Access mediation is the process of granting or denying specific requests to: 1) obtain and use information and related information processing services; and 2) enter specific physical facilities (e.g., Federal buildings, military establishments, border crossing entrances). Access mediation decisions should enforce least privilege by granting access for scoped durations to prevent privilege creep and, where applicable, implement just-in-time (JIT) access. Denial decisions may prevent initial access or terminate access that has already been granted, ensuring continuous enforcement of security policies.
0 NIST0 mitigations167 inferred
Open technique →Access modeling captures and records the access permissions granted to identities (e.g., administrators, users, groups, systems) and optionally includes details on how these identities are stored, managed, and shared across systems.
0 NIST0 mitigations24 inferred
Open technique →Access policy administration is the systematic process of defining, implementing, and managing access control policies that dictate user permissions to resources.
0 NIST0 mitigations117 inferred
Open technique →The process of temporarily disabling user accounts on a system or domain.
8 NIST1 mitigations17 inferred
Open technique →Actively collecting PKI certificates by connecting to the server and downloading its server certificates for analysis.
0 NIST0 mitigations6 inferred
Open technique →Active logical link mapping sends and receives network traffic as a means to map the whole data link layer, where the links represent logical data flows rather than physical connection
0 NIST0 mitigations7 inferred
Open technique →Active physical link mapping sends and receives network traffic as a means to map the physical layer.
0 NIST0 mitigations7 inferred
Open technique →Detection of unauthorized use of administrative network protocols by analyzing network activity against a baseline.
0 NIST0 mitigations8 inferred
Open technique →Agent authentication is the process of verifying the identities of agents to ensure they are authorized and trustworthy participants within a system.
0 NIST0 mitigations38 inferred
Open technique →Modifying an application's configuration to reduce its attack surface.
1 NIST3 mitigations4 inferred
Open technique →Monitoring the failures of system counters and timers.
0 NIST0 mitigations14 inferred
Open technique →Application Hardening makes an executable application more resilient to a class of exploits which either introduce new code or execute unwanted existing code. These techniques may be applied at compile-time or on an application binary.
2 NIST1 mitigations16 inferred
Open technique →Monitoring the count and duration of the application or program cycle.
0 NIST0 mitigations14 inferred
Open technique →Analyzing application protocol level remote commands to detect unauthorized activity.
0 NIST0 mitigations72 inferred
Open technique →Application code which prevents its own subroutines from accessing intra-process / internal memory space.
0 NIST0 mitigations15 inferred
Open technique →Asset inventorying identifies and records the organization's assets and enriches each inventory item with knowledge about their vulnerabilities.
0 NIST0 mitigations120 inferred
Open technique →Asset vulnerability enumeration enriches inventory items with knowledge identifying their vulnerabilities.
0 NIST0 mitigations27 inferred
Open technique →Removing tokens or credentials from an authentication cache to prevent further user associated account accesses.
0 NIST2 mitigations20 inferred
Open technique →Collecting authentication events, creating a baseline user profile, and determining whether authentication events are consistent with the baseline profile.
0 NIST2 mitigations0 inferred
Open technique →Collecting authorization events, creating a baseline user profile, and determining whether authorization events are consistent with the baseline profile.
0 NIST1 mitigations0 inferred
Open technique →Using biological measures in order to authenticate a user.
0 NIST0 mitigations17 inferred
Open technique →Cryptographically authenticating the bootloader software before system boot.
0 NIST2 mitigations1 inferred
Open technique →Broadcast isolation restricts the number of computers a host can contact on their LAN.
0 NIST1 mitigations0 inferred
Open technique →Applies cryptographic primitives to individual bus frames to verify the sender's identity and ensure the integrity of the data payload.
0 NIST0 mitigations0 inferred
Open technique →Analyzing sequences of bytes and determining if they likely represent malicious shellcode.
0 NIST0 mitigations0 inferred
Open technique →Analyzing Public Key Infrastructure certificates to detect if they have been misconfigured or spoofed using both network traffic, certificate fields and third-party logs.
0 NIST0 mitigations6 inferred
Open technique →Persisting either a server's X.509 certificate or their public key and comparing that to server's presented identity to allow for greater client confidence in the remote server's identity for SSL connections.
0 NIST1 mitigations1 inferred
Open technique →Certificate rotation involves replacing digital certificates and their private keys to maintain cryptographic integrity and trust, mitigating key compromise risks and ensuring continuous secure communications.
0 NIST0 mitigations21 inferred
Open technique →Requiring a digital certificate in order to authenticate a user.
0 NIST0 mitigations18 inferred
Open technique →Changing the default password means replacing the factory-set credentials with a strong, unique password before the device is deployed, preventing unauthorized access.
0 NIST0 mitigations20 inferred
Open technique →Comparing client-server request and response payloads to a baseline profile to identify outliers.
