Detecttechnique

D3-FIMFile Integrity Monitoring

File Integrity Monitoring

Definition

Detecting any suspicious changes to files in a computer system.

Defends against99

TypeTargetConfidenceTier
SubTechniqueLocal Data Stagingt1074.001100%live
TechniqueSteal or Forge Authentication Certificatest1649100%live
SubTechniqueMshtat1218.005100%live
SubTechniqueRename System Utilitiest1036.003100%live
TechniqueSystem Network Configuration Discoveryt1016100%live
SubTechniqueWeb Protocolst1071.001100%live
TechniqueData Encrypted for Impactt1486100%live
TechniqueXSL Script Processingt1220100%live
SubTechniqueOffice Template Macrost1137.001100%live
SubTechniqueLaunch Daemont1543.004100%live
SubTechniqueLocal Email Collectiont1114.001100%live
SubTechniqueNetwork Logon Scriptt1037.003100%live
TechniqueData from Local Systemt1005100%live
SubTechniqueRegistry Run Keys / Startup Foldert1547.001100%live
TechniqueArchive Collected Datat1560100%live
SubTechniquePluggable Authentication Modulest1556.003100%live
SubTechniqueCredentials from Web Browserst1555.003100%live
SubTechniquePortable Executable Injectiont1055.002100%live
SubTechniqueWeb Shellt1505.003100%live
SubTechniqueEmondt1546.014100%live
TechniqueExfiltration Over C2 Channelt1041100%live
SubTechniqueAccessibility Featurest1546.008100%live
SubTechniquePlist Modificationt1547.011100%live
SubTechniqueMSBuildt1127.001100%live
SubTechniqueProc Filesystemt1003.007100%live
TechniqueInternal Spearphishingt1534100%live
SubTechniqueVBA Stompingt1564.007100%live
SubTechniqueOutlook Formst1137.003100%live
SubTechniqueSpearphishing Attachmentt1566.001100%live
SubTechniqueRC Scriptst1037.004100%live

Showing top 30 of 99 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
System File Analysis
Defence
File Hashing
Defence
File Content Analysis
Defence
File Content Rules
Defence
File Encryption
Defence
System Daemon Monitoring
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.