Isolatetechnique

D3-EDLExecutable Denylisting

Executable Denylisting

Definition

Blocking the execution of files on a host in accordance with defined application policy rules.

Defends against51

TypeTargetConfidenceTier
TechniqueSystem Service Discoveryt1007100%live
SubTechniquePowerShell Profilet1546.013100%live
SubTechniqueMalicious Filet1204.002100%live
SubTechniqueSQL Stored Procedurest1505.001100%live
SubTechniqueRename System Utilitiest1036.003100%live
TechniqueCommand and Scripting Interpretert1059100%live
SubTechniqueProcess Doppelgängingt1055.013100%live
SubTechniqueLC_LOAD_DYLIB Additiont1546.006100%live
TechniqueRemote System Discoveryt1018100%live
SubTechniqueAccessibility Featurest1546.008100%live
SubTechniqueOffice Template Macrost1137.001100%live
TechniqueSystem Information Discoveryt1082100%live
SubTechniqueNetwork Logon Scriptt1037.003100%live
SubTechniqueRC Scriptst1037.004100%live
SubTechniqueMshtat1218.005100%live
SubTechniqueInvalid Code Signaturet1036.001100%live
SubTechniqueParent PID Spoofingt1134.004100%live
TechniqueProcess Discoveryt1057100%live
SubTechniqueControl Panelt1218.002100%live
SubTechniqueThread Execution Hijackingt1055.003100%live
TechniqueSystem Network Configuration Discoveryt1016100%live
SubTechniqueCompiled HTML Filet1218.001100%live
SubTechniqueComponent Object Model Hijackingt1546.015100%live
SubTechniqueImpair Command History Loggingt1562.003100%live
TechniqueWindows Management Instrumentationt1047100%live
SubTechniquePath Interception by Search Order Hijackingt1574.008100%live
TechniqueScheduled Task/Jobt1053100%live
SubTechniqueCMSTPt1218.003100%live
SubTechniqueScreensavert1546.002100%live
TechniqueDeobfuscate/Decode Files or Informationt1140100%live

Showing top 30 of 51 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Executable Allowlisting
Defence
DNS Denylisting
Defence
Hierarchical Domain Denylisting
Defence
Email Filtering
Defence
Script Execution Analysis
Defence
File Encryption
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.