Umbra Wiki defense defense/D3-CCSA
Back to wiki

D3-CCSA — Credential Compromise Scope Analysis

provenance: imported · ATT&CK: T1003 T1003.003 T1003.005 T1003.008 T1098 T1098.001 T1110 T1110.001 T1110.002 T1110.003 T1134 T1134.001 T1134.002 T1134.003 T1528 T1539 T1550 T1550.001 T1550.004 T1552 T1552.001 T1552.002 T1552.003 T1552.004 T1552.005 T1552.006 T1552.007 T1552.008 T1558 T1558.001 T1558.002 T1558.003 T1558.004 T1558.005 T1606 T1606.001 T1606.002

D3-CCSA: Credential Compromise Scope Analysis

MITRE D3FEND countermeasure

What it does

Determining which credentials may have been compromised by analyzing the user logon history of a particular system.

Attacks this counters

The chain in this corpus runs CVE → CWE → CAPEC → ATT&CK technique, which ends at what an adversary does. This is the hop after: what stops it.

Source