ASOM-Fedv6.1Open the explorer
Reference · MITRE D3FEND

D3FEND Is a Better Parts Catalog. This Is Where the Parts Go.

D3FEND catalogs 272 defensive countermeasures, and its taxonomy is more granular than anything here. ASOM-Fed is not a rival catalog — it is a scheme for arraying one. So the useful question is not which is bigger, it is whether every part in the catalog has somewhere to sit in the scheme.

D3FEND v1.5.0 · 432 technique-to-technique mappings · every figure on this page computed from the published register

The Number

240 of 272, and a Reason for the Rest.

The denominator is the whole point. A coverage claim that lists only what it covers is the shape of a document that overstates itself, so the full D3FEND register is published alongside the mapping and this page counts against it.

272In D3FENDVersion 1.5.0
240Reached88% of the catalog
432MappingsFrom 148 techniques
32Not reachedEach with a reason

4 of the seven tactics are reached in full. The shortfall is concentrated in Harden at 63%, and it is not an oversight — most of what sits there is configuration hardening inherited from the SP 800-53 baseline, which a scheme of maneuver assumes rather than schedules. Every gap is listed below with the reason it is a gap.

New to this vocabulary? The framework fixes 10 object classes, and four of them are ordinary English words doing exact work. The object model states each one with the question it answers and the class it is most often mistaken for.

By Tactic

Where the Coverage Sits, and Where It Does Not.

D3FEND's seven tactics are not a sequence and do not map onto the six campaign phases. They are kinds of countermeasure, which is exactly why a scheme of maneuver has to reach all of them.

Model

27/27

100% reached · complete

Harden

35/56

63% reached · 21 not reached

Detect

80/90

89% reached · 10 not reached

Isolate

56/57

98% reached · 1 not reached

Deceive

11/11

100% reached · complete

Evict

19/19

100% reached · complete

Restore

12/12

100% reached · complete

The Join

Every Mapping, Both Directions.

The join is technique-to-technique. Mapping ASOM-Fed's controls onto D3FEND would cross abstraction levels — a control is an assessable obligation, a D3FEND technique is a countermeasure, and the thing with a countermeasure's shape here is the technique.

