D3FEND™ - A knowledge graph of cybersecurity countermeasures

IRI:
http://d3fend.mitre.org/ontologies/d3fend.owl
Version IRI:
http://d3fend.mitre.org/ontologies/d3fend/0.12.0-BETA-1/d3fend.owl
Current version :
0.12.0-BETA-1
Other visualisation :
Ontology source - WebVowl

Abstract

Use of the D3FEND Knowledge Graph, and the associated references from this ontology are subject to the Terms of Use. D3FEND is funded by the National Security Agency (NSA) Cybersecurity Directorate and managed by the National Security Engineering Center (NSEC) which is operated by The MITRE Corporation. D3FEND™ and the D3FEND logo are trademarks of The MITRE Corporation. This software was produced for the U.S. Government under Basic Contract No. W56KGU-18-D0004, and is subject to the Rights in Noncommercial Computer Software and Noncommercial Computer Software Documentation Clause 252.227-7014 (FEB 2012) Copyright 2022 The MITRE Corporation.

Table of Content

  1. Classes
  2. Object Properties
  3. Data Properties
  4. Named Individuals
  5. Annotation Properties
  6. General Axioms
  7. Namespace Declarations

Classes

.bash_profile and .bashrcc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.004

has super-classes
Event Triggered Executionc
modifiesop some User Init Configuration Filec
is also defined as
named individual

/etc/passwd and /etc/shadowc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.008

has super-classes
OS Credential Dumpingc
accessesop some Encrypted Credentialc
accessesop some Password Filec
is also defined as
named individual

Abuse Elevation Control Mechanismc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1548

has super-classes
Defense Evasion Techniquec
Privilege Escalation Techniquec
has sub-classes
Bypass User Access Controlc, Elevated Execution with Promptc, Setuid and Setgidc, Sudo and Sudo Cachingc

Academic Articlec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AcademicArticle

has super-classes
Articlec
has sub-classes
Conference Paperc, Journal Articlec

Academic Paper Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AcademicPaperReference

has super-classes
Technique Referencec
has members
Reference - Analysis of the Windows Vista Security Model - Symantec Corporationni, Reference - Continuous authentication by analysis of keyboard typing characteristics - Bradford Univ., UKni, Reference - Dagger: Modeling and visualization for mission impact situational awarenessni, Reference - Dead code eliminationni, Reference - Detecting DDoS Attack Using Snortni, Reference - Enhancing Network Security By Preventing User-Initiated Malware Execution - MITREni, Reference - Firmware Behavior Analysis ConFirmni, Reference - Firmware Behavior Analysis VIPERni, Reference - Firmware Embedded Monitoring Code Symbiotesni, Reference - Indirect Branching Callsni, Reference - Mission Dependency Modeling for Cyber Situational Awarenessni, Reference - Network-Based Buffer Overflow Detection by Exploit Code Analysis - Information Security Research Centreni, Reference - Network-level polymorphic shellcode detection using emulationni, Reference - Predicting Domain Generation Algorithms with Long Short-Term Memory Networksni, Reference - Testing Metrics for Password Creation Policies by Attacking Large Sets of Revealed Passwordsni

Access Control Configurationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AccessControlConfiguration

has super-classes
Configuration Resourcec
has sub-classes
Access Control Listc, Group Policyc
is also defined as
named individual

Access Control Listc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AccessControlList

is defined by
http://dbpedia.org/resource/Access-control_list
has super-classes
Access Control Configurationc

Access Modelingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AccessModeling

has super-classes
Operational Activity Mappingc
mapsop some Access Control Configurationc
mapsop some User Accountc
is also defined as
named individual

Access Tokenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AccessToken

has super-classes
Credentialc
has sub-classes
Kerberos Ticketc, Ticket Granting Ticketc
has members
Token Impersonation/Theftni
is also defined as
named individual

Access Token Manipulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134

has super-classes
Defense Evasion Techniquec
Privilege Escalation Techniquec
has sub-classes
Create Process with Tokenc, Make and Impersonate Tokenc, Parent PID Spoofingc, SID-History Injectionc, Token Impersonation/Theftc

Accessibility Featuresc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1015

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Accessibility Featuresc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.008

has super-classes
Event Triggered Executionc
may-createop some Intranet Administrative Network Trafficc
may-modifyop some Executable Binaryc
may-modifyop some System Configuration Database Recordc
is also defined as
named individual

Account Access Removalc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1531

has super-classes
Impact Techniquec
modifiesop some User Accountc
is also defined as
named individual

Account Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1087

has super-classes
Discovery Techniquec
has sub-classes
Email Accountc

Account Lockingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AccountLocking

has super-classes
Credential Evictionc
disablesop some User Accountc
is also defined as
named individual

Account Manipulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098

has super-classes
Persistence Techniquec
modifiesop some User Accountc
has sub-classes
Add Office 365 Global Administrator Rolec, Additional Azure Service Principal Credentialsc, Device Registrationc, Exchange Email Delegate Permissionsc, SSH Authorized Keysc
is also defined as
named individual

Acquire Infrastructurec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1583

has super-classes
Resource Development Techniquec
has sub-classes
Botnetc, DNS Serverc, Domainsc, Serverc, Virtual Private Serverc, Web Servicesc

Active Certificate Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ActiveCertificateAnalysis

has super-classes
Certificate Analysisc
has members
Active Certificate Analysisni
is also defined as
named individual

Active Logical Link Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ActiveLogicalLinkMapping

has super-classes
Logical Link Mappingc
may-queryop some Network Agentc
is also defined as
named individual

Active Physical Link Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ActivePhysicalLinkMapping

has super-classes
Physical Link Mappingc
may-queryop some Network Agentc
is disjoint with
Passive Physical Link Mappingc
is also defined as
named individual

Active Scanningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1595

has super-classes
Reconnaissance Techniquec
has sub-classes
Scanning IP Blocksc, Vulnerability Scanningc, Wordlist Scanningc

Active Setupc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.014

has super-classes
Boot or Logon Autostart Executionc

Activityc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Activity

has super-classes
D3FEND Thingc
has sub-classes
Organizational Activityc

Activity Dependencyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ActivityDependency

has super-classes
Dependencyc

Add Office 365 Global Administrator Rolec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098.003

has super-classes
Account Manipulationc
modifiesop some Global User Accountc
is also defined as
named individual

Add-insc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.006

has super-classes
Office Application Startupc
addsop some Softwarec
may-modifyop some System Configuration Databasec
modifiesop some Office Applicationc
is also defined as
named individual

Additional Azure Service Principal Credentialsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098.001

has super-classes
Account Manipulationc
createsop some Credentialc
producesop some Intranet Administrative Network Trafficc
is also defined as
named individual

Address Spacec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AddressSpace

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Digital Artifactc
has sub-classes
Memory Address Spacec

Admin Feature Assessmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AdminFeatureAssessment

has super-classes
Feature Assessmentc
assessesop some Admin Feature Claimc

Admin Feature Claimc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AdminFeatureClaim

has super-classes
Capability Feature Claimc
citesop some Information Content Entityc
claimsop some Administrative Featurec
featuresop only Administrative Featurec

Administrative Featurec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AdministrativeFeature

has super-classes
Capability Featurec

Administrative Network Activity Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AdministrativeNetworkActivityAnalysis

has super-classes
Network Traffic Analysisc
analyzesop some Intranet Administrative Network Trafficc
is also defined as
named individual

Administrative Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AdministrativeNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Intranet Administrative Network Trafficc
is also defined as
named individual

Agentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Agent

has super-classes
D3FEND Catalog Thingc
has sub-classes
Organizationc, Personc

Aliasc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Alias

is defined by
http://dbpedia.org/resource/Alias_(Mac_OS)
has super-classes
Slow Symbolic Linkc

Allocate Memoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AllocateMemory

has super-classes
System Callc
createsop some Memory Blockc
is also defined as
named individual

Analysis of Alternativesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AnalysisOfAlternatives

has super-classes
D3FEND Catalog Thingc
analyzesop some Portfolio Assessmentc
authorop some Agentc

Analytic Latencyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AnalyticLatency

has super-classes
Latencyc
has members
non-real-time-analyticni, real-time-analyticni

AppCert DLLsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1182

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

AppCert DLLsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.009

has super-classes
Event Triggered Executionc
invokesop some Create Processc
loadsop some Shared Library Filec
modifiesop some System Configuration Database Recordc
is also defined as
named individual

AppInit DLLsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1103

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

AppInit DLLsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.010

has super-classes
Event Triggered Executionc
invokesop some Create Processc
loadsop some Shared Library Filec
modifiesop some System Configuration Database Recordc
is also defined as
named individual

AppleScriptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1155

has super-classes
Execution Techniquec

AppleScript Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059.002

has super-classes
Command and Scripting Interpreter Executionc

Appliancec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Appliance

has super-classes
Productc

Applicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Application

has super-classes
Softwarec
may-containop some Application Configurationc
has sub-classes
Client Applicationc, Password Managerc, Service Applicationc, User Applicationc
is also defined as
named individual

Application Access Tokenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1527

has super-classes
Defense Evasion Techniquec
Lateral Movement Techniquec

Application Access Tokenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550.001

has super-classes
Use Alternate Authentication Materialc
may-produceop some Network Trafficc
usesop some Access Tokenc
is also defined as
named individual

Application Configurationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationConfiguration

has super-classes
Configuration Resourcec
has sub-classes
Application Configuration Database Recordc, Application Process Configurationc, Application Rulec, Process Environment Variablec
is also defined as
named individual

Application Configuration Databasec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationConfigurationDatabase

has super-classes
Configuration Databasec
containsop some Application Configuration Database Recordc
has sub-classes
Shim Databasec
is also defined as
named individual

Application Configuration Database Recordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationConfigurationDatabaseRecord

has super-classes
Application Configurationc
Configuration Database Recordc
is also defined as
named individual

Application Configuration Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationConfigurationFile

has super-classes
Configuration Filec
containsop some Application Configurationc
has sub-classes
Compiler Configuration Filec
is also defined as
named individual

Application Configuration Hardeningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationConfigurationHardening

has super-classes
Application Hardeningc
hardensop some Application Configurationc
is also defined as
named individual

Application Deployment Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1017

has super-classes
Lateral Movement Techniquec

Application Exhaustion Floodc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1499.003

has super-classes
Endpoint Denial of Servicec

Application Hardeningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationHardening

has super-classes
Defensive Techniquec
enablesop some Hardenc
has sub-classes
Application Configuration Hardeningc, Dead Code Eliminationc, Exception Handler Pointer Validationc, Pointer Authenticationc, Process Segment Execution Preventionc, Segment Address Offset Randomizationc, Stack Frame Canary Validationc
has members
Application Configuration Hardeningni, Dead Code Eliminationni, Exception Handler Pointer Validationni, Pointer Authenticationni, Process Segment Execution Preventionni, Segment Address Offset Randomizationni, Stack Frame Canary Validationni
is also defined as
named individual

Application Installerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationInstaller

has super-classes
User Applicationc
is also defined as
named individual

Application Inventory Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationInventorySensor

has super-classes
Endpoint Sensorc
monitorsop some Applicationc
is also defined as
named individual

Application Layer Firewallc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationLayerFirewall

is defined by
http://dbpedia.org/resource/Application_firewall
has super-classes
Firewallc
has sub-classes
Web Application Firewallc

Application Layer Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationLayerLink

has super-classes
Logical Linkc

Application Layer Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071

has super-classes
Command and Control Techniquec
may-transferop some Certificate Filec
producesop some Outbound Internet Network Trafficc
has sub-classes
DNSc, File Transfer Protocolsc, Mail Protocolsc, Web Protocolsc
is also defined as
named individual

Application or System Exploitationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1499.004

has super-classes
Endpoint Denial of Servicec

Application Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationProcess

has super-classes
User Processc
runsop some Applicationc
has sub-classes
Container Processc, Script Application Processc, Service Application Processc
is also defined as
named individual

