271 defences1,851 crosswalks

D3FENDD3FEND defensive matrix

7 tactics · 271 defensive techniques · 1,851 defends_against crosswalks to MITRE ATT&CK. Authored by Adam Lundqvist.

TACTICModelHardenDetectIsolateDeceiveEvictRestoreLEVELTechniqueSub-technique
ATT&CK coverage
0
1
2-3
4-5
6+

MODModel0 techniques

HARHarden0 techniques

DETDetect0 techniques

ISOIsolate31 techniques

D3-AMED
Access Mediation
D3-APA
Access Policy Administration
D3-CF
Content Filtering
D3-NRAM
Network Resource Access Mediation
D3-CQ
Content Quarantine
D3-CV
Content Validation
D3-LFP
Local File Permissions
D3-CM
Content Modification
D3-NI
Network Isolation
D3-NTF
Network Traffic Filtering
D3-EI
Execution Isolation
D3-SCF
System Call Filtering
D3-EAL
Executable Allowlisting
D3-EDL
Executable Denylisting
D3-HBPI
Hardware-based Process Isolation
D3-CTS
Credential Transmission Scoping
D3-UAP
User Account Permissions
D3-ABPI
Application-based Process Isolation
D3-KBPI
Kernel-based Process Isolation
D3-IOPR
IO Port Restriction
D3-DNSAL
DNS Allowlisting
D3-DNSDL
DNS Denylisting
D3-DTP
Domain Trust Policy
D3-BDI
Broadcast Domain Isolation
D3-DNL
Directional Network Link
D3-ET
Encrypted Tunnels
D3-NAM
Network Access Mediation
D3-OPR
Operating Mode Restriction
D3-OVAR
OT Variable Access Restriction
D3-PAM
Physical Access Mediation
D3F-UGPH
User Group Permissions

DECDeceive0 techniques

EVIEvict0 techniques

RESRestore10 techniques

D3-RO
Restore Object
D3-RF
Restore File
D3-RC
Restore Configuration
D3-RA
Restore Access
D3-RS
Restore Software
D3-RD
Restore Database
D3-RIC
Reissue Credential
D3-RUAA
Restore User Account Access
D3-RNA
Restore Network Access
D3-RDI
Restore Disk Image
Sourced from MITRE D3FEND ontology. Cross-walks ingested via the D3FEND CSV feed. Curated by Adam Lundqvist, Founder at SQUR.
D3FEND defensive matrix | SQUR Knowledge Base