0 NIST0 mitigations72 inferred
Open technique →Configuration inventory identifies and records the configuration of software and hardware and their components throughout the organization.
0 NIST0 mitigations53 inferred
Open technique →A decoy service, system, or environment, that is connected to the enterprise network, and simulates or emulates certain functionality to the network, without exposing full access to a production system.
0 NIST0 mitigations1 inferred
Open technique →Analyzing failed connections in a network to detect unauthorized activity.
0 NIST0 mitigations15 inferred
Open technique →Analyzing a Container Image with respect to a set of policies.
0 NIST0 mitigations27 inferred
Open technique →Removing specific, potentially malicious, parts of content
0 NIST0 mitigations99 inferred
Open technique →Content Filtering techniques aid in the process of analyzing an input file for malicious or erroneous content and outputting a sanitized version.
0 NIST0 mitigations113 inferred
Open technique →Content format conversion is mechanical transformation from one format to another which may be normalization or specifically flattening.
0 NIST0 mitigations99 inferred
Open technique →Modify content that does not comply with policy.
0 NIST0 mitigations99 inferred
Open technique →Transfer content that does not comply with policy to a quarantine zone.
0 NIST0 mitigations112 inferred
Open technique →Rebuild the file according to the spec so any unreferenced components or objects are removed.
0 NIST0 mitigations99 inferred
Open technique →Modifies specific digital content information by replacing it with something else.
0 NIST0 mitigations99 inferred
Open technique →Verify and validate contents complies with policy
0 NIST0 mitigations100 inferred
Open technique →Enforcing legal control flow transfers during application process execution.
0 NIST0 mitigations0 inferred
Open technique →Determining which credentials may have been compromised by analyzing the user logon history of a particular system.
0 NIST0 mitigations20 inferred
Open technique →Credential Eviction techniques disable or remove compromised credentials from a computer network.
0 NIST0 mitigations37 inferred
Open technique →Credential Hardening techniques modify system or network properties in order to protect system or network/domain credentials.
0 NIST0 mitigations38 inferred
Open technique →Deleting a set of credentials permanently to prevent them from being used to authenticate.
0 NIST0 mitigations20 inferred
Open technique →Credential rotation is a security procedure in which authentication credentials, such as passwords, API keys, or certificates, are regularly changed or replaced to minimize the risk of unauthorized access.
0 NIST0 mitigations21 inferred
Open technique →The systematic removal of hard-coded credentials from source code to prevent accidental exposure and unauthorized access.
0 NIST0 mitigations1 inferred
Open technique →Limiting the transmission of a credential to a scoped set of relying parties.
0 NIST0 mitigations20 inferred
Open technique →Data exchange mapping identifies and models the organization's intended design for the flows of the data types, formats, and volumes between systems at the application layer.
0 NIST0 mitigations0 inferred
Open technique →Data inventorying identifies and records the schemas, formats, volumes, and locations of data stored and used on the organization's architecture.
0 NIST0 mitigations29 inferred
Open technique →Analyzing database queries to detect [SQL Injection](https://capec.mitre.org/data/definitions/66.html).
0 NIST0 mitigations1 inferred
Open technique →Removing unreachable or "dead code" from compiled source code.
0 NIST0 mitigations0 inferred
Open technique →A Decoy Environment comprises hosts and networks for the purposes of deceiving an attacker.
2 NIST1 mitigations1 inferred
Open technique →A file created for the purposes of deceiving an adversary.
0 NIST0 mitigations99 inferred
Open technique →Deploying a network resource for the purposes of deceiving an adversary.
0 NIST0 mitigations8 inferred
Open technique →A Decoy Object is created and deployed for the purposes of deceiving attackers.
2 NIST1 mitigations125 inferred
Open technique →Establishing a fake online identity to misdirect, deceive, and or interact with adversaries.
0 NIST0 mitigations0 inferred
Open technique →Issuing publicly released media to deceive adversaries.
0 NIST0 mitigations0 inferred
Open technique →An authentication token created for the purposes of deceiving an adversary.
0 NIST0 mitigations0 inferred
Open technique →A Credential created for the purpose of deceiving an adversary.
0 NIST0 mitigations20 inferred
Open technique →Direct physical link mapping creates a physical link map by direct observation and recording of the physical network links.
0 NIST0 mitigations7 inferred
Open technique →Enforce one-way network communication by preventing two-way communication.
0 NIST0 mitigations0 inferred
Open technique →Limiting access to a computing device which is not required through or from a non-organization-controlled network.
0 NIST0 mitigations4 inferred
Open technique →Encrypting a hard disk partition to prevent cleartext access to a file system.
0 NIST1 mitigations2 inferred
Open technique →Disk Erasure is the process of securely deleting all data on a disk to ensure that it cannot be recovered by any means.
