271 indexed

D3FENDD3FEND defensive techniques

271 MITRE D3FEND defences across 7 tactics (Model, Harden, Detect, Isolate, Deceive, Evict, Restore). Filter to a tactic or browse the full set. Authored by Adam Lundqvist.

27 in Model · 271 total

IDTitleSummary
D3-AIAsset Inventory
D3-ALLMActive Logical Link MappingActive logical link mapping sends and receives network traffic as a means to map the whole data link layer, where the links represent logical data flows rather…
D3-AMAccess ModelingAccess modeling captures and records the access permissions granted to identities (e.g., administrators, users, groups, systems) and optionally includes detail…
D3-APLMActive Physical Link MappingActive physical link mapping sends and receives network traffic as a means to map the physical layer.
D3-AVEAsset Vulnerability EnumerationAsset vulnerability enumeration enriches inventory items with knowledge identifying their vulnerabilities.
D3-CIConfiguration InventoryConfiguration inventory identifies and records the configuration of software and hardware and their components throughout the organization.
D3-CIAContainer Image AnalysisAnalyzing a Container Image with respect to a set of policies.
D3-DEMData Exchange MappingData exchange mapping identifies and models the organization's intended design for the flows of the data types, formats, and volumes between systems at the app…
D3-DIData InventoryData inventorying identifies and records the schemas, formats, volumes, and locations of data stored and used on the organization's architecture.
D3-DPLMDirect Physical Link MappingDirect physical link mapping creates a physical link map by direct observation and recording of the physical network links.
D3-HCIHardware Component InventoryHardware component inventorying identifies and records the hardware items in the organization's architecture.
D3-LLMLogical Link MappingLogical link mapping creates a model of existing or previous node-to-node connections using network-layer data or metadata.
D3-NMNetwork Mapping
D3-NNINetwork Node InventoryNetwork node inventorying identifies and records all the network nodes (hosts, routers, switches, firewalls, etc.) in the organization's architecture.
D3-NTPMNetwork Traffic Policy MappingNetwork traffic policy mapping identifies and models the allowed pathways of data at the network, transport, and/or application levels.
D3-NVANetwork Vulnerability AssessmentNetwork vulnerability assessment relates all the vulnerabilities of a network's components in the context of their configuration and interdependencies and can …
D3-OAMOperational Activity Mapping
D3-ODMOperational Dependency MappingOperational dependency mapping identifies and models the dependencies of the organization's activities on each other and on the organization's performers (peop…
D3-OMOrganization MappingOrganization mapping identifies and models the people, roles, and groups with an organization and the relations between them.
D3-ORAOperational Risk AssessmentOperational risk assessment identifies and models the vulnerabilities of, and risks to, an organization's activities individually and as a whole.
D3-PLLMPassive Logical Link MappingPassive logical link mapping only listens to network traffic as a means to map the the whole data link layer, where the links represent logical data flows rath…
D3-PLMPhysical Link MappingPhysical link mapping identifies and models the link connectivity of the network devices within a physical network.
D3-SVCDMService Dependency MappingService dependency mapping determines the services on which each given service relies.
D3-SWISoftware InventorySoftware inventorying identifies and records the software items in the organization's architecture.
D3-SYSDMSystem Dependency MappingSystem dependency mapping identifies and models the dependencies of system components on each other to carry out their function.
D3-SYSMSystem Mapping
D3-SYSVASystem Vulnerability AssessmentSystem vulnerability assessment relates all the vulnerabilities of a system's components in the context of their configuration and internal dependencies and ca…
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, Founder at SQUR.
MITRE D3FEND defensive techniques — by tactic | SQUR Knowledge Base