D3FEND 防御知识库
技术列表 · 只读官方知识数据
D3FEND 标识技术名称战术父技术子技术ATT&CK
D3-AMEDAccess MediationAccess mediation is the process of granting or denying specific requests to: 1) obtain and use information and related information processing services; and 2) enter specific physical facilities (e.g., Federal buildings, military establishments, border crossing entrances). Access mediation decisions should enforce least privilege by granting access for scoped durations to prevent privilege creep and, where applicable, implement just-in-time (JIT) access. Denial decisions may prevent initial access or terminate access that has already been granted, ensuring continuous enforcement of security policies.Isolate--80D3-AMAccess ModelingAccess modeling captures and records the access permissions granted to identities (e.g., administrators, users, groups, systems) and optionally includes details on how these identities are stored, managed, and shared across systems.ModelOperationalActivityMapping027D3-APAAccess Policy AdministrationAccess policy administration is the systematic process of defining, implementing, and managing access control policies that dictate user permissions to resources.Isolate--40D3-ALAccount LockingThe process of temporarily disabling user accounts on a system or domain.EvictCredentialEviction019D3-ACAActive Certificate AnalysisActively collecting PKI certificates by connecting to the server and downloading its server certificates for analysis.DetectCertificateAnalysis00D3-ALLMActive Logical Link MappingActive logical link mapping sends and receives network traffic as a means to map the whole data link layer, where the links represent logical data flows rather than physical connectionModelLogicalLinkMapping00D3-APLMActive Physical Link MappingActive physical link mapping sends and receives network traffic as a means to map the physical layer.ModelPhysicalLinkMapping00D3-ANAAAdministrative Network Activity AnalysisDetection of unauthorized use of administrative network protocols by analyzing network activity against a baseline.DetectNetworkTrafficAnalysis08D3-AAAgent AuthenticationAgent authentication is the process of verifying the identities of agents to ensure they are authorized and trustworthy participants within a system.Harden--519D3-ACHApplication Configuration HardeningModifying an application's configuration to reduce its attack surface.HardenApplicationHardening110D3-AEMApplication Exception MonitoringMonitoring the failures of system counters and timers.DetectApplicationPerformanceMonitoring016D3-AHApplication HardeningApplication Hardening makes an executable application more resilient to a class of exploits which either introduce new code or execute unwanted existing code. These techniques may be applied at compile-time or on an application binary.Harden--80D3-APMApplication Performance MonitoringMonitoring the count and duration of the application or program cycle.DetectPlatformMonitoring10D3-APCAApplication Protocol Command AnalysisAnalyzing application protocol level remote commands to detect unauthorized activity.DetectNetworkTrafficAnalysis190D3-ABPIApplication-based Process IsolationApplication code which prevents its own subroutines from accessing intra-process / internal memory space.IsolateExecutionIsolation023D3-AIAsset InventoryAsset inventorying identifies and records the organization's assets and enriches each inventory item with knowledge about their vulnerabilities.Model--60D3-AVEAsset Vulnerability EnumerationAsset vulnerability enumeration enriches inventory items with knowledge identifying their vulnerabilities.ModelAssetInventory145D3-ANCIAuthentication Cache InvalidationRemoving tokens or credentials from an authentication cache to prevent further user associated account accesses.EvictCredentialEviction025D3-ANETAuthentication Event ThresholdingCollecting authentication events, creating a baseline user profile, and determining whether authentication events are consistent with the baseline profile.DetectUserBehaviorAnalysis00D3-AZETAuthorization Event ThresholdingCollecting authorization events, creating a baseline user profile, and determining whether authorization events are consistent with the baseline profile.DetectUserBehaviorAnalysis00D3-BANBiometric AuthenticationUsing biological measures in order to authenticate a user.HardenAgentAuthentication00D3-BABootloader AuthenticationCryptographically authenticating the bootloader software before system boot.HardenPlatformHardening04D3-BDIBroadcast Domain IsolationBroadcast isolation restricts the number of computers a host can contact on their LAN.IsolateNetworkIsolation00D3-BMABus Message AuthenticationApplies cryptographic primitives to individual bus frames to verify the sender's identity and ensure the integrity of the data payload.HardenMessageAuthentication00D3-BSEByte Sequence EmulationAnalyzing sequences of bytes and determining if they likely represent malicious shellcode.DetectNetworkTrafficAnalysis00D3-CACertificate AnalysisAnalyzing Public Key Infrastructure certificates to detect if they have been misconfigured or spoofed using both network traffic, certificate fields and third-party logs.DetectNetworkTrafficAnalysis26D3-CPCertificate PinningPersisting either a server's X.509 certificate or their public key and comparing that to server's presented identity to allow for greater client confidence in the remote server's identity for SSL connections.HardenCredentialHardening01D3-CEROCertificate RotationCertificate rotation involves replacing digital certificates and their private keys to maintain cryptographic integrity and trust, mitigating key compromise risks and ensuring continuous secure communications.HardenCredentialRotation01D3-CBANCertificate-based AuthenticationRequiring a digital certificate in order to authenticate a user.HardenAgentAuthentication01D3-CDPChange Default PasswordChanging the default password means replacing the factory-set credentials with a strong, unique password before the device is deployed, preventing unauthorized access.HardenStrongPasswordPolicy023
共 272 条 · 第 1/10 页
上一页下一页