0 NIST0 mitigations1 inferred
Open technique →Disk Formatting is the process of preparing a data storage device, such as a hard drive, solid-state drive, or USB flash drive, for initial use.
0 NIST0 mitigations3 inferred
Open technique →Disk Partitioning is the process of dividing a disk into multiple distinct sections, known as partitions.
0 NIST0 mitigations3 inferred
Open technique →Permitting only approved domains and their subdomains to be resolved.
0 NIST1 mitigations2 inferred
Open technique →Flushing DNS to clear any IP addresses or other DNS records from the cache.
0 NIST0 mitigations0 inferred
Open technique →Blocking DNS Network Traffic based on criteria such as IP address, domain name, or DNS query type.
0 NIST1 mitigations2 inferred
Open technique →Analysis of domain name metadata, including name and DNS records, to determine whether the domain is likely to resolve to an undesirable host.
0 NIST0 mitigations3 inferred
Open technique →Monitoring the existence of or changes to Domain User Accounts.
2 NIST2 mitigations5 inferred
Open technique →Validation of variable state in the context of the domain application.
0 NIST0 mitigations1 inferred
Open technique →Analyzing the reputation of a domain name.
0 NIST0 mitigations0 inferred
Open technique →The process of performing a takedown of the attacker's domain registration infrastructure.
0 NIST0 mitigations0 inferred
Open technique →Restricting inter-domain trust by modifying domain configuration.
1 NIST1 mitigations1 inferred
Open technique →Ensuring the integrity of drivers loaded during initialization of the operating system.
2 NIST3 mitigations0 inferred
Open technique →Executing or opening a file in a synthetic "sandbox" environment to determine if the file is a malicious program or if the file exploits another program such as a document reader.
2 NIST1 mitigations38 inferred
Open technique →The application of physical and material-level design measures to electronic systems, components, or facilities to reduce their susceptibility to damage or disruption from electromagnetic threats.
0 NIST0 mitigations11 inferred
Open technique →Monitoring electronic lock and door hardware states and access events (e.g., locked/unlocked, access granted/denied, door forced/held, tamper) to detect and respond to unauthorized entry.
0 NIST0 mitigations0 inferred
Open technique →Filtering incoming email traffic based on specific criteria.
0 NIST0 mitigations4 inferred
Open technique →The email removal technique deletes email files from system storage.
0 NIST0 mitigations6 inferred
Open technique →Emulating instructions in a file looking for specific patterns.
0 NIST0 mitigations38 inferred
Open technique →Encrypted encapsulation of routable network traffic.
1 NIST2 mitigations0 inferred
Open technique →Monitoring the security status of an endpoint by sending periodic messages with health status, where absence of a response may indicate that the endpoint has been compromised.
0 NIST0 mitigations7 inferred
Open technique →Endpoint-based web server access mediation regulates web server access directly from user endpoints by implementing mechanisms such as client-side certificates and endpoint security software to authenticate devices and ensure compliant access.
0 NIST0 mitigations16 inferred
Open technique →Validates that a referenced exception handler pointer is a valid exception handler.
0 NIST1 mitigations0 inferred
Open technique →Using a digital signature to authenticate a file before opening.
3 NIST3 mitigations51 inferred
Open technique →Blocking the execution of files on a host in accordance with defined application policy rules.
4 NIST3 mitigations51 inferred
Open technique →Execution Isolation techniques prevent application processes from accessing non-essential system resources, such as memory, devices, or files.
2 NIST0 mitigations62 inferred
Open technique →Analyzing the files accessed by a process to identify unauthorized activity.
0 NIST0 mitigations0 inferred
Open technique →File Analysis is an analytic process to determine a file's status. For example: virus, trojan, benign, malicious, trusted, unauthorized, sensitive, etc.
3 NIST1 mitigations99 inferred
Open technique →Identifying and extracting files from network application protocols through the use of network stream reassembly software.
0 NIST0 mitigations2 inferred
Open technique →Employing a pattern matching algorithm to statically analyze the content of files.
0 NIST0 mitigations99 inferred
Open technique →Checking if compressed or encoded data sections can be successfully decompressed or decoded. Can follow with further analysis with semantic knowledge
0 NIST0 mitigations99 inferred
Open technique →Employing a pattern matching rule language to analyze the content of files.
1 NIST1 mitigations99 inferred
Open technique →Analyzing the properties of file create system call invocations.
0 NIST0 mitigations2 inferred
Open technique →Encrypting a file using a cryptographic key.
0 NIST1 mitigations99 inferred
Open technique →File eviction techniques delete files from system storage.
0 NIST0 mitigations101 inferred
Open technique →Verifying that a file conforms to its expected format specifications
0 NIST0 mitigations100 inferred
Open technique →Analyzing the reputation of a file hash.
