Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

MITRE D3FEND™ Learning Center

Model

The model tactic is used to apply security engineering, vulnerability, threat, and risk analyses to digital systems. This is accomplished by creating and maintaining a common understanding of the systems being defended, the operations on those systems, actors using the systems, and the relationships and interactions between these elements.

27Techniques
4Top-level families

Complete tactic directory

Browse all 27 Model techniques.

27 of 27 techniques shown
D3-AMModel

Access Modeling

Access modeling captures and records the access permissions granted to identities (e.g., administrators, users, groups, systems) and optionally includes details on how these identities are stored, managed, and shared across systems.

0 NIST0 mitigations24 inferred
Open technique →
D3-ALLMModel

Active Logical Link Mapping

Active logical link mapping sends and receives network traffic as a means to map the whole data link layer, where the links represent logical data flows rather than physical connection

0 NIST0 mitigations7 inferred
Open technique →
D3-AIModel

Asset Inventory

Asset inventorying identifies and records the organization's assets and enriches each inventory item with knowledge about their vulnerabilities.

0 NIST0 mitigations120 inferred
Open technique →
D3-DEMModel

Data Exchange Mapping

Data exchange mapping identifies and models the organization's intended design for the flows of the data types, formats, and volumes between systems at the application layer.

0 NIST0 mitigations0 inferred
Open technique →
D3-DIModel

Data Inventory

Data inventorying identifies and records the schemas, formats, volumes, and locations of data stored and used on the organization's architecture.

0 NIST0 mitigations29 inferred
Open technique →
D3-NMModel

Network Mapping

Network mapping encompasses the techniques to identify and model the physical layer, network layer, and data exchange layers of the organization's network and their physical location, and determine allowed pathways through that network.

0 NIST0 mitigations15 inferred
Open technique →
D3-NNIModel

Network Node Inventory

Network node inventorying identifies and records all the network nodes (hosts, routers, switches, firewalls, etc.) in the organization's architecture.

0 NIST0 mitigations7 inferred
Open technique →
D3-NVAModel

Network Vulnerability Assessment

Network vulnerability assessment relates all the vulnerabilities of a network's components in the context of their configuration and interdependencies and can also include assessing risk emerging from the network's design as a whole, not just the sum of individual network node or network segment vulnerabilities.

0 NIST0 mitigations0 inferred
Open technique →
D3-OAMModel

Operational Activity Mapping

Operational activity mapping identifies activities of the organization and the organization's suborganizations, groups, roles, and individuals that carry out the activities and then establishes the dependencies of the activities on the systems and people that perform those activities.

0 NIST0 mitigations24 inferred
Open technique →
D3-ODMModel

Operational Dependency Mapping

Operational dependency mapping identifies and models the dependencies of the organization's activities on each other and on the organization's performers (people, systems, and services.) This may include modeling the higher- and lower-level activities of an organization forming a hierarchy, or layering, of the dependencies in an organization's activities.

0 NIST0 mitigations0 inferred
Open technique →
D3-PLLMModel

Passive Logical Link Mapping

Passive logical link mapping only listens to network traffic as a means to map the whole data link layer, where the links represent logical data flows rather than physical connections.

0 NIST0 mitigations7 inferred
Open technique →
D3-SYSMModel

System Mapping

System mapping encompasses the techniques to identify the organization's systems, how they are configured and decomposed into subsystems and components, how they are dependent on one another, and where they are physically located.

0 NIST0 mitigations1 inferred
Open technique →
D3-SYSVAModel

System Vulnerability Assessment

System vulnerability assessment relates all the vulnerabilities of a system's components in the context of their configuration and internal dependencies and can also include assessing risk emerging from the system's design as a whole, not just the sum of individual component vulnerabilities.

0 NIST0 mitigations1 inferred
Open technique →