271 indexed

D3FENDD3FEND defensive techniques

271 MITRE D3FEND defences across 7 tactics (Model, Harden, Detect, Isolate, Deceive, Evict, Restore). Filter to a tactic or browse the full set. Authored by Adam Lundqvist.

57 in Isolate · 271 total

IDTitleSummary
D3-ABPIApplication-based Process IsolationApplication code which prevents its own subroutines from accessing intra-process / internal memory space.
D3-AMEDAccess Mediation
D3-APAAccess Policy Administration
D3-BDIBroadcast Domain IsolationBroadcast isolation restricts the number of computers a host can contact on their LAN.
D3-CFContent Filtering
D3-CFCContent Format ConversionContent format conversion is mechanical transformation from one format to another which may be normalization or specifically flattening.
D3-CMContent ModificationModify content that does not comply with policy.
D3-CNEContent ExcisionRemoving specific, potentially malicious, parts of content
D3-CNRContent RebuildRebuild the file according to the spec so any unreferenced components or objects are removed.
D3-CNSContent SubstitutionModifies specific digital content information by replacing it with something else.
D3-CQContent QuarantineTransfer content that does not comply with policy to a quarantine zone.
D3-CTSCredential Transmission ScopingLimiting the transmission of a credential to a scoped set of relying parties.
D3-CVContent ValidationVerify and validate contents complies with policy
D3-DNLDirectional Network LinkEnforce one-way network communication by preventing two-way communication.
D3-DNSALDNS AllowlistingPermitting only approved domains and their subdomains to be resolved.
D3-DNSDLDNS DenylistingBlocking DNS Network Traffic based on criteria such as IP address, domain name, or DNS query type.
D3-DTPDomain Trust PolicyRestricting inter-domain trust by modifying domain configuration.
D3-EALExecutable AllowlistingUsing a digital signature to authenticate a file before opening.
D3-EBWSAMEndpoint-based Web Server Access MediationEndpoint-based web server access mediation regulates web server access directly from user endpoints by implementing mechanisms such as client-side certificates…
D3-EDLExecutable DenylistingBlocking the execution of files on a host in accordance with defined application policy rules.
D3-EFEmail FilteringFiltering incoming email traffic based on specific criteria.
D3-EIExecution Isolation
D3-EPLPhysical LockingEmploy a mechanical locking device for securing moveable portions of physical barriers (e.g., doors, gates, drawers) in a secured position.
D3-ETEncrypted TunnelsEncrypted encapsulation of routable network traffic.
D3-FCDCFile Content Decompression CheckingChecking if compressed or encoded data sections can be successfully decompressed or decoded. Can follow with further analysis with semantic knowledge
D3-FFVFile Format VerificationVerifying that a file conforms to its expected format specifications
D3-FISVFile Internal Structure VerificationThe process of checking specific static values within a file, such as file signatures or magic numbers, to ensure they match the expected values defined by the…
D3-FMBVFile Magic Byte VerificationUtilizing the magic number to verify the file
D3-FMCVFile Metadata Consistency ValidationThe process of validating the consistency between a file's metadata and its actual content, ensuring that elements like declared lengths, pointers, and checksu…
D3-FMVVFile Metadata Value VerificationThe process of checking specific static values within a file, such as file signatures or magic numbers, to ensure they match the expected values defined by the…
D3-FRDDLForward Resolution Domain DenylistingBlocking a lookup based on the query's domain name value.
D3-FRIDLForward Resolution IP DenylistingBlocking a DNS lookup's answer's IP address value.
D3-HBPIHardware-based Process IsolationPreventing one process from writing to the memory space of another process through hardware based address manager implementations.
D3-HDDLHierarchical Domain DenylistingBlocking the resolution of any subdomain of a specified domain name.
D3-HDLHomoglyph DenylistingBlocking DNS queries that are deceptively similar to legitimate domain names.
D3-IOPRIO Port RestrictionLimiting access to computer input/output (IO) ports to restrict unauthorized devices.
D3-ITFInbound Traffic FilteringRestricting network traffic originating from untrusted networks destined towards a private host or enclave.
D3-KBPIKernel-based Process IsolationUsing kernel-level capabilities to isolate processes.
D3-LAMEDLAN Access MediationLAN access mediation encompasses the application of strict access control policies, systematic verification of devices, and authentication mechanisms to govern…
D3-LFAMLocal File Access MediationLocal file access mediation is the process of an operating system granting or denying a specific access request to a local file.
D3-LFPLocal File PermissionsLocal file permissions is the systematic process of defining, implementing, and managing access control policies that dictate user permissions for accessing fi…
D3-NAMNetwork Access MediationNetwork access mediation is the control method for authorizing access to a system by a user (or a process acting on behalf of a user) communicating through a n…
D3-NINetwork Isolation
D3-NRAMNetwork Resource Access MediationControl of access to organizational systems and services by users or processes over a network.
D3-NTFNetwork Traffic FilteringRestricting network traffic originating from any location.
D3-OPROperating Mode RestrictionRestricting unauthorized changes to the operating mode prevents devices from switching into inappropriate or vulnerable states during normal use.
D3-OTFOutbound Traffic FilteringRestricting network traffic originating from a private host or enclave destined towards untrusted networks.
D3-OVAROT Variable Access RestrictionAssign read/write access controls on designated registers or data tags to prevent unauthorized writes.
D3-PAMPhysical Access MediationPhysical access mediation is the process of granting or denying specific requests to enter specific physical facilities (e.g., Federal buildings, military esta…
D3-PBWSAMProxy-based Web Server Access MediationProxy-based web server access mediation focuses on the regulation of web server access through intermediary proxy servers.
D3-RAMRouting Access MediationRouting access mediation is a network security approach that manages and controls access at the network layer using VPNs, tunneling protocols, firewall rules, …
D3-RFAMRemote File Access MediationRemote file access mediation is the process of managing and securing access to file systems over a network to ensure that only authorized users or processes ca…
D3-RRIDReverse Resolution IP DenylistingBlocking a reverse lookup based on the query's IP address value.
D3-SCFSystem Call FilteringControlling access to local computer system resources with kernel-level capabilities.
D3-UAPUser Account PermissionsRestricting a user account's access to resources.
D3-WSAMWeb Session Access MediationWeb session access mediation secures user sessions in web applications by employing robust authentication and integrity validation, along with adaptive threat …
D3F-UGPHUser Group PermissionsAccess control where access is determined based on attributes associated with users and the objects being accessed.
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, Founder at SQUR.
MITRE D3FEND defensive techniques — by tactic | SQUR Knowledge Base