271 defences1,353 crosswalks

D3FENDD3FEND defensive matrix

7 tactics · 271 defensive techniques · 1,353 defends_against crosswalks to MITRE ATT&CK. Authored by Adam Lundqvist.

TACTICModelHardenDetectIsolateDeceiveEvictRestoreLEVELTechniqueSub-technique
ATT&CK coverage
0
1
2-3
4-5
6+

MODModel5 techniques

D3-CIA
Container Image Analysis
D3-ALLM
Active Logical Link Mapping
D3-APLM
Active Physical Link Mapping
D3-DPLM
Direct Physical Link Mapping
D3-PLLM
Passive Logical Link Mapping

HARHarden11 techniques

D3-CDP
Change Default Password
D3-CERO
Certificate Rotation
D3-OTP
One-time Password
D3-PR
Password Rotation
D3-EMH
Electromagnetic Radiation Hardening
D3-RFS
RF Shielding
D3-DRA
Disable Remote Access
D3-BMA
Bus Message Authentication
D3-MBSV
Memory Block Start Validation
D3-NPC
Null Pointer Checking
D3-OLV
Operational Logic Validation

DETDetect0 techniques

ISOIsolate26 techniques

D3-FFV
File Format Verification
D3-CFC
Content Format Conversion
D3-CNE
Content Excision
D3-CNR
Content Rebuild
D3-CNS
Content Substitution
D3-FCDC
File Content Decompression Checking
D3-FISV
File Internal Structure Verification
D3-FMBV
File Magic Byte Verification
D3-FMCV
File Metadata Consistency Validation
D3-FMVV
File Metadata Value Verification
D3-RFAM
Remote File Access Mediation
D3-OTF
Outbound Traffic Filtering
D3-EBWSAM
Endpoint-based Web Server Access Mediation
D3-PBWSAM
Proxy-based Web Server Access Mediation
D3-LFAM
Local File Access Mediation
D3-ITF
Inbound Traffic Filtering
D3-WSAM
Web Session Access Mediation
D3-EF
Email Filtering
D3-FRDDL
Forward Resolution Domain Denylisting
D3-HDDL
Hierarchical Domain Denylisting
D3-HDL
Homoglyph Denylisting
D3-RRID
Reverse Resolution IP Denylisting
D3-EPL
Physical Locking
D3-FRIDL
Forward Resolution IP Denylisting
D3-LAMED
LAN Access Mediation
D3-RAM
Routing Access Mediation

DECDeceive0 techniques

EVIEvict0 techniques

RESRestore0 techniques

Sourced from MITRE D3FEND ontology. Cross-walks ingested via the D3FEND CSV feed. Curated by Adam Lundqvist, Founder at SQUR.
D3FEND defensive matrix | SQUR Knowledge Base