D3FEND 防御知识库
技术列表 · 只读官方知识数据
D3FEND 标识技术名称战术父技术子技术ATT&CK
D3-DFDecoy FileA file created for the purposes of deceiving an adversary.DeceiveDecoyObject0110D3-DNRDecoy Network ResourceDeploying a network resource for the purposes of deceiving an adversary.DeceiveDecoyObject08D3-DODecoy ObjectA Decoy Object is created and deployed for the purposes of deceiving attackers.Deceive--60D3-DPDecoy PersonaEstablishing a fake online identity to misdirect, deceive, and or interact with adversaries.DeceiveDecoyObject00D3-DPRDecoy Public ReleaseIssuing publicly released media to deceive adversaries.DeceiveDecoyObject00D3-DSTDecoy Session TokenAn authentication token created for the purposes of deceiving an adversary.DeceiveDecoyObject00D3-DUCDecoy User CredentialA Credential created for the purpose of deceiving an adversary.DeceiveDecoyObject025D3-DPLMDirect Physical Link MappingDirect physical link mapping creates a physical link map by direct observation and recording of the physical network links.ModelPhysicalLinkMapping00D3-DNLDirectional Network LinkEnforce one-way network communication by preventing two-way communication.IsolateNetworkIsolation05D3-DRADisable Remote AccessLimiting access to a computing device which is not required through or from a non-organization-controlled network.HardenApplicationConfigurationHardening010D3-DENCRDisk EncryptionEncrypting a hard disk partition to prevent cleartext access to a file system.HardenPlatformHardening05D3-DKEDisk ErasureDisk Erasure is the process of securely deleting all data on a disk to ensure that it cannot be recovered by any means.EvictDiskFormatting02D3-DKFDisk FormattingDisk Formatting is the process of preparing a data storage device, such as a hard drive, solid-state drive, or USB flash drive, for initial use.EvictObjectEviction22D3-DKPDisk PartitioningDisk Partitioning is the process of dividing a disk into multiple distinct sections, known as partitions.EvictDiskFormatting02D3-DAMDomain Account MonitoringMonitoring the existence of or changes to Domain User Accounts.DetectUserBehaviorAnalysis05D3-DLVDomain Logic ValidationValidation of variable state in the context of the domain application.HardenSourceCodeHardening12D3-DNRADomain Name Reputation AnalysisAnalyzing the reputation of a domain name.DetectIdentifierReputationAnalysis00D3-DRTDomain Registration TakedownThe process of performing a takedown of the attacker's domain registration infrastructure.EvictObjectEviction00D3-DTPDomain Trust PolicyRestricting inter-domain trust by modifying domain configuration.IsolateAccessPolicyAdministration01D3-DLICDriver Load Integrity CheckingEnsuring the integrity of drivers loaded during initialization of the operating system.HardenPlatformHardening00D3-DADynamic AnalysisExecuting or opening a file in a synthetic "sandbox" environment to determine if the file is a malicious program or if the file exploits another program such as a document reader.DetectFileAnalysis043D3-EMHElectromagnetic Radiation HardeningThe application of physical and material-level design measures to electronic systems, components, or facilities to reduce their susceptibility to damage or disruption from electromagnetic threats.HardenRadiationHardening10D3-ELMElectronic Lock MonitoringMonitoring electronic lock and door hardware states and access events (e.g., locked/unlocked, access granted/denied, door forced/held, tamper) to detect and respond to unauthorized entry.DetectPhysicalAccessMonitoring00D3-EFEmail FilteringFiltering incoming email traffic based on specific criteria.IsolateInboundTrafficFiltering05D3-EREmail RemovalThe email removal technique deletes email files from system storage.EvictFileEviction07D3-EFAEmulated File AnalysisEmulating instructions in a file looking for specific patterns.DetectFileAnalysis043D3-ETEncrypted TunnelsEncrypted encapsulation of routable network traffic.IsolateNetworkIsolation00D3-EHBEndpoint Health BeaconMonitoring the security status of an endpoint by sending periodic messages with health status, where absence of a response may indicate that the endpoint has been compromised.DetectOperatingSystemMonitoring017D3-EBWSAMEndpoint-based Web Server Access MediationEndpoint-based web server access mediation regulates web server access directly from user endpoints by implementing mechanisms such as client-side certificates and endpoint security software to authenticate devices and ensure compliant access.IsolateWebSessionAccessMediation00D3-EHPVException Handler Pointer ValidationValidates that a referenced exception handler pointer is a valid exception handler.HardenApplicationHardening00