271 defences2,365 crosswalks
D3FENDD3FEND defensive matrix
7 tactics · 271 defensive techniques · 2,365 defends_against crosswalks to MITRE ATT&CK. Authored by Adam Lundqvist.
ATT&CK coverage
0
1
2-3
4-5
6+
MODModel0 techniques
HARHarden0 techniques
DETDetect68 techniques
D3-PM
D3-PM Platform Monitoring
Counters 138 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FA
D3-FA File Analysis
Counters 99 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FCOA
D3-FCOA File Content Analysis
Counters 99 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FH
D3-FH File Hashing
Counters 99 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FIM
D3-FIM File Integrity Monitoring
Counters 99 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-UBA
D3-UBA User Behavior Analysis
Counters 95 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-NTA
D3-NTA Network Traffic Analysis
Counters 74 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-APCA
D3-APCA Application Protocol Command Analysis
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-CSPP
D3-CSPP Client-server Payload Profiling
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-NTCD
D3-NTCD Network Traffic Community Deviation
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-NTSA
D3-NTSA Network Traffic Signature Analysis
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PHDURA
D3-PHDURA Per Host Download-Upload Ratio Analysis
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PMAD
D3-PMAD Protocol Metadata Anomaly Detection
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-RTSD
D3-RTSD Remote Terminal Session Detection
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-UGLPA
D3-UGLPA User Geolocation Logon Pattern Analysis
Counters 72 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PA
D3-PA Process Analysis
Counters 59 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-OSM
D3-OSM Operating System Monitoring
Counters 43 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SCA
D3-SCA System Call Analysis
Counters 40 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-DA
D3-DA Dynamic Analysis
Counters 38 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-EFA
D3-EFA Emulated File Analysis
Counters 38 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PSA
D3-PSA Process Spawn Analysis
Counters 36 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-RPA
D3-RPA Relay Pattern Analysis
Counters 31 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-CCSA
D3-CCSA Credential Compromise Scope Analysis
Counters 19 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-CAA
D3-CAA Connection Attempt Analysis
Counters 15 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-APM
D3-APM Application Performance Monitoring
Counters 14 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PSMD
D3-PSMD Process Self-Modification Detection
Counters 14 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-OPM
D3-OPM Operational Process Monitoring
Counters 13 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-ANAA
D3-ANAA Administrative Network Activity Analysis
Counters 8 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-HD
D3-HD Homoglyph Detection
Counters 7 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-ID
D3-ID Identifier Analysis
Counters 7 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PCSV
D3-PCSV Process Code Segment Verification
Counters 7 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-CA
D3-CA Certificate Analysis
Counters 6 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-ISVA
D3-ISVA Inbound Session Volume Analysis
Counters 6 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-DAM
D3-DAM Domain Account Monitoring
Counters 5 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SSC
D3-SSC Shadow Stack Comparisons
Counters 5 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FBA
D3-FBA Firmware Behavior Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FEMC
D3-FEMC Firmware Embedded Monitoring Code
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FV
D3-FV Firmware Verification
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-IAA
D3-IAA Identifier Activity Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-IRA
D3-IRA Identifier Reputation Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-MA
D3-MA Message Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SMRA
D3-SMRA Sender MTA Reputation Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SRA
D3-SRA Sender Reputation Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-UA
D3-UA URL Analysis
Counters 4 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-DNSTA
D3-DNSTA DNS Traffic Analysis
Counters 3 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-LAM
D3-LAM Local Account Monitoring
Counters 3 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FC
D3-FC File Carving
Counters 2 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-DQSA
D3-DQSA Database Query String Analysis
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-IPCTA
D3-IPCTA IPC Traffic Analysis
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-PHAM
D3-PHAM Physical Access Monitoring
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-RTA
D3-RTA RPC Traffic Analysis
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-VS
D3-VS Video Surveillance
Counters 1 ATT&CK technique
Tactic: Detect · Level: technique · Click to inspect
D3-ANET
D3-ANET Authentication Event Thresholding
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-AZET
D3-AZET Authorization Event Thresholding
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-BSE
D3-BSE Byte Sequence Emulation
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-ELM
D3-ELM Electronic Lock Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-FAPA
D3-FAPA File Access Pattern Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-IBCA
D3-IBCA Indirect Branch Call Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-JFAPA
D3-JFAPA Job Function Access Pattern Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-MSM
D3-MSM Motion Sensor Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-OMM
D3-OMM Operating Mode Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PSM
D3-PSM Proximity Sensor Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-PUM
D3-PUM Platform Uptime Monitoring
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-RAPA
D3-RAPA Resource Access Pattern Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SDA
D3-SDA Session Duration Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-SEA
D3-SEA Script Execution Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-UDTA
D3-UDTA User Data Transfer Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
D3-WSAA
D3-WSAA Web Session Activity Analysis
Counters 0 ATT&CK techniques
Tactic: Detect · Level: technique · Click to inspect
ISOIsolate0 techniques
DECDeceive11 techniques
D3-DO
D3-DO Decoy Object
Counters 124 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DF
D3-DF Decoy File
Counters 99 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DUC
D3-DUC Decoy User Credential
Counters 19 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DNR
D3-DNR Decoy Network Resource
Counters 8 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-CHN
D3-CHN Connected Honeynet
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-DE
D3-DE Decoy Environment
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-IHN
D3-IHN Integrated Honeynet
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-SHN
D3-SHN Standalone Honeynet
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-DP
D3-DP Decoy Persona
Counters 0 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DPR
D3-DPR Decoy Public Release
Counters 0 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DST
D3-DST Decoy Session Token
Counters 0 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
EVIEvict15 techniques
D3-OE
D3-OE Object Eviction
Counters 104 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-FEV
D3-FEV File Eviction
Counters 101 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-CE
D3-CE Credential Eviction
Counters 36 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-PE
D3-PE Process Eviction
Counters 22 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-ANCI
D3-ANCI Authentication Cache Invalidation
Counters 19 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-CR
D3-CR Credential Revocation
Counters 19 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-AL
D3-AL Account Locking
Counters 17 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-HS
D3-HS Host Shutdown
Counters 14 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-PS
D3-PS Process Suspension
Counters 14 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-PT
D3-PT Process Termination
Counters 14 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-ST
D3-ST Session Termination
Counters 8 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-DKF
D3-DKF Disk Formatting
Counters 3 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-RKD
D3-RKD Registry Key Deletion
Counters 1 ATT&CK technique
Tactic: Evict · Level: technique · Click to inspect
D3-DNSCE
D3-DNSCE DNS Cache Eviction
Counters 0 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect
D3-DRT
D3-DRT Domain Registration Takedown
Counters 0 ATT&CK techniques
Tactic: Evict · Level: technique · Click to inspect