Deceivetechnique

D3-DODecoy Object

Decoy Object

Definition

Defends against124

TypeTargetConfidenceTier
SubTechniquePassword Guessingt1110.001100%live
SubTechniqueKernel Modules and Extensionst1547.006100%live
SubTechniqueDynamic-link Library Injectiont1055.001100%live
SubTechniqueRundll32t1218.011100%live
SubTechniqueCredentials In Filest1552.001100%live
SubTechniqueApplication Access Tokent1550.001100%live
SubTechniqueDLL Side-Loadingt1574.002100%live
SubTechniqueGolden Tickett1558.001100%live
TechniqueRootkitt1014100%live
SubTechniqueCredentials from Web Browserst1555.003100%live
SubTechniqueOffice Template Macrost1137.001100%live
SubTechniqueVDSO Hijackingt1055.014100%live
SubTechniqueShortcut Modificationt1547.009100%live
SubTechniqueMatch Legitimate Name or Locationt1036.005100%live
SubTechniquePassword Crackingt1110.002100%live
SubTechniqueLogin Hookt1037.002100%live
SubTechniqueNetwork Logon Scriptt1037.003100%live
SubTechniqueRun Virtual Instancet1564.006100%live
SubTechniqueSharepointt1213.002100%live
TechniqueSteal Web Session Cookiet1539100%live
SubTechniqueCreate Process with Tokent1134.002100%live
SubTechniqueHidden Userst1564.002100%live
SubTechniqueArchive via Custom Methodt1560.003100%live
TechniqueSteal or Forge Authentication Certificatest1649100%live
SubTechniqueWeb Session Cookiet1550.004100%live
TechniqueDeobfuscate/Decode Files or Informationt1140100%live
SubTechniqueSpace after Filenamet1036.006100%live
SubTechniqueAppCert DLLst1546.009100%live
TechniqueCommand and Scripting Interpretert1059100%live
SubTechniqueSpearphishing Linkt1566.002100%live

Showing top 30 of 124 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Decoy Environment
Defence
Restore Object
Defence
Object Eviction
Defence
Asset Inventory
Defence
Platform Monitoring
Defence
Application Hardening
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.