Isolatesubtechnique

D3-FFVFile Format Verification

Definition

Verifying that a file conforms to its expected format specifications

Defends against100

TypeTargetConfidenceTier
SubTechniqueRename System Utilitiest1036.003100%live
SubTechniqueHidden Userst1564.002100%live
SubTechniqueCredentials In Filest1552.001100%live
SubTechniqueComponent Object Model Hijackingt1546.015100%live
SubTechniqueSpearphishing via Servicet1566.003100%live
SubTechniqueAppCert DLLst1546.009100%live
SubTechniqueMSBuildt1127.001100%live
SubTechniqueThread Execution Hijackingt1055.003100%live
SubTechniqueProc Memoryt1055.009100%live
SubTechniqueKernel Modules and Extensionst1547.006100%live
SubTechniqueDLL Search Order Hijackingt1574.001100%live
SubTechniqueNetwork Logon Scriptt1037.003100%live
SubTechniqueStored Data Manipulationt1565.001100%live
SubTechniqueSpace after Filenamet1036.006100%live
SubTechniqueImpair Command History Loggingt1562.003100%live
SubTechniqueLogin Hookt1037.002100%live
SubTechniqueSpearphishing Attachmentt1566.001100%live
TechniqueExfiltration Over C2 Channelt1041100%live
SubTechniqueSudo and Sudo Cachingt1548.003100%live
SubTechniqueLocal Data Stagingt1074.001100%live
SubTechniqueScreensavert1546.002100%live
SubTechniqueRC Scriptst1037.004100%live
SubTechniqueFile Deletiont1070.004100%live
SubTechniqueArchive via Utilityt1560.001100%live
SubTechniqueAsymmetric Cryptographyt1573.002100%live
TechniqueApplication Layer Protocolt1071100%live
SubTechniqueRegistry Run Keys / Startup Foldert1547.001100%live
SubTechniqueLaunch Agentt1543.001100%live
SubTechniqueLaunchdt1053.004100%live
SubTechniqueDylib Hijackingt1574.004100%live

Showing top 30 of 100 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
File Metadata Value Verification
Defence
File Internal Structure Verification
Defence
File Magic Byte Verification
Defence
File Metadata Consistency Validation
Defence
Content Validation
Defence
File Content Decompression Checking
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.