Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

MITRE D3FEND™ Learning Center

Detect

The detect tactic is used to identify adversary access to or unauthorized activity on computer networks.

90Techniques
8Top-level families

Top-level technique families

Start with the major branches.

These techniques sit directly beneath the Defensive Technique root and organize the more specific techniques in this tactic.

D3-FA

File Analysis

File Analysis is an analytic process to determine a file's status. For example: virus, trojan, benign, malicious, trusted, unauthorized, sensitive, etc.

4 direct child techniques →
D3-ID

Identifier Analysis

Analyzing identifier artifacts such as IP address, domain names, or URL(I)s.

4 direct child techniques →
D3-MA

Message Analysis

Analyzing email or instant message content to detect unauthorized activity.

2 direct child techniques →
D3-NTA

Network Traffic Analysis

Analyzing intercepted or summarized computer network traffic to detect unauthorized activity.

17 direct child techniques →
D3-PHAM

Physical Access Monitoring

Monitoring the physical access of a specified environment through detection, recording, reviewing, and logging of who/what enters and exists areas.

4 direct child techniques →
D3-PM

Platform Monitoring

Monitoring platform components such as operating systems software, hardware devices, or firmware.

9 direct child techniques →
D3-PA

Process Analysis

Process Analysis consists of observing a running application process and analyzing it to watch for certain behaviors or conditions which may indicate adversary activity. Analysis can occur inside of the process or through a third-party monitoring application. Examples include monitoring system and privileged calls, monitoring process initiation chains, and memory boundary allocations.

9 direct child techniques →
D3-UBA

User Behavior Analysis

User behavior analytics ("UBA") as defined by Gartner, is a cybersecurity process about detection of insider threats, targeted attacks, and financial fraud. UBA solutions look at patterns of human behavior, and then apply algorithms and statistical analysis to detect meaningful anomalies from those patterns-anomalies that indicate potential threats.' Instead of tracking devices or security events, UBA tracks a system's users. Big data platforms are increasing UBA functionality by allowing them to analyze petabytes worth of data to detect insider threats and advanced persistent threats.

11 direct child techniques →

Complete tactic directory

Browse all 90 Detect techniques.

48 of 90 techniques shown
D3-CADetect

Certificate Analysis

Analyzing Public Key Infrastructure certificates to detect if they have been misconfigured or spoofed using both network traffic, certificate fields and third-party logs.

0 NIST0 mitigations6 inferred
Open technique →
D3-DNSTADetect

DNS Traffic Analysis

Analysis of domain name metadata, including name and DNS records, to determine whether the domain is likely to resolve to an undesirable host.

0 NIST0 mitigations3 inferred
Open technique →
D3-DADetect

Dynamic Analysis

Executing or opening a file in a synthetic "sandbox" environment to determine if the file is a malicious program or if the file exploits another program such as a document reader.

2 NIST1 mitigations38 inferred
Open technique →
D3-ELMDetect

Electronic Lock Monitoring

Monitoring electronic lock and door hardware states and access events (e.g., locked/unlocked, access granted/denied, door forced/held, tamper) to detect and respond to unauthorized entry.

0 NIST0 mitigations0 inferred
Open technique →
D3-EHBDetect

Endpoint Health Beacon

Monitoring the security status of an endpoint by sending periodic messages with health status, where absence of a response may indicate that the endpoint has been compromised.

0 NIST0 mitigations7 inferred
Open technique →
D3-FADetect

File Analysis

File Analysis is an analytic process to determine a file's status. For example: virus, trojan, benign, malicious, trusted, unauthorized, sensitive, etc.

3 NIST1 mitigations99 inferred
Open technique →
D3-FCDetect

File Carving

Identifying and extracting files from network application protocols through the use of network stream reassembly software.

0 NIST0 mitigations2 inferred
Open technique →