Detectsubtechnique
D3-SFASystem File Analysis
Definition
Monitoring system files such as authentication databases, configuration files, system logs, and system executables for modification or tampering.
Defends against16
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | Proc Memoryt1055.009 | 100% | live |
| SubTechnique | Dynamic Linker Hijackingt1574.006 | 100% | live |
| Technique | Exploitation for Credential Accesst1212 | 100% | live |
| SubTechnique | Pluggable Authentication Modulest1556.003 | 100% | live |
| Technique | Steal or Forge Authentication Certificatest1649 | 100% | live |
| SubTechnique | Sudo and Sudo Cachingt1548.003 | 100% | live |
| SubTechnique | Rename System Utilitiest1036.003 | 100% | live |
| Technique | Software Deployment Toolst1072 | 100% | live |
| SubTechnique | Proc Filesystemt1003.007 | 100% | live |
| SubTechnique | Run Virtual Instancet1564.006 | 100% | live |
| SubTechnique | Executable Installer File Permissions Weaknesst1574.005 | 100% | live |
| Technique | Remote System Discoveryt1018 | 100% | live |
| SubTechnique | Clear Linux or Mac System Logst1070.002 | 100% | live |
| SubTechnique | Services File Permissions Weaknesst1574.010 | 100% | live |
| SubTechnique | Web Portal Capturet1056.003 | 100% | live |
| SubTechnique | Systemd Servicet1543.002 | 100% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.