Defensive measures
272 pages, showing 1–100, ordered by identifier.
- D3-AA — Agent Authentication Agent authentication is the process of verifying the identities of agents to ensure they are authorized and...
- D3-ABPI — Application-based Process Isolation Application code which prevents its own subroutines from accessing intra-process / internal memory space.
- D3-ACA — Active Certificate Analysis Actively collecting PKI certificates by connecting to the server and downloading its server certificates for analysis.
- D3-ACH — Application Configuration Hardening Modifying an application's configuration to reduce its attack surface.
- D3-AEM — Application Exception Monitoring Monitoring the failures of system counters and timers.
- D3-AH — Application Hardening Application Hardening makes an executable application more resilient to a class of exploits which either introduce...
- D3-AI — Asset Inventory Asset inventorying identifies and records the organization's assets and enriches each inventory item with knowledge...
- D3-AL — Account Locking The process of temporarily disabling user accounts on a system or domain.
- D3-ALLM — Active Logical Link Mapping Active logical link mapping sends and receives network traffic as a means to map the whole data link layer, where...
- D3-AM — Access Modeling Access modeling captures and records the access permissions granted to identities (e.g., administrators, users,...
- D3-AMED — Access Mediation Access mediation is the process of granting or denying specific requests to: 1) obtain and use information and...
- D3-ANAA — Administrative Network Activity Analysis Detection of unauthorized use of administrative network protocols by analyzing network activity against a baseline.
- D3-ANCI — Authentication Cache Invalidation Removing tokens or credentials from an authentication cache to prevent further user associated account accesses.
- D3-ANET — Authentication Event Thresholding Collecting authentication events, creating a baseline user profile, and determining whether authentication events...
- D3-APA — Access Policy Administration Access policy administration is the systematic process of defining, implementing, and managing access control...
- D3-APCA — Application Protocol Command Analysis Analyzing application protocol level remote commands to detect unauthorized activity.
- D3-APLM — Active Physical Link Mapping Active physical link mapping sends and receives network traffic as a means to map the physical layer.
- D3-APM — Application Performance Monitoring Monitoring the count and duration of the application or program cycle.
- D3-ARMA — ARMA Model Autoregressive-moving-average (ARMA) models provide a parsimonious description of a (weakly) stationary stochastic...
- D3-AVE — Asset Vulnerability Enumeration Asset vulnerability enumeration enriches inventory items with knowledge identifying their vulnerabilities.
- D3-AZET — Authorization Event Thresholding Collecting authorization events, creating a baseline user profile, and determining whether authorization events are...
- D3-BA — Bootloader Authentication Cryptographically authenticating the bootloader software before system boot.
- D3-BAN — Biometric Authentication Using biological measures in order to authenticate a user.
- D3-BDI — Broadcast Domain Isolation Broadcast isolation restricts the number of computers a host can contact on their LAN.
- D3-BMA — Bus Message Authentication Applies cryptographic primitives to individual bus frames to verify the sender's identity and ensure the integrity...
- D3-BSE — Byte Sequence Emulation Analyzing sequences of bytes and determining if they likely represent malicious shellcode.
- D3-CA — Certificate Analysis Analyzing Public Key Infrastructure certificates to detect if they have been misconfigured or spoofed using both...
- D3-CAA — Connection Attempt Analysis Analyzing failed connections in a network to detect unauthorized activity.
- D3-CBAN — Certificate-based Authentication Requiring a digital certificate in order to authenticate a user.
- D3-CCSA — Credential Compromise Scope Analysis Determining which credentials may have been compromised by analyzing the user logon history of a particular system.
- D3-CDP — Change Default Password Changing the default password means replacing the factory-set credentials with a strong, unique password before the...
- D3-CE — Credential Eviction Credential Eviction techniques disable or remove compromised credentials from a computer network.
- D3-CERO — Certificate Rotation Certificate rotation involves replacing digital certificates and their private keys to maintain cryptographic...
- D3-CF — Content Filtering Content Filtering techniques aid in the process of analyzing an input file for malicious or erroneous content and...
- D3-CFC — Content Format Conversion Content format conversion is mechanical transformation from one format to another which may be normalization or...
- D3-CFI — Control Flow Integrity Enforcing legal control flow transfers during application process execution.
- D3-CH — Credential Hardening Credential Hardening techniques modify system or network properties in order to protect system or network/domain credentials.
- D3-CHN — Connected Honeynet A decoy service, system, or environment, that is connected to the enterprise network, and simulates or emulates...
- D3-CI — Configuration Inventory Configuration inventory identifies and records the configuration of software and hardware and their components...
- D3-CIA — Container Image Analysis Analyzing a Container Image with respect to a set of policies.
- D3-CM — Content Modification Modify content that does not comply with policy.
- D3-CNE — Content Excision Removing specific, potentially malicious, parts of content
- D3-CNR — Content Rebuild Rebuild the file according to the spec so any unreferenced components or objects are removed.
- D3-CNS — Content Substitution Modifies specific digital content information by replacing it with something else.
- D3-CP — Certificate Pinning Persisting either a server's X.509 certificate or their public key and comparing that to server's presented identity...
- D3-CQ — Content Quarantine Transfer content that does not comply with policy to a quarantine zone.
- D3-CR — Credential Revocation Deleting a set of credentials permanently to prevent them from being used to authenticate.
- D3-CRO — Credential Rotation Credential rotation is a security procedure in which authentication credentials, such as passwords, API keys, or...
- D3-CS — Credential Scrubbing The systematic removal of hard-coded credentials from source code to prevent accidental exposure and unauthorized access.
- D3-CSPP — Client-server Payload Profiling Comparing client-server request and response payloads to a baseline profile to identify outliers.
- D3-CTS — Credential Transmission Scoping Limiting the transmission of a credential to a scoped set of relying parties.
- D3-CV — Content Validation Verify and validate contents complies with policy
- D3-DA — Dynamic Analysis Executing or opening a file in a synthetic 'sandbox' environment to determine if the file is a malicious program or...
- D3-DAM — Domain Account Monitoring Monitoring the existence of or changes to Domain User Accounts.
- D3-DCE — Dead Code Elimination Removing unreachable or 'dead code' from compiled source code.
- D3-DE — Decoy Environment A Decoy Environment comprises hosts and networks for the purposes of deceiving an attacker.
- D3-DEM — Data Exchange Mapping Data exchange mapping identifies and models the organization's intended design for the flows of the data types,...
- D3-DENCR — Disk Encryption Encrypting a hard disk partition to prevent cleartext access to a file system.
- D3-DF — Decoy File A file created for the purposes of deceiving an adversary.
- D3-DI — Data Inventory Data inventorying identifies and records the schemas, formats, volumes, and locations of data stored and used on the...
- D3-DKE — Disk Erasure Disk Erasure is the process of securely deleting all data on a disk to ensure that it cannot be recovered by any means.
- D3-DKF — Disk Formatting Disk Formatting is the process of preparing a data storage device, such as a hard drive, solid-state drive, or USB...
- D3-DKP — Disk Partitioning Disk Partitioning is the process of dividing a disk into multiple distinct sections, known as partitions.
- D3-DLIC — Driver Load Integrity Checking Ensuring the integrity of drivers loaded during initialization of the operating system.
- D3-DLV — Domain Logic Validation Validation of variable state in the context of the domain application.
- D3-DNL — Directional Network Link Enforce one-way network communication by preventing two-way communication.
- D3-DNR — Decoy Network Resource Deploying a network resource for the purposes of deceiving an adversary.
- D3-DNRA — Domain Name Reputation Analysis Analyzing the reputation of a domain name.
- D3-DNSAL — DNS Allowlisting Permitting only approved domains and their subdomains to be resolved.
- D3-DNSCE — DNS Cache Eviction Flushing DNS to clear any IP addresses or other DNS records from the cache.
- D3-DNSDL — DNS Denylisting Blocking DNS Network Traffic based on criteria such as IP address, domain name, or DNS query type.
- D3-DNSTA — DNS Traffic Analysis Analysis of domain name metadata, including name and DNS records, to determine whether the domain is likely to...
- D3-DO — Decoy Object A Decoy Object is created and deployed for the purposes of deceiving attackers.
- D3-DP — Decoy Persona Establishing a fake online identity to misdirect, deceive, and or interact with adversaries.
- D3-DPLM — Direct Physical Link Mapping Direct physical link mapping creates a physical link map by direct observation and recording of the physical network links.
- D3-DPR — Decoy Public Release Issuing publicly released media to deceive adversaries.
- D3-DQSA — Database Query String Analysis Analyzing database queries to detect SQL Injection.
- D3-DRA — Disable Remote Access Limiting access to a computing device which is not required through or from a non-organization-controlled network.
- D3-DRT — Domain Registration Takedown The process of performing a takedown of the attacker's domain registration infrastructure.
- D3-DST — Decoy Session Token An authentication token created for the purposes of deceiving an adversary.
- D3-DTP — Domain Trust Policy Restricting inter-domain trust by modifying domain configuration.
- D3-DUC — Decoy User Credential A Credential created for the purpose of deceiving an adversary.
- D3-EAL — Executable Allowlisting Using a digital signature to authenticate a file before opening.
- D3-EBWSAM — Endpoint-based Web Server Access Mediation Endpoint-based web server access mediation regulates web server access directly from user endpoints by implementing...
- D3-EDL — Executable Denylisting Blocking the execution of files on a host in accordance with defined application policy rules.
- D3-EF — Email Filtering Filtering incoming email traffic based on specific criteria.
- D3-EFA — Emulated File Analysis Emulating instructions in a file looking for specific patterns.
- D3-EHB — Endpoint Health Beacon Monitoring the security status of an endpoint by sending periodic messages with health status, where absence of a...
- D3-EHPV — Exception Handler Pointer Validation Validates that a referenced exception handler pointer is a valid exception handler.
- D3-EI — Execution Isolation Execution Isolation techniques prevent application processes from accessing non-essential system resources, such as...
- D3-ELM — Electronic Lock Monitoring Monitoring electronic lock and door hardware states and access events (e.g., locked/unlocked, access granted/denied,...
- D3-EMH — Electromagnetic Radiation Hardening The application of physical and material-level design measures to electronic systems, components, or facilities to...
- D3-EPL — Physical Locking Employ a mechanical locking device for securing moveable portions of physical barriers (e.g., doors, gates, drawers)...
- D3-ER — Email Removal The email removal technique deletes email files from system storage.
- D3-ET — Encrypted Tunnels Encrypted encapsulation of routable network traffic.
- D3-FA — File Analysis File Analysis is an analytic process to determine a file's status. For example: virus, trojan, benign, malicious,...
- D3-FAPA — File Access Pattern Analysis Analyzing the files accessed by a process to identify unauthorized activity.
- D3-FBA — Firmware Behavior Analysis Analyzing the behavior of embedded code in firmware and looking for anomalous behavior and suspicious activity.
- D3-FC — File Carving Identifying and extracting files from network application protocols through the use of network stream reassembly software.
- D3-FCA — File Creation Analysis Analyzing the properties of file create system call invocations.
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.