Detecttechnique

D3-OSMOperating System Monitoring

Operating System Monitoring

Definition

The operating system software, for D3FEND's purposes, includes the kernel and its process management functions, hardware drivers, initialization or boot logic. It also includes and other key system daemons and their configuration. The monitoring or analysis of these components for unauthorized activity constitute **Operating System Monitoring**.

Defends against43

TypeTargetConfidenceTier
SubTechniquePluggable Authentication Modulest1556.003100%live
TechniqueRemote System Discoveryt1018100%live
SubTechniqueScheduled Taskt1053.005100%live
SubTechniqueProc Filesystemt1003.007100%live
SubTechniqueTransport Agentt1505.002100%live
SubTechniqueRegistry Run Keys / Startup Foldert1547.001100%live
SubTechniqueSudo and Sudo Cachingt1548.003100%live
TechniqueAudio Capturet1123100%live
SubTechniqueProcess Hollowingt1055.012100%live
TechniqueScheduled Task/Jobt1053100%live
SubTechniqueHidden Userst1564.002100%live
SubTechniqueDynamic Linker Hijackingt1574.006100%live
TechniqueSteal or Forge Authentication Certificatest1649100%live
SubTechniqueServices Registry Permissions Weaknesst1574.011100%live
SubTechniqueProc Memoryt1055.009100%live
SubTechniqueStartup Itemst1037.005100%live
TechniqueVideo Capturet1125100%live
SubTechniqueRevert Cloud Instancet1578.004100%live
TechniqueExploitation for Client Executiont1203100%live
SubTechniqueCreate Cloud Instancet1578.002100%live
SubTechniqueSystemd Servicet1543.002100%live
SubTechniqueDelete Cloud Instancet1578.003100%live
SubTechniqueMasquerade Task or Servicet1036.004100%live
SubTechniqueSafe Mode Boott1562.009100%live
SubTechniqueRun Virtual Instancet1564.006100%live
TechniqueExploitation for Privilege Escalationt1068100%live
SubTechniqueCredential API Hookingt1056.004100%live
SubTechniqueKeyloggingt1056.001100%live
SubTechniqueRC Scriptst1037.004100%live
SubTechniqueUnix Shell Configuration Modificationt1546.004100%live

Showing top 30 of 43 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
System Daemon Monitoring
Defence
Operational Process Monitoring
Defence
System File Analysis
Defence
System Call Filtering
Defence
System Call Analysis
Defence
System Dependency Mapping
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.