Umbra Wiki defense defense/D3-PA
Back to wiki

D3-PA — Process Analysis

provenance: imported

D3-PA: Process Analysis

MITRE D3FEND countermeasure

What it does

Process Analysis consists of observing a running application process and analyzing it to watch for certain behaviors or conditions which may indicate adversary activity. Analysis can occur inside of the process or through a third-party monitoring application. Examples include monitoring system and privileged calls, monitoring process initiation chains, and memory boundary allocations.

Attacks this counters

No ATT&CK technique in this corpus maps to this countermeasure. D3FEND may map it to techniques outside the Enterprise matrix, or to ones MITRE has since revoked — absence here is about this corpus, not about the countermeasure.

Source