271 defences2,244 crosswalks
D3FENDD3FEND defensive matrix
7 tactics · 271 defensive techniques · 2,244 defends_against crosswalks to MITRE ATT&CK. Authored by Adam Lundqvist.
ATT&CK coverage
0
1
2-3
4-5
6+
MODModel0 techniques
HARHarden44 techniques
D3-PH
D3-PH Platform Hardening
Counters 138 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-FE
D3-FE File Encryption
Counters 99 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-AA
D3-AA Agent Authentication
Counters 37 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-CH
D3-CH Credential Hardening
Counters 37 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-MFA
D3-MFA Multi-factor Authentication
Counters 36 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SU
D3-SU Software Update
Counters 25 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-TBA
D3-TBA Token-based Authentication
Counters 24 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-CRO
D3-CRO Credential Rotation
Counters 20 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-PWA
D3-PWA Password Authentication
Counters 20 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SPP
D3-SPP Strong Password Policy
Counters 20 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-TB
D3-TB Token Binding
Counters 19 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-CBAN
D3-CBAN Certificate-based Authentication
Counters 18 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-BAN
D3-BAN Biometric Authentication
Counters 17 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-AH
D3-AH Application Hardening
Counters 16 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SCP
D3-SCP System Configuration Permissions
Counters 13 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-PSEP
D3-PSEP Process Segment Execution Prevention
Counters 12 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SAOR
D3-SAOR Segment Address Offset Randomization
Counters 12 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-RH
D3-RH Radiation Hardening
Counters 11 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-SFCV
D3-SFCV Stack Frame Canary Validation
Counters 5 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-ACH
D3-ACH Application Configuration Hardening
Counters 4 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-DENCR
D3-DENCR Disk Encryption
Counters 2 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-BA
D3-BA Bootloader Authentication
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-CP
D3-CP Certificate Pinning
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-CS
D3-CS Credential Scrubbing
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-DLV
D3-DLV Domain Logic Validation
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-HBWP
D3-HBWP Hardware-based Write Protection
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-SCH
D3-SCH Source Code Hardening
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-TL
D3-TL Trusted Library
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-VI
D3-VI Variable Initialization
Counters 1 ATT&CK technique
Tactic: Harden · Level: technique · Click to inspect
D3-CFI
D3-CFI Control Flow Integrity
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-DCE
D3-DCE Dead Code Elimination
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-DLIC
D3-DLIC Driver Load Integrity Checking
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-EHPV
D3-EHPV Exception Handler Pointer Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-IRV
D3-IRV Integer Range Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-MAN
D3-MAN Message Authentication
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-MENCR
D3-MENCR Message Encryption
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-MH
D3-MH Message Hardening
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-PAN
D3-PAN Pointer Authentication
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-PEH
D3-PEH Physical Enclosure Hardening
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-PV
D3-PV Pointer Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-RN
D3-RN Reference Nullification
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-TAAN
D3-TAAN Transfer Agent Authentication
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-TBI
D3-TBI TPM Boot Integrity
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
D3-VTV
D3-VTV Variable Type Validation
Counters 0 ATT&CK techniques
Tactic: Harden · Level: technique · Click to inspect
DETDetect0 techniques
ISOIsolate31 techniques
D3-AMED
D3-AMED Access Mediation
Counters 166 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-APA
D3-APA Access Policy Administration
Counters 117 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CF
D3-CF Content Filtering
Counters 113 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-NRAM
D3-NRAM Network Resource Access Mediation
Counters 113 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CQ
D3-CQ Content Quarantine
Counters 112 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CV
D3-CV Content Validation
Counters 100 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-LFP
D3-LFP Local File Permissions
Counters 100 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CM
D3-CM Content Modification
Counters 99 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-NI
D3-NI Network Isolation
Counters 74 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-NTF
D3-NTF Network Traffic Filtering
Counters 74 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-EI
D3-EI Execution Isolation
Counters 62 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-SCF
D3-SCF System Call Filtering
Counters 52 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-EAL
D3-EAL Executable Allowlisting
Counters 51 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-EDL
D3-EDL Executable Denylisting
Counters 51 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-HBPI
D3-HBPI Hardware-based Process Isolation
Counters 36 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-CTS
D3-CTS Credential Transmission Scoping
Counters 19 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-UAP
D3-UAP User Account Permissions
Counters 17 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-ABPI
D3-ABPI Application-based Process Isolation
Counters 15 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-KBPI
D3-KBPI Kernel-based Process Isolation
Counters 14 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-IOPR
D3-IOPR IO Port Restriction
Counters 7 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-DNSAL
D3-DNSAL DNS Allowlisting
Counters 2 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-DNSDL
D3-DNSDL DNS Denylisting
Counters 2 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-DTP
D3-DTP Domain Trust Policy
Counters 1 ATT&CK technique
Tactic: Isolate · Level: technique · Click to inspect
D3-BDI
D3-BDI Broadcast Domain Isolation
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-DNL
D3-DNL Directional Network Link
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-ET
D3-ET Encrypted Tunnels
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-NAM
D3-NAM Network Access Mediation
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-OPR
D3-OPR Operating Mode Restriction
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-OVAR
D3-OVAR OT Variable Access Restriction
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3-PAM
D3-PAM Physical Access Mediation
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
D3F-UGPH
D3F-UGPH User Group Permissions
Counters 0 ATT&CK techniques
Tactic: Isolate · Level: technique · Click to inspect
DECDeceive11 techniques
D3-DO
D3-DO Decoy Object
Counters 124 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DF
D3-DF Decoy File
Counters 99 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DUC
D3-DUC Decoy User Credential
Counters 19 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DNR
D3-DNR Decoy Network Resource
Counters 8 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-CHN
D3-CHN Connected Honeynet
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-DE
D3-DE Decoy Environment
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-IHN
D3-IHN Integrated Honeynet
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-SHN
D3-SHN Standalone Honeynet
Counters 1 ATT&CK technique
Tactic: Deceive · Level: technique · Click to inspect
D3-DP
D3-DP Decoy Persona
Counters 0 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DPR
D3-DPR Decoy Public Release
Counters 0 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect
D3-DST
D3-DST Decoy Session Token
Counters 0 ATT&CK techniques
Tactic: Deceive · Level: technique · Click to inspect