ASOM-Fedv6.1Open the explorer
D3-DNSDL · Isolate tactic · MITRE D3FEND v1.5.0

DNS Denylisting

Where It Sits in the Scheme

3 ASOM-Fed techniques reach this countermeasure, across 2 forms of maneuver.

This is the direction the forward mapping cannot answer. A reader who works in D3FEND arrives holding D3-DNSDL and needs to know where it is employed in a scheme of maneuver — not which of MITRE's tactics it belongs to, which they already know.

Reached By

  • M4.04 DNS Control and SinkholingM4 Obstacle / Canalization · T3 Networks

    Route resolution through controlled resolvers, log it, and sinkhole known-bad and newly registered domains.

  • M9.01 Advisory-Driven Pre-BlockingM9 Spoiling Attack · TX Cross-Cutting

    Block infrastructure named in partner reporting before it is used against you, on a stated clock.

  • M9.03 Staged Infrastructure DenialM9 Spoiling Attack · T3 Networks

    Deny resolution and reachability to infrastructure observed staging against the sector, not only against you.

Forms That Arrive Here

A countermeasure reached from more than one form is employed more than one way. D3FEND has no notion of a form, so this join exists only here.

  • M4 Obstacle / CanalizationThe formForce the adversary onto ground you own and watch.
  • M9 Spoiling AttackThe formDisrupt adversary staging before the attack is launched.

What This Does Not Claim

That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.

MITRE's own entry for this technique is at d3fend.mitre.org, and it is the authority on what the countermeasure is. This page is the authority only on where it sits in ASOM-Fed. D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.