271 defences387 crosswalks

D3FENDD3FEND defensive matrix

7 tactics · 271 defensive techniques · 387 defends_against crosswalks to MITRE ATT&CK. Authored by Adam Lundqvist.

TACTICModelHardenDetectIsolateDeceiveEvictRestoreLEVELTechniqueSub-technique
ATT&CK coverage
0
1
2-3
4-5
6+

MODModel5 techniques

D3-CIA
Container Image Analysis
D3-ALLM
Active Logical Link Mapping
D3-APLM
Active Physical Link Mapping
D3-DPLM
Direct Physical Link Mapping
D3-PLLM
Passive Logical Link Mapping

HARHarden11 techniques

D3-CDP
Change Default Password
D3-CERO
Certificate Rotation
D3-OTP
One-time Password
D3-PR
Password Rotation
D3-EMH
Electromagnetic Radiation Hardening
D3-RFS
RF Shielding
D3-DRA
Disable Remote Access
D3-BMA
Bus Message Authentication
D3-MBSV
Memory Block Start Validation
D3-NPC
Null Pointer Checking
D3-OLV
Operational Logic Validation

DETDetect22 techniques

D3-FCR
File Content Rules
D3-SBV
Service Binary Verification
D3-SFA
System File Analysis
D3-AEM
Application Exception Monitoring
D3-PLA
Process Lineage Analysis
D3-EHB
Endpoint Health Beacon
D3-MBT
Memory Boundary Tracking
D3-ACA
Active Certificate Analysis
D3-PCA
Passive Certificate Analysis
D3-SICA
System Init Config Analysis
D3-URA
URL Reputation Analysis
D3-IDA
Input Device Analysis
D3-SDM
System Daemon Monitoring
D3-FCA
File Creation Analysis
D3-SFV
System Firmware Verification
D3-SJA
Scheduled Job Analysis
D3-USICA
User Session Init Config Analysis
D3-DNRA
Domain Name Reputation Analysis
D3-FHRA
File Hash Reputation Analysis
D3-IPRA
IP Reputation Analysis
D3-PFV
Peripheral Firmware Verification
D3-RFUM
Remote Firmware Update Monitoring

ISOIsolate0 techniques

DECDeceive0 techniques

EVIEvict0 techniques

RESRestore2 techniques

D3-ULA
Unlock Account
D3-RE
Restore Email
Sourced from MITRE D3FEND ontology. Cross-walks ingested via the D3FEND CSV feed. Curated by Adam Lundqvist, Founder at SQUR.
D3FEND defensive matrix | SQUR Knowledge Base