ASOM-Fed techniqueReaches
M1.01 External Attack Surface EnumerationD3-AI Asset InventoryD3-NM Network MappingD3-NVA Network Vulnerability AssessmentD3-SYSVA System Vulnerability Assessment
M1.02 Shadow and Forgotten Asset DiscoveryD3-AI Asset InventoryD3-CI Configuration InventoryD3-DI Data InventoryD3-NNI Network Node InventoryD3-SWI Software Inventory
M1.03 Certificate and Domain WatchD3-HD Homoglyph DetectionD3-DNRA Domain Name Reputation AnalysisD3-ACA Active Certificate AnalysisD3-PCA Passive Certificate Analysis
M1.04 Perimeter Canary TokensD3-DO Decoy ObjectD3-DNR Decoy Network Resource
M1.05 Authentication Geography BaselineD3-ID Identifier AnalysisD3-IAA Identifier Activity AnalysisD3-UBA User Behavior AnalysisD3-UGLPA User Geolocation Logon Pattern Analysis
M1.06 Credential Exposure MonitoringD3-IRA Identifier Reputation AnalysisD3-CCSA Credential Compromise Scope Analysis
M1.07 Partner and Advisory IntakeD3-AVE Asset Vulnerability EnumerationD3-ORA Operational Risk Assessment
M1.08 Public Service Abuse TelemetryD3-FA File AnalysisD3-FCOA File Content AnalysisD3-CSPP Client-server Payload ProfilingD3-CAA Connection Attempt AnalysisD3-ISVA Inbound Session Volume AnalysisD3-WSAA Web Session Activity Analysis
M1.09 Supply Chain and Vendor WatchD3-ODM Operational Dependency MappingD3-SVCDM Service Dependency Mapping
M1.10 Named-Campaign Indicator WatchD3-IRA Identifier Reputation AnalysisD3-NTSA Network Traffic Signature Analysis
M1.11 Operational Technology Asset DiscoveryD3-AI Asset InventoryD3-HCI Hardware Component InventoryD3-NNI Network Node InventoryD3-PLLM Passive Logical Link MappingD3-RFUM Remote Firmware Update MonitoringD3-IDA Input Device Analysis
M1.12 Workforce Credential Exposure MonitoringD3-OM Organization MappingD3-IRA Identifier Reputation AnalysisD3-CCSA Credential Compromise Scope Analysis
M1.13 Physical Access Anomaly DetectionD3-PLM Physical Link MappingD3-APLM Active Physical Link MappingD3-DPLM Direct Physical Link MappingD3-PHAM Physical Access MonitoringD3-ELM Electronic Lock MonitoringD3-MSM Motion Sensor MonitoringD3-PSM Proximity Sensor MonitoringD3-VS Video Surveillance
M1.14 Supplier Exposure MonitoringD3-AVE Asset Vulnerability EnumerationD3-CIA Container Image AnalysisD3-SWI Software Inventory
M1.15 Device Estate DiscoveryD3-AI Asset InventoryD3-HCI Hardware Component InventoryD3-NNI Network Node InventoryD3-SWI Software InventoryD3-EHB Endpoint Health Beacon
M2.01 Trust Zone ArchitectureD3-NI Network IsolationD3-BDI Broadcast Domain Isolation
M2.02 Policy Enforcement Point PlacementD3-ACMD Access MediationD3-NAM Network Access Mediation
M2.03 Crown-Jewel EnclaveD3-NRAM Network Resource Access MediationD3-NI Network Isolation
M2.04 Independent Control RedundancyD3-SVCDM Service Dependency MappingD3-SYSDM System Dependency Mapping
M2.05 Endpoint Detection and Response CoverageD3-FIM File Integrity MonitoringD3-OSM Operating System MonitoringD3-EHB Endpoint Health BeaconD3-MBT Memory Boundary TrackingD3-SFA System File AnalysisD3-PA Process AnalysisD3-PCSV Process Code Segment Verification
M2.06 Device Posture GatingD3-AA Agent AuthenticationD3-NAM Network Access Mediation
M2.07 Web Application ProtectionD3-DA Dynamic AnalysisD3-EFA Emulated File AnalysisD3-BSE Byte Sequence EmulationD3-WSAM Web Session Access MediationD3-EBWSAM Endpoint-based Web Server Access MediationD3-PBWSAM Proxy-based Web Server Access MediationD3-CF Content FilteringD3-ITF Inbound Traffic Filtering
M2.08 API Authorization EnforcementD3-NRAM Network Resource Access MediationD3-APA Access Policy Administration
M2.09 Data-at-Rest Encryption and Key SeparationD3-DENCR Disk EncryptionD3-FE File Encryption
