Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

MITRE D3FEND™ Learning Center

Harden

The harden tactic is used to increase the opportunity cost of computer network exploitation. Hardening differs from Detection in that it generally is conducted before a system is online and operational.

55Techniques
6Top-level families

Top-level technique families

Start with the major branches.

These techniques sit directly beneath the Defensive Technique root and organize the more specific techniques in this tactic.

Complete tactic directory

Browse all 55 Harden techniques.

48 of 55 techniques shown
D3-AAHarden

Agent Authentication

Agent authentication is the process of verifying the identities of agents to ensure they are authorized and trustworthy participants within a system.

0 NIST0 mitigations38 inferred
Open technique →
D3-AHHarden

Application Hardening

Application Hardening makes an executable application more resilient to a class of exploits which either introduce new code or execute unwanted existing code. These techniques may be applied at compile-time or on an application binary.

2 NIST1 mitigations16 inferred
Open technique →
D3-CPHarden

Certificate Pinning

Persisting either a server's X.509 certificate or their public key and comparing that to server's presented identity to allow for greater client confidence in the remote server's identity for SSL connections.

0 NIST1 mitigations1 inferred
Open technique →
D3-CEROHarden

Certificate Rotation

Certificate rotation involves replacing digital certificates and their private keys to maintain cryptographic integrity and trust, mitigating key compromise risks and ensuring continuous secure communications.

0 NIST0 mitigations21 inferred
Open technique →
D3-CDPHarden

Change Default Password

Changing the default password means replacing the factory-set credentials with a strong, unique password before the device is deployed, preventing unauthorized access.

0 NIST0 mitigations20 inferred
Open technique →
D3-CROHarden

Credential Rotation

Credential rotation is a security procedure in which authentication credentials, such as passwords, API keys, or certificates, are regularly changed or replaced to minimize the risk of unauthorized access.

0 NIST0 mitigations21 inferred
Open technique →
D3-MHHarden

Message Hardening

The application of security controls to user-to-user and system-to-system communications so messages remain confidential, unaltered, and verifiable while resisting injection, replay, and tampering.

0 NIST0 mitigations0 inferred
Open technique →
D3-PWAHarden

Password Authentication

Password authentication is a security mechanism used to verify the identity of a user or entity attempting to access a system or resource by requiring the input of a secret string of characters, known as a password, that is associated with the user or entity.

0 NIST0 mitigations20 inferred
Open technique →
D3-PRHarden

Password Rotation

Password rotation is a security policy that mandates the periodic change of user account passwords to mitigate the risk of unauthorized access due to compromised credentials.

0 NIST0 mitigations20 inferred
Open technique →
D3-PHHarden

Platform Hardening

Hardening components of a Platform with the intention of making them more difficult to exploit. Platforms includes components such as: * BIOS UEFI Subsystems * Hardware security devices such as Trusted Platform Modules * Boot process logic or code * Kernel software components

5 NIST1 mitigations139 inferred
Open technique →
D3-RHHarden

Radiation Hardening

Radiation hardening is the process of making electronic components and circuits resistant to damage or malfunction caused by high levels of ionizing radiation.

0 NIST0 mitigations11 inferred
Open technique →