Detecttechnique

D3-DADynamic Analysis

Dynamic Analysis

Definition

Executing or opening a file in a synthetic "sandbox" environment to determine if the file is a malicious program or if the file exploits another program such as a document reader.

Defends against38

TypeTargetConfidenceTier
SubTechniqueSpearphishing Attachmentt1566.001100%live
SubTechniqueInvalid Code Signaturet1036.001100%live
SubTechniqueOutlook Formst1137.003100%live
SubTechniqueMalicious Filet1204.002100%live
SubTechniqueAccessibility Featurest1546.008100%live
SubTechniqueRuntime Data Manipulationt1565.003100%live
SubTechniqueWeb Shellt1505.003100%live
SubTechniqueBinary Paddingt1027.001100%live
SubTechniqueTrapt1546.005100%live
SubTechniqueComponent Object Model Hijackingt1546.015100%live
SubTechniqueLC_LOAD_DYLIB Additiont1546.006100%live
SubTechniqueBypass User Account Controlt1548.002100%live
SubTechniquePath Interception by Unquoted Patht1574.009100%live
SubTechniqueCompile After Deliveryt1027.004100%live
SubTechniqueOffice Template Macrost1137.001100%live
SubTechniqueImpair Command History Loggingt1562.003100%live
SubTechniqueRC Scriptst1037.004100%live
SubTechniquePowerShell Profilet1546.013100%live
SubTechniqueSoftware Packingt1027.002100%live
SubTechniqueRename System Utilitiest1036.003100%live
TechniqueCommand and Scripting Interpretert1059100%live
SubTechniquePath Interception by PATH Environment Variablet1574.007100%live
SubTechniqueRegistry Run Keys / Startup Foldert1547.001100%live
TechniqueXSL Script Processingt1220100%live
SubTechniqueLogin Hookt1037.002100%live
SubTechniqueScreensavert1546.002100%live
SubTechniqueLogon Script (Windows)t1037.001100%live
TechniqueDeobfuscate/Decode Files or Informationt1140100%live
SubTechniqueNetwork Logon Scriptt1037.003100%live
SubTechniqueMshtat1218.005100%live

Showing top 30 of 38 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
File Content Analysis
Defence
Emulated File Analysis
Defence
Script Execution Analysis
Defence
File Access Pattern Analysis
Defence
System File Analysis
Defence
File Hashing
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.