Where It Sits in the Scheme
10 ASOM-Fed techniques reach this countermeasure, across 5 forms of maneuver.
This is the direction the forward mapping cannot answer. A reader who works in D3FEND arrives holding D3-NAM and needs to know where it is employed in a scheme of maneuver — not which of MITRE's tactics it belongs to, which they already know.
Reached By
- M2.02 Policy Enforcement Point PlacementM2 Defense in Depth · T3 Networks
Place an enforcement point at every zone boundary so that crossing is a decision, not a route.
- M2.06 Device Posture GatingM2 Defense in Depth · T2 Devices
Make device health a precondition of access, so a compromised or non-compliant endpoint cannot spend a valid credential.
- M3.20 Supplier Identity FederationM3 Envelopment · T9 Supply Chain
Bring supplier access under the agency's own identity plane rather than standing local accounts the agency cannot see or revoke.
- M4.06 Administrative Path RestrictionM4 Obstacle / Canalization · T3 Networks
Confine administrative protocols to declared corridors from declared sources.
- M4.10 Bastion and Jump-Host EnforcementM4 Obstacle / Canalization · T3 Networks
Force privileged access to decisive systems through recorded, brokered hosts.
- M4.16 Maintenance Access ConstraintM4 Obstacle / Canalization · T8 Facilities
Force vendor and remote maintenance onto a supervised, time-boxed path instead of standing access into the estate.
- M4.17 Supplier Access CanalisationM4 Obstacle / Canalization · T9 Supply Chain
Route every supplier into a defined broker rather than directly onto mission systems, so their traffic crosses ground you instrument.
- M8.10 Third-Party Connection CutoutM8 Isolation / Retrograde · T3 Networks
Cut a specific partner or vendor connection on decision without taking down the shared boundary.
- M8.16 Supplier SeveranceM8 Isolation / Retrograde · T9 Supply Chain
Be able to cut a supplier's access immediately and continue the mission, because the alternative is negotiating with an intrusion.
- M9.06 Vendor Compromise ResponseM9 Spoiling Attack · TX Cross-Cutting
Hold a rehearsed path to constrain a compromised vendor or integrator connection on disclosure.
Forms That Arrive Here
A countermeasure reached from more than one form is employed more than one way. D3FEND has no notion of a form, so this join exists only here.
- M2 Defense in DepthThe formEnsure no single failure is decisive.
- M3 EnvelopmentThe formMake identity, not network location, the decisive plane — surround the adversary with policy.
- M4 Obstacle / CanalizationThe formForce the adversary onto ground you own and watch.
- M8 Isolation / RetrogradeThe formGive ground deliberately to preserve the force. Degrade gracefully; never fail open.
- M9 Spoiling AttackThe formDisrupt adversary staging before the attack is launched.
What This Does Not Claim
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
MITRE's own entry for this technique is at d3fend.mitre.org, and it is the authority on what the countermeasure is. This page is the authority only on where it sits in ASOM-Fed. D3FEND™ and ATT&CK® are trademarks of The MITRE Corporation. This mapping is published by threatDefendr and is neither produced nor endorsed by MITRE.