Isolatesubtechnique
D3-FMCVFile Metadata Consistency Validation
Definition
The process of validating the consistency between a file's metadata and its actual content, ensuring that elements like declared lengths, pointers, and checksums accurately describe the file's content.
Defends against99
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Local Data Stagingt1074.001 | 100% | live |
| SubTechnique | Web Protocolst1071.001 | 100% | live |
| SubTechnique | Accessibility Featurest1546.008 | 100% | live |
| Technique | Internal Spearphishingt1534 | 100% | live |
| SubTechnique | Dynamic Linker Hijackingt1574.006 | 100% | live |
| SubTechnique | PowerShell Profilet1546.013 | 100% | live |
| SubTechnique | Proc Filesystemt1003.007 | 100% | live |
| SubTechnique | Portable Executable Injectiont1055.002 | 100% | live |
| SubTechnique | Mshtat1218.005 | 100% | live |
| SubTechnique | Kernel Modules and Extensionst1547.006 | 100% | live |
| SubTechnique | Clear Linux or Mac System Logst1070.002 | 100% | live |
| SubTechnique | Proc Memoryt1055.009 | 100% | live |
| SubTechnique | Bypass User Account Controlt1548.002 | 100% | live |
| SubTechnique | Bash Historyt1552.003 | 100% | live |
| SubTechnique | Binary Paddingt1027.001 | 100% | live |
| Technique | Deobfuscate/Decode Files or Informationt1140 | 100% | live |
| SubTechnique | Dylib Hijackingt1574.004 | 100% | live |
| SubTechnique | Systemd Servicet1543.002 | 100% | live |
| SubTechnique | Asymmetric Cryptographyt1573.002 | 100% | live |
| SubTechnique | Rundll32t1218.011 | 100% | live |
| SubTechnique | Emondt1546.014 | 100% | live |
| Technique | Software Deployment Toolst1072 | 100% | live |
| SubTechnique | Archive via Custom Methodt1560.003 | 100% | live |
| SubTechnique | Archive via Utilityt1560.001 | 100% | live |
| SubTechnique | Archive via Libraryt1560.002 | 100% | live |
| SubTechnique | Launch Daemont1543.004 | 100% | live |
| SubTechnique | DLL Side-Loadingt1574.002 | 100% | live |
| SubTechnique | LC_LOAD_DYLIB Additiont1546.006 | 100% | live |
| SubTechnique | Dynamic-link Library Injectiont1055.001 | 100% | live |
| Technique | Application Layer Protocolt1071 | 100% | live |
Showing top 30 of 99 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.