Application Process Configurationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationProcessConfiguration

has super-classes
Application Configurationc

Application Rulec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationRule

has super-classes
Application Configurationc
has sub-classes
Email Rulec

Application Shimc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationShim

has super-classes
Shimc

Application Shimmingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1138

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Application Shimmingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.011

has super-classes
Event Triggered Executionc
createsop some Shimc
modifiesop some Shim Databasec
is also defined as
named individual

Application Window Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1010

has super-classes
Discovery Techniquec
may-invokeop some Create Processc
may-invokeop some Get Open Windowsc
is also defined as
named individual

Archive Collected Datac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1560

has super-classes
Collection Techniquec
createsop some Archive Filec
has sub-classes
Archive via Custom Methodc, Archive via Libraryc, Archive via Utilityc
is also defined as
named individual

Archive Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ArchiveFile

has super-classes
Filec
has sub-classes
Custom Archive Filec, Java Archivec
is also defined as
named individual

Archive via Custom Methodc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1560.003

has super-classes
Archive Collected Datac
createsop some Custom Archive Filec
is also defined as
named individual

Archive via Libraryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1560.002

has super-classes
Archive Collected Datac
createsop some Archive Filec
is also defined as
named individual

Archive via Utilityc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1560.001

has super-classes
Archive Collected Datac
createsop some Archive Filec
is also defined as
named individual

ARP Cache Poisoningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1557.002

has super-classes
Man-in-the-Middlec

Articlec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Article

has super-classes
Documentc
has sub-classes
Academic Articlec, News Articlec

Artifactc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Artifact

has super-classes
D3FEND Thingc
has sub-classes
Digital Artifactc, Physical Artifactc, Systemc
is in domain of
may have weaknessop
is in range of
d3fend-tactical-verb-propertyop, may be weakness ofop

Artifact Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ArtifactServer

has super-classes
Web Serverc
has sub-classes
Data Artifact Serverc, Software Artifact Serverc

AS-REP Roastingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1558.004

has super-classes
Steal or Forge Kerberos Ticketsc

Assessmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Assessment

is defined by
http://wordnet-rdf.princeton.edu/id/05741528-n
has super-classes
D3FEND Catalog Thingc
authorop some Agentc
expectation ratingdp only { "below" , "exceeded" , "met" }
has sub-classes
Capability Assessmentc, Feature Assessmentc, Portfolio Assessmentc

Asset Inventoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AssetInventory

has super-classes
Defensive Techniquec
enablesop some Modelc
has sub-classes
Asset Vulnerability Enumerationc, Configuration Inventoryc, Data Inventoryc, Hardware Component Inventoryc, Network Node Inventoryc, Software Inventoryc
has members
Asset Vulnerability Enumerationni, Configuration Inventoryni, Data Inventoryni, Hardware Component Inventoryni, Network Node Inventoryni, Software Inventoryni
is also defined as
named individual

Asset Vulnerability Enumerationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AssetVulnerabilityEnumeration

has super-classes
Asset Inventoryc
evaluatesop some Digital Artifactc
identifiesop some vulnerabilityc
is also defined as
named individual

Asymmetric Cryptographyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1573.002

has super-classes
Encrypted Channelc
may-transferop some Certificate Filec
createsop some Outbound Internet Encrypted Trafficc
is also defined as
named individual

Asymmetric Keyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AsymmetricKey

has super-classes
Cryptographic Keyc
has sub-classes
Private Keyc, Public Keyc

Asynchronous Procedure Callc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.004

has super-classes
Process Injectionc
may-invokeop some Create Processc
is also defined as
named individual

At (Linux) Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053.001

has super-classes
Scheduled Task/Job Executionc

At (Windows) Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053.002

has super-classes
Scheduled Task/Job Executionc

ATTACK Mitigationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ATTACKMitigation

has super-classes
ATTACK Thingc
semantic-relationop some Defensive Techniquec
d3fend-commentdp some string
has members
Account Use Policiesni, Active Directory Configurationni, Antivirus/Antimalwareni, Application Developer Guidanceni, Application Isolation and Sandboxingni, Auditni, Behavior Prevention on Endpointni, Boot Integrityni, Code Signingni, Credential Access Protectionni, Data Backupni, Disable or Remove Feature or Programni, Do Not Mitigateni, Encrypt Sensitive Informationni, Environment Variable Permissionsni, Execution Preventionni, Exploit Protectionni, Filter Network Trafficni, Limit Access to Resource Over Networkni, Limit Hardware Installationni, Limit Software Installationni, Multi-factor Authenticationni, Network Intrusion Preventionni, Network Segmentationni, Operating System Configurationni, Password Policiesni, Pre-compromiseni, Privileged Account Managementni, Privileged Process Integrityni, Remote Data Storageni, Restrict File and Directory Permissionsni, Restrict Library Loadingni, Restrict Registry Permissionni, Restrict Web-Based Contentni, SSL/TLS Inspectionni, Software Configurationni, Threat Intelligence Programni, Update Softwareni, User Account Controlni, User Account Managementni, User Trainingni, Vulnerability Scanningni

ATTACK Thingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ATTACKThing

has sub-classes
ATTACK Mitigationc, Offensive Tacticc, Offensive Techniquec

Audio Capturec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1123

has super-classes
Collection Techniquec
accessesop some Audio Input Devicec
is also defined as
named individual

Audio Input Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AudioInputDevice

has super-classes
Input Devicec
is also defined as
named individual

Authenticate Userc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticateUser

has super-classes
System Callc
authenticatesop some User Accountc
is also defined as
named individual

Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Authentication

has super-classes
User Actionc
authenticatesop some Userc
may-createop some Intranet Network Trafficc
originates-fromop some Physical Locationc
has sub-classes
Web Authenticationc
has members
Authenticationni
is also defined as
named individual

Authentication Cache Invalidationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationCacheInvalidation

has super-classes
Credential Evictionc
deletesop some Credentialc
is also defined as
named individual

Authentication Event Thresholdingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationEventThresholding

has super-classes
User Behavior Analysisc
analyzesop some Authenticationc
is also defined as
named individual

Authentication Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationFunction

has super-classes
Subroutinec
authenticatesop some User Accountc
is also defined as
named individual

Authentication Logc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationLog

has super-classes
Logc
recordsop some Authenticationc
is also defined as
named individual

Authentication Packagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1131

has super-classes
Persistence Techniquec

Authentication Packagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.002

has super-classes
Boot or Logon Autostart Executionc
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Authentication Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationServer

is defined by
http://dbpedia.org/resource/Authentication_server
has super-classes
Serverc

Authentication Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationService

has super-classes
Service Application Processc
has sub-classes
Local Authentication Servicec, Remote Authentication Servicec
is also defined as
named individual

Authorizationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Authorization

has super-classes
User Actionc
authorizesop some Network Resource Accessc
has sub-classes
Cloud Service Authorizationc
is also defined as
named individual

Authorization Event Thresholdingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthorizationEventThresholding

has super-classes
User Behavior Analysisc
analyzesop some Authorizationc
is also defined as
named individual

Authorization Logc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthorizationLog

has super-classes
Logc
recordsop some Network Resource Accessc
is also defined as
named individual

Authorization Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthorizationService

is defined by
https://www.sciencedirect.com/referencework/9780122272400/encyclopedia-of-information-systems
has super-classes
Network Servicec
Service Application Processc
has sub-classes
Local Authorization Servicec, Remote Authorization Servicec

Automated Collectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1119

has super-classes
Collection Techniquec
accessesop some Filec
is also defined as
named individual

Automated Exfiltrationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1020

has super-classes
Exfiltration Techniquec
producesop some Internet Network Trafficc
has sub-classes
Traffic Duplicationc
is also defined as
named individual

Barcode Scanner Input Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BarcodeScannerInputDevice

is defined by
http://dbpedia.org/resource/Barcode_reader
has super-classes
Image Scanner Input Devicec

Bash Historyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1139

has super-classes
Credential Access Techniquec

Bash Historyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.003

has super-classes
Unsecured Credentialsc
accessesop some Command History Log Filec
is also defined as
named individual

Bidirectional Communicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1102.002

has super-classes
Web Servicec

Binary Large Objectc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BinaryLargeObject

is defined by
http://dbpedia.org/resource/Binary_large_object
has super-classes
Digital Artifactc
has sub-classes
JavaScript Blobc

Binary Paddingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1009

has super-classes
Defense Evasion Techniquec

Binary Paddingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.001

has super-classes
Obfuscated Files or Informationc
modifiesop some Executable Binaryc
is also defined as
named individual

Binary Segmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BinarySegment

has super-classes
Digital Artifactc
has sub-classes
Image Segmentc, Process Segmentc

Biometric Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BiometricAuthentication

has super-classes
Credential Hardeningc
authenticatesop some User Accountc
is also defined as
named individual

BITS Jobsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1197

has super-classes
Defense Evasion Techniquec
Persistence Techniquec
may-produceop some Intranet IPC Network Trafficc
may-produceop some Intranet Web Network Trafficc
may-produceop some Outbound Internet Web Trafficc
is also defined as
named individual

Blobc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Blob

is defined by
http://dbpedia.org/resource/Binary_large_object
has super-classes
Digital Artifactc

Block Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BlockDevice

has super-classes
Digital Artifactc
containsop some Boot Sectorc
containsop some Partitionc
containsop some Partition Tablec
may-containop some Volumec
is also defined as
named individual

Book Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BookReference

has super-classes
Technique Referencec
has members
Reference - Organizational Management in SAP ERP HCMni

Boot Loaderc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BootLoader

has super-classes
Digital Artifactc
has sub-classes
First-stage Boot Loaderc, Second-stage Boot Loaderc
is also defined as
named individual

Boot or Logon Autostart Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec
has sub-classes
Active Setupc, Authentication Packagec, Kernel Modules and Extensionsc, LSASS Driverc, Login Itemsc, Plist Modificationc, Port Monitorsc, Print Processorsc, Re-opened Applicationsc, Registry Run Keys / Startup Folderc, Security Support Providerc, Shortcut Modificationc, Time Providersc, Winlogon Helper DLLc, XDG Autostart Entriesc

Boot or Logon Initialization Scriptsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec
has sub-classes
Logon Script (Mac)c, Logon Script (Windows)c, Network Logon Scriptc, Rc.commonc, Startup Itemsc

Boot Recordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BootRecord

has super-classes
Recordc
has sub-classes
Boot Sectorc, Volume Boot Recordc

Boot Sectorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BootSector

has super-classes
Boot Recordc
is also defined as
named individual

Bootkitc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1067

has super-classes
Persistence Techniquec

Bootkitc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1542.003

has super-classes
Pre-OS Bootc
may-modifyop some Boot Loaderc
may-modifyop some Boot Sectorc
may-modifyop some Volume Boot Recordc
is also defined as
named individual

Bootloader Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BootloaderAuthentication

has super-classes
Platform Hardeningc
authenticatesop some Boot Loaderc
is also defined as
named individual

Botnetc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1583.005

has super-classes
Acquire Infrastructurec

Botnetc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1584.005

has super-classes
Compromise Infrastructurec

Broadcast Domain Isolationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BroadcastDomainIsolation

has super-classes
Network Isolationc
filtersop some Local Area Network Trafficc
is also defined as
named individual

Browserc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Browser

has super-classes
User Applicationc
may-containop some Browser Extensionc
is also defined as
named individual

Browser Bookmark Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1217

has super-classes
Discovery Techniquec

Browser Extensionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BrowserExtension

has super-classes
User Applicationc
extendsop some Browserc
is also defined as
named individual

Browser Extensionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1176

has super-classes
Persistence Techniquec
modifiesop some Browser Extensionc
is also defined as
named individual

Brute Forcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1110

has super-classes
Credential Access Techniquec
has sub-classes
Credential Stuffingc, Password Crackingc, Password Guessingc, Password Sprayingc

Build Image on Hostc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1612

has super-classes
Defense Evasion Techniquec

Build Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BuildTool

has super-classes
Developer Applicationc
has sub-classes
Compilerc, Software Packaging Toolc