0 NIST0 mitigations0 inferred
Open technique →Employing file hash comparisons to detect known malware.
0 NIST1 mitigations99 inferred
Open technique →Detecting any suspicious changes to files in a computer system.
0 NIST0 mitigations99 inferred
Open technique →The process of checking specific static values within a file, such as file signatures or magic numbers, to ensure they match the expected values defined by the file format specification.
0 NIST0 mitigations99 inferred
Open technique →Utilizing the magic number to verify the file
0 NIST0 mitigations99 inferred
Open technique →The process of validating the consistency between a file's metadata and its actual content, ensuring that elements like declared lengths, pointers, and checksums accurately describe the file's content.
0 NIST0 mitigations99 inferred
Open technique →The process of checking specific static values within a file, such as file signatures or magic numbers, to ensure they match the expected values defined by the file format specification.
0 NIST0 mitigations99 inferred
Open technique →Analyzing the behavior of embedded code in firmware and looking for anomalous behavior and suspicious activity.
0 NIST0 mitigations4 inferred
Open technique →Monitoring code is injected into firmware for integrity monitoring of firmware and firmware data.
0 NIST0 mitigations4 inferred
Open technique →Cryptographically verifying firmware integrity.
7 NIST0 mitigations4 inferred
Open technique →Blocking a lookup based on the query's domain name value.
0 NIST0 mitigations2 inferred
Open technique →Blocking a DNS lookup's answer's IP address value.
0 NIST0 mitigations0 inferred
Open technique →Hardware component inventorying identifies and records the hardware items in the organization's architecture.
0 NIST0 mitigations11 inferred
Open technique →Preventing one process from writing to the memory space of another process through hardware based address manager implementations.
1 NIST2 mitigations36 inferred
Open technique →Physical methods of preventing data from being written to computer storage.
0 NIST0 mitigations1 inferred
Open technique →Blocking the resolution of any subdomain of a specified domain name.
0 NIST0 mitigations2 inferred
Open technique →Blocking DNS queries that are deceptively similar to legitimate domain names.
0 NIST0 mitigations2 inferred
Open technique →Comparing strings using a variety of techniques to determine if a deceptive or malicious string is being presented to a user.
0 NIST0 mitigations7 inferred
Open technique →Initiating a host's reboot sequence to terminate all running processes.
0 NIST0 mitigations14 inferred
Open technique →Initiating a host's shutdown sequence to terminate all running processes.
0 NIST0 mitigations14 inferred
Open technique →Taking known malicious identifiers and determining if they are present in a system.
0 NIST0 mitigations4 inferred
Open technique →Analyzing identifier artifacts such as IP address, domain names, or URL(I)s.
2 NIST0 mitigations7 inferred
Open technique →Analyzing the reputation of an identifier.
0 NIST0 mitigations4 inferred
Open technique →Analyzing inbound network session or connection attempt volume.
0 NIST1 mitigations6 inferred
Open technique →Restricting network traffic originating from untrusted networks destined towards a private host or enclave.
21 NIST4 mitigations8 inferred
Open technique →Analyzing vendor specific branch call recording in order to detect ROP style attacks.
0 NIST0 mitigations0 inferred
Open technique →Operating system level mechanisms to prevent abusive input device exploitation.
0 NIST0 mitigations3 inferred
Open technique →Ensuring that an integer is within a valid range.
0 NIST0 mitigations0 inferred
Open technique →The practice of setting decoys in a production environment to entice interaction from attackers.
0 NIST0 mitigations1 inferred
Open technique →Limiting access to computer input/output (IO) ports to restrict unauthorized devices.
0 NIST1 mitigations7 inferred
Open technique →Analyzing the reputation of an IP address.
0 NIST0 mitigations0 inferred
Open technique →Analyzing standard inter process communication (IPC) protocols to detect deviations from normal protocol activity.
0 NIST0 mitigations1 inferred
Open technique →Detecting anomalies in user access patterns by comparing user access activity to behavioral profiles that categorize users by role such as job title, function, department.
1 NIST1 mitigations0 inferred
Open technique →Using kernel-level capabilities to isolate processes.
0 NIST0 mitigations14 inferred
Open technique →LAN access mediation encompasses the application of strict access control policies, systematic verification of devices, and authentication mechanisms to govern connectivity to a Local Area Network.
0 NIST0 mitigations0 inferred
Open technique →Analyzing local user accounts to detect unauthorized activity.
16 NIST2 mitigations3 inferred
Open technique →Local file access mediation is the process of an operating system granting or denying a specific access request to a local file.
0 NIST0 mitigations14 inferred
Open technique →Local file permissions is the systematic process of defining, implementing, and managing access control policies that dictate user permissions for accessing files on a local system through the configuration of operating system functionality.