M2.10 Egress Data Loss PreventionD3-DEM Data Exchange MappingD3-UDTA User Data Transfer AnalysisD3-CF Content FilteringD3-CM Content ModificationD3-CNE Content ExcisionD3-CQ Content QuarantineD3-OTF Outbound Traffic Filtering
M2.11 Workload Hardening BaselineD3-AH Application HardeningD3-ACH Application Configuration HardeningD3-PH Platform HardeningD3-SCP System Configuration PermissionsD3-SCF System Call Filtering
M2.12 Secrets ManagementD3-CH Credential HardeningD3-CRO Credential RotationD3-CS Credential ScrubbingD3-ANCI Authentication Cache Invalidation
M2.13 Backup Isolation and ImmutabilityD3-BA Bootloader AuthenticationD3-DLIC Driver Load Integrity CheckingD3-HBWP Hardware-based Write ProtectionD3-TBI TPM Boot IntegrityD3-RDI Restore Disk Image
M2.14 Control Failure DetectionD3-PM Platform MonitoringD3-EHB Endpoint Health BeaconD3-SDM System Daemon Monitoring
M2.15 Safety Instrumented Layer IntegrityD3-MAN Message AuthenticationD3-BMA Bus Message AuthenticationD3-MENCR Message EncryptionD3-TAAN Transfer Agent AuthenticationD3-OMM Operating Mode MonitoringD3-OPR Operating Mode Restriction
M2.16 Role-Based Privilege MinimizationD3-UAP User Account PermissionsD3-UGPH User Group Permissions
M2.17 Facility Defense in DepthD3-PEH Physical Enclosure HardeningD3-PAM Physical Access MediationD3-EPL Physical Locking
M2.18 Component Provenance VerificationD3-CIA Container Image AnalysisD3-SWI Software InventoryD3-TL Trusted Library
M3.01 Phishing-Resistant AuthenticationD3-CBAN Certificate-based AuthenticationD3-MFA Multi-factor AuthenticationD3-TBA Token-based Authentication
M3.02 Conditional Access Policy EngineD3-ACMD Access MediationD3-APA Access Policy Administration
M3.03 Continuous AuthorizationD3-AZET Authorization Event ThresholdingD3-APA Access Policy Administration
M3.04 Just-in-Time PrivilegeD3-CRO Credential RotationD3-UAP User Account Permissions
M3.05 Privileged Access WorkstationsD3-PH Platform HardeningD3-EI Execution IsolationD3-ABPI Application-based Process IsolationD3-HBPI Hardware-based Process IsolationD3-KBPI Kernel-based Process Isolation
M3.06 Machine and Service Identity GovernanceD3-AA Agent AuthenticationD3-CP Certificate PinningD3-CRO Credential RotationD3-CERO Certificate Rotation
M3.07 Standing Privilege EliminationD3-UAP User Account PermissionsD3-UGPH User Group Permissions
M3.08 Identity Lifecycle EnforcementD3-AL Account LockingD3-CR Credential Revocation
M3.09 External-User Identity AssuranceD3-BAN Biometric AuthenticationD3-MFA Multi-factor AuthenticationD3-PWA Password AuthenticationD3-OTP One-time PasswordD3-SPP Strong Password PolicyD3-CDP Change Default Password
M3.10 Device-Bound CredentialsD3-CBAN Certificate-based AuthenticationD3-CP Certificate PinningD3-TB Token Binding
M3.11 Session and Token Revocation PathD3-ANCI Authentication Cache InvalidationD3-CR Credential RevocationD3-ST Session Termination
M3.12 Authorization Policy as CodeD3-APA Access Policy AdministrationD3-LFP Local File PermissionsD3-UGPH User Group Permissions
M3.13 Federation Trust Boundary ControlD3-DTP Domain Trust Policy
M3.14 Entitlement RecertificationD3-JFAPA Job Function Access Pattern AnalysisD3-UAP User Account Permissions
M3.15 Break-Glass Account ControlD3-ANET Authentication Event ThresholdingD3-AL Account Locking
M3.16 Token Replay ProtectionD3-TB Token BindingD3-CTS Credential Transmission Scoping
M3.17 Authentication Anomaly ScoringD3-UBA User Behavior AnalysisD3-ANET Authentication Event ThresholdingD3-UGLPA User Geolocation Logon Pattern Analysis
M3.18 Identity Provider Tamper DetectionD3-SICA System Init Config AnalysisD3-DAM Domain Account Monitoring
