Umbra Wiki defense defense/D3-ANAA
Back to wiki

D3-ANAA — Administrative Network Activity Analysis

provenance: imported · ATT&CK: T1003 T1003.006 T1047 T1098 T1098.001 T1110 T1110.003 T1110.004 T1207 T1546 T1546.003 T1546.008

D3-ANAA: Administrative Network Activity Analysis

MITRE D3FEND countermeasure

What it does

Detection of unauthorized use of administrative network protocols by analyzing network activity against a baseline.

Attacks this counters

The chain in this corpus runs CVE → CWE → CAPEC → ATT&CK technique, which ends at what an adversary does. This is the hop after: what stops it.

Source