Business Communication Platform Clientc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BusinessCommunicationPlatformClient

is defined by
http://dbpedia.org/resource/Business_communication
has super-classes
Collaborative Softwarec

Business Relationshipsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1591.002

has super-classes
Gather Victim Org Informationc

Bypass User Access Controlc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1548.002

has super-classes
Abuse Elevation Control Mechanismc
executesop some Executable Filec
invokesop some Create Processc
may-modifyop some System Configuration Database Recordc
is also defined as
named individual

Bypass User Account Controlc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1088

has super-classes
Defense Evasion Techniquec
Privilege Escalation Techniquec

Byte Sequence Emulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ByteSequenceEmulation

has super-classes
Network Traffic Analysisc
is also defined as
named individual

CA Certificate Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CACertificateFile

has super-classes
Certificate Filec

Cached Domain Credentialsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.005

has super-classes
OS Credential Dumpingc
accessesop some Encrypted Credentialc
may-modifyop some Logc
is also defined as
named individual

Call Stackc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CallStack

has super-classes
Digital Artifactc
containsop some Stack Framec
is also defined as
named individual

Capabilityc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Capability

is defined by
http://dbpedia.org/resource/Capability_(systems_engineering)
has super-classes
D3FEND Thingc
assessed-byop some Capability Assessmentc
has-featureop some Capability Featurec

Capability Assessmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CapabilityAssessment

has super-classes
Assessmentc
has-implementationop some Capability Implementationc
assessesop some Capabilityc
has-evidenceop some Admin Feature Assessmentc
has-evidenceop some Defensive Technique Assessmentc

Capability Featurec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CapabilityFeature

has super-classes
D3FEND Catalog Thingc
has sub-classes
Administrative Featurec, Defensive Techniquec
is in range of
featuresop

Capability Feature Claimc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CapabilityFeatureClaim

has super-classes
Statementc
assessed-byop some Defensive Technique Assessmentc
authorop some Agentc
implemented-byop some Capability Implementationc
commentsdp some string
date createddp some date time
date modifieddp some date time
has sub-classes
Admin Feature Claimc, Defensive Technique Claimc
is in domain of
commentsdp, featuresop

Capability Implementationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CapabilityImplementation

has super-classes
D3FEND Catalog Thingc
featuresop some Administrative Featurec
latencyop some D3FEND Catalog Thingc
operating-systemdp some string
versiondp some string
has sub-classes
Productc, Servicec
is in domain of
implementsop, operating-systemdp
is in range of
implemented-byop

CAPEC Thingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CAPECThing

has sub-classes
Common Attack Patternc

Catalogc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Catalog

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Information Content Entityc
has sub-classes
Control Catalogc

CCI Controlc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCIControl

has super-classes
External Controlc
member-ofop some Control Correlation Identifier Catalogc
control-namedp some string
date publisheddp some date time
has members
CCI-000015ni, CCI-000016ni, CCI-000017ni, CCI-000018ni, CCI-000020ni, CCI-000022ni, CCI-000025ni, CCI-000027ni, CCI-000029ni, CCI-000030ni, CCI-000032ni, CCI-000034ni, CCI-000035ni, CCI-000037ni, CCI-000040ni, CCI-000044ni, CCI-000047ni, CCI-000056ni, CCI-000057ni, CCI-000058ni, CCI-000060ni, CCI-000066ni, CCI-000067ni, CCI-000068ni, CCI-000071ni, CCI-000139ni, CCI-000143ni, CCI-000144ni, CCI-000162ni, CCI-000163ni, CCI-000164ni, CCI-000185ni, CCI-000186ni, CCI-000187ni, CCI-000192ni, CCI-000193ni, CCI-000194ni, CCI-000195ni, CCI-000196ni, CCI-000197ni, CCI-000198ni, CCI-000199ni, CCI-000200ni, CCI-000205ni, CCI-000213ni, CCI-000218ni, CCI-000219ni, CCI-000226ni, CCI-000346ni, CCI-000352ni, CCI-000374ni, CCI-000381ni, CCI-000382ni, CCI-000386ni, CCI-000417ni, CCI-000663ni, CCI-000764ni, CCI-000765ni, CCI-000766ni, CCI-000767ni, CCI-000768ni, CCI-000771ni, CCI-000772ni, CCI-000774ni, CCI-000776ni, CCI-000804ni, CCI-000831ni, CCI-000877ni, CCI-000880ni, CCI-000884ni, CCI-000888ni, CCI-001009ni, CCI-001019ni, CCI-001067ni, CCI-001069ni, CCI-001082ni, CCI-001083ni, CCI-001084ni, CCI-001085ni, CCI-001086ni, CCI-001087ni, CCI-001089ni, CCI-001090ni, CCI-001092ni, CCI-001094ni, CCI-001096ni, CCI-001100ni, CCI-001109ni, CCI-001111ni, CCI-001115ni, CCI-001117ni, CCI-001118ni, CCI-001124ni, CCI-001125ni, CCI-001127ni, CCI-001128ni, CCI-001133ni, CCI-001144ni, CCI-001145ni, CCI-001146ni, CCI-001147ni, CCI-001150ni, CCI-001166ni, CCI-001169ni, CCI-001170ni, CCI-001178ni, CCI-001185ni, CCI-001199ni, CCI-001200ni, CCI-001210ni, CCI-001211ni, CCI-001233ni, CCI-001237ni, CCI-001239ni, CCI-001242ni, CCI-001262ni, CCI-001297ni, CCI-001305ni, CCI-001310ni, CCI-001350ni, CCI-001352ni, CCI-001356ni, CCI-001368ni, CCI-001372ni, CCI-001373ni, CCI-001374ni, CCI-001376ni, CCI-001377ni, CCI-001399ni, CCI-001400ni, CCI-001401ni, CCI-001403ni, CCI-001404ni, CCI-001405ni, CCI-001414ni, CCI-001424ni, CCI-001425ni, CCI-001426ni, CCI-001427ni, CCI-001428ni, CCI-001436ni, CCI-001452ni, CCI-001453ni, CCI-001454ni, CCI-001493ni, CCI-001494ni, CCI-001495ni, CCI-001496ni, CCI-001499ni, CCI-001555ni, CCI-001556ni, CCI-001557ni, CCI-001574ni, CCI-001589ni, CCI-001619ni, CCI-001632ni, CCI-001662ni, CCI-001668ni, CCI-001677ni, CCI-001682ni, CCI-001683ni, CCI-001684ni, CCI-001685ni, CCI-001686ni, CCI-001695ni, CCI-001744ni, CCI-001749ni, CCI-001762ni, CCI-001764ni, CCI-001767ni, CCI-001774ni, CCI-001811ni, CCI-001812ni, CCI-001813ni, CCI-001855ni, CCI-001858ni, CCI-001936ni, CCI-001937ni, CCI-001941ni, CCI-001953ni, CCI-001954ni, CCI-001957ni, CCI-001991ni, CCI-002005ni, CCI-002009ni, CCI-002010ni, CCI-002015ni, CCI-002016ni, CCI-002041ni, CCI-002145ni, CCI-002165ni, CCI-002169ni, CCI-002178ni, CCI-002179ni, CCI-002201ni, CCI-002205ni, CCI-002207ni, CCI-002211ni, CCI-002218ni, CCI-002233ni, CCI-002235ni, CCI-002238ni, CCI-002262ni, CCI-002263ni, CCI-002264ni, CCI-002272ni, CCI-002277ni, CCI-002281ni, CCI-002282ni, CCI-002283ni, CCI-002284ni, CCI-002289ni, CCI-002290ni, CCI-002302ni, CCI-002306ni, CCI-002307ni, CCI-002308ni, CCI-002309ni, CCI-002322ni, CCI-002346ni, CCI-002347ni, CCI-002353ni, CCI-002355ni, CCI-002357ni, CCI-002358ni, CCI-002359ni, CCI-002361ni, CCI-002363ni, CCI-002364ni, CCI-002381ni, CCI-002382ni, CCI-002384ni, CCI-002385ni, CCI-002394ni, CCI-002397ni, CCI-002400ni, CCI-002403ni, CCI-002409ni, CCI-002411ni, CCI-002420ni, CCI-002421ni, CCI-002422ni, CCI-002423ni, CCI-002425ni, CCI-002426ni, CCI-002460ni, CCI-002462ni, CCI-002463ni, CCI-002464ni, CCI-002465ni, CCI-002466ni, CCI-002467ni, CCI-002468ni, CCI-002470ni, CCI-002475ni, CCI-002476ni, CCI-002530ni, CCI-002531ni, CCI-002533ni, CCI-002536ni, CCI-002546ni, CCI-002605ni, CCI-002607ni, CCI-002613ni, CCI-002614ni, CCI-002617ni, CCI-002618ni, CCI-002630ni, CCI-002631ni, CCI-002661ni, CCI-002662ni, CCI-002684ni, CCI-002688ni, CCI-002689ni, CCI-002690ni, CCI-002691ni, CCI-002710ni, CCI-002711ni, CCI-002712ni, CCI-002715ni, CCI-002716ni, CCI-002717ni, CCI-002718ni, CCI-002723ni, CCI-002724ni, CCI-002726ni, CCI-002729ni, CCI-002740ni, CCI-002743ni, CCI-002746ni, CCI-002748ni, CCI-002749ni, CCI-002771ni, CCI-002824ni, CCI-002883ni, CCI-002890ni, CCI-002891ni, CCI-003014ni, CCI-003123ni

CDNsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1596.004

has super-classes
Search Open Technical Databasesc

Central Processing Unitc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CentralProcessingUnit

has super-classes
Processorc
containsop some Processor Registerc
may-containop some Processor Cache Memoryc
may-containop some Memory Management Unitc
may-containop some Memory Protection Unitc
is also defined as
named individual

Certificatec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Certificate

has super-classes
Digital Artifactc
containsop some Identifierc
containsop some Public Keyc
is also defined as
named individual

Certificate Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CertificateAnalysis

has super-classes
Network Traffic Analysisc
analyzesop some Certificate Filec
has sub-classes
Active Certificate Analysisc, Passive Certificate Analysisc
has members
Active Certificate Analysisni, Certificate Analysisni, Passive Certificate Analysisni
is also defined as
named individual

Certificate Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CertificateFile

has super-classes
Filec
containsop some Certificatec
has sub-classes
CA Certificate Filec
is also defined as
named individual

Certificate Pinningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CertificatePinning

has super-classes
Credential Hardeningc
authenticatesop some Public Keyc
is also defined as
named individual

Certificate Trust Storec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CertificateTrustStore

has super-classes
Trust Storec
containsop some Certificatec
is also defined as
named individual

Certificate-based Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Certificate-basedAuthentication

has super-classes
Credential Hardeningc
is also defined as
named individual

Change Default File Associationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1042

has super-classes
Persistence Techniquec

Change Default File Associationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.001

has super-classes
Event Triggered Executionc
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Chatroom Clientc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ChatroomClient

is defined by
http://dbpedia.org/resource/Chat_room
has super-classes
Collaborative Softwarec

Child Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ChildProcess

is defined by
http://dbpedia.org/resource/Child_process
has super-classes
Processc

Clear Command Historyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.003

has super-classes
Indicator Removal on Hostc
modifiesop some Command History Logc
is also defined as
named individual

Clear Command Historyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1146

has super-classes
Defense Evasion Techniquec

Clear Linux or Mac System Logsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.002

has super-classes
Indicator Removal on Hostc
modifiesop some Operating System Log Filec
is also defined as
named individual

Clear Windows Event Logsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.001

has super-classes
Indicator Removal on Hostc
modifiesop some Event Logc
is also defined as
named individual

Client Applicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ClientApplication

has super-classes
Applicationc
is also defined as
named individual

Client Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ClientComputer

is defined by
http://dbpedia.org/resource/Client_(computing)
has super-classes
Hostc
has sub-classes
Embedded Computerc, Personal Computerc, Shared Computerc

Client Configurationsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1592.004

has super-classes
Gather Victim Host Informationc

Client-server Payload Profilingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Client-serverPayloadProfiling

has super-classes
Network Traffic Analysisc
analyzesop some Network Trafficc
is also defined as
named individual

