Umbra Wiki defense defense/D3-EFA
Back to wiki

D3-EFA — Emulated File Analysis

provenance: imported · ATT&CK: T1016 T1016.001 T1016.002 T1027 T1027.001 T1027.002 T1027.004 T1036 T1036.001 T1036.003 T1037 T1037.001 T1037.002 T1037.003 T1037.004 T1055 T1055.003 T1059 T1059.001 T1059.002 T1059.003 T1059.004 T1059.005 T1059.006 T1059.007 T1059.008 T1059.009 T1059.010 T1059.011 T1059.012 T1059.013 T1114 T1114.001 T1137 T1137.001 T1137.003 T1140 T1204 T1204.002 T1218 T1218.005 T1220 T1505 T1505.003 T1534 T1546 T1546.002 T1546.005 T1546.006 T1546.008 T1546.013 T1546.015 T1547 T1547.001 T1547.009 T1548 T1548.002 T1564 T1564.007 T1565 T1565.003 T1566 T1566.001 T1566.002 T1574 T1574.007 T1574.008 T1574.009

D3-EFA: Emulated File Analysis

MITRE D3FEND countermeasure

What it does

Emulating instructions in a file looking for specific patterns.

Attacks this counters

The chain in this corpus runs CVE → CWE → CAPEC → ATT&CK technique, which ends at what an adversary does. This is the hop after: what stops it.

Source