MBT Memory Boundary Tracking
Counters 7 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-PCSV
D3-PCSV Process Code Segment Verification
Counters 7 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-ACA
D3-ACA Active Certificate Analysis
Counters 6 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-CA
D3-CA Certificate Analysis
Counters 6 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-ISVA
D3-ISVA Inbound Session Volume Analysis
Counters 6 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PCA
D3-PCA Passive Certificate Analysis
Counters 6 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-DAM
D3-DAM Domain Account Monitoring
Counters 5 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SICA
D3-SICA System Init Config Analysis
Counters 5 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-SSC
D3-SSC Shadow Stack Comparisons
Counters 5 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FBA
D3-FBA Firmware Behavior Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FEMC
D3-FEMC Firmware Embedded Monitoring Code
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FV
D3-FV Firmware Verification
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-IAA
D3-IAA Identifier Activity Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-IRA
D3-IRA Identifier Reputation Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-MA
D3-MA Message Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SMRA
D3-SMRA Sender MTA Reputation Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SRA
D3-SRA Sender Reputation Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-UA
D3-UA URL Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-URA
D3-URA URL Reputation Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-DNSTA
D3-DNSTA DNS Traffic Analysis
Counters 3 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-IDA
D3-IDA Input Device Analysis
Counters 3 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-LAM
D3-LAM Local Account Monitoring
Counters 3 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SDM
D3-SDM System Daemon Monitoring
Counters 3 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-FC
D3-FC File Carving
Counters 2 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FCA
D3-FCA File Creation Analysis
Counters 2 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-SFV
D3-SFV System Firmware Verification
Counters 2 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-SJA
D3-SJA Scheduled Job Analysis
Counters 2 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-USICA
D3-USICA User Session Init Config Analysis
Counters 2 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-DQSA
D3-DQSA Database Query String Analysis
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-IPCTA
D3-IPCTA IPC Traffic Analysis
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-PHAM
D3-PHAM Physical Access Monitoring
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-RTA
D3-RTA RPC Traffic Analysis
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-VS
D3-VS Video Surveillance
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-ANET
D3-ANET Authentication Event Thresholding
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-AZET
D3-AZET Authorization Event Thresholding
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-BSE
D3-BSE Byte Sequence Emulation
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-DNRA
D3-DNRA Domain Name Reputation Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-ELM
D3-ELM Electronic Lock Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FAPA
D3-FAPA File Access Pattern Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FHRA
D3-FHRA File Hash Reputation Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-IBCA
D3-IBCA Indirect Branch Call Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-IPRA
D3-IPRA IP Reputation Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-JFAPA
D3-JFAPA Job Function Access Pattern Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-MSM
D3-MSM Motion Sensor Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-OMM
D3-OMM Operating Mode Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PFV
D3-PFV Peripheral Firmware Verification
Counters 0 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-PSM
D3-PSM Proximity Sensor Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PUM
D3-PUM Platform Uptime Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-RAPA
D3-RAPA Resource Access Pattern Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-RFUM
D3-RFUM Remote Firmware Update Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: subtechnique · Click to inspect
D3-SDA
D3-SDA Session Duration Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SEA
D3-SEA Script Execution Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-UDTA
D3-UDTA User Data Transfer Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-WSAA
D3-WSAA Web Session Activity Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
ISOIsolate57 techniques
D3-AMED
D3-AMED Access Mediation
Counters 166 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-APA
D3-APA Access Policy Administration
Counters 117 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CF
D3-CF Content Filtering
Counters 113 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-NRAM
D3-NRAM Network Resource Access Mediation
Counters 113 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CQ
D3-CQ Content Quarantine
Counters 112 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CV
D3-CV Content Validation
Counters 100 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-FFV
D3-FFV File Format Verification
Counters 100 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-LFP
D3-LFP Local File Permissions
Counters 100 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CFC
D3-CFC Content Format Conversion
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-CM
D3-CM Content Modification
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CNE
D3-CNE Content Excision
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-CNR
D3-CNR Content Rebuild
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-CNS
D3-CNS Content Substitution
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-FCDC
D3-FCDC File Content Decompression Checking
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-FISV
D3-FISV File Internal Structure Verification
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-FMBV
D3-FMBV File Magic Byte Verification
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-FMCV
D3-FMCV File Metadata Consistency Validation
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-FMVV
D3-FMVV File Metadata Value Verification
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-RFAM
D3-RFAM Remote File Access Mediation
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-NI
D3-NI Network Isolation
Counters 74 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-NTF
D3-NTF Network Traffic Filtering
Counters 74 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-EI
D3-EI Execution Isolation
Counters 62 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-SCF
D3-SCF System Call Filtering
Counters 52 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-EAL
D3-EAL Executable Allowlisting
Counters 51 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-EDL
D3-EDL Executable Denylisting
Counters 51 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-HBPI
D3-HBPI Hardware-based Process Isolation