Clipboardc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Clipboard

has super-classes
Digital Artifactc
is also defined as
named individual

Clipboard Datac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1115

has super-classes
Collection Techniquec
readsop some Clipboardc
is also defined as
named individual

Cloud Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1087.004

has super-classes
Create Accountc
createsop some Cloud User Accountc
is also defined as
named individual

Cloud Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1136.003

has super-classes
Create Accountc

Cloud Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078.004

has super-classes
Valid Accountsc
usesop some Cloud User Accountc
is also defined as
named individual

Cloud Configurationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CloudConfiguration

has super-classes
Configuration Resourcec
has sub-classes
Cloud Instance Metadatac
is also defined as
named individual

Cloud Groupsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1069.003

has super-classes
Permission Groups Discoveryc

Cloud Infrastructure Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1580

has super-classes
Discovery Techniquec

Cloud Instance Metadatac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CloudInstanceMetadata

has super-classes
Cloud Configurationc
is also defined as
named individual

Cloud Instance Metadata APIc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.005

has super-classes
Unsecured Credentialsc
accessesop some Cloud Instance Metadatac
is also defined as
named individual

Cloud Instance Metadata APIc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1522

has super-classes
Credential Access Techniquec

Cloud Service Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CloudServiceAuthentication

has super-classes
Web Authenticationc
is also defined as
named individual

Cloud Service Authorizationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CloudServiceAuthorization

has super-classes
Authorizationc
is also defined as
named individual

Cloud Service Dashboardc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1538

has super-classes
Discovery Techniquec
accessesop some Cloud Configurationc
is also defined as
named individual

Cloud Service Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1526

has super-classes
Discovery Techniquec
readsop some Cloud Configurationc
is also defined as
named individual

Cloud Service Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CloudServiceSensor

has super-classes
Sensorc
monitorsop some Cloud Service Authenticationc
monitorsop some Cloud Service Authorizationc
is also defined as
named individual

Cloud Storagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CloudStorage

has super-classes
Secondary Storagec
is also defined as
named individual

Cloud Storage Object Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1619

has super-classes
Discovery Techniquec
accessesop some Cloud Storagec
is also defined as
named individual

Cloud User Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CloudUserAccount

has super-classes
User Accountc
is also defined as
named individual

CMSTPc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1191

has super-classes
Defense Evasion Techniquec
Execution Techniquec

CMSTPc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.003

has super-classes
Signed Binary Proxy Executionc
invokesop some Create Processc
may-produceop some Network Trafficc
is also defined as
named individual

Code Analyzerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CodeAnalyzer

has super-classes
Developer Applicationc
has sub-classes
Dynamic Analysis Toolc, Static Analysis Toolc

Code Repositoriesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1213.003

has super-classes
Data from Information Repositoriesc
readsop some Code Repositoryc
is also defined as
named individual

Code Repositoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CodeRepository

has super-classes
Databasec
containsop some Source Codec
is also defined as
named individual

Code Signingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1116

has super-classes
Defense Evasion Techniquec

Code Signingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.002

has super-classes
Subvert Trust Controlsc
enablesop some Defense Evasionc
is also defined as
named individual

Code Signing Certificatesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1587.002

has super-classes
Develop Capabilitiesc

Code Signing Certificatesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1588.003

has super-classes
Obtain Capabilitiesc

Code Signing Policy Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.006

has super-classes
Subvert Trust Controlsc

Collaborative Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CollaborativeSoftware

is defined by
http://dbpedia.org/resource/Collaborative_software
has super-classes
User Applicationc
has sub-classes
Business Communication Platform Clientc, Chatroom Clientc, Instant Messaging Clientc

Collectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Collection

has super-classes
Offensive Tacticc
is also defined as
named individual

Collection Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CollectionTechnique

has super-classes
Offensive Techniquec
enablesop some Collectionc
has sub-classes
Archive Collected Datac, Audio Capturec, Automated Collectionc, Clipboard Datac, Data Stagedc, Data from Cloud Storage Objectc, Data from Configuration Repositoryc, Data from Information Repositoriesc, Data from Local Systemc, Data from Network Shared Drivec, Data from Removable Mediac, Email Collectionc, Input Capturec, Man in the Browserc, Man-in-the-Middlec, Screen Capturec, Video Capturec
is also defined as
named individual

Commandc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Command

has super-classes
Digital Artifactc
Digital Eventc
has sub-classes
Database Queryc, Remote Commandc
is also defined as
named individual

Command And Controlc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CommandAndControl

has super-classes
Offensive Tacticc
is also defined as
named individual

Command and Control Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CommandAndControlTechnique

has super-classes
Offensive Techniquec
enablesop some Command And Controlc
has sub-classes
Application Layer Protocolc, Communication Through Removable Mediac, Custom Command and Control Protocolc, Custom Cryptographic Protocolc, Data Encodingc, Data Obfuscationc, Domain Frontingc, Domain Generation Algorithmsc, Dynamic Resolutionc, Encrypted Channelc, Fallback Channelsc, Ingress Tool Transferc, Multi-Stage Channelsc, Multi-hop Proxyc, Multilayer Encryptionc, Non-Application Layer Protocolc, Non-Standard Portc, Protocol Tunnelingc, Proxyc, Remote Access Softwarec, Standard Cryptographic Protocolc, Traffic Signalingc, Uncommonly Used Portc, Web Servicec
is also defined as
named individual

Command and Scripting Interpreter Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059

has super-classes
Execution Techniquec
executesop some Executable Scriptc
has sub-classes
AppleScript Executionc, JavaScript/JScriptc, Network Device CLIc, PowerShell Executionc, Python Executionc, Unix Shell Executionc, VBScript Executionc, Windows Command Shell Executionc
is also defined as
named individual

Command History Logc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CommandHistoryLog

has super-classes
Event Logc
is also defined as
named individual

Command History Log Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CommandHistoryLogFile

has super-classes
Log Filec
containsop some Command History Logc
is also defined as
named individual

Command Line Interfacec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CommandLineInterface

is defined by
http://dbpedia.org/resource/Command-line_interface
has super-classes
User Interfacec

Common Attack Patternc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CommonAttackPattern

has super-classes
CAPEC Thingc
has sub-classes
Exploitation of Transient Instruction Executionc
has members
Exploitation of Transient Instruction Executionni

Communication Through Removable Mediac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1092

has super-classes
Command and Control Techniquec
modifiesop some Removable Media Devicec
is also defined as
named individual

Compile After Deliveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.004

has super-classes
Obfuscated Files or Informationc
createsop some Executable Filec
is also defined as
named individual

Compile After Deliveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1500

has super-classes
Defense Evasion Techniquec

Compiled HTML Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.001

has super-classes
Signed Binary Proxy Executionc
invokesop some Create Filec
invokesop some Create Processc
is also defined as
named individual

Compiled HTML Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1223

has super-classes
Defense Evasion Techniquec
Execution Techniquec

Compilerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Compiler

has super-classes
Build Toolc
readsop some Compiler Configuration Filec
is also defined as
named individual

Compiler Configuration Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CompilerConfigurationFile

has super-classes
Application Configuration Filec
is also defined as
named individual

Component Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1109

has super-classes
Defense Evasion Techniquec
Persistence Techniquec

Component Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1542.002

has super-classes
Pre-OS Bootc
modifiesop some Firmwarec
is also defined as
named individual

Component Object Model Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1559.001

has super-classes
Inter-Process Communication Executionc

Component Object Model Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1122

has super-classes
Defense Evasion Techniquec
Persistence Techniquec

Component Object Model Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.015

has super-classes
Event Triggered Executionc
loadsop some Executable Binaryc
modifiesop some System Configuration Databasec
is also defined as
named individual

Composite Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CompositeTechnique

has super-classes
D3FEND Thingc

Compromise Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1586

has super-classes
Resource Development Techniquec
has sub-classes
Email Accountsc, Social Media Accountsc

Compromise Client Software Binaryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1554

has super-classes
Persistence Techniquec
modifiesop some Client Applicationc
is also defined as
named individual

Compromise Hardware Supply Chainc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1195.003

has super-classes
Supply Chain Compromisec
modifiesop some Hardware Devicec
is also defined as
named individual

Compromise Infrastructurec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1584

has super-classes
Resource Development Techniquec
has sub-classes
Botnetc, DNS Serverc, Domainsc, Serverc, Virtual Private Serverc, Web Servicesc

Compromise Software Dependencies and Development Toolsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1195.001

has super-classes
Supply Chain Compromisec
modifiesop some Softwarec
is also defined as
named individual

Compromise Software Supply Chainc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1195.002

has super-classes
Supply Chain Compromisec
modifiesop some Softwarec
is also defined as
named individual

Computing Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ComputingServer

is defined by
https://www.encyclopedia.com/computing/dictionaries-thesauruses-pictures-and-press-releases/compute-server
has super-classes
Serverc

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-362

has super-classes
Weaknessc
weakness ofop some Shared Resource Access Functionc
is also defined as
named individual

Conference Paperc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConferencePaper

has super-classes
Academic Articlec

Configuration Databasec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConfigurationDatabase

has super-classes
Configuration Resourcec
containsop some Configuration Database Recordc
has sub-classes
Application Configuration Databasec, Configuration Management Databasec
is also defined as
named individual

Configuration Database Recordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConfigurationDatabaseRecord

has super-classes
Configuration Resourcec
Recordc
has sub-classes
Application Configuration Database Recordc, System Configuration Database Recordc
is also defined as
named individual

Configuration Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConfigurationFile

is defined by
http://dbpedia.org/resource/Configuration_file
has super-classes
Filec
has sub-classes
Application Configuration Filec, Operating System Configuration Filec, Property List Filec, User Init Configuration Filec

Configuration Inventoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConfigurationInventory

has super-classes
Asset Inventoryc
inventoriesop some Configuration Resourcec
is also defined as
named individual

Configuration Management Databasec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConfigurationManagementDatabase

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Configuration Databasec

Configuration Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConfigurationResource

has super-classes
Resourcec
has sub-classes
Access Control Configurationc, Application Configurationc, Cloud Configurationc, Configuration Databasec, Configuration Database Recordc, Operating System Configurationc
is also defined as
named individual

Confluencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1213.001

has super-classes
Data from Information Repositoriesc
accessesop some Web File Resourcec
is also defined as
named individual

Connect Socketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConnectSocket

has super-classes
System Callc
connectsop some Pipec
is also defined as
named individual

Connected Honeynetc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConnectedHoneynet

has super-classes
Decoy Environmentc
spoofsop some Local Area Networkc
is also defined as
named individual

Connection Attempt Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConnectionAttemptAnalysis

has super-classes
Network Traffic Analysisc
analyzesop some Intranet Network Trafficc
is also defined as
named individual

Console Output Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConsoleOutputFunction

has super-classes
Subroutinec

Container Administration Commandc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1609

has super-classes
Execution Techniquec

Container and Resource Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1613

has super-classes
Discovery Techniquec

Container APIc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.007

has super-classes
Unsecured Credentialsc

Container Build Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ContainerBuildTool

has super-classes
Software Packaging Toolc

Container Imagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ContainerImage

has super-classes
Filec
is also defined as
named individual

Container Orchestration Jobc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053.007

has super-classes
Scheduled Task/Job Executionc

Container Orchestration Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ContainerOrchestrationSoftware

has super-classes
Service Applicationc
is also defined as
named individual

Container Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ContainerProcess

has super-classes
Application Processc

Container Runtimec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ContainerRuntime

has super-classes
Service Applicationc
runsop some Container Imagec
is also defined as
named individual

contributionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Contribution

has super-classes
D3FEND Thingc
has contributorop some Agentc
date createddp some date time

Control Catalogc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ControlCatalog

has super-classes
Catalogc
has-memberop some External Controlc
versiondp some integer or string
has sub-classes
Control Correlation Identifier Catalogc, NIST SP 800-53 Control Catalogc

Control Correlation Identifier Catalogc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ControlCorrelationIdentifierCatalog

has super-classes
Control Catalogc
has-memberop some CCI Controlc
has members
CCI Catalog v2022-04-05ni