M3.19 Human-to-Account BindingD3-DAM Domain Account MonitoringD3-LAM Local Account Monitoring
M3.20 Supplier Identity FederationD3-NAM Network Access MediationD3-DTP Domain Trust Policy
M4.01 MicrosegmentationD3-NI Network IsolationD3-BDI Broadcast Domain Isolation
M4.02 East-West Deny by DefaultD3-NI Network IsolationD3-NTF Network Traffic Filtering
M4.03 Egress Filtering and Allow-ListingD3-CF Content FilteringD3-CFC Content Format ConversionD3-OTF Outbound Traffic Filtering
M4.04 DNS Control and SinkholingD3-DNSAL DNS AllowlistingD3-DNSDL DNS DenylistingD3-FRDDL Forward Resolution Domain DenylistingD3-HDDL Hierarchical Domain DenylistingD3-HDL Homoglyph Denylisting
M4.05 Application Allow-ListingD3-SCF System Call FilteringD3-ABPI Application-based Process IsolationD3-EAL Executable AllowlistingD3-EDL Executable Denylisting
M4.06 Administrative Path RestrictionD3-NAM Network Access MediationD3-LAMED LAN Access MediationD3-RAM Routing Access Mediation
M4.07 Cloud Boundary EnforcementD3-APA Access Policy AdministrationD3-NI Network Isolation
M4.08 Instrumented Corridor DesignD3-NTA Network Traffic AnalysisD3-NI Network Isolation
M4.09 Removable Media ControlD3-IOPR IO Port RestrictionD3-LFAM Local File Access MediationD3-LFP Local File Permissions
M4.10 Bastion and Jump-Host EnforcementD3-NAM Network Access MediationD3-RFAM Remote File Access Mediation
M4.11 Protocol and Port RestrictionD3-NTF Network Traffic FilteringD3-ITF Inbound Traffic Filtering
M4.12 Denied-Path Register EnforcementD3-NTPM Network Traffic Policy MappingD3-NTF Network Traffic Filtering
M4.13 Operational Technology SegregationD3-NI Network IsolationD3-BDI Broadcast Domain IsolationD3-DNL Directional Network Link
M4.14 Control Protocol ConstraintD3-APCA Application Protocol Command AnalysisD3-CTS Credential Transmission ScopingD3-OPR Operating Mode RestrictionD3-OVAR OT Variable Access Restriction
M4.15 Physical Zone SegregationD3-PAM Physical Access MediationD3-EPL Physical Locking
M4.16 Maintenance Access ConstraintD3-DRA Disable Remote AccessD3-IOPR IO Port RestrictionD3-NAM Network Access Mediation
M4.17 Supplier Access CanalisationD3-NAM Network Access MediationD3-NRAM Network Resource Access Mediation
M5.01 Decoy Records in the Data LayerD3-DO Decoy ObjectD3-DF Decoy File
M5.02 Honeytokens in Document StoresD3-DO Decoy ObjectD3-DF Decoy File
M5.03 Decoy CredentialsD3-DUC Decoy User Credential
M5.04 Honeypot Services in CorridorsD3-CHN Connected HoneynetD3-DNR Decoy Network Resource
M5.05 Canary Files on EndpointsD3-DF Decoy File
M5.06 Decoy Service EndpointsD3-DNR Decoy Network Resource
M5.07 Identity-Plane DeceptionD3-DP Decoy PersonaD3-DST Decoy Session TokenD3-DUC Decoy User Credential
M5.08 Decoy Cloud ResourcesD3-DO Decoy ObjectD3-DNR Decoy Network Resource
M5.09 Deception Alert RoutingD3-DE Decoy Environment
M5.10 Deception Coverage MeasurementD3-DE Decoy Environment
M5.11 Control Network DeceptionD3-IHN Integrated HoneynetD3-DNR Decoy Network Resource
M5.12 Phishing Deception and ReportingD3-EF Email FilteringD3-DP Decoy PersonaD3-DPR Decoy Public Release
M5.13 Physical DeceptionD3-SHN Standalone HoneynetD3-DO Decoy Object
M6.01 Adaptive Rate LimitingD3-ISVA Inbound Session Volume AnalysisD3-ITF Inbound Traffic Filtering
M6.02 Step-Up Authentication on AnomalyD3-MFA Multi-factor AuthenticationD3-OTP One-time PasswordD3-ANET Authentication Event Thresholding
M6.03 Bulk Export ThrottlingD3-UDTA User Data Transfer AnalysisD3-OTF Outbound Traffic Filtering
M6.04 Session Duration Reduction Under AlertD3-SDA Session Duration AnalysisD3-ANCI Authentication Cache InvalidationD3-ST Session Termination
