Account Locking
The process of temporarily disabling user accounts on a system or domain.
MITRE D3FEND™ Learning Center
The eviction tactic is used to remove an adversary from a computer network.
Top-level technique families
These techniques sit directly beneath the Defensive Technique root and organize the more specific techniques in this tactic.
Credential Eviction techniques disable or remove compromised credentials from a computer network.
3 direct child techniques →D3-OETerminate or remove an object from a host machine. This is the broadest class for object eviction.
5 direct child techniques →D3-PEProcess eviction techniques terminate or remove running process.
4 direct child techniques →Complete tactic directory
The process of temporarily disabling user accounts on a system or domain.
Removing tokens or credentials from an authentication cache to prevent further user associated account accesses.
Credential Eviction techniques disable or remove compromised credentials from a computer network.
Deleting a set of credentials permanently to prevent them from being used to authenticate.
Disk Erasure is the process of securely deleting all data on a disk to ensure that it cannot be recovered by any means.
Disk Formatting is the process of preparing a data storage device, such as a hard drive, solid-state drive, or USB flash drive, for initial use.
Disk Partitioning is the process of dividing a disk into multiple distinct sections, known as partitions.
Flushing DNS to clear any IP addresses or other DNS records from the cache.
The process of performing a takedown of the attacker's domain registration infrastructure.
The email removal technique deletes email files from system storage.
File eviction techniques delete files from system storage.
Initiating a host's reboot sequence to terminate all running processes.
Initiating a host's shutdown sequence to terminate all running processes.
Terminate or remove an object from a host machine. This is the broadest class for object eviction.
Process eviction techniques terminate or remove running process.
Suspending a running process on a computer system.
Terminating a running application process on a computer system.
Delete a registry key.
Forcefully end all active sessions associated with compromised accounts or devices.
Try a shorter term or clear the filters.