Control Panel Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.002

has super-classes
Signed Binary Proxy Executionc
invokesop some Create Processc
may-modifyop some System Configuration Database Recordc
is also defined as
named individual

Control Panel Itemsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1196

has super-classes
Defense Evasion Techniquec
Execution Techniquec

Copy Memory Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CopyMemoryFunction

has super-classes
Subroutinec
copiesop some Memory Blockc
is also defined as
named individual

Copy Tokenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CopyToken

has super-classes
System Callc
copiesop some Access Tokenc
has members
Copy Tokenni
is also defined as
named individual

COR_PROFILERc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.012

has super-classes
Hijack Execution Flowc
addsop some Shared Library Filec
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Create Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1136

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec
createsop some User Accountc
has sub-classes
Cloud Accountc, Cloud Accountc, Domain Accountc, Domain Accountc, Local Accountc, Local Accountc
is also defined as
named individual

Create Cloud Instancec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1578.002

has super-classes
Modify Cloud Compute Infrastructurec

Create Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CreateFile

has super-classes
System Callc
createsop some Filec
is also defined as
named individual

Create or Modify System Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1543

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec
has sub-classes
Launch Agentc, Launch Daemonc, Systemd Servicec, Windows Servicec

Create Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CreateProcess

has super-classes
System Callc
createsop some Processc
has members
Linux Execni
is also defined as
named individual

Create Process with Tokenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.002

has super-classes
Access Token Manipulationc
copiesop some Access Tokenc
may-modifyop some Event Logc
is also defined as
named individual

Create Snapshotc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1578.001

has super-classes
Modify Cloud Compute Infrastructurec

Create Socketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CreateSocket

has super-classes
System Callc
createsop some Pipec
is also defined as
named individual

Create Threadc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CreateThread

has super-classes
System Callc
createsop some Threadc
is also defined as
named individual

Credentialc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Credential

has super-classes
Digital Artifactc
authenticatesop some User Accountc
has sub-classes
Access Tokenc, Encrypted Credentialc, Passwordc, Session Cookiec
is also defined as
named individual

Credential Accessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialAccess

has super-classes
Offensive Tacticc
is also defined as
named individual

Credential Access Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialAccessTechnique

has super-classes
Offensive Techniquec
accessesop some Credentialc
enablesop some Credential Accessc
may-accessop some Password Filec
may-invokeop some Create Processc
has sub-classes
Bash Historyc, Brute Forcec, Cloud Instance Metadata APIc, Credentials from Password Storesc, Credentials from Web Browsersc, Credentials in Filesc, Credentials in Registryc, Exploitation for Credential Accessc, Forced Authenticationc, Forge Web Credentialsc, Hookingc, Input Capturec, Input Promptc, Kerberoastingc, Keychainc, LLMNR/NBT-NS Poisoning and Relayc, Man-in-the-Middlec, Modify Authentication Processc, Multi-Factor Authentication Request Generationc, Network Sniffingc, OS Credential Dumpingc, Password Filter DLLc, Private Keysc, Securityd Memoryc, Steal Application Access Tokenc, Steal Web Session Cookiec, Steal or Forge Kerberos Ticketsc, Two-Factor Authentication Interceptionc, Unsecured Credentialsc
is also defined as
named individual

Credential API Hookingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1056.004

has super-classes
Input Capturec
may-modifyop some Process Code Segmentc
is also defined as
named individual

Credential Compromise Scope Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialCompromiseScopeAnalysis

has super-classes
User Behavior Analysisc
analyzesop some Credentialc
is also defined as
named individual

Credential Evictionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialEviction

has super-classes
Defensive Techniquec
enablesop some Evictc
has sub-classes
Account Lockingc, Authentication Cache Invalidationc, Credential Revokingc
has members
Account Lockingni, Authentication Cache Invalidationni, Credential Revokingni
is also defined as
named individual

Credential Hardeningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialHardening

has super-classes
Defensive Techniquec
enablesop some Hardenc
has sub-classes
Biometric Authenticationc, Certificate Pinningc, Certificate-based Authenticationc, Credential Transmission Scopingc, Domain Trust Policyc, Multi-factor Authenticationc, One-time Passwordc, Strong Password Policyc, User Account Permissionsc
has members
Biometric Authenticationni, Certificate Pinningni, Certificate-based Authenticationni, Credential Transmission Scopingni, Domain Trust Policyni, Multi-factor Authenticationni, One-time Passwordni, Strong Password Policyni, User Account Permissionsni
is also defined as
named individual

Credential Management Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialManagementSystem

has super-classes
Service Applicationc
is also defined as
named individual

Credential Revokingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialRevoking

has super-classes
Credential Evictionc
deletesop some Credentialc
is also defined as
named individual

Credential Stuffingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1110.004

has super-classes
Brute Forcec
may-createop some Intranet Administrative Network Trafficc
modifiesop some Authentication Logc
producesop some Authenticationc
is also defined as
named individual

Credential Transmission Scopingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialTransmissionScoping

has super-classes
Credential Hardeningc
restrictsop some Credentialc
is also defined as
named individual

Credentialsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1589.001

has super-classes
Gather Victim Identity Informationc

Credentials from Password Storesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555

has super-classes
Credential Access Techniquec
accessesop some Password Storec
may-accessop some Database Filec
has sub-classes
Credentials from Web Browsersc, Keychainc, Password Managersc, Securityd Memoryc, Windows Credential Managerc
is also defined as
named individual

Credentials from Web Browsersc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1503

has super-classes
Credential Access Techniquec

Credentials from Web Browsersc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555.003

has super-classes
Credentials from Password Storesc
accessesop some Database Filec
may-accessop some In-memory Password Storec
may-invokeop some Read Filec
is also defined as
named individual

Credentials in Filesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1081

has super-classes
Credential Access Techniquec

Credentials in Filesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.001

has super-classes
Unsecured Credentialsc
accessesop some Filec
is also defined as
named individual

Credentials in Registryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1214

has super-classes
Credential Access Techniquec

Credentials in Registryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.002

has super-classes
Unsecured Credentialsc
accessesop some System Configuration Databasec
is also defined as
named individual

Cron Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053.003

has super-classes
Scheduled Task/Job Executionc

Cross-Site Request Forgery (CSRF)c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-352

has super-classes
Weaknessc
weakness ofop some User Input Functionc
is also defined as
named individual

Cryptographic Keyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CryptographicKey

is defined by
http://dbpedia.org/resource/Public-key_cryptography
has super-classes
Digital Artifactc
has sub-classes
Asymmetric Keyc, Symmetric Keyc

Custom Archive Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CustomArchiveFile

has super-classes
Archive Filec
is also defined as
named individual

Custom Command and Control Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1094

has super-classes
Command and Control Techniquec

Custom Cryptographic Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1024

has super-classes
Command and Control Techniquec

D3FEND Catalog Thingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#D3FENDCatalogThing

has super-classes
D3FEND Thingc
has sub-classes
Agentc, Analysis of Alternativesc, Assessmentc, Capability Featurec, Capability Implementationc, Information Content Entityc, Propositionc

D3FEND Use Casec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#D3FENDUseCase

has super-classes
D3FEND Use Case Thingc
has audienceop some Target Audiencec
has goalop some Use Case Goalc
has prerequisiteop some Use Case Prerequisitec
has procedureop some Use Case Procedurec
is disjoint with
Target Audiencec, Use Case Goalc, Use Case Prerequisitec, Use Case Procedurec, Use Case Stepc

D3FEND Use Case Thingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#D3FENDUseCaseThing

has super-classes
D3FEND Thingc
has sub-classes
D3FEND Use Casec, Target Audiencec, Use Case Goalc, Use Case Prerequisitec, Use Case Procedurec, Use Case Stepc

Data Artifact Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DataArtifactServer

has super-classes
Artifact Serverc

Data Compressedc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1002

has super-classes
Exfiltration Techniquec

Data Dependencyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DataDependency

has super-classes
Dependencyc
is also defined as
named individual

Data Destructionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1485

has super-classes
Impact Techniquec

Data Encodingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1132

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Network Trafficc
has sub-classes
Non-Standard Encodingc, Standard Encodingc
is also defined as
named individual

Data Encryptedc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1022

has super-classes
Exfiltration Techniquec

Data Encrypted for Impactc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1486

has super-classes
Impact Techniquec

Data Exchange Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DataExchangeMapping

has super-classes
System Mappingc
mapsop some Data Dependencyc
is also defined as
named individual

Data from Cloud Storage Objectc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1530

has super-classes
Collection Techniquec

Data from Configuration Repositoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1602

has super-classes
Collection Techniquec
has sub-classes
Network Device Configuration Dumpc, SNMP (MIB Dump)c

Data from Information Repositoriesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1213

has super-classes
Collection Techniquec
Discovery Techniquec
accessesop some Resourcec
has sub-classes
Code Repositoriesc, Confluencec, Sharepointc
is also defined as
named individual

Data from Local Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1005

has super-classes
Collection Techniquec
accessesop some Filec
accessesop some Local Resourcec
is also defined as
named individual

Data from Network Shared Drivec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1039

has super-classes
Collection Techniquec
accessesop some Network File Share Resourcec
is also defined as
named individual

Data from Removable Mediac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1025

has super-classes
Collection Techniquec
accessesop some Removable Media Devicec
is also defined as
named individual

Data Inventoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DataInventory

has super-classes
Asset Inventoryc
inventoriesop some Databasec
inventoriesop some Document Filec
inventoriesop some Emailc
inventoriesop some Multimedia Document Filec
is also defined as
named individual

Data Link Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DataLinkLink

has super-classes
Logical Linkc

Data Manipulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1565

has super-classes
Impact Techniquec
has sub-classes
Runtime Data Manipulationc, Stored Data Manipulationc, Transmitted Data Manipulationc

Data Obfuscationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1001

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Network Trafficc
has sub-classes
Junk Datac, Protocol Impersonationc, Steganographyc
is also defined as
named individual

Data Stagedc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1074

has super-classes
Collection Techniquec
readsop some Resourcec
has sub-classes
Local Data Stagingc, Remote Data Stagingc
is also defined as
named individual

Data Transfer Size Limitsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1030

has super-classes
Exfiltration Techniquec
producesop some Internet Network Trafficc
is also defined as
named individual

Databasec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Database

has super-classes
Digital Artifactc
has sub-classes
Code Repositoryc, Password Databasec, System Configuration Databasec
is also defined as
named individual

Database Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DatabaseFile

has super-classes
Filec
is also defined as
named individual

Database Queryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DatabaseQuery

has super-classes
Commandc
has sub-classes
Remote Database Queryc
is also defined as
named individual

Database Query String Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DatabaseQueryStringAnalysis

has super-classes
Process Analysisc
analyzesop some Database Queryc
is also defined as
named individual

Database Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DatabaseServer

has super-classes
Serverc
containsop some Databasec
is also defined as
named individual

DCSyncc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.006

has super-classes
OS Credential Dumpingc
may-modifyop some Event Logc
producesop some Intranet Administrative Network Trafficc
is also defined as
named individual

Dead Code Eliminationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DeadCodeElimination

has super-classes
Application Hardeningc
is also defined as
named individual

Dead Drop Resolverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1102.001

has super-classes
Web Servicec

Debugger Evasionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1622

has super-classes
Defense Evasion Techniquec
Discovery Techniquec

Deceivec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Deceive

has super-classes
Defensive Tacticc
is also defined as
named individual

Decoy Artifactc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyArtifact

has super-classes
Digital Artifactc
may-containop some Digital Artifactc
is also defined as
named individual

Decoy Environmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyEnvironment

has super-classes
Defensive Techniquec
enablesop some Deceivec
managesop some Decoy Artifactc
has sub-classes
Connected Honeynetc, Integrated Honeynetc, Standalone Honeynetc
has members
Connected Honeynetni, Integrated Honeynetni, Standalone Honeynetni
is also defined as
named individual

Decoy Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyFile

has super-classes
Decoy Objectc
spoofsop some Filec
is also defined as
named individual