M6.05 Approval Gates on High-Impact ActionsD3-APA Access Policy AdministrationD3-UAP User Account Permissions
M6.06 Tarpitting and Response DelayD3-ITF Inbound Traffic Filtering
M6.07 Progressive LockoutD3-ANET Authentication Event ThresholdingD3-AL Account Locking
M6.08 Change and Deploy Freeze Under ContactD3-SU Software Update
M6.09 Query Complexity LimitsD3-DLV Domain Logic ValidationD3-DQSA Database Query String AnalysisD3-CV Content Validation
M6.10 Update Staging and SoakD3-SWI Software InventoryD3-SU Software Update
M7.01 Hypothesis-Driven HuntingD3-NTA Network Traffic AnalysisD3-PA Process AnalysisD3-UBA User Behavior Analysis
M7.02 Fusion-Fed Hunt BacklogD3-ORA Operational Risk Assessment
M7.03 Automated Containment PlaybooksD3-NI Network IsolationD3-PT Process TerminationD3-ST Session Termination
M7.04 Host Isolation on ConfirmationD3-NI Network IsolationD3-HS Host ShutdownD3-HR Host Reboot
M7.05 Credential Reset SweepD3-CRO Credential RotationD3-CR Credential RevocationD3-RIC Reissue Credential
M7.06 Build Pipeline Integrity HuntD3-CIA Container Image AnalysisD3-SBV Service Binary VerificationD3-SEA Script Execution AnalysisD3-CNR Content RebuildD3-CNS Content Substitution
M7.07 Persistence SweepD3-SJA Scheduled Job AnalysisD3-SDM System Daemon MonitoringD3-SICA System Init Config AnalysisD3-USICA User Session Init Config AnalysisD3-IBCA Indirect Branch Call AnalysisD3-PSMD Process Self-Modification DetectionD3-SSC Shadow Stack ComparisonsD3-RKD Registry Key Deletion
M7.08 Lateral Path AuditD3-NM Network MappingD3-LLM Logical Link MappingD3-ALLM Active Logical Link MappingD3-AM Access Modeling
M7.09 Detection Engineering from HuntD3-FCR File Content RulesD3-NTSA Network Traffic Signature Analysis
M7.10 Purple-Team ValidationD3-NVA Network Vulnerability AssessmentD3-SYSVA System Vulnerability Assessment
M7.11 Eviction SequencingD3-CE Credential EvictionD3-OE Object EvictionD3-DNSCE DNS Cache EvictionD3-FEV File EvictionD3-PE Process Eviction
M7.12 Adversary Dwell ReconstructionD3-RTSD Remote Terminal Session DetectionD3-FAPA File Access Pattern AnalysisD3-PSA Process Spawn AnalysisD3-PLA Process Lineage AnalysisD3-SCA System Call AnalysisD3-FCA File Creation Analysis
M7.13 Hunt Coverage AccountingD3-SYSM System Mapping
M7.14 Process Anomaly HuntingD3-OMM Operating Mode MonitoringD3-OPM Operational Process MonitoringD3-PUM Platform Uptime Monitoring
M7.15 Insider Risk InvestigationD3-UBA User Behavior AnalysisD3-JFAPA Job Function Access Pattern AnalysisD3-RAPA Resource Access Pattern AnalysisD3-SDA Session Duration Analysis
M7.16 Supply Chain Compromise HuntingD3-CIA Container Image AnalysisD3-FIM File Integrity MonitoringD3-SBV Service Binary VerificationD3-FFV File Format VerificationD3-FCDC File Content Decompression CheckingD3-FISV File Internal Structure VerificationD3-FMCV File Metadata Consistency ValidationD3-FMVV File Metadata Value VerificationD3-FMBV File Magic Byte Verification
M7.17 Malicious Message EvictionD3-EF Email FilteringD3-ER Email Removal
M8.01 Automated Segment SeveringD3-NI Network IsolationD3-BDI Broadcast Domain Isolation
M8.02 Estate-Wide Session RevocationD3-ANCI Authentication Cache InvalidationD3-CR Credential RevocationD3-ST Session Termination
M8.03 Read-Only Service DegradationD3-OPR Operating Mode RestrictionD3-PS Process SuspensionD3-PT Process Termination
M8.04 Fail-Secure Default PostureD3-APA Access Policy Administration
M8.05 Federation Trust SuspensionD3-DTP Domain Trust Policy
M8.06 Cloud Account QuarantineD3-UAP User Account PermissionsD3-AL Account Locking
