What It Does
Discover devices reaching the estate from the identity plane outward rather than from the management console, because the console can only report what it already manages.
Observable indicator. Devices authenticating to the estate but absent from the inventory trend to zero.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM1 Screen / GuardGain early warning and buy reaction time before the adversary touches key terrain.
- Terrain layerT2 DevicesThe entry fords. Key terrain: Mission-staff laptops, contractor devices, the server and VM fleet.
- Position in the form15 of 15M1 carries 15 cataloged techniques; this is the 15th in catalog order.
Phases It Is Employed In
Employed in one phase of the campaign. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
- Phase 0ShapeContinuous terrain preparation, zero-trust hardening, partnerships, threat intelligence.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- TM-1 Terrain Inventory and OverlayTerrain Management — To establish one authoritative positional picture of the estate, so that every later judgment about priority, reachability and risk is made against the same ground.
- TM-6 Terrain CurrencyTerrain Management — To keep the overlay current against both the clock and the change, so that planning is conducted against ground as it currently is.
- DV-1 Device Terrain IdentificationDevices Terrain — To make devices positional, so that the crossings into the estate are known and can be defended rather than merely counted.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-AI Asset InventoryModel tactic
- D3-HCI Hardware Component InventoryModel tactic
- D3-NNI Network Node InventoryModel tactic
- D3-SWI Software InventoryModel tactic
- D3-EHB Endpoint Health BeaconDetect tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 11 that share at least one control.
- 3 shared controlsM1.02 Shadow and Forgotten Asset DiscoveryM1 Screen / Guard · T3 Networks
- DV-1
- TM-1
- TM-6
- 2 shared controlsM1.01 External Attack Surface EnumerationM1 Screen / Guard · T3 Networks
- TM-1
- TM-6
- 2 shared controlsM10.03 Terrain Overlay UpdateM10 Exploitation & Pursuit · TX Cross-Cutting
- TM-1
- TM-6
- 2 shared controlsM2.05 Endpoint Detection and Response CoverageM2 Defense in Depth · T2 Devices
- DV-1
- TM-6
- 1 shared controlM1.03 Certificate and Domain WatchM1 Screen / Guard · T3 Networks
- TM-1
- 1 shared controlM3.08 Identity Lifecycle EnforcementM3 Envelopment · T1 Identity
- TM-6