D3-AZET — Authorization Event Thresholding
D3-AZET: Authorization Event Thresholding
MITRE D3FEND countermeasure
What it does
Collecting authorization events, creating a baseline user profile, and determining whether authorization events are consistent with the baseline profile.
Attacks this counters
No ATT&CK technique in this corpus maps to this countermeasure. D3FEND may map it to techniques outside the Enterprise matrix, or to ones MITRE has since revoked — absence here is about this corpus, not about the countermeasure.