M8.07 Egress BlackholeD3-FRIDL Forward Resolution IP DenylistingD3-RRID Reverse Resolution IP DenylistingD3-OTF Outbound Traffic Filtering
M8.09 Contained Forensic PreservationD3-FH File HashingD3-FC File Carving
M8.10 Third-Party Connection CutoutD3-NAM Network Access MediationD3-NTF Network Traffic Filtering
M8.11 Restoration PreconditionsD3-RO Restore Object
M8.13 Safe-State IsolationD3-OMM Operating Mode MonitoringD3-OPR Operating Mode Restriction
M8.14 Rapid Offboarding and RevocationD3-AL Account LockingD3-ANCI Authentication Cache InvalidationD3-CR Credential Revocation
M8.15 Facility IsolationD3-PAM Physical Access MediationD3-EPL Physical Locking
M8.16 Supplier SeveranceD3-NAM Network Access MediationD3-CR Credential Revocation
M8.17 Device Decommissioning and SanitizationD3-CR Credential RevocationD3-DKF Disk FormattingD3-DKE Disk ErasureD3-DKP Disk Partitioning
M9.01 Advisory-Driven Pre-BlockingD3-DNSDL DNS DenylistingD3-FRDDL Forward Resolution Domain DenylistingD3-FRIDL Forward Resolution IP Denylisting
M9.02 Targeted Emergency PatchingD3-AVE Asset Vulnerability EnumerationD3-SU Software UpdateD3-FBA Firmware Behavior AnalysisD3-FEMC Firmware Embedded Monitoring CodeD3-FV Firmware VerificationD3-PFV Peripheral Firmware VerificationD3-SFV System Firmware Verification
M9.03 Staged Infrastructure DenialD3-NTCD Network Traffic Community DeviationD3-PMAD Protocol Metadata Anomaly DetectionD3-RPA Relay Pattern AnalysisD3-DNSDL DNS DenylistingD3-RRID Reverse Resolution IP DenylistingD3-DRT Domain Registration Takedown
M9.04 Sector Intelligence ExchangeD3-IRA Identifier Reputation Analysis
M9.05 Pre-Emptive Credential InvalidationD3-PR Password RotationD3-CR Credential Revocation
M9.06 Vendor Compromise ResponseD3-SVCDM Service Dependency MappingD3-NAM Network Access Mediation
M9.07 Exploited-Vulnerability Catalog EnforcementD3-AVE Asset Vulnerability EnumerationD3-SYSVA System Vulnerability AssessmentD3-SU Software Update
M9.09 Supplier Advisory Pre-emptionD3-AVE Asset Vulnerability EnumerationD3-SU Software Update
M10.01 Indicator-to-Detection ConversionD3-FCR File Content RulesD3-IRA Identifier Reputation AnalysisD3-FHRA File Hash Reputation AnalysisD3-URA URL Reputation AnalysisD3-UA URL AnalysisD3-SMRA Sender MTA Reputation AnalysisD3-SRA Sender Reputation AnalysisD3-NTSA Network Traffic Signature Analysis
M10.02 Avenue Closure VerificationD3-NVA Network Vulnerability AssessmentD3-SYSVA System Vulnerability Assessment
M10.03 Terrain Overlay UpdateD3-AI Asset InventoryD3-NM Network MappingD3-SYSM System Mapping
M10.07 Supply Chain Lesson PropagationD3-SVCDM Service Dependency Mapping
M11.01 Recovery Objective DeclarationD3-OAM Operational Activity MappingD3-ODM Operational Dependency Mapping
M11.02 Isolated Recovery EnvironmentD3-HBWP Hardware-based Write ProtectionD3-NI Network Isolation
M11.03 Golden Image and Rebuild PathD3-RDI Restore Disk ImageD3-RS Restore Software
M11.04 Identity Plane ReconstitutionD3-RA Restore AccessD3-RIC Reissue CredentialD3-RUAA Restore User Account AccessD3-ULA Unlock Account
M11.05 Recovery Data Integrity VerificationD3-FH File HashingD3-FIM File Integrity MonitoringD3-RD Restore Database
M11.06 Service Restoration SequencingD3-RNA Restore Network AccessD3-RC Restore ConfigurationD3-RS Restore Software
M11.07 Reconstitution ExerciseD3-RO Restore ObjectD3-RF Restore File
M11.08 Key Personnel ContinuityD3-OM Organization Mapping
M11.09 Alternate Facility ActivationD3-RA Restore AccessD3-RNA Restore Network AccessD3-RC Restore Configuration
M11.10 Supplier-Independent RebuildD3-RDI Restore Disk ImageD3-RS Restore Software
M11.11 Mailbox and Message RestorationD3-FH File HashingD3-RO Restore ObjectD3-RE Restore Email

