Active Certificate Analysis
Actively collecting PKI certificates by connecting to the server and downloading its server certificates for analysis.
MITRE D3FEND™ Learning Center
The detect tactic is used to identify adversary access to or unauthorized activity on computer networks.
Top-level technique families
These techniques sit directly beneath the Defensive Technique root and organize the more specific techniques in this tactic.
File Analysis is an analytic process to determine a file's status. For example: virus, trojan, benign, malicious, trusted, unauthorized, sensitive, etc.
4 direct child techniques →D3-IDAnalyzing identifier artifacts such as IP address, domain names, or URL(I)s.
4 direct child techniques →D3-MAAnalyzing email or instant message content to detect unauthorized activity.
2 direct child techniques →D3-NTAAnalyzing intercepted or summarized computer network traffic to detect unauthorized activity.
17 direct child techniques →D3-PHAMMonitoring the physical access of a specified environment through detection, recording, reviewing, and logging of who/what enters and exists areas.
4 direct child techniques →D3-PMMonitoring platform components such as operating systems software, hardware devices, or firmware.
9 direct child techniques →D3-PAProcess Analysis consists of observing a running application process and analyzing it to watch for certain behaviors or conditions which may indicate adversary activity. Analysis can occur inside of the process or through a third-party monitoring application. Examples include monitoring system and privileged calls, monitoring process initiation chains, and memory boundary allocations.
9 direct child techniques →D3-UBAUser behavior analytics ("UBA") as defined by Gartner, is a cybersecurity process about detection of insider threats, targeted attacks, and financial fraud. UBA solutions look at patterns of human behavior, and then apply algorithms and statistical analysis to detect meaningful anomalies from those patterns-anomalies that indicate potential threats.' Instead of tracking devices or security events, UBA tracks a system's users. Big data platforms are increasing UBA functionality by allowing them to analyze petabytes worth of data to detect insider threats and advanced persistent threats.
11 direct child techniques →Complete tactic directory
Actively collecting PKI certificates by connecting to the server and downloading its server certificates for analysis.
Detection of unauthorized use of administrative network protocols by analyzing network activity against a baseline.
Monitoring the failures of system counters and timers.
Monitoring the count and duration of the application or program cycle.
Analyzing application protocol level remote commands to detect unauthorized activity.
Collecting authentication events, creating a baseline user profile, and determining whether authentication events are consistent with the baseline profile.
Collecting authorization events, creating a baseline user profile, and determining whether authorization events are consistent with the baseline profile.
Analyzing sequences of bytes and determining if they likely represent malicious shellcode.
Analyzing Public Key Infrastructure certificates to detect if they have been misconfigured or spoofed using both network traffic, certificate fields and third-party logs.
Comparing client-server request and response payloads to a baseline profile to identify outliers.
Analyzing failed connections in a network to detect unauthorized activity.
Determining which credentials may have been compromised by analyzing the user logon history of a particular system.
Analyzing database queries to detect [SQL Injection](https://capec.mitre.org/data/definitions/66.html).
Analysis of domain name metadata, including name and DNS records, to determine whether the domain is likely to resolve to an undesirable host.
Monitoring the existence of or changes to Domain User Accounts.
Analyzing the reputation of a domain name.
Executing or opening a file in a synthetic "sandbox" environment to determine if the file is a malicious program or if the file exploits another program such as a document reader.
Monitoring electronic lock and door hardware states and access events (e.g., locked/unlocked, access granted/denied, door forced/held, tamper) to detect and respond to unauthorized entry.
Emulating instructions in a file looking for specific patterns.
Monitoring the security status of an endpoint by sending periodic messages with health status, where absence of a response may indicate that the endpoint has been compromised.
Analyzing the files accessed by a process to identify unauthorized activity.
File Analysis is an analytic process to determine a file's status. For example: virus, trojan, benign, malicious, trusted, unauthorized, sensitive, etc.
Identifying and extracting files from network application protocols through the use of network stream reassembly software.
Employing a pattern matching algorithm to statically analyze the content of files.
Employing a pattern matching rule language to analyze the content of files.
Analyzing the properties of file create system call invocations.
Analyzing the reputation of a file hash.
Employing file hash comparisons to detect known malware.
Detecting any suspicious changes to files in a computer system.
Analyzing the behavior of embedded code in firmware and looking for anomalous behavior and suspicious activity.
Monitoring code is injected into firmware for integrity monitoring of firmware and firmware data.
Cryptographically verifying firmware integrity.
Comparing strings using a variety of techniques to determine if a deceptive or malicious string is being presented to a user.
Taking known malicious identifiers and determining if they are present in a system.
Analyzing identifier artifacts such as IP address, domain names, or URL(I)s.
Analyzing the reputation of an identifier.
Analyzing inbound network session or connection attempt volume.
Analyzing vendor specific branch call recording in order to detect ROP style attacks.
Operating system level mechanisms to prevent abusive input device exploitation.
