Where It Sits in the Scheme
5 ASOM-Fed techniques reach this countermeasure, across 2 forms of maneuver.
This is the direction the forward mapping cannot answer. A reader who works in D3FEND arrives holding D3-AVE and needs to know where it is employed in a scheme of maneuver — not which of MITRE's tactics it belongs to, which they already know.
Reached By
- M1.07 Partner and Advisory IntakeM1 Screen / Guard · TX Cross-Cutting
Operate a named, timed intake path for CISA, sector and law-enforcement reporting that ends in a decision rather than a mailbox.
- M1.14 Supplier Exposure MonitoringM1 Screen / Guard · T9 Supply Chain
Monitor the suppliers and components that reach into the estate for breach disclosure, advisory and exposure, because their compromise is your compromise.
- M9.02 Targeted Emergency PatchingM9 Spoiling Attack · T4 Applications and Workloads
Patch out of cycle when intelligence — not the calendar — says a specific weakness is being used now.
- M9.07 Exploited-Vulnerability Catalog EnforcementM9 Spoiling Attack · T4 Applications and Workloads
Treat authoritative known-exploited catalogs as a directive with an owner and a due date on the terrain register.
- M9.09 Supplier Advisory Pre-emptionM9 Spoiling Attack · T9 Supply Chain
Act on supplier and component advisories before exploitation reaches you, including by staging the update or constraining the access.
Forms That Arrive Here
A countermeasure reached from more than one form is employed more than one way. D3FEND has no notion of a form, so this join exists only here.
What This Does Not Claim
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
MITRE's own entry for this technique is at d3fend.mitre.org, and it is the authority on what the countermeasure is. This page is the authority only on where it sits in ASOM-Fed. D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.