That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework. Each D3FEND identifier links to its own entry here, which lists the ASOM-Fed techniques that reach it — the direction a reader arriving from D3FEND actually needs.

The Gaps

32 Countermeasures This Framework Does Not Reach.

Published rather than omitted. A coverage claim is only checkable if the misses are named, and several of these are scope statements rather than gaps — a maneuver framework that scheduled every configuration setting would be a baseline, not a scheme.

D3FENDTacticWhy it is not reached
D3-AEM Application Exception MonitoringDetectBelow the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline.
D3-ANAA Administrative Network Activity AnalysisDetectBelow the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline.
D3-APM Application Performance MonitoringDetectBelow the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline.
D3-CA Certificate AnalysisDetectBelow the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline.
D3-CFI Control Flow IntegrityHardenSource-code and compiler hardening. ASOM-Fed excludes secure SDLC (PR.PS-06) as inherited from SA-15.
D3-DCE Dead Code EliminationHardenCompiler-level. Secure SDLC, inherited.
D3-DNSTA DNS Traffic AnalysisDetectBelow the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline.
D3-EHPV Exception Handler Pointer ValidationHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-EMH Electromagnetic Radiation HardeningHardenElectromagnetic radiation hardening — outside the archetype.
D3-ET Encrypted TunnelsIsolateBelow the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline.
D3-IPCTA IPC Traffic AnalysisDetectBelow the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline.
D3-IPRA IP Reputation AnalysisDetectSubsumed by D3-IRA Identifier Reputation Analysis, which M1.06, M1.10, M9.04 and M10.01 cover.
D3-IRV Integer Range ValidationHardenInput-validation countermeasure at code level. Secure SDLC, inherited.
D3-MA Message AnalysisDetectAbstract parent of message-analysis techniques; children are covered via M1.08 and M5.12.
D3-MBSV Memory Block Start ValidationHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-MH Message HardeningHardenAbstract parent of message-hardening techniques; children are covered via M2.15.
D3-NPC Null Pointer CheckingHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-OLV Operational Logic ValidationHardenCode-level logic validation. Secure SDLC, inherited.
D3-PAN Pointer AuthenticationHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-PHDURA Per Host Download-Upload Ratio AnalysisDetectBelow the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline.
D3-PRH Particle Radiation HardeningHardenParticle radiation hardening — outside the archetype.
D3-PSEP Process Segment Execution PreventionHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-PV Pointer ValidationHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-RFS RF ShieldingHardenRF shielding — outside the archetype.
D3-RH Radiation HardeningHardenRadiation hardening — spacecraft and high-radiation environments outside the Federal Reference Agency archetype.
D3-RN Reference NullificationHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-RTA RPC Traffic AnalysisDetectBelow the maneuver-planning level of abstraction; inherited from the SP 800-53 baseline.
D3-SAOR Segment Address Offset RandomizationHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-SCH Source Code HardeningHardenSource Code Hardening is the parent of the above. Explicitly out of scope per Framework section 6.
D3-SFCV Stack Frame Canary ValidationHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-VI Variable InitializationHardenMemory-safety countermeasure. Secure SDLC, inherited.
D3-VTV Variable Type ValidationHardenMemory-safety countermeasure. Secure SDLC, inherited.
The Other Direction

And Six Techniques With Nothing to Map To.

D3FEND catalogs countermeasures. These six are governance, doctrine and reporting acts, and an absent mapping is recorded so it stays distinguishable from a forgotten one.

M8.08

Statutory Availability Floor — a legal constraint on defensive action, not a countermeasure.

M8.12

Degradation Rehearsal — an exercise activity.

M9.08

Workforce Threat Briefing — a human preparation activity.

M10.04

Intelligence Requirement Revision — an analytic governance activity.

M10.05

Community Reporting — an information-sharing obligation.

M10.06

Doctrine and Catalog Update — a framework maintenance activity.

D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.