What It Does
Sweep systematically for persistence across identity, endpoint, cloud and application layers before declaring eradication.
Observable indicator. Eradication is declared on evidence across every layer.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM7 CounterattackSeize the initiative and evict before the adversary reaches the objective.
- Terrain layerT2 DevicesThe entry fords. Key terrain: Mission-staff laptops, contractor devices, the server and VM fleet.
- Position in the form7 of 17M7 carries 17 cataloged techniques; this is the 7th in catalog order.
Phases It Is Employed In
Employed in 2 of the campaign’s six phases. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- SM-6 Maneuver Effectiveness ValidationScheme of Maneuver — To replace assumed effectiveness with demonstrated effectiveness, so the coverage figure reflects what controls do rather than what was assumed of them.
- CG-4 Findings DispositionCommand and Governance — To ensure every finding reaches a decision, so that the open set reflects work in progress rather than accumulated neglect.
- EN-5 Eradication and Transition to RecoveryEngagement and Pursuit — To ensure the adversary is actually gone before the mission is restored, and that the transition is a decision rather than a drift.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-SJA Scheduled Job AnalysisDetect tactic
- D3-SDM System Daemon MonitoringDetect tactic
- D3-SICA System Init Config AnalysisDetect tactic
- D3-USICA User Session Init Config AnalysisDetect tactic
- D3-IBCA Indirect Branch Call AnalysisDetect tactic
- D3-PSMD Process Self-Modification DetectionDetect tactic
- D3-SSC Shadow Stack ComparisonsDetect tactic
- D3-RKD Registry Key DeletionEvict tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 19 that share at least one control.
- 2 shared controlsM8.11 Restoration PreconditionsM8 Isolation / Retrograde · TX Cross-Cutting
- CG-4
- EN-5
- 1 shared controlM1.07 Partner and Advisory IntakeM1 Screen / Guard · TX Cross-Cutting
- CG-4
- 1 shared controlM10.01 Indicator-to-Detection ConversionM10 Exploitation & Pursuit · TX Cross-Cutting
- SM-6
- 1 shared controlM3.14 Entitlement RecertificationM3 Envelopment · T1 Identity
- CG-4
- 1 shared controlM4.12 Denied-Path Register EnforcementM4 Obstacle / Canalization · T3 Networks
- SM-6
- 1 shared controlM7.06 Build Pipeline Integrity HuntM7 Counterattack · T4 Applications and Workloads
- SM-6