Qortora · Search · Indexed page

d3fend.mitre.orgFetched 2026-08-17T11:02:37Z

MITRE D3FEND Knowledge Graph

D3FEND is a knowledge base of cybersecurity countermeasure techniques. In the simplest sense, it is a catalog of defensive cybersecurity techniques and their relationships to offensive/adversary techniques. The primary goal of the initial D3FEND release is to help standardize the vocabulary used to describe defensive cybersecurity technology functionality.

Open original source · Full cached text

D3FEND Matrix | MITRE D3FEND™ domains CAD ontology artifacts about resources contribute faq blog search D3FEND™ A knowledge graph of cybersecurity countermeasures 1.5.0 EnterpriseICSSPARTAMobileATLAS T1001 - Data Obfuscation T1001.001 - Junk Data T1001.002 - Steganography T1001.003 - Protocol or Service Impersonation T1003 - OS Credential Dumping T1003.001 - LSASS Memory T1003.002 - Security Account Manager T1003.003 - NTDS T1003.004 - LSA Secrets T1003.005 - Cached Domain Credentials T1003.006 - DCSync T1003.007 - Proc Filesystem T1003.008 - /etc/passwd and /etc/shadow T1005 - Data from Local System T1006 - Direct Volume Access T1007 - System Service Discovery T1008 - Fallback Channels T1010 - Application Window Discovery T1011 - Exfiltration Over Other Network Medium T1011.001 - Exfiltration Over Bluetooth T1012 - Query Registry T1014 - Rootkit T1016 - System Network Configuration Discovery T1016.001 - Internet Connection Discovery T1016.002 - Wi-Fi Discovery T1018 - Remote System Discovery T1020 - Automated Exfiltration T1020.001 - Traffic Duplication T1021 - Remote Services T1021.001 - Remote Desktop Protocol T1021.002 - SMB/Windows Admin Shares T1021.003 - Distributed Component Object Model T1021.004 - SSH T1021.005 - VNC T1021.006 - Windows Remote Management T1021.007 - Cloud Services T1021.008 - Direct Cloud VM Connections T1025 - Data from Removable Media T1027 - Obfuscated Files or Information T1027.001 - Binary Padding T1027.002 - Software Packing T1027.003 - Steganography T1027.004 - Compile After Delivery T1027.005 - Indicator Removal from Tools T1027.006 - HTML Smuggling T1027.007 - Dynamic API Resolution T1027.008 - Stripped Payloads T1027.009 - Embedded Payloads T1027.010 - Command Obfuscation T1027.011 - Fileless Storage T1027.012 - LNK Icon Smuggling T1027.013 - Encrypted/Encoded File T1027.014 - Polymorphic Code T1027.015 - Compression T1027.016 - Junk Code Insertion T1027.017 - SVG Smuggling T1027.018 - Invisible Unicode T1029 - Scheduled Transfer T1030 - Data Transfer Size Limits T1033 - System Owner/User Discovery T1036 - Masquerading T1036.001 - Invalid Code Signature T1036.002 - Right-to-Left Override T1036.003 - Rename Legitimate Utilities T1036.004 - Masquerade Task or Service T1036.005 - Match Legitimate Resource Name or Location T1036.006 - Space after Filename T1036.007 - Double File Extension T1036.008 - Masquerade File Type T1036.009 - Break Process Trees T1036.010 - Masquerade Account Name T1036.011 - Overwrite Process Arguments T1036.012 - Browser Fingerprint T1037 - Boot or Logon Initialization Scripts T1037.001 - Logon Script (Windows) T1037.002 - Login Hook T1037.003 - Network Logon Script T1037.004 - RC Scripts T1037.005 - Startup Items T1039 - Data from Network Shared Drive T1040 - Network Sniffing T1041 - Exfiltration Over C2 Channel T1046 - Network Service Discovery T1047 - Windows Management Instrumentation T1048 - Exfiltration Over Alternative Protocol T1048.001 - Exfiltration Over Symmetric Encrypted Non-C2 Protocol T1048.002 - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol T1049 - System Network Connections Discovery T1052 - Exfiltration Over Physical Medium T1052.001 - Exfiltration over USB T1053 - Scheduled Task/Job T1053.002 - At T1053.003 - Cron T1053.005 - Scheduled Task T1053.006 - Systemd Timers T1053.007 - Container Orchestration Job T1055 - Process Injection T1055.001 - Dynamic-link Library Injection T1055.002 - Portable Executable Injection T1055.003 - Thread Execution Hijacking T1055.004 - Asynchronous Procedure Call T1055.005 - Thread Local Storage T1055.008 - Ptrace System Calls T1055.009 - Proc Memory T1055.011 - Extra Window Memory Injection T1055.012 - Process Hollowing T1055.013 - Process Doppelgänging T1055.014 - VDSO Hijacking T1055.015 - ListPlanting T1056 - Input Capture T1056.001 - Keylogging T1056.002 - GUI Input Capture T1056.003 - Web Portal Capture T1056.004 - Credential API Hooking T1057 - Process Discovery T1059 - Command and Scripting Interpreter T1059.001 - PowerShell T1059.002 - AppleScript T1059.003 - Windows Command Shell T1059.004 - Unix Shell T1059.005 - Visual Basic T1059.006 - Python T1059.007 - JavaScript T1059.008 - Network Device CLI T1059.009 - Cloud API T1059.010 - AutoHotKey & AutoIT T1059.011 - Lua T1059.012 - Hypervisor CLI T1059.013 - Container CLI/API T1068 - Exploitation for Privilege Escalation T1069 - Permission Groups Discovery T1069.001 - Local Groups T1069.002 - Domain Groups T1069.003 - Cloud Groups T1070 - Indicator Removal T1070.003 - Clear Command History T1070.004 - File Deletion T1070.005 - Network Share Connection Removal T1070.006 - Timestomp T1070.007 - Clear Network Connection History and Configurations T1070.008 - Clear Mailbox Data T1070.009 - Clear Persistence T1070.010 - Relocate Malware T1071 - Application Layer Protocol T1071.001 - Web Protocols T1071.002 - File Transfer Protocols T1071.003 - Mail Protocols T1071.004 - DNS T1071.005 - Publish/Subscribe Protocols T1072 - Software Deployment Tools T1074 - Data Staged T1074.001 - Local Data Staging T1074.002 - Remote Data Staging T1078 - Valid Accounts T1078.001 - Default Accounts T1078.002 - Domain Accounts T1078.003 - Local Accounts T1078.004 - Cloud Accounts T1080 - Taint Shared Content T1082 - System Information Discovery T1083 - File and Directory Discovery T1087 - Account Discovery T1087.001 - Local Account T1087.002 - Domain Account T1087.003 - Email Account T1087.004 - Cloud Account T1090 - Proxy T1090.001 - Internal Proxy T1090.002 - External Proxy T1090.003 - Multi-hop Proxy T1090.004 - Domain Fronting T1091 - Replication Through Removable Media T1092 - Communication Through Removable Media T1095 - Non-Application Layer Protocol T1098 - Account Manipulation T1098.001 - Additional Cloud Credentials T1098.002 - Additional Email Delegate Permissions T1098.003 - Additional Cloud Roles T1098.004 - SSH Authorized Keys T1098.005 - Device Registration T1098.006 - Additional Container Cluster Roles T1098.007 - Additional Local or Domain Groups T1102 - Web Service T1102.001 - Dead Drop Resolver T1102.002 - Bidirectional Communication T1102.003 - One-Way Communication T1104 - Multi-Stage Channels T1105 - Ingress Tool Transfer T1106 - Native API T1110 - Brute Force T1110.001 - Password Guessing T1110.002 - Password Cracking T1110.003 - Password Spraying T1110.004 - Credential Stuffing T1111 - Multi-Factor Authentication Interception T1112 - Modify Registry T1113 - Screen Capture T1114 - Email Collection T1114.001 - Local Email Collection T1114.002 - Remote Email Collection T1114.003 - Email Forwarding Rule T1115 - Clipboard Data T1119 - Automated Collection T1120 - Peripheral Device Discovery T1123 - Audio Capture T1124 - System Time Discovery T1125 - Video Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - MSBuild T1127.002 - ClickOnce T1127.003 - JamPlus T1129 - Shared Modules T1132 - Data Encoding T1132.001 - Standard Encoding T1132.002 - Non-Standard Encoding T1133 - External Remote Services T1134 - Access Token Manipulation T1134.001 - Token Impersonation/Theft T1134.002 - Create Process with Token T1134.003 - Make and Impersonate Token T1134.004 - Parent PID Spoofing T1134.005 - SID-History Injection T1135 - Network Share Discovery T1136 - Create Account T1136.001 - Local Account T1136.002 - Domain Account T1136.003 - Cloud Account T1137 - Office Application Startup T1137.001 - Office Template Macros T1137.002 - Office Test T1137.003 - Outlook Forms T1137.004 - Outlook Home Page T1137.005 - Outlook Rules T1137.006 - Add-ins T1140 - Deobfuscate/Decode Files or Information T1176 - Software Extensions T1176.001 - Browser Extensions T1176.002 - IDE Extensions T1185 - Browser Session Hijacking T1187 - Forced Authentication T1189 - Drive-by Compromise T1190 - Exploit Public-Facing Application T1195 - Supply Chain Compromise T1195.001 - Compromise Software Dependencies and Development Tools T1195.002 - Compromise Software Supply Chain T1195.003 - Compromise Hardware Supply Chain T1197 - BITS Jobs T1199 - Trusted Relationship T1200 - Hardware Additions T1201 - Password Policy Discovery T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1204.001 - Malicious Link T1204.002 - Malicious File T1204.003 - Malicious Image T1204.004 - Malicious Copy and Paste T1204.005 - Malicious Library T1205 - Traffic Signaling T1205.001 - Port Knocking T1205.002 - Socket Filters T1207 - Rogue Domain Controller T1210 - Exploitation of Remote Services T1211 - Exploitation for Stealth T1212 - Exploitation for Credential Access T1213 - Data from Information Repositories T1213.001 - Confluence T1213.002 - Sharepoint T1213.003 - Code Repositories T1213.004 - Customer Relationship Management Software T1213.005 - Messaging Applications T1213.006 - Databases T1216 - System Script Proxy Execution T1216.001 - PubPrn T1216.002 - SyncAppvPublishingServer T1217 - Browser Information Discovery T1218 - System Binary Proxy Execution T1218.001 - Compiled HTML File T1218.002 - Control Panel T1218.003 - CMSTP T1218.004 - InstallUtil T1218.005 - Mshta T1218.007 - Msiexec T1218.008 - Odbcconf T1218.009 - Regsvcs/Regasm T1218.010 - Regsvr32 T1218.011 - Rundll32 T1218.012 - Verclsid T1218.013 - Mavinject T1218.014 - MMC T1218.015 - Electron Applications T1219 - Remote Access Tools T1219.001 - IDE Tunneling T1219.002 - Remote Desktop Software T1219.003 - Remote Access Hardware T1220 - XSL Script Processing T1221 - Template Injection T1222 - File and Directory Permissions Modification T1222.001 - Windows Permissions T1222.002 - Linux and Mac Permissions T1480 - Execution Guardrails T1480.001 - Environmental Keying T1480.002 - Mutual Exclusion T1482 - Domain Trust Discovery T1484 - Domain or Tenant Policy Modification T1484.001 - Group Policy Modification T1484.002 - Trust Modification T1485 - Data Destruction T1485.001 - Lifecycle-Triggered Deletion T1486 - Data Encrypted for Impact T1489 - Service Stop T1490 - Inhibit System Recovery T1491 - Defacement T1491.001 - Internal Defacement T1491.002 - External Defacement T1495 - Firmware Corruption T1496 - Resource Hijacking T1496.001 - Compute Hijacking T1496.002 - Bandwidth Hijacking T1496.003 - SMS Pumping T1496.004 - Cloud Service Hijacking T1497 - Virtualization/Sandbox Evasion T1497.001 - System Checks T1497.002 - User Activity Based Checks T1497.003 - Time Based Checks T1498 - Network Denial of Service T1498.001 - Direct Network Flood T1498.002 - Reflection Amplification T1499 - Endpoint Denial of Service T1499.001 - OS Exhaustion Flood T1499.002 - Service Exhaustion Flood T1499.003 - Application Exhaustion Flood T1499.004 - Application or System Exploitation T1505 - Server Software Component T1505.001 - SQL Stored Procedures T1505.002 - Transport Agent T1505.003 - Web Shell T1505.004 - IIS Components T1505.005 - Terminal Services DLL T1505.006 - vSphere Installation Bundles T1518 - Software Discovery T1518.001 - Security Software Discovery T1518.002 - Backup Software Discovery T1525 - Implant Internal Image T1526 - Cloud Service Discovery T1528 - Steal Application Access Token T1529 - System Shutdown/Reboot T1530 - Data from Cloud Storage T1531 - Account Access Removal T1534 - Internal Spearphishing T1535 - Unused/Unsupported Cloud Regions T1537 - Transfer Data to Cloud Account T1538 - Cloud Service Dashboard T1539 - Steal Web Session Cookie T1542 - Pre-OS Boot T1542.001 - System Firmware T1542.002 - Component Firmware T1542.003 - Bootkit T1542.004 - ROMMONkit T1542.005 - TFTP Boot T1543 - Create or Modify System Process T1543.001 - Launch Agent T1543.002 - Systemd Service T1543.003 - Windows Service T1543.004 - Launch Daemon T1543.005 - Container Service T1546 - Event Triggered Execution T1546.001 - Change Default File Association T1546.002 - Screensaver T1546.003 - Windows Management Instrumentation Event Subscription T1546.004 - Unix Shell Configuration Modification T…