Umbra Wiki defense defense/D3-CAA
Back to wiki

D3-CAA — Connection Attempt Analysis

provenance: imported · ATT&CK: T1003 T1003.006 T1021 T1021.001 T1021.002 T1021.003 T1021.004 T1021.005 T1021.006 T1021.007 T1021.008 T1047 T1090 T1090.001 T1098 T1098.001 T1110 T1110.003 T1110.004 T1197 T1199 T1207 T1210 T1546 T1546.003 T1546.008 T1557 T1557.001 T1570

D3-CAA: Connection Attempt Analysis

MITRE D3FEND countermeasure

What it does

Analyzing failed connections in a network to detect unauthorized activity.

Attacks this counters

The chain in this corpus runs CVE → CWE → CAPEC → ATT&CK technique, which ends at what an adversary does. This is the hop after: what stops it.

Source