Where It Sits in the Scheme
5 ASOM-Fed techniques reach this countermeasure, across 2 forms of maneuver.
This is the direction the forward mapping cannot answer. A reader who works in D3FEND arrives holding D3-DO and needs to know where it is employed in a scheme of maneuver — not which of MITRE's tactics it belongs to, which they already know.
Reached By
- M1.04 Perimeter Canary TokensM1 Screen / Guard · T5 Data
Seed uniquely identifying tokens in externally reachable surfaces so that reconnaissance touching them is unambiguous.
- M5.01 Decoy Records in the Data LayerM5 Ambush · T5 Data
Seed the record stores with realistic decoy records whose only purpose is to be accessed by someone who should not.
- M5.02 Honeytokens in Document StoresM5 Ambush · T5 Data
Place tokenized documents in collaboration and file estate where staged collection would find them.
- M5.08 Decoy Cloud ResourcesM5 Ambush · T4 Applications and Workloads
Stand up monitored buckets, roles and secrets that legitimate workloads never call.
- M5.13 Physical DeceptionM5 Ambush · T8 Facilities
Seed facilities with tokens whose only plausible use is by someone who should not have them — dropped media, decoy badges, decoy racks.
Forms That Arrive Here
A countermeasure reached from more than one form is employed more than one way. D3FEND has no notion of a form, so this join exists only here.
What This Does Not Claim
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
MITRE's own entry for this technique is at d3fend.mitre.org, and it is the authority on what the countermeasure is. This page is the authority only on where it sits in ASOM-Fed. D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.