What It Does
Execute a scoped, ordered reset of credentials and tokens across the compromised blast radius.
Observable indicator. The reset completes without leaving a re-entry credential.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM7 CounterattackSeize the initiative and evict before the adversary reaches the objective.
- Terrain layerT1 IdentityThe high ground. Key terrain: The ICAM policy decision point, privileged accounts, external-user and mission-staff identities.
- Position in the form5 of 17M7 carries 17 cataloged techniques; this is the 5th in catalog order.
Phases It Is Employed In
Employed in one phase of the campaign. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
- Phase IIIDominateHunt, contain, evict.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- TA-4 Pre-authorized ResponseTempo and Temporal Advantage — To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.
- SM-5 Branches and SequelsScheme of Maneuver — To decide contingency responses before contact, so that the decision loop under pressure is a selection rather than a design exercise.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-CRO Credential RotationHarden tactic
- D3-CR Credential RevocationEvict tactic
- D3-RIC Reissue CredentialRestore tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 24 that share at least one control.
- 2 shared controlsM7.03 Automated Containment PlaybooksM7 Counterattack · TX Cross-Cutting
- SM-5
- TA-4
- 2 shared controlsM8.01 Automated Segment SeveringM8 Isolation / Retrograde · T3 Networks
- SM-5
- TA-4
- 2 shared controlsM8.02 Estate-Wide Session RevocationM8 Isolation / Retrograde · T1 Identity
- SM-5
- TA-4
- 1 shared controlM1.06 Credential Exposure MonitoringM1 Screen / Guard · T1 Identity
- TA-4
- 1 shared controlM2.13 Backup Isolation and ImmutabilityM2 Defense in Depth · T5 Data
- SM-5
- 1 shared controlM8.03 Read-Only Service DegradationM8 Isolation / Retrograde · T4 Applications and Workloads
- SM-5