D3-PA — Process Analysis
D3-PA: Process Analysis
MITRE D3FEND countermeasure
What it does
Process Analysis consists of observing a running application process and analyzing it to watch for certain behaviors or conditions which may indicate adversary activity. Analysis can occur inside of the process or through a third-party monitoring application. Examples include monitoring system and privileged calls, monitoring process initiation chains, and memory boundary allocations.
Attacks this counters
No ATT&CK technique in this corpus maps to this countermeasure. D3FEND may map it to techniques outside the Enterprise matrix, or to ones MITRE has since revoked — absence here is about this corpus, not about the countermeasure.