8 NIST2 mitigations100 inferred
Open technique →Logical link mapping creates a model of existing or previous node-to-node connections using network-layer data or metadata.
0 NIST0 mitigations7 inferred
Open technique →Ensuring that a pointer accurately references the beginning of a designated memory block.
0 NIST0 mitigations0 inferred
Open technique →Analyzing a call stack for return addresses which point to unexpected memory locations.
0 NIST0 mitigations7 inferred
Open technique →Analyzing email or instant message content to detect unauthorized activity.
2 NIST0 mitigations4 inferred
Open technique →Authenticating the sender of a message and ensuring message integrity.
1 NIST0 mitigations0 inferred
Open technique →Encrypting a message body using a cryptographic key.
0 NIST1 mitigations0 inferred
Open technique →The application of security controls to user-to-user and system-to-system communications so messages remain confidential, unaltered, and verifiable while resisting injection, replay, and tampering.
0 NIST0 mitigations0 inferred
Open technique →Monitoring events from motion detectors (e.g., passive IR, microwave, dual-technology) to detect presence or movement within protected areas.
0 NIST0 mitigations0 inferred
Open technique →Requiring proof of two or more pieces of evidence in order to authenticate a user.
4 NIST1 mitigations37 inferred
Open technique →Network access mediation is the control method for authorizing access to a system by a user (or a process acting on behalf of a user) communicating through a network, including a local area network, a wide area network, and the Internet.
0 NIST0 mitigations0 inferred
Open technique →Network Isolation techniques prevent network hosts from accessing non-essential system network resources.
1 NIST2 mitigations74 inferred
Open technique →Network mapping encompasses the techniques to identify and model the physical layer, network layer, and data exchange layers of the organization's network and their physical location, and determine allowed pathways through that network.
0 NIST0 mitigations15 inferred
Open technique →Network node inventorying identifies and records all the network nodes (hosts, routers, switches, firewalls, etc.) in the organization's architecture.
0 NIST0 mitigations7 inferred
Open technique →Control of access to organizational systems and services by users or processes over a network.
0 NIST0 mitigations113 inferred
Open technique →Analyzing intercepted or summarized computer network traffic to detect unauthorized activity.
8 NIST3 mitigations74 inferred
Open technique →Establishing baseline communities of network hosts and identifying statistically divergent inter-community communication.
0 NIST0 mitigations72 inferred
Open technique →Restricting network traffic originating from any location.
0 NIST0 mitigations74 inferred
Open technique →Network traffic policy mapping identifies and models the allowed pathways of data at the network, transport, and/or application levels.
0 NIST0 mitigations8 inferred
Open technique →Analyzing network traffic and compares it to known signatures
0 NIST0 mitigations72 inferred
Open technique →Network vulnerability assessment relates all the vulnerabilities of a network's components in the context of their configuration and interdependencies and can also include assessing risk emerging from the network's design as a whole, not just the sum of individual network node or network segment vulnerabilities.
0 NIST0 mitigations0 inferred
Open technique →Checking if a pointer is NULL.
0 NIST0 mitigations0 inferred
Open technique →Terminate or remove an object from a host machine. This is the broadest class for object eviction.
0 NIST0 mitigations104 inferred
Open technique →A one-time password is valid for only one user authentication.
0 NIST1 mitigations20 inferred
Open technique →Detects operating modes such as Program, Run, Remote, or Stop.
0 NIST0 mitigations0 inferred
Open technique →Restricting unauthorized changes to the operating mode prevents devices from switching into inappropriate or vulnerable states during normal use.
0 NIST0 mitigations0 inferred
Open technique →The operating system software, for D3FEND's purposes, includes the kernel and its process management functions, hardware drivers, initialization or boot logic. It also includes and other key system daemons and their configuration. The monitoring or analysis of these components for unauthorized activity constitute **Operating System Monitoring**.
1 NIST0 mitigations44 inferred
Open technique →Operational activity mapping identifies activities of the organization and the organization's suborganizations, groups, roles, and individuals that carry out the activities and then establishes the dependencies of the activities on the systems and people that perform those activities.
0 NIST0 mitigations24 inferred
Open technique →Operational dependency mapping identifies and models the dependencies of the organization's activities on each other and on the organization's performers (people, systems, and services.) This may include modeling the higher- and lower-level activities of an organization forming a hierarchy, or layering, of the dependencies in an organization's activities.
0 NIST0 mitigations0 inferred
Open technique →Validation of variable state in the context of the control logic of the operational application.
0 NIST0 mitigations0 inferred
Open technique →Monitoring physical parameters and operator actions related to an operational environment.
0 NIST0 mitigations13 inferred
Open technique →Operational risk assessment identifies and models the vulnerabilities of, and risks to, an organization's activities individually and as a whole.
