Isolatetechnique

D3-CQContent Quarantine

Content Quarantine

Definition

Transfer content that does not comply with policy to a quarantine zone.

Defends against112

TypeTargetConfidenceTier
SubTechniquePort Monitorst1547.010100%live
SubTechniqueRegistry Run Keys / Startup Foldert1547.001100%live
SubTechniqueCredentials In Filest1552.001100%live
SubTechniqueShortcut Modificationt1547.009100%live
TechniqueXSL Script Processingt1220100%live
SubTechniqueArchive via Custom Methodt1560.003100%live
SubTechniquePortable Executable Injectiont1055.002100%live
SubTechniqueBinary Paddingt1027.001100%live
SubTechniqueOffice Testt1137.002100%live
TechniqueRootkitt1014100%live
SubTechniqueDLL Search Order Hijackingt1574.001100%live
SubTechniqueLocal Data Stagingt1074.001100%live
SubTechniqueLC_LOAD_DYLIB Additiont1546.006100%live
SubTechniqueOutlook Formst1137.003100%live
SubTechniqueMatch Legitimate Name or Locationt1036.005100%live
TechniqueFile and Directory Discoveryt1083100%live
SubTechniqueServices Registry Permissions Weaknesst1574.011100%live
SubTechniqueWeb Protocolst1071.001100%live
SubTechniqueNetsh Helper DLLt1546.007100%live
SubTechniqueInvalid Code Signaturet1036.001100%live
SubTechniqueLaunch Daemont1543.004100%live
SubTechniqueMalicious Filet1204.002100%live
SubTechniqueLSASS Drivert1547.008100%live
SubTechniqueSoftware Packingt1027.002100%live
SubTechniqueControl Panelt1218.002100%live
SubTechniqueLaunchdt1053.004100%live
SubTechniqueTime Providerst1547.003100%live
SubTechniqueDynamic Linker Hijackingt1574.006100%live
SubTechniqueRundll32t1218.011100%live
SubTechniqueMSBuildt1127.001100%live

Showing top 30 of 112 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Content Modification
Defence
Content Validation
Defence
Content Excision
Defence
Email Filtering
Defence
Content Substitution
Defence
Network Traffic Filtering
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.