Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

MITRE D3FEND™ Learning Center

Move from adversary behavior and controls to defensive engineering.

Explore the D3FEND 1.6.0 knowledge graph through seven defensive tactics, 271 defensive techniques, source-controlled semantic mappings, and original Bare Metal Cyber implementation guidance.

7Defensive tactics
271Techniques
180NIST mappings
89Mitigation mappings

Ontology 1.6.0 · Released 2026-08-31 · Source-controlled local learning layer

Open official D3FEND resources ↗

Defensive tactics

Choose the defensive objective.

D3FEND organizes technical countermeasure techniques by the goal they support. Tactic definitions and technique relationships below are derived from the official ontology.

Technique directory

Search every defensive technique.

Search by D3FEND ID, name, synonym, tactic, technique family, artifact context, or implementation concept.

48 of 271 techniques shown
D3-AMEDIsolate

Access Mediation

Access mediation is the process of granting or denying specific requests to: 1) obtain and use information and related information processing services; and 2) enter specific physical facilities (e.g., Federal buildings, military establishments, border crossing entrances). Access mediation decisions should enforce least privilege by granting access for scoped durations to prevent privilege creep and, where applicable, implement just-in-time (JIT) access. Denial decisions may prevent initial access or terminate access that has already been granted, ensuring continuous enforcement of security policies.

0 NIST0 mitigations167 inferred
Open technique →
D3-AMModel

Access Modeling

Access modeling captures and records the access permissions granted to identities (e.g., administrators, users, groups, systems) and optionally includes details on how these identities are stored, managed, and shared across systems.

0 NIST0 mitigations24 inferred
Open technique →
D3-ALLMModel

Active Logical Link Mapping

Active logical link mapping sends and receives network traffic as a means to map the whole data link layer, where the links represent logical data flows rather than physical connection

0 NIST0 mitigations7 inferred
Open technique →
D3-AAHarden

Agent Authentication

Agent authentication is the process of verifying the identities of agents to ensure they are authorized and trustworthy participants within a system.

0 NIST0 mitigations38 inferred
Open technique →
D3-AHHarden

Application Hardening

Application Hardening makes an executable application more resilient to a class of exploits which either introduce new code or execute unwanted existing code. These techniques may be applied at compile-time or on an application binary.

2 NIST1 mitigations16 inferred
Open technique →
D3-AIModel

Asset Inventory

Asset inventorying identifies and records the organization's assets and enriches each inventory item with knowledge about their vulnerabilities.

0 NIST0 mitigations120 inferred
Open technique →
D3-CADetect

Certificate Analysis

Analyzing Public Key Infrastructure certificates to detect if they have been misconfigured or spoofed using both network traffic, certificate fields and third-party logs.

0 NIST0 mitigations6 inferred
Open technique →
D3-CPHarden

Certificate Pinning

Persisting either a server's X.509 certificate or their public key and comparing that to server's presented identity to allow for greater client confidence in the remote server's identity for SSL connections.

0 NIST1 mitigations1 inferred
Open technique →
D3-CEROHarden

Certificate Rotation

Certificate rotation involves replacing digital certificates and their private keys to maintain cryptographic integrity and trust, mitigating key compromise risks and ensuring continuous secure communications.

0 NIST0 mitigations21 inferred
Open technique →
D3-CDPHarden

Change Default Password

Changing the default password means replacing the factory-set credentials with a strong, unique password before the device is deployed, preventing unauthorized access.

0 NIST0 mitigations20 inferred
Open technique →
D3-CHNDeceive

Connected Honeynet

A decoy service, system, or environment, that is connected to the enterprise network, and simulates or emulates certain functionality to the network, without exposing full access to a production system.

0 NIST0 mitigations1 inferred
Open technique →
D3-CFIsolate

Content Filtering

Content Filtering techniques aid in the process of analyzing an input file for malicious or erroneous content and outputting a sanitized version.

0 NIST0 mitigations113 inferred
Open technique →

Mapping discipline

Curated mappings and inferred relationships are not the same thing.

NIST SP 800-53 and ATT&CK Enterprise mitigation mappings preserve the semantic relation encoded in the D3FEND ontology. Offensive-technique relationships generated from the full mapping dataset are presented separately and explicitly labeled inferred and experimental.

No relationship on this site is presented as proof that a product implements a technique, that a control is effective, or that one countermeasure guarantees prevention of an adversary behavior.