Decoy Network Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyNetworkResource

has super-classes
Decoy Objectc
spoofsop some Network Resourcec
is also defined as
named individual

Decoy Objectc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyObject

has super-classes
Defensive Techniquec
enablesop some Deceivec
has sub-classes
Decoy Filec, Decoy Network Resourcec, Decoy Personac, Decoy Public Releasec, Decoy Session Tokenc, Decoy User Credentialc
has members
Decoy Fileni, Decoy Network Resourceni, Decoy Personani, Decoy Public Releaseni, Decoy Session Tokenni, Decoy User Credentialni
is also defined as
named individual

Decoy Personac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyPersona

has super-classes
Decoy Objectc
spoofsop some Userc
is also defined as
named individual

Decoy Public Releasec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyPublicRelease

has super-classes
Decoy Objectc
is also defined as
named individual

Decoy Session Tokenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoySessionToken

has super-classes
Decoy Objectc
spoofsop some Access Tokenc
is also defined as
named individual

Decoy User Credentialc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyUserCredential

has super-classes
Decoy Objectc
spoofsop some Credentialc
is also defined as
named individual

Defacementc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1491

has super-classes
Impact Techniquec
has sub-classes
External Defacementc, Internal Defacementc

Default Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078.001

has super-classes
Valid Accountsc
usesop some Default User Accountc
is also defined as
named individual

Default User Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefaultUserAccount

has super-classes
User Accountc
is also defined as
named individual

Defense Evasionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefenseEvasion

has super-classes
Offensive Tacticc
is also defined as
named individual

Defense Evasion Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefenseEvasionTechnique

has super-classes
Offensive Techniquec
enablesop some Defense Evasionc
has sub-classes
Abuse Elevation Control Mechanismc, Access Token Manipulationc, Application Access Tokenc, BITS Jobsc, Binary Paddingc, Build Image on Hostc, Bypass User Account Controlc, CMSTPc, Clear Command Historyc, Code Signingc, Compile After Deliveryc, Compiled HTML Filec, Component Firmwarec, Component Object Model Hijackingc, Control Panel Itemsc, DLL Search Order Hijackingc, DLL Side-Loadingc, Debugger Evasionc, Deobfuscate/Decode Files or Informationc, Deploy Containerc, Direct Volume Accessc, Disabling Security Toolsc, Execution Guardrailsc, Exploitation for Defense Evasionc, Extra Window Memory Injectionc, File Deletionc, File and Directory Permissions Modificationc, Gatekeeper Bypassc, Group Policy Modificationc, HISTCONTROLc, Hidden Files and Directoriesc, Hidden Usersc, Hidden Windowc, Hide Artifactsc, Hijack Execution Flowc, Image File Execution Options Injectionc, Impair Defensesc, Indicator Blockingc, Indicator Removal from Toolsc, Indicator Removal on Hostc, Indirect Command Executionc, Install Root Certificatec, InstallUtilc, Launchctlc, Masqueradingc, Modify Authentication Processc, Modify Cloud Compute Infrastructurec, Modify Registryc, Modify System Imagec, Mshtac, NTFS File Attributesc, Network Boundary Bridgingc, Network Share Connection Removalc, Obfuscated Files or Informationc, Parent PID Spoofingc, Plist File Modificationc, Plist Modificationc, Pre-OS Bootc, Process Doppelgängingc, Process Hollowingc, Process Injectionc, Reflective Code Loadingc, Regsvcs/Regasmc, Regsvr32c, Revert Cloud Instancec, Rogue Domain Controllerc, Rootkitc, Rundll32c, SIP and Trust Provider Hijackingc, Signed Binary Proxy Executionc, Signed Script Proxy Executionc, Software Packingc, Space after Filenamec, Subvert Trust Controlsc, Template Injectionc, Timestompc, Traffic Signalingc, Trusted Developer Utilities Proxy Executionc, Unused/Unsupported Cloud Regionsc, Use Alternate Authentication Materialc, Valid Accountsc, Virtualization/Sandbox Evasionc, Weaken Encryptionc, Web Session Cookiec, XSL Script Processingc
is also defined as
named individual

Defensive Tacticc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefensiveTactic

is defined by
http://wordnet-rdf.princeton.edu/id/05913746-n
has super-classes
D3FEND Thingc
enabled-byop some Defensive Techniquec
has sub-classes
Deceivec, Detectc, Evictc, Hardenc, Isolatec, Modelc
has members
Deceiveni, Detectni, Evictni, Hardenni, Isolateni, Modelni

Defensive Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefensiveTechnique

has super-classes
Capability Featurec
D3FEND Thingc
Techniquec
enablesop some Defensive Tacticc
kb-referenceop some Technique Referencec
d3fend-iddp some string
datedp some date time
has sub-classes
Application Hardeningc, Asset Inventoryc, Credential Evictionc, Credential Hardeningc, Decoy Environmentc, Decoy Objectc, Execution Isolationc, File Analysisc, File Evictionc, Identifier Analysisc, Message Analysisc, Message Hardeningc, Network Isolationc, Network Mappingc, Network Traffic Analysisc, Operational Activity Mappingc, Platform Hardeningc, Platform Monitoringc, Process Analysisc, Process Evictionc, System Mappingc, User Behavior Analysisc
is in domain of
d3fend-tactical-verb-propertyop, may-be-tactically-associated-withop
has members
Application Hardeningni, Asset Inventoryni, Credential Evictionni, Credential Hardeningni, Decoy Environmentni, Decoy Objectni, Execution Isolationni, File Analysisni, File Evictionni, Identifier Analysisni, Message Analysisni, Message Hardeningni, Network Isolationni, Network Mappingni, Network Traffic Analysisni, Operational Activity Mappingni, Platform Hardeningni, Platform Monitoringni, Process Analysisni, Process Evictionni, System Mappingni, User Behavior Analysisni
is also defined as
named individual

Defensive Technique Assessmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefensiveTechniqueAssessment

has super-classes
Feature Assessmentc
assessesop some Defensive Technique Claimc
countersop some Offensive Techniquec
confidencedp some integer
ratingdp only { "0" , "1" , "2" , "3" }
stagedp only { "Deceive" , "Detect" , "Evict" , "Harden" , "Isolate" }
ratingdp exactly 1
stagedp exactly 1
is in range of
assessesop

Defensive Technique Claimc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefensiveTechniqueClaim

has super-classes
Capability Feature Claimc
citesop some Information Content Entityc
claimsop some Defensive Techniquec
is in domain of
assessesop

Delete Cloud Instancec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1578.003

has super-classes
Modify Cloud Compute Infrastructurec

Deobfuscate/Decode Files or Informationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1140

has super-classes
Defense Evasion Techniquec
invokesop some Create Processc
may-addop some Executable Filec
may-modifyop some Event Logc
is also defined as
named individual

Dependencyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Dependency

has super-classes
Digital Artifactc
dependentop some D3FEND Thingc
providerop some D3FEND Thingc
has sub-classes
Activity Dependencyc, Data Dependencyc, Service Dependencyc, System Dependencyc
is also defined as
named individual

Deploy Containerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1610

has super-classes
Defense Evasion Techniquec
Execution Techniquec

Deserialization Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DeserializationFunction

has super-classes
Subroutinec
is also defined as
named individual

Deserialization of Untrusted Datac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-502

has super-classes
Weaknessc
may be weakness ofop some User Input Functionc
weakness ofop some Deserialization Functionc
is also defined as
named individual

Desktop Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DesktopComputer

is defined by
http://dbpedia.org/resource/Desktop_computer
has super-classes
Personal Computerc

Detectc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Detect

has super-classes
Defensive Tacticc
is also defined as
named individual

Determine Physical Locationsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1591.001

has super-classes
Gather Victim Org Informationc

Develop Capabilitiesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1587

has super-classes
Resource Development Techniquec
has sub-classes
Code Signing Certificatesc, Digital Certificatesc, Exploitsc, Malwarec

Developer Applicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DeveloperApplication

has super-classes
User Applicationc
has sub-classes
Build Toolc, Code Analyzerc, Network Traffic Analysis Softwarec, Test Execution Toolc, Version Control Toolc

Device Registrationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098.005

has super-classes
Account Manipulationc

DHCP Spoofingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1557.003

has super-classes
Man-in-the-Middlec

Dial Up Modemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DialUpModem

is defined by
http://dbpedia.org/resource/Modem#Dial-up
has super-classes
Modemc

Digital Artifactc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DigitalArtifact

has super-classes
Artifactc
Digital Objectc
has sub-classes
Address Spacec, Binary Large Objectc, Binary Segmentc, Blobc, Block Devicec, Boot Loaderc, Call Stackc, Certificatec, Clipboardc, Commandc, Credentialc, Cryptographic Keyc, DNS Lookupc, Databasec, Decoy Artifactc, Dependencyc, Digital Systemc, Directoryc, Display Serverc, Domain Registrationc, Enclavec, File Sectionc, File Systemc, File System Linkc, Hardware Devicec, Hardware Driverc, Identifierc, Interprocess Communicationc, Intrusion Detection Systemc, Kernel Process Tablec, Linkc, Logc, Memory Addressc, Memory Extentc, Metadatac, Networkc, Network Flowc, Network Nodec, Network Trafficc, Operating Systemc, Page Tablec, Partitionc, Partition Tablec, Physical Locationc, Platformc, Pointerc, Processc, Process Imagec, Process Treec, Recordc, Resourcec, Sensorc, Sessionc, Shadow Stackc, Softwarec, Software Packagec, Stack Componentc, Storagec, System Callc, Task Schedulec, Threadc, Trust Storec, Userc, User Accountc, User Actionc, User Behaviorc, User Interfacec, User to User Messagec, Volumec
is in domain of
d3fend-artifact-data-propertydp
is in range of
hidesop
has members
Network Traffic Analysis Softwareni
is also defined as
named individual

Digital Certificatesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1587.003

has super-classes
Develop Capabilitiesc

Digital Certificatesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1588.004

has super-classes
Obtain Capabilitiesc

Digital Certificatesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1596.003

has super-classes
Search Open Technical Databasesc

Digital Eventc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DigitalEvent

has super-classes
D3FEND Thingc
has sub-classes
Commandc, DNS Lookupc, Resource Accessc, System Callc, User Actionc

Digital Objectc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DigitalObject

has super-classes
D3FEND Thingc
has sub-classes
Digital Artifactc

Digital Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DigitalSystem

has super-classes
Digital Artifactc
Systemc
has sub-classes
Legacy Systemc
is also defined as
named individual

Direct Network Floodc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1498.001

has super-classes
Network Denial of Servicec
createsop some Inbound Internet Network Trafficc
is also defined as
named individual

Direct Volume Accessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1006

has super-classes
Defense Evasion Techniquec
accessesop some Volumec
is also defined as
named individual

Directoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Directory

has super-classes
Digital Artifactc
may-containop some Filec
has sub-classes
Startup Directoryc, System Startup Directoryc
is also defined as
named individual

Directory Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DirectoryService

has super-classes
Network Servicec
is also defined as
named individual

Disable Cloud Logsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.008

has super-classes
Impair Defensesc

Disable Crypto Hardwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1600.002

has super-classes
Weaken Encryptionc

Disable or Modify Cloud Firewallc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.007

has super-classes
Impair Defensesc

Disable or Modify System Firewallc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.004

has super-classes
Impair Defensesc
modifiesop some System Firewall Configurationc
is also defined as
named individual

Disable or Modify Toolsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.001

has super-classes
Impair Defensesc
disablesop some Operating System Processc
is also defined as
named individual

Disable Windows Event Loggingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.002

has super-classes
Impair Defensesc
may-modifyop some Application Configurationc
may-modifyop some Operating System Configuration Componentc
is also defined as
named individual