Analyzing the reputation of an IP address.
Analyzing standard inter process communication (IPC) protocols to detect deviations from normal protocol activity.
Detecting anomalies in user access patterns by comparing user access activity to behavioral profiles that categorize users by role such as job title, function, department.
Analyzing local user accounts to detect unauthorized activity.
Analyzing a call stack for return addresses which point to unexpected memory locations.
Analyzing email or instant message content to detect unauthorized activity.
Monitoring events from motion detectors (e.g., passive IR, microwave, dual-technology) to detect presence or movement within protected areas.
Analyzing intercepted or summarized computer network traffic to detect unauthorized activity.
Establishing baseline communities of network hosts and identifying statistically divergent inter-community communication.
Analyzing network traffic and compares it to known signatures
Detects operating modes such as Program, Run, Remote, or Stop.
The operating system software, for D3FEND's purposes, includes the kernel and its process management functions, hardware drivers, initialization or boot logic. It also includes and other key system daemons and their configuration. The monitoring or analysis of these components for unauthorized activity constitute **Operating System Monitoring**.
Monitoring physical parameters and operator actions related to an operational environment.
Collecting host certificates from network traffic or other passive sources like a certificate transparency log and analyzing them for unauthorized activity.
Detecting anomalies that indicate malicious activity by comparing the amount of data downloaded versus data uploaded by a host.
Cryptographically verifying peripheral firmware integrity.
Monitoring the physical access of a specified environment through detection, recording, reviewing, and logging of who/what enters and exists areas.
Monitoring platform components such as operating systems software, hardware devices, or firmware.
Monitor the amount of time since the last power cycle or restart.
Process Analysis consists of observing a running application process and analyzing it to watch for certain behaviors or conditions which may indicate adversary activity. Analysis can occur inside of the process or through a third-party monitoring application. Examples include monitoring system and privileged calls, monitoring process initiation chains, and memory boundary allocations.
Comparing the "text" or "code" memory segments to a source of truth.
Identification of suspicious processes executing on an end-point device by examining the ancestry and siblings of a process, and the associated metadata of each node on the tree, such as process execution, duration, and order relative to siblings and ancestors.
Detects processes that modify, change, or replace their own code at runtime.
Analyzing spawn arguments or attributes of a process to detect processes that are unauthorized.
Collecting network communication protocol metadata and identifying statistical outliers.
Monitoring events from proximity sensors that indicate a credential or tagged asset is within the sensor’s read range or a defined zone. Common enabling technologies include RFID, Bluetooth Low Energy (BLE), and Ultra-Wideband (UWB).
The detection of an internal host relaying traffic between the internal network and the external network.
Monitoring of remote firmware update commands to identify unauthorized software installations.
Detection of an unauthorized remote live terminal console session by examining network traffic to a network host.
Analyzing the resources accessed by a user to identify unauthorized activity.
Monitoring the activity of remote procedure calls in communication traffic to establish standard protocol operations and potential attacker activities.
Analysis of source files, processes, destination files, or destination servers associated with a scheduled job to detect unauthorized use of job scheduling.
Analyzing the execution of a script to detect unauthorized user activity.
Characterizing the reputation of mail transfer agents (MTA) to determine the security risk in emails.
Ascertaining sender reputation based on information associated with a message (e.g. email/instant messaging).
Analyzing changes in service binary files by comparing to a source of truth.
Analyzing the duration of user sessions in order to detect unauthorized activity.
Comparing a call stack in system memory with a shadow call stack maintained by the processor to determine unauthorized shellcode activity.
Analyzing system calls to determine whether a process is exhibiting unauthorized behavior.
Tracking changes to the state or configuration of critical system level processes.
Monitoring system files such as authentication databases, configuration files, system logs, and system executables for modification or tampering.
Cryptographically verifying installed system firmware integrity.
Analysis of any system process startup configuration.
Determining if a URL is benign or malicious by analyzing the URL or its components.
Analyzing the reputation of a URL.
User behavior analytics ("UBA") as defined by Gartner, is a cybersecurity process about detection of insider threats, targeted attacks, and financial fraud. UBA solutions look at patterns of human behavior, and then apply algorithms and statistical analysis to detect meaningful anomalies from those patterns-anomalies that indicate potential threats.' Instead of tracking devices or security events, UBA tracks a system's users. Big data platforms are increasing UBA functionality by allowing them to analyze petabytes worth of data to detect insider threats and advanced persistent threats.
Analyzing the amount of data transferred by a user.
Monitoring geolocation data of user logon attempts and comparing it to a baseline user behavior profile to identify anomalies in logon location.
Analyzing modifications to user session config files such as .bashrc or .bash_profile.
Monitoring of physical areas via camera video feeds to deter, detect, and investigate unauthorized access and related security events.
Monitoring changes in user web session behavior by comparing current web session activity to a baseline behavior profile or a catalog of predetermined malicious behavior.
Try a shorter term or clear the filters.