What It Does
Deny resolution and reachability to infrastructure observed staging against the sector, not only against you.
Observable indicator. Sector-staged infrastructure never reaches an avenue of approach.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM9 Spoiling AttackDisrupt adversary staging before the attack is launched.
- Terrain layerT3 NetworksThe corridors. Key terrain: TIC 3.0 access points, segment boundaries, cloud VPC peering.
- Position in the form3 of 9M9 carries 9 cataloged techniques; this is the 3rd in catalog order.
Phases It Is Employed In
Employed in 2 of the campaign’s six phases. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- KT-3 Avenue of Approach AnalysisKey Terrain and Decisive Points — To convert the estate's connectivity into a set of named approach routes, so that defense can be emplaced on the routes that exist rather than distributed evenly across ground.
- CE-2 Priority Intelligence RequirementsCycle Execution and Assurance — To direct analytic effort at named questions, so that collection and hunting answer what the accountable authority needs rather than processing what arrives.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-NTCD Network Traffic Community DeviationDetect tactic
- D3-PMAD Protocol Metadata Anomaly DetectionDetect tactic
- D3-RPA Relay Pattern AnalysisDetect tactic
- D3-DNSDL DNS DenylistingIsolate tactic
- D3-RRID Reverse Resolution IP DenylistingIsolate tactic
- D3-DRT Domain Registration TakedownEvict tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 30 that share at least one control.
- 2 shared controlsM1.04 Perimeter Canary TokensM1 Screen / Guard · T5 Data
- CE-2
- KT-3
- 2 shared controlsM5.06 Decoy Service EndpointsM5 Ambush · T4 Applications and Workloads
- CE-2
- KT-3
- 1 shared controlM1.03 Certificate and Domain WatchM1 Screen / Guard · T3 Networks
- KT-3
- 1 shared controlM1.05 Authentication Geography BaselineM1 Screen / Guard · T1 Identity
- CE-2
- 1 shared controlM1.06 Credential Exposure MonitoringM1 Screen / Guard · T1 Identity
- CE-2
- 1 shared controlM1.07 Partner and Advisory IntakeM1 Screen / Guard · TX Cross-Cutting
- CE-2