Isolatesubtechnique

D3-FMVVFile Metadata Value Verification

Definition

The process of checking specific static values within a file, such as file signatures or magic numbers, to ensure they match the expected values defined by the file format specification.

Defends against99

TypeTargetConfidenceTier
SubTechniqueOffice Template Macrost1137.001100%live
SubTechniqueArchive via Utilityt1560.001100%live
SubTechniqueProc Memoryt1055.009100%live
SubTechniqueArchive via Libraryt1560.002100%live
SubTechniqueMSBuildt1127.001100%live
SubTechniqueCredentials In Filest1552.001100%live
SubTechniqueCredentials from Web Browserst1555.003100%live
SubTechniqueSoftware Packingt1027.002100%live
SubTechniqueRC Scriptst1037.004100%live
SubTechniquePassword Filter DLLt1556.002100%live
SubTechniqueDynamic Linker Hijackingt1574.006100%live
SubTechniqueOutlook Formst1137.003100%live
SubTechniqueThread Execution Hijackingt1055.003100%live
TechniqueCredentials from Password Storest1555100%live
SubTechniqueBinary Paddingt1027.001100%live
SubTechniqueRun Virtual Instancet1564.006100%live
SubTechniqueExfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002100%live
SubTechniqueSpearphishing via Servicet1566.003100%live
TechniqueSteal or Forge Authentication Certificatest1649100%live
SubTechniqueNetwork Logon Scriptt1037.003100%live
SubTechniqueCompile After Deliveryt1027.004100%live
SubTechniqueLSASS Drivert1547.008100%live
SubTechniqueSpace after Filenamet1036.006100%live
SubTechniqueBash Historyt1552.003100%live
SubTechniqueTrapt1546.005100%live
SubTechniqueSpearphishing Attachmentt1566.001100%live
SubTechniqueScreensavert1546.002100%live
SubTechniqueAppCert DLLst1546.009100%live
SubTechniqueLocal Email Collectiont1114.001100%live
SubTechniquePowerShell Profilet1546.013100%live

Showing top 30 of 99 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
File Internal Structure Verification
Defence
File Metadata Consistency Validation
Defence
File Format Verification
Defence
File Magic Byte Verification
Defence
Firmware Verification
Defence
File Content Decompression Checking
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.