0 NIST0 mitigations0 inferred
Open technique →Organization mapping identifies and models the people, roles, and groups with an organization and the relations between them.
0 NIST0 mitigations0 inferred
Open technique →Assign read/write access controls on designated registers or data tags to prevent unauthorized writes.
0 NIST0 mitigations0 inferred
Open technique →Restricting network traffic originating from a private host or enclave destined towards untrusted networks.
21 NIST2 mitigations30 inferred
Open technique →Collecting host certificates from network traffic or other passive sources like a certificate transparency log and analyzing them for unauthorized activity.
0 NIST0 mitigations6 inferred
Open technique →Passive logical link mapping only listens to network traffic as a means to map the whole data link layer, where the links represent logical data flows rather than physical connections.
0 NIST0 mitigations7 inferred
Open technique →Password authentication is a security mechanism used to verify the identity of a user or entity attempting to access a system or resource by requiring the input of a secret string of characters, known as a password, that is associated with the user or entity.
0 NIST0 mitigations20 inferred
Open technique →Password rotation is a security policy that mandates the periodic change of user account passwords to mitigate the risk of unauthorized access due to compromised credentials.
0 NIST0 mitigations20 inferred
Open technique →Detecting anomalies that indicate malicious activity by comparing the amount of data downloaded versus data uploaded by a host.
0 NIST0 mitigations72 inferred
Open technique →Cryptographically verifying peripheral firmware integrity.
2 NIST0 mitigations0 inferred
Open technique →Physical access mediation is the process of granting or denying specific requests to enter specific physical facilities (e.g., Federal buildings, military establishments, border crossing entrances.)
0 NIST0 mitigations0 inferred
Open technique →Monitoring the physical access of a specified environment through detection, recording, reviewing, and logging of who/what enters and exists areas.
0 NIST0 mitigations1 inferred
Open technique →Physical changes to a computer enclosure which reduce the ability for agents or the environment to affect the contained computer system.
0 NIST0 mitigations0 inferred
Open technique →Physical link mapping identifies and models the link connectivity of the network devices within a physical network.
0 NIST0 mitigations7 inferred
Open technique →Employ a mechanical locking device for securing moveable portions of physical barriers (e.g., doors, gates, drawers) in a secured position.
0 NIST0 mitigations0 inferred
Open technique →Hardening components of a Platform with the intention of making them more difficult to exploit.
Platforms includes components such as:
* BIOS UEFI Subsystems
* Hardware security devices such as Trusted Platform Modules
* Boot process logic or code
* Kernel software components
5 NIST1 mitigations139 inferred
Open technique →Monitoring platform components such as operating systems software, hardware devices, or firmware.
3 NIST0 mitigations139 inferred
Open technique →Monitor the amount of time since the last power cycle or restart.
0 NIST0 mitigations0 inferred
Open technique →Comparing the cryptographic hash or derivative of a pointer's value to an expected value.
0 NIST0 mitigations0 inferred
Open technique →Ensuring that a pointer variable has the required properties for use.
0 NIST0 mitigations0 inferred
Open technique →Process Analysis consists of observing a running application process and analyzing it to watch for certain behaviors or conditions which may indicate adversary activity. Analysis can occur inside of the process or through a third-party monitoring application. Examples include monitoring system and privileged calls, monitoring process initiation chains, and memory boundary allocations.
3 NIST1 mitigations59 inferred
Open technique →Comparing the "text" or "code" memory segments to a source of truth.
0 NIST0 mitigations7 inferred
Open technique →Process eviction techniques terminate or remove running process.
0 NIST0 mitigations22 inferred
Open technique →Identification of suspicious processes executing on an end-point device by examining the ancestry and siblings of a process, and the associated metadata of each node on the tree, such as process execution, duration, and order relative to siblings and ancestors.
0 NIST0 mitigations14 inferred
Open technique →Preventing execution of any address in a memory region other than the code segment.
0 NIST2 mitigations12 inferred
Open technique →Detects processes that modify, change, or replace their own code at runtime.
0 NIST0 mitigations14 inferred
Open technique →Analyzing spawn arguments or attributes of a process to detect processes that are unauthorized.
0 NIST0 mitigations36 inferred
Open technique →Suspending a running process on a computer system.
0 NIST0 mitigations14 inferred
Open technique →Terminating a running application process on a computer system.
0 NIST0 mitigations14 inferred
Open technique →Collecting network communication protocol metadata and identifying statistical outliers.
0 NIST0 mitigations72 inferred
Open technique →Monitoring events from proximity sensors that indicate a credential or tagged asset is within the sensor’s read range or a defined zone. Common enabling technologies include RFID, Bluetooth Low Energy (BLE), and Ultra-Wideband (UWB).
0 NIST0 mitigations0 inferred
Open technique →Proxy-based web server access mediation focuses on the regulation of web server access through intermediary proxy servers.
