Isolatetechnique

D3-EALExecutable Allowlisting

Executable Allowlisting

Definition

Using a digital signature to authenticate a file before opening.

Defends against51

TypeTargetConfidenceTier
SubTechniquePath Interception by Search Order Hijackingt1574.008100%live
SubTechniqueProcess Doppelgängingt1055.013100%live
SubTechniqueImpair Command History Loggingt1562.003100%live
SubTechniqueControl Panelt1218.002100%live
SubTechniqueWeb Shellt1505.003100%live
SubTechniqueAppInit DLLst1546.010100%live
SubTechniqueTrapt1546.005100%live
TechniqueRemote System Discoveryt1018100%live
SubTechniqueParent PID Spoofingt1134.004100%live
TechniqueScheduled Task/Jobt1053100%live
TechniqueWindows Management Instrumentationt1047100%live
SubTechniqueRename System Utilitiest1036.003100%live
SubTechniqueBinary Paddingt1027.001100%live
SubTechniqueSQL Stored Procedurest1505.001100%live
SubTechniqueInvalid Code Signaturet1036.001100%live
TechniqueApplication Window Discoveryt1010100%live
SubTechniqueAsynchronous Procedure Callt1055.004100%live
SubTechniqueShortcut Modificationt1547.009100%live
SubTechniqueSoftware Packingt1027.002100%live
TechniqueSystem Service Discoveryt1007100%live
SubTechniqueComponent Object Model Hijackingt1546.015100%live
SubTechniqueCompile After Deliveryt1027.004100%live
TechniqueCommand and Scripting Interpretert1059100%live
SubTechniquePowerShell Profilet1546.013100%live
TechniqueSystem Information Discoveryt1082100%live
SubTechniqueScreensavert1546.002100%live
SubTechniqueRundll32t1218.011100%live
TechniqueSystem Network Configuration Discoveryt1016100%live
SubTechniqueLC_LOAD_DYLIB Additiont1546.006100%live
SubTechniqueLogon Script (Windows)t1037.001100%live

Showing top 30 of 51 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Executable Denylisting
Defence
File Encryption
Defence
Dynamic Analysis
Defence
Bootloader Authentication
Defence
File Hashing
Defence
Emulated File Analysis
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.