Detecttechnique

D3-FAFile Analysis

File Analysis

Definition

Defends against99

TypeTargetConfidenceTier
SubTechniqueRun Virtual Instancet1564.006100%live
SubTechniqueCredentials In Filest1552.001100%live
SubTechniqueVBA Stompingt1564.007100%live
TechniqueDeobfuscate/Decode Files or Informationt1140100%live
SubTechniqueDynamic-link Library Injectiont1055.001100%live
SubTechniqueScreensavert1546.002100%live
SubTechniquePassword Filter DLLt1556.002100%live
SubTechniqueNetwork Logon Scriptt1037.003100%live
SubTechniqueLaunch Daemont1543.004100%live
SubTechniqueOutlook Formst1137.003100%live
SubTechniqueSpearphishing Attachmentt1566.001100%live
SubTechniqueRuntime Data Manipulationt1565.003100%live
SubTechniqueLocal Data Stagingt1074.001100%live
SubTechniqueClear Linux or Mac System Logst1070.002100%live
SubTechniqueSoftware Packingt1027.002100%live
TechniqueApplication Layer Protocolt1071100%live
SubTechniqueWeb Protocolst1071.001100%live
TechniqueRootkitt1014100%live
SubTechniquePortable Executable Injectiont1055.002100%live
SubTechniqueArchive via Utilityt1560.001100%live
TechniqueExfiltration Over C2 Channelt1041100%live
SubTechniqueLogin Hookt1037.002100%live
TechniqueXSL Script Processingt1220100%live
TechniqueFile and Directory Discoveryt1083100%live
SubTechniqueSystemd Servicet1543.002100%live
SubTechnique/etc/passwd and /etc/shadowt1003.008100%live
SubTechniqueTrapt1546.005100%live
SubTechniqueAppInit DLLst1546.010100%live
SubTechniqueStored Data Manipulationt1565.001100%live
SubTechniquePath Interception by Search Order Hijackingt1574.008100%live

Showing top 30 of 99 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Identifier Analysis
Defence
Process Analysis
Defence
Content Filtering
Defence
System Mapping
Defence
Network Mapping
Defence
Application Hardening
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.