Counters 36 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-OTF
D3-OTF Outbound Traffic Filtering
Counters 31 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-CTS
D3-CTS Credential Transmission Scoping
Counters 19 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-UAP
D3-UAP User Account Permissions
Counters 17 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-EBWSAM
D3-EBWSAM Endpoint-based Web Server Access Mediation
Counters 16 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-PBWSAM
D3-PBWSAM Proxy-based Web Server Access Mediation
Counters 16 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-ABPI
D3-ABPI Application-based Process Isolation
Counters 15 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-KBPI
D3-KBPI Kernel-based Process Isolation
Counters 14 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-LFAM
D3-LFAM Local File Access Mediation
Counters 14 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-ITF
D3-ITF Inbound Traffic Filtering
Counters 8 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-WSAM
D3-WSAM Web Session Access Mediation
Counters 8 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-IOPR
D3-IOPR IO Port Restriction
Counters 7 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-EF
D3-EF Email Filtering
Counters 4 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-DNSAL
D3-DNSAL DNS Allowlisting
Counters 2 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-DNSDL
D3-DNSDL DNS Denylisting
Counters 2 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-FRDDL
D3-FRDDL Forward Resolution Domain Denylisting
Counters 2 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-HDDL
D3-HDDL Hierarchical Domain Denylisting
Counters 2 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-HDL
D3-HDL Homoglyph Denylisting
Counters 2 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-RRID
D3-RRID Reverse Resolution IP Denylisting
Counters 2 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-DTP
D3-DTP Domain Trust Policy
Counters 1 ATT&CK technique
Tactic: Isolate · Level: technique · Click to inspect
D3-BDI
D3-BDI Broadcast Domain Isolation
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-DNL
D3-DNL Directional Network Link
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-EPL
D3-EPL Physical Locking
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-ET
D3-ET Encrypted Tunnels
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-FRIDL
D3-FRIDL Forward Resolution IP Denylisting
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-LAMED
D3-LAMED LAN Access Mediation
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3-NAM
D3-NAM Network Access Mediation
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-OPR
D3-OPR Operating Mode Restriction
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-OVAR
D3-OVAR OT Variable Access Restriction
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-PAM
D3-PAM Physical Access Mediation
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-RAM
D3-RAM Routing Access Mediation
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: subtechnique · Click to inspect
D3F-UGPH
D3F-UGPH User Group Permissions
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
DECDeceive11 techniques
D3-DO
D3-DO Decoy Object
Counters 124 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DF
D3-DF Decoy File
Counters 99 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DUC
D3-DUC Decoy User Credential
Counters 19 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DNR
D3-DNR Decoy Network Resource
Counters 8 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-CHN
D3-CHN Connected Honeynet
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-DE
D3-DE Decoy Environment
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-IHN
D3-IHN Integrated Honeynet
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-SHN
D3-SHN Standalone Honeynet
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-DP
D3-DP Decoy Persona
Counters 0 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DPR
D3-DPR Decoy Public Release
Counters 0 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DST
D3-DST Decoy Session Token
Counters 0 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
EVIEvict19 techniques
D3-OE
D3-OE Object Eviction
Counters 104 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-FEV
D3-FEV File Eviction
Counters 101 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-CE
D3-CE Credential Eviction
Counters 36 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-PE
D3-PE Process Eviction
Counters 22 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-ANCI
D3-ANCI Authentication Cache Invalidation
Counters 19 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-CR
D3-CR Credential Revocation
Counters 19 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-AL
D3-AL Account Locking
Counters 17 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-HR
D3-HR Host Reboot
Counters 14 ATT&CK techniques
Tactic: Evict · Level: subtechnique · Click to inspect
D3-HS
D3-HS Host Shutdown
Counters 14 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-PS
D3-PS Process Suspension
Counters 14 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-PT
D3-PT Process Termination
Counters 14 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-ST
D3-ST Session Termination
Counters 8 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-ER
D3-ER Email Removal
Counters 6 ATT&CK techniques
Tactic: Evict · Level: subtechnique · Click to inspect
D3-DKF
D3-DKF Disk Formatting
Counters 3 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-DKP
D3-DKP Disk Partitioning
Counters 3 ATT&CK techniques
Tactic: Evict · Level: subtechnique · Click to inspect
D3-DKE
D3-DKE Disk Erasure
Counters 1 ATT&CK technique
Tactic: Evict · Level: subtechnique · Click to inspect
D3-RKD
D3-RKD Registry Key Deletion
Counters 1 ATT&CK technique
Tactic: Evict · Level: technique · Click to inspect
D3-DNSCE
D3-DNSCE DNS Cache Eviction
Counters 0 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-DRT
D3-DRT Domain Registration Takedown
Counters 0 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
RESRestore12 techniques
D3-RO
D3-RO Restore Object
Counters 171 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect
D3-RF
D3-RF Restore File
Counters 99 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect
D3-RC
D3-RC Restore Configuration
Counters 53 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect
D3-RA
D3-RA Restore Access
Counters 42 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect
D3-RS
D3-RS Restore Software
Counters 25 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect
D3-RD
D3-RD Restore Database
Counters 22 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect
D3-RIC
D3-RIC Reissue Credential
Counters 19 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect
D3-RUAA
D3-RUAA Restore User Account Access
Counters 17 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect
D3-ULA
D3-ULA Unlock Account
Counters 17 ATT&CK techniques
Tactic: Restore · Level: subtechnique · Click to inspect
D3-RNA
D3-RNA Restore Network Access
Counters 6 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect
D3-RE
D3-RE Restore Email
Counters 4 ATT&CK techniques
Tactic: Restore · Level: subtechnique · Click to inspect
D3-RDI
D3-RDI Restore Disk Image
Counters 0 ATT&CK techniques
Tactic: Restore · Level: technique · Click to inspect