0 NIST0 mitigations16 inferred
Open technique →Radiation hardening is the process of making electronic components and circuits resistant to damage or malfunction caused by high levels of ionizing radiation.
0 NIST0 mitigations11 inferred
Open technique →Invalidating all pointers that reference a specific memory block, ensuring that the block cannot be accessed or modified after deallocation.
0 NIST0 mitigations0 inferred
Open technique →Delete a registry key.
0 NIST0 mitigations1 inferred
Open technique →Issue a new credential to a user which supersedes their old credential.
0 NIST0 mitigations20 inferred
Open technique →The detection of an internal host relaying traffic between the internal network and the external network.
0 NIST0 mitigations30 inferred
Open technique →Remote file access mediation is the process of managing and securing access to file systems over a network to ensure that only authorized users or processes can interact with remote files.
0 NIST0 mitigations99 inferred
Open technique →Monitoring of remote firmware update commands to identify unauthorized software installations.
0 NIST0 mitigations0 inferred
Open technique →Detection of an unauthorized remote live terminal console session by examining network traffic to a network host.
0 NIST0 mitigations72 inferred
Open technique →Analyzing the resources accessed by a user to identify unauthorized activity.
1 NIST1 mitigations0 inferred
Open technique →Restoring an entity's access to resources.
0 NIST0 mitigations43 inferred
Open technique →Restoring an software configuration.
0 NIST0 mitigations53 inferred
Open technique →Restoring the data in a database.
0 NIST0 mitigations22 inferred
Open technique →Restoring a previously captured disk image a hard drive.
0 NIST0 mitigations0 inferred
Open technique →Restoring an email for an entity to access.
0 NIST0 mitigations4 inferred
Open technique →Restoring a file for an entity to access.
0 NIST0 mitigations99 inferred
Open technique →Restoring a entity's access to a computer network.
0 NIST0 mitigations6 inferred
Open technique →Restoring an object for an entity to access. This is the broadest class for object restoral.
0 NIST0 mitigations172 inferred
Open technique →Restoring software to a host.
0 NIST0 mitigations26 inferred
Open technique →Restoring a user account's access to resources.
0 NIST0 mitigations17 inferred
Open technique →Blocking a reverse lookup based on the query's IP address value.
0 NIST0 mitigations2 inferred
Open technique →Adding physical barriers to a platform to prevent undesired radio interference.
0 NIST0 mitigations11 inferred
Open technique →Routing access mediation is a network security approach that manages and controls access at the network layer using VPNs, tunneling protocols, firewall rules, and traffic inspection to ensure secure and efficient data routing.
0 NIST0 mitigations0 inferred
Open technique →Monitoring the activity of remote procedure calls in communication traffic to establish standard protocol operations and potential attacker activities.
0 NIST0 mitigations1 inferred
Open technique →Analysis of source files, processes, destination files, or destination servers associated with a scheduled job to detect unauthorized use of job scheduling.
0 NIST0 mitigations2 inferred
Open technique →Analyzing the execution of a script to detect unauthorized user activity.
0 NIST0 mitigations0 inferred
Open technique →Randomizing the base (start) address of one or more segments of memory during the initialization of a process.
0 NIST0 mitigations12 inferred
Open technique →Characterizing the reputation of mail transfer agents (MTA) to determine the security risk in emails.
0 NIST0 mitigations4 inferred
Open technique →Ascertaining sender reputation based on information associated with a message (e.g. email/instant messaging).
0 NIST0 mitigations4 inferred
Open technique →Analyzing changes in service binary files by comparing to a source of truth.
0 NIST1 mitigations17 inferred
Open technique →Service dependency mapping determines the services on which each given service relies.
0 NIST0 mitigations0 inferred
Open technique →Analyzing the duration of user sessions in order to detect unauthorized activity.
0 NIST1 mitigations0 inferred
Open technique →Forcefully end all active sessions associated with compromised accounts or devices.
0 NIST0 mitigations8 inferred
Open technique →Comparing a call stack in system memory with a shadow call stack maintained by the processor to determine unauthorized shellcode activity.
0 NIST1 mitigations5 inferred
Open technique →Software inventorying identifies and records the software items in the organization's architecture.
0 NIST0 mitigations26 inferred
Open technique →Replacing old software on a computer system component.
8 NIST1 mitigations26 inferred
Open technique →Hardening source code with the intention of making it more difficult to exploit and less error prone.
0 NIST0 mitigations1 inferred
Open technique →Comparing a value stored in a stack frame with a known good value in order to prevent or detect a memory segment overwrite.
0 NIST0 mitigations5 inferred
Open technique →An environment created for the purpose of attracting attackers and eliciting their behaviors that is not connected to any production enterprise systems.
0 NIST0 mitigations1 inferred
Open technique →Modifying system configuration to increase password strength.
0 NIST2 mitigations20 inferred
Open technique →Analyzing system calls to determine whether a process is exhibiting unauthorized behavior.
0 NIST0 mitigations40 inferred
Open technique →Controlling access to local computer system resources with kernel-level capabilities.
1 NIST6 mitigations52 inferred
Open technique →Restricting system configuration modifications to a specific user or group of users.
11 NIST2 mitigations13 inferred
Open technique →Tracking changes to the state or configuration of critical system level processes.
0 NIST0 mitigations3 inferred
Open technique →System dependency mapping identifies and models the dependencies of system components on each other to carry out their function.
0 NIST0 mitigations0 inferred
Open technique →Monitoring system files such as authentication databases, configuration files, system logs, and system executables for modification or tampering.
0 NIST2 mitigations17 inferred
Open technique →Cryptographically verifying installed system firmware integrity.
2 NIST0 mitigations2 inferred
Open technique →Analysis of any system process startup configuration.
0 NIST0 mitigations5 inferred
Open technique →System mapping encompasses the techniques to identify the organization's systems, how they are configured and decomposed into subsystems and components, how they are dependent on one another, and where they are physically located.
0 NIST0 mitigations1 inferred
Open technique →System vulnerability assessment relates all the vulnerabilities of a system's components in the context of their configuration and internal dependencies and can also include assessing risk emerging from the system's design as a whole, not just the sum of individual component vulnerabilities.
0 NIST0 mitigations1 inferred
Open technique →Token binding is a security mechanism used to enhance the protection of tokens, such as cookies or OAuth tokens, by binding them to a specific connection.
0 NIST0 mitigations20 inferred
Open technique →Token-based authentication is an authentication protocol where users verify their identity in exchange for a unique access token. Users can then access the website, application, or resource for the life of the token without having to re-enter their credentials.
0 NIST0 mitigations24 inferred
Open technique →Assuring the integrity of a platform by demonstrating that the boot process starts from a trusted combination of hardware and software and continues until the operating system has fully booted and applications are running. Sometimes called Static Root of Trust Measurement (STRM).
0 NIST1 mitigations0 inferred
Open technique →Validating that server components of a messaging infrastructure are authorized to send a particular message.
0 NIST0 mitigations0 inferred
Open technique →A trusted library is a collection of pre-verified and secure code modules or components that are used within software applications to perform specific functions. These libraries are considered reliable and have been vetted for security vulnerabilities, ensuring they do not introduce risks into the application.
0 NIST0 mitigations1 inferred
Open technique →Restoring a user account's access to resources by unlocking a locked User Account.
0 NIST0 mitigations17 inferred
Open technique →Determining if a URL is benign or malicious by analyzing the URL or its components.
0 NIST1 mitigations4 inferred
Open technique →Analyzing the reputation of a URL.
0 NIST0 mitigations4 inferred
Open technique →Restricting a user account's access to resources.
9 NIST1 mitigations17 inferred
Open technique →User behavior analytics ("UBA") as defined by Gartner, is a cybersecurity process about detection of insider threats, targeted attacks, and financial fraud. UBA solutions look at patterns of human behavior, and then apply algorithms and statistical analysis to detect meaningful anomalies from those patterns-anomalies that indicate potential threats.' Instead of tracking devices or security events, UBA tracks a system's users. Big data platforms are increasing UBA functionality by allowing them to analyze petabytes worth of data to detect insider threats and advanced persistent threats.
4 NIST0 mitigations96 inferred
Open technique →Analyzing the amount of data transferred by a user.
1 NIST1 mitigations0 inferred
Open technique →Monitoring geolocation data of user logon attempts and comparing it to a baseline user behavior profile to identify anomalies in logon location.
0 NIST1 mitigations72 inferred
Open technique →Access control where access is determined based on attributes associated with users and the objects being accessed.
0 NIST0 mitigations0 inferred
Open technique →Analyzing modifications to user session config files such as .bashrc or .bash_profile.
0 NIST0 mitigations2 inferred
Open technique →Setting variables to a known value before use.
0 NIST0 mitigations1 inferred
Open technique →Ensuring that a variable has the correct type.
0 NIST0 mitigations0 inferred
Open technique →Monitoring of physical areas via camera video feeds to deter, detect, and investigate unauthorized access and related security events.
0 NIST0 mitigations1 inferred
Open technique →Web session access mediation secures user sessions in web applications by employing robust authentication and integrity validation, along with adaptive threat mitigation techniques, to ensure that access to web resources is authorized and protected from session-related attacks.
0 NIST0 mitigations8 inferred
Open technique →Monitoring changes in user web session behavior by comparing current web session activity to a baseline behavior profile or a catalog of predetermined malicious behavior.
0 NIST1 mitigations0 inferred
Open technique →