What It Does
Hunt for the specific behaviors a compromised supplier or component would produce, on the assumption that it is already inside.
Observable indicator. Supplier-origin behaviors are hunted on a stated cadence, not only on advisory.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM7 CounterattackSeize the initiative and evict before the adversary reaches the objective.
- Terrain layerT9 Supply ChainThe lines of communication. Key terrain: Suppliers with production access, component provenance, the update path into the estate.
- Position in the form16 of 17M7 carries 17 cataloged techniques; this is the 16th in catalog order.
Phases It Is Employed In
Employed in one phase of the campaign. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
- Phase IIIDominateHunt, contain, evict.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- LC-2 Component ProvenanceLines of Communication — To know where deployed components came from and what is inside them, so that a compromise disclosed anywhere can be located here.
- LC-4 Update Integrity and StagingLines of Communication — To limit the blast radius of a compromised trusted update, so that supply chain compromise reaches a ring rather than the estate.
- CE-2 Priority Intelligence RequirementsCycle Execution and Assurance — To direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-CIA Container Image AnalysisModel tactic
- D3-FIM File Integrity MonitoringDetect tactic
- D3-SBV Service Binary VerificationDetect tactic
- D3-FFV File Format VerificationIsolate tactic
- D3-FCDC File Content Decompression CheckingIsolate tactic
- D3-FISV File Internal Structure VerificationIsolate tactic
- D3-FMCV File Metadata Consistency ValidationIsolate tactic
- D3-FMVV File Metadata Value VerificationIsolate tactic
- D3-FMBV File Magic Byte VerificationIsolate tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 31 that share at least one control.
- 2 shared controlsM2.18 Component Provenance VerificationM2 Defense in Depth · T9 Supply Chain
- LC-2
- LC-4
- 2 shared controlsM6.10 Update Staging and SoakM6 Delay · T9 Supply Chain
- LC-2
- LC-4
- 2 shared controlsM9.09 Supplier Advisory Pre-emptionM9 Spoiling Attack · T9 Supply Chain
- CE-2
- LC-4
- 1 shared controlM1.04 Perimeter Canary TokensM1 Screen / Guard · T5 Data
- CE-2
- 1 shared controlM1.05 Authentication Geography BaselineM1 Screen / Guard · T1 Identity
- CE-2
- 1 shared controlM1.06 Credential Exposure MonitoringM1 Screen / Guard · T1 Identity
- CE-2