Isolatesubtechnique

D3-CNEContent Excision

Definition

Removing specific, potentially malicious, parts of content

Defends against99

TypeTargetConfidenceTier
SubTechniqueHidden Windowt1564.003100%live
TechniqueFile and Directory Discoveryt1083100%live
SubTechniqueCredentials In Filest1552.001100%live
SubTechniqueSpace after Filenamet1036.006100%live
SubTechniqueMshtat1218.005100%live
SubTechniqueRun Virtual Instancet1564.006100%live
SubTechniqueArchive via Utilityt1560.001100%live
TechniqueRootkitt1014100%live
SubTechniqueAccessibility Featurest1546.008100%live
SubTechniqueUnix Shell Configuration Modificationt1546.004100%live
SubTechnique/etc/passwd and /etc/shadowt1003.008100%live
SubTechniqueImpair Command History Loggingt1562.003100%live
SubTechniqueThread Execution Hijackingt1055.003100%live
SubTechniqueExfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002100%live
TechniqueForced Authenticationt1187100%live
SubTechniqueOffice Template Macrost1137.001100%live
TechniqueXSL Script Processingt1220100%live
SubTechniqueLaunchdt1053.004100%live
TechniqueSteal or Forge Authentication Certificatest1649100%live
SubTechniqueBinary Paddingt1027.001100%live
SubTechniqueLogon Script (Windows)t1037.001100%live
SubTechniqueProc Memoryt1055.009100%live
SubTechniqueSystemd Servicet1543.002100%live
SubTechniquePath Interception by Unquoted Patht1574.009100%live
SubTechniqueClear Linux or Mac System Logst1070.002100%live
TechniqueDeobfuscate/Decode Files or Informationt1140100%live
SubTechniqueCOR_PROFILERt1574.012100%live
SubTechniqueWeb Protocolst1071.001100%live
TechniqueCredentials from Password Storest1555100%live
SubTechniqueDLL Search Order Hijackingt1574.001100%live

Showing top 30 of 99 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Content Substitution
Defence
Content Rebuild
Defence
Content Quarantine
Defence
Content Validation
Defence
File Eviction
Defence
File Content Decompression Checking
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.