Disabling Security Toolsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1089

has super-classes
Defense Evasion Techniquec

Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Discovery

has super-classes
Offensive Tacticc
is also defined as
named individual

Discovery Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DiscoveryTechnique

has super-classes
Offensive Techniquec
enablesop some Discoveryc
has sub-classes
Account Discoveryc, Application Window Discoveryc, Browser Bookmark Discoveryc, Cloud Infrastructure Discoveryc, Cloud Service Dashboardc, Cloud Service Discoveryc, Cloud Storage Object Discoveryc, Container and Resource Discoveryc, Data from Information Repositoriesc, Debugger Evasionc, Domain Trust Discoveryc, File and Directory Discoveryc, Group Policy Discoveryc, Network Service Scanningc, Network Share Discoveryc, Network Sniffingc, Password Policy Discoveryc, Peripheral Device Discoveryc, Permission Groups Discoveryc, Process Discoveryc, Query Registryc, Remote System Discoveryc, Security Software Discoveryc, Software Discoveryc, System Information Discoveryc, System Location Discoveryc, System Network Configuration Discoveryc, System Network Connections Discoveryc, System Owner/User Discoveryc, System Service Discoveryc, System Time Discoveryc
is also defined as
named individual

Disk Content Wipec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1488

has super-classes
Impact Techniquec

Disk Content Wipec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1561.001

has super-classes
Disk Wipec
may-modifyop some Boot Sectorc
may-modifyop some Partitionc
may-modifyop some Partition Tablec
may-modifyop some Volumec
modifiesop some Block Devicec
is also defined as
named individual

Disk Encryptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DiskEncryption

has super-classes
Platform Hardeningc
encryptsop some Storagec
is also defined as
named individual

Disk Structure Wipec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1487

has super-classes
Impact Techniquec

Disk Structure Wipec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1561.002

has super-classes
Disk Wipec
may-modifyop some Boot Sectorc
may-modifyop some Partition Tablec
is also defined as
named individual

Disk Wipec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1561

has super-classes
Impact Techniquec
has sub-classes
Disk Content Wipec, Disk Structure Wipec

Display Adapterc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DisplayAdapter

has super-classes
Output Devicec
is also defined as
named individual

Display Device Driverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DisplayDeviceDriver

has super-classes
Hardware Driverc
drivesop some Display Adapterc
is also defined as
named individual

Display Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DisplayServer

has super-classes
Digital Artifactc
is also defined as
named individual

Distributed Component Object Modelc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021.003

has super-classes
Remote Servicesc

DLL Search Order Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1038

has super-classes
Defense Evasion Techniquec
Persistence Techniquec
Privilege Escalation Techniquec

DLL Search Order Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.001

has super-classes
Hijack Execution Flowc
may-createop some Shared Library Filec
is also defined as
named individual

DLL Side-Loadingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1073

has super-classes
Defense Evasion Techniquec

DLL Side-Loadingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.002

has super-classes
Hijack Execution Flowc
may-createop some Shared Library Filec
may-modifyop some Shared Library Filec
is also defined as
named individual

DNSc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071.004

has super-classes
Application Layer Protocolc
producesop some Outbound Internet DNS Lookup Trafficc
is also defined as
named individual

DNSc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1590.002

has super-classes
Gather Victim Network Informationc

DNS Allowlistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSAllowlisting

has super-classes
Network Isolationc
blocksop some Outbound Internet DNS Lookup Trafficc
is also defined as
named individual

DNS Calculationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1568.003

has super-classes
Dynamic Resolutionc

DNS Denylistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSDenylisting

has super-classes
Network Isolationc
blocksop some DNS Network Trafficc
has sub-classes
Forward Resolution Domain Denylistingc, Forward Resolution IP Denylistingc, Reverse Resolution Domain Denylistingc, Reverse Resolution IP Denylistingc
has members
Forward Resolution Domain Denylistingni, Forward Resolution IP Denylistingni, Reverse Resolution Domain Denylistingni, Reverse Resolution IP Denylistingni
is also defined as
named individual

DNS Lookupc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSLookup

has super-classes
Digital Artifactc
Digital Eventc
has sub-classes
Internet DNS Lookupc, Intranet DNS Lookupc
is also defined as
named individual

DNS Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Outbound Internet DNS Lookup Trafficc
is also defined as
named individual

DNS Recordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSRecord

has super-classes
Recordc

DNS Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSServer

is defined by
http://dbpedia.org/resource/Name_server
has super-classes
Serverc

DNS Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1583.002

has super-classes
Acquire Infrastructurec

DNS Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1584.002

has super-classes
Compromise Infrastructurec

DNS Traffic Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSTrafficAnalysis

has super-classes
Network Traffic Analysisc
analyzesop some Outbound Internet DNS Lookup Trafficc
may-containop some DNS Lookupc
is also defined as
named individual

DNS/Passive DNSc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1596.001

has super-classes
Search Open Technical Databasesc

Documentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Document

has super-classes
Information Content Entityc
has sub-classes
Articlec, Patentc, Policyc, Specificationc, User Manualc

Document Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DocumentFile

has super-classes
Filec
may-containop some Executable Scriptc
has sub-classes
Emailc, Email Attachmentc, HTML Filec, Multimedia Document Filec, Office Application Filec
has members
Adobe PDF File 1.3ni, Microsoft Word DOC Fileni, Microsoft Word DOCB Fileni, Microsoft Word DOCM Fileni, Microsoft Word DOCX Fileni, Microsoft Word DOT Fileni, Microsoft Word DOTM Fileni, Microsoft Word DOTX Fileni, Microsoft Word WBK Fileni
is also defined as
named individual

Domain Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1087.002

has super-classes
Create Accountc
createsop some Domain User Accountc
is also defined as
named individual

Domain Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1136.002

has super-classes
Create Accountc

Domain Account Monitoringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainAccountMonitoring

has super-classes
User Behavior Analysisc
monitorsop some Domain User Accountc
is also defined as
named individual

Domain Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078.002

has super-classes
Valid Accountsc
usesop some Domain User Accountc
is also defined as
named individual

Domain Controller Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1556.001

has super-classes
Modify Authentication Processc

Domain Frontingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1090.004

has super-classes
Proxyc
producesop some Outbound Internet Encrypted Web Trafficc
is also defined as
named individual

Domain Frontingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1172

has super-classes
Command and Control Techniquec

Domain Generation Algorithmsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1483

has super-classes
Command and Control Techniquec

Domain Generation Algorithmsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1568.002

has super-classes
Dynamic Resolutionc

Domain Groupsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1069.002

has super-classes
Permission Groups Discoveryc

Domain Namec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainName

has super-classes
Identifierc
identifiesop some IP Addressc
has members
ASCII Domain Nameni, FQDN Domain Nameni, Hostnameni, Internationalized Domain Nameni
is also defined as
named individual

Domain Name Reputation Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainNameReputationAnalysis

has super-classes
Identifier Reputation Analysisc
analyzesop some Domain Namec
is also defined as
named individual

Domain Propertiesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1590.001

has super-classes
Gather Victim Network Informationc

Domain Registrationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainRegistration

has super-classes
Digital Artifactc
may-containop some Domain Namec
has members
WHOIS Compatible Domain Registrationni
is also defined as
named individual

Domain Trust Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1482

has super-classes
Discovery Techniquec

Domain Trust Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1484.002

has super-classes
Group Policy Modificationc

Domain Trust Policyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainTrustPolicy

has super-classes
Credential Hardeningc
restrictsop some Directory Servicec
restrictsop some Domain Accountc
is also defined as
named individual

Domain User Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainUserAccount

has super-classes
User Accountc
has sub-classes
Global User Accountc
is also defined as
named individual

Domainsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1583.001

has super-classes
Acquire Infrastructurec

Domainsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1584.001

has super-classes
Compromise Infrastructurec

Double File Extensionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.007

has super-classes
Masqueradingc
modifiesop some File System Metadatac
is also defined as
named individual

Downgrade Attackc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.010

has super-classes
Impair Defensesc
accessesop some Legacy Systemc
is also defined as
named individual

Downgrade System Imagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1601.002

has super-classes
Modify System Imagec

Drive-by Compromisec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1189

has super-classes
Initial Access Techniquec
modifiesop some Process Segmentc
producesop some Outbound Internet Network Trafficc
producesop some URLc
is also defined as
named individual

Drive-by Targetc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1608.004

has super-classes
Stage Capabilitiesc

Driver Load Integrity Checkingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DriverLoadIntegrityChecking

has super-classes
Platform Hardeningc
authenticatesop some Hardware Driverc
is also defined as
named individual

Dylib Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1157

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Dylib Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.004

has super-classes
Hijack Execution Flowc
may-createop some Shared Library Filec
may-modifyop some Shared Library Filec
is also defined as
named individual

Dynamic Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DynamicAnalysis

has super-classes
File Analysisc
analyzesop some Document Filec
analyzesop some Executable Filec
is also defined as
named individual

Dynamic Analysis Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DynamicAnalysisTool

is defined by
http://dbpedia.org/resource/Dynamic_program_analysis
has super-classes
Code Analyzerc

Dynamic Data Exchangec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1173

has super-classes
Execution Techniquec

Dynamic Data Exchange Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1559.002

has super-classes
Inter-Process Communication Executionc

Dynamic Resolutionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1568

has super-classes
Command and Control Techniquec
producesop some Outbound Internet DNS Lookup Trafficc
has sub-classes
DNS Calculationc, Domain Generation Algorithmsc, Fast Flux DNSc
is also defined as
named individual

Dynamic-link Library Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.001

has super-classes
Process Injectionc
addsop some Shared Library Filec
invokesop some System Callc
loadsop some Shared Library Filec
is also defined as
named individual

Elevated Execution with Promptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1514

has super-classes
Privilege Escalation Techniquec

Elevated Execution with Promptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1548.004

has super-classes
Abuse Elevation Control Mechanismc
createsop some System Configuration Databasec
invokesop some System Callc
is also defined as
named individual

Emailc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Email

has super-classes
Document Filec
may-containop some Filec
may-containop some URLc
has members
MSG Email Fileni
is also defined as
named individual

Email Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1087.003

has super-classes
Account Discoveryc

Email Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1585.002

has super-classes
Establish Accountsc

Email Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1586.002

has super-classes
Compromise Accountsc

Email Addressesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1589.002

has super-classes
Gather Victim Identity Informationc

Email Attachmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EmailAttachment

has super-classes
Document Filec
attached-toop some Emailc
is also defined as
named individual

Email Collectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1114

has super-classes
Collection Techniquec
accessesop some Resourcec
has sub-classes
Email Forwarding Rulec, Local Email Collectionc, Remote Email Collectionc
is also defined as
named individual

Email Forwarding Rulec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1114.003

has super-classes
Email Collectionc
modifiesop some Application Configurationc
is also defined as
named individual

Email Hiding Rulesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.008

has super-classes
Hide Artifactsc
may-createop some Email Rulec
may-modifyop some Email Rulec
modifiesop some Application Configurationc
is also defined as
named individual

Email Removalc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EmailRemoval

has super-classes
File Removalc
deletesop some Emailc
may-accessop some Mail Serverc
is also defined as
named individual

Email Rulec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EmailRule

has super-classes
Application Rulec
is also defined as
named individual

Embedded Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EmbeddedComputer

is defined by
http://dbpedia.org/resource/Embedded_system
has super-classes
Client Computerc

Emondc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1519

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Emondc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.014

has super-classes
Event Triggered Executionc
may-createop some Property List Filec
may-modifyop some Property List Filec
modifiesop some Configuration Resourcec
is also defined as
named individual

Employee Namesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1589.003

has super-classes
Gather Victim Identity Informationc

Emulated File Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EmulatedFileAnalysis

has super-classes
File Analysisc
analyzesop some Document Filec
analyzesop some Executable Filec
is also defined as
named individual

Enclavec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Enclave

has super-classes
Digital Artifactc
may-containop some Local Area Networkc
is also defined as
named individual

Encrypted Channelc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1573

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Encrypted Trafficc
has sub-classes
Asymmetric Cryptographyc, Symmetric Cryptographyc
is also defined as
named individual

Encrypted Credentialc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EncryptedCredential

has super-classes
Credentialc
has sub-classes
Encrypted Passwordc
is also defined as
named individual

Encrypted Passwordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EncryptedPassword

has super-classes
Encrypted Credentialc
Passwordc

Encrypted Tunnelsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EncryptedTunnels

has super-classes
Network Isolationc
isolatesop some Intranet Networkc
is also defined as
named individual

Endpoint Denial of Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1499

has super-classes
Impact Techniquec
has sub-classes
Application Exhaustion Floodc, Application or System Exploitationc, OS Exhaustion Floodc

Endpoint Health Beaconc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EndpointHealthBeacon

has super-classes
Operating System Monitoringc
is also defined as
named individual

Endpoint Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EndpointSensor

has super-classes
Sensorc
has sub-classes
Application Inventory Sensorc, File System Sensorc, Firmware Sensorc, Host Configuration Sensorc, Kernel API Sensorc
is also defined as
named individual

Environmental Keyingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1480.001

has super-classes
Execution Guardrailsc

Escape to Hostc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1611

has super-classes
Privilege Escalation Techniquec

Establish Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1585

has super-classes
Resource Development Techniquec
has sub-classes
Email Accountsc, Social Media Accountsc

Eval Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EvalFunction

has super-classes
Subroutinec
invokesop some Subroutinec
is also defined as
named individual

Event Logc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EventLog

has super-classes
Logc
has sub-classes
Command History Logc
is also defined as
named individual

Event Triggered Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec
has sub-classes
.bash_profile and .bashrcc, Accessibility Featuresc, AppCert DLLsc, AppInit DLLsc, Application Shimmingc, Change Default File Associationc, Component Object Model Hijackingc, Emondc, Image File Execution Options Injectionc, LC_LOAD_DYLIB Additionc, Netsh Helper DLLc, PowerShell Profilec, Screensaverc, Trapc, Windows Management Instrumentation Event Subscriptionc

Evictc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Evict

has super-classes
Defensive Tacticc
is also defined as
named individual

Eviction Latencyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EvictionLatency

has super-classes
Latencyc
has members
non-real-time-evictionni, real-time-evictionni

Exception Handlerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExceptionHandler

has super-classes
Subroutinec

Exception Handler Pointer Validationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExceptionHandlerPointerValidation

has super-classes
Application Hardeningc
validatesop some Pointerc
is also defined as
named individual

Exchange Email Delegate Permissionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098.002

has super-classes
Account Manipulationc
modifiesop some Domain User Accountc
is also defined as
named individual

Executable Allowlistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutableAllowlisting

has super-classes
Execution Isolationc
blocksop some Executable Filec
restrictsop some Create Processc
is also defined as
named individual

Executable Binaryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutableBinary

has super-classes
Executable Filec
containsop some Image Code Segmentc
containsop some Image Data Segmentc
may-interpretop some Executable Scriptc
has members
Linux ELF File 32bitni, Linux ELF File 64bitni, PE32 Executable Fileni, PE32+ Executable Fileni
is also defined as
named individual

Executable Denylistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutableDenylisting

has super-classes
Execution Isolationc
blocksop some Executable Filec
restrictsop some Create Processc
is also defined as
named individual

Executable Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutableFile

has super-classes
Filec
containsop some Subroutinec
has sub-classes
Executable Binaryc, Executable Scriptc
is also defined as
named individual

Executable Installer File Permissions Weaknessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.005

has super-classes
Hijack Execution Flowc
modifiesop some Service Applicationc
is also defined as
named individual

Executable Scriptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutableScript

has super-classes
Executable Filec
has sub-classes
Init Scriptc, Python Script Filec, System Init Scriptc, User Init Scriptc, User Startup Script Filec, Web Script Filec
has members
Bash Script Fileni, Javascript Fileni, Lua Script Fileni, Powershell Script Fileni, Ruby Script Fileni, Windows Batch Fileni
is also defined as
named individual

Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Execution

has super-classes
Offensive Tacticc
is also defined as
named individual

Execution Guardrailsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1480

has super-classes
Defense Evasion Techniquec
has sub-classes
Environmental Keyingc

Execution Isolationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutionIsolation

has super-classes
Defensive Techniquec
enablesop some Isolatec
has sub-classes
Executable Allowlistingc, Executable Denylistingc, Hardware-based Process Isolationc, IO Port Restrictionc, Kernel-based Process Isolationc
has members
Executable Denylistingni, Hardware-based Process Isolationni, IO Port Restrictionni, Kernel-based Process Isolationni
is also defined as
named individual

Execution Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutionTechnique

has super-classes
Offensive Techniquec
enablesop some Executionc
has sub-classes
AppleScriptc, CMSTPc, Command and Scripting Interpreter Executionc, Compiled HTML Filec, Container Administration Commandc, Control Panel Itemsc, Deploy Containerc, Dynamic Data Exchangec, Exploitation for Client Executionc, InstallUtilc, Inter-Process Communication Executionc, LSASS Driverc, Launchctlc, Local Job Schedulingc, Mshtac, Native API Executionc, PowerShellc, Regsvcs/Regasmc, Regsvr32c, Rundll32c, Scheduled Task/Job Executionc, Service Executionc, Shared Modules Executionc, Signed Binary Proxy Executionc, Signed Script Proxy Executionc, Software Deployment Tools Executionc, Space after Filenamec, System Servicesc, Trapc, User Executionc, Windows Management Instrumentation Executionc, Windows Remote Managementc
is also defined as
named individual

Exfiltrationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Exfiltration

has super-classes
Offensive Tacticc
is also defined as
named individual

Exfiltration Over Alternative Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1048

has super-classes
Exfiltration Techniquec
producesop some Internet Network Trafficc
has sub-classes
Exfiltration Over Asymmetric Encrypted Non-C2 Protocolc, Exfiltration Over Symmetric Encrypted Non-C2 Protocolc, Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocolc
is also defined as
named individual

Exfiltration Over Asymmetric Encrypted Non-C2 Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1048.002

has super-classes
Exfiltration Over Alternative Protocolc
may-transferop some Certificate Filec
producesop some Outbound Internet Encrypted Trafficc
is also defined as
named individual

Exfiltration Over Bluetoothc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1011.001

has super-classes
Exfiltration Over Other Network Mediumc

Exfiltration Over C2 Channelc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1041

has super-classes
Exfiltration Techniquec
may-transferop some Certificate Filec
producesop some Internet Network Trafficc
is also defined as
named individual

Exfiltration Over Other Network Mediumc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1011

has super-classes
Exfiltration Techniquec
producesop some Internet Network Trafficc
has sub-classes
Exfiltration Over Bluetoothc
is also defined as
named individual

Exfiltration Over Physical Mediumc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1052

has super-classes
Exfiltration Techniquec
has sub-classes
Exfiltration over USBc

Exfiltration Over Symmetric Encrypted Non-C2 Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1048.001

has super-classes
Exfiltration Over Alternative Protocolc
producesop some Outbound Internet Encrypted Trafficc
is also defined as
named individual

Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1048.003

has super-classes
Exfiltration Over Alternative Protocolc
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

Exfiltration over USBc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1052.001

has super-classes
Exfiltration Over Physical Mediumc
modifiesop some Removable Media Devicec
is also defined as
named individual

Exfiltration Over Web Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1567

has super-classes
Exfiltration Techniquec
producesop some Outbound Internet Web Trafficc
has sub-classes
Exfiltration to Cloud Storagec, Exfiltration to Code Repositoryc
is also defined as
named individual

Exfiltration Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExfiltrationTechnique

has super-classes
Offensive Techniquec
enablesop some Exfiltrationc
has sub-classes
Automated Exfiltrationc, Data Compressedc, Data Encryptedc, Data Transfer Size Limitsc, Exfiltration Over Alternative Protocolc, Exfiltration Over C2 Channelc, Exfiltration Over Other Network Mediumc, Exfiltration Over Physical Mediumc, Exfiltration Over Web Servicec, Scheduled Transferc, Transfer Data to Cloud Accountc
is also defined as
named individual

Exfiltration to Cloud Storagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1567.002

has super-classes
Exfiltration Over Web Servicec
producesop some Outbound Internet Encrypted Web Trafficc
is also defined as
named individual

Exfiltration to Code Repositoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1567.001

has super-classes
Exfiltration Over Web Servicec
may-produceop some Outbound Internet Encrypted Remote Terminal Trafficc
may-produceop some Outbound Internet Encrypted Web Trafficc
is also defined as
named individual

Exploit Public-Facing Applicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1190

has super-classes
Initial Access Techniquec
injectsop some Database Queryc
modifiesop some Process Segmentc
producesop some Inbound Internet Network Trafficc
is also defined as
named individual

Exploitation for Client Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1203

has super-classes
Execution Techniquec
modifiesop some Process Code Segmentc
modifiesop some Stack Framec
is also defined as
named individual

Exploitation for Credential Accessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1212

has super-classes
Credential Access Techniquec
may-accessop some Authentication Servicec
may-accessop some Credential Management Systemc
may-modifyop some Process Code Segmentc
may-modifyop some Stack Framec
is also defined as
named individual

Exploitation for Defense Evasionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1211

has super-classes
Defense Evasion Techniquec
may-modifyop some Process Code Segmentc
may-modifyop some Stack Framec
is also defined as
named individual

Exploitation for Privilege Escalationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1068

has super-classes
Privilege Escalation Techniquec
enablesop some Privilege Escalationc
may-modifyop some Stack Framec
modifiesop some Process Code Segmentc
is also defined as
named individual

Exploitation of Remote Servicesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1210

has super-classes
Lateral Movement Techniquec
may-modifyop some Process Code Segmentc
may-modifyop some Process Segmentc
may-modifyop some Stack Framec
producesop some Intranet Network Trafficc
is also defined as
named individual

Exploitation of Transient Instruction Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CAPEC-663

has super-classes
Common Attack Patternc
is also defined as
named individual

Exploitsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1587.004

has super-classes
Develop Capabilitiesc

Exploitsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1588.005

has super-classes
Obtain Capabilitiesc

External Content Inclusion Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExternalContentInclusionFunction

has super-classes
Subroutinec
is also defined as
named individual

External Controlc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExternalControl

has super-classes
D3FEND Thingc
member-ofop some Control Catalogc
semantic-relationop some Defensive Techniquec
has sub-classes
CCI Controlc, NIST Controlc

External Defacementc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1491.002

has super-classes
Defacementc
modifiesop some Network Resourcec
is also defined as
named individual

External Knowledge Basec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExternalKnowledgeBase

has super-classes
Information Content Entityc
Technique Referencec
has members
Reference - CAR-2013-01-002: Autorun Differences - MITREni, Reference - CAR-2013-01-003: SMB Events Monitoring - MITREni, Reference - CAR-2013-02-003: Processes Spawning cmd.exe - MITREni, Reference - CAR-2013-02-008: Simultaneous Logins on a Host - MITREni, Reference - CAR-2013-02-012: User Logged in to Multiple Hosts - MITREni, Reference - CAR-2013-03-001: Reg.exe called from Command Shell - MITREni, Reference - CAR-2013-04-002: Quick execution of a series of suspicious commands - MITREni, Reference - CAR-2013-05-002: Suspicious Run Locations - MITREni, Reference - CAR-2013-05-003: SMB Write Request - MITREni, Reference - CAR-2013-05-004: Execution with AT - MITREni, Reference - CAR-2013-05-005: SMB Copy and Execution - MITREni, Reference - CAR-2013-07-001: Suspicious Arguments - MITREni, Reference - CAR-2013-07-002: RDP Connection Detection - MITREni, Reference - CAR-2013-07-005: Command Line Usage of Archiving Software - MITREni, Reference - CAR-2013-08-001: Execution with schtasks - MITREni, Reference - CAR-2013-09-003: SMB Session Setups - MITREni, Reference - CAR-2013-09-005: Service Outlier Executables - MITREni, Reference - CAR-2013-10-001: User Login Activity Monitoring - MITREni, Reference - CAR-2013-10-002: DLL Injection via Load Library - MITREni, Reference - CAR-2014-02-001: Service Binary Modifications - MITREni, Reference - CAR-2014-03-001: SMB Write Request - NamedPipes - MITREