Isolatetechnique
D3-SCFSystem Call Filtering
System Call Filtering
Definition
Controlling access to local computer system resources with kernel-level capabilities.
Defends against52
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Security Software Discoveryt1518.001 | 100% | live |
| SubTechnique | Disable or Modify Toolst1562.001 | 100% | live |
| Technique | Multi-Factor Authentication Request Generationt1621 | 100% | live |
| Technique | Query Registryt1012 | 100% | live |
| Technique | Windows Management Instrumentationt1047 | 100% | live |
| SubTechnique | Control Panelt1218.002 | 100% | live |
| SubTechnique | Mshtat1218.005 | 100% | live |
| Technique | System Service Discoveryt1007 | 100% | live |
| SubTechnique | Mavinjectt1218.013 | 100% | live |
| SubTechnique | Security Account Managert1003.002 | 100% | live |
| Technique | Native APIt1106 | 100% | live |
| Technique | System Information Discoveryt1082 | 100% | live |
| SubTechnique | Compiled HTML Filet1218.001 | 100% | live |
| Technique | Modify Authentication Processt1556 | 100% | live |
| SubTechnique | AppInit DLLst1546.010 | 100% | live |
| SubTechnique | Credentials from Web Browserst1555.003 | 100% | live |
| Technique | Deobfuscate/Decode Files or Informationt1140 | 100% | live |
| SubTechnique | Transport Agentt1505.002 | 100% | live |
| SubTechnique | Elevated Execution with Promptt1548.004 | 100% | live |
| Technique | Scheduled Task/Jobt1053 | 100% | live |
| SubTechnique | Web Shellt1505.003 | 100% | live |
| SubTechnique | Thread Execution Hijackingt1055.003 | 100% | live |
| SubTechnique | Ptrace System Callst1055.008 | 100% | live |
| SubTechnique | Match Legitimate Name or Locationt1036.005 | 100% | live |
| Technique | System Network Connections Discoveryt1049 | 100% | live |
| SubTechnique | LSASS Memoryt1003.001 | 100% | live |
| Technique | System Owner/User Discoveryt1033 | 100% | live |
| SubTechnique | Thread Local Storaget1055.005 | 100% | live |
| SubTechnique | AppCert DLLst1546.009 | 100% | live |
| Technique | Exploitation for Credential Accesst1212 | 100% | live |
Showing top 30 of 52 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.