Detecttechnique

D3-PMPlatform Monitoring

Platform Monitoring

Definition

Defends against138

TypeTargetConfidenceTier
SubTechniqueLaunch Daemont1543.004100%live
SubTechniqueDLL Side-Loadingt1574.002100%live
TechniqueForced Authenticationt1187100%live
SubTechniqueProc Filesystemt1003.007100%live
SubTechniqueOutlook Formst1137.003100%live
SubTechniquePath Interception by Search Order Hijackingt1574.008100%live
TechniqueExploitation for Privilege Escalationt1068100%live
SubTechniqueLaunchdt1053.004100%live
SubTechniqueRundll32t1218.011100%live
SubTechniqueHidden Userst1564.002100%live
SubTechniqueOffice Template Macrost1137.001100%live
SubTechniquePlist Modificationt1547.011100%live
SubTechniqueWindows Management Instrumentation Event Subscriptiont1546.003100%live
SubTechniqueMshtat1218.005100%live
SubTechniqueDLL Search Order Hijackingt1574.001100%live
SubTechniqueShortcut Modificationt1547.009100%live
SubTechniqueInvalid Code Signaturet1036.001100%live
TechniqueRemote System Discoveryt1018100%live
SubTechniquePath Interception by Unquoted Patht1574.009100%live
SubTechniqueClear Command Historyt1070.003100%live
SubTechniqueRemote Email Collectiont1114.002100%live
SubTechniqueKeyloggingt1056.001100%live
TechniqueFile and Directory Discoveryt1083100%live
SubTechniqueSoftware Packingt1027.002100%live
SubTechniquePortable Executable Injectiont1055.002100%live
TechniqueArchive Collected Datat1560100%live
TechniqueCommand and Scripting Interpretert1059100%live
SubTechniqueWeb Portal Capturet1056.003100%live
SubTechniqueRevert Cloud Instancet1578.004100%live
SubTechniqueCredential API Hookingt1056.004100%live

Showing top 30 of 138 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
Platform Hardening
Defence
Network Mapping
Defence
Operational Activity Mapping
Defence
Application Hardening
Defence
Process Analysis
Defence
Physical Access Monitoring
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.