Detectsubtechnique

D3-FCRFile Content Rules

Definition

Employing a pattern matching rule language to analyze the content of files.

Defends against99

TypeTargetConfidenceTier
SubTechniqueThread Execution Hijackingt1055.003100%live
SubTechniquePluggable Authentication Modulest1556.003100%live
TechniqueSteal or Forge Authentication Certificatest1649100%live
TechniqueSystem Owner/User Discoveryt1033100%live
SubTechniqueLaunchdt1053.004100%live
SubTechniqueVBA Stompingt1564.007100%live
SubTechniqueOutlook Formst1137.003100%live
SubTechniqueCredentials from Web Browserst1555.003100%live
SubTechniqueLSASS Drivert1547.008100%live
SubTechniqueRC Scriptst1037.004100%live
SubTechniqueImpair Command History Loggingt1562.003100%live
TechniqueApplication Layer Protocolt1071100%live
SubTechniqueSoftware Packingt1027.002100%live
SubTechniqueRuntime Data Manipulationt1565.003100%live
SubTechniqueCOR_PROFILERt1574.012100%live
SubTechniquePath Interception by Search Order Hijackingt1574.008100%live
SubTechniqueLaunch Agentt1543.001100%live
SubTechniqueLogin Hookt1037.002100%live
TechniqueData from Local Systemt1005100%live
SubTechniqueDylib Hijackingt1574.004100%live
SubTechniquePath Interception by Unquoted Patht1574.009100%live
SubTechniqueVDSO Hijackingt1055.014100%live
SubTechniqueExfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002100%live
SubTechniqueBash Historyt1552.003100%live
TechniqueSoftware Deployment Toolst1072100%live
TechniqueCredentials from Password Storest1555100%live
SubTechniqueEmondt1546.014100%live
SubTechniqueKernel Modules and Extensionst1547.006100%live
SubTechniqueArchive via Custom Methodt1560.003100%live
SubTechniqueTrapt1546.005100%live

Showing top 30 of 99 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
File Content Analysis
Defence
File Content Decompression Checking
Defence
File Hashing
Defence
File Integrity Monitoring
Defence
File Format Verification
Defence
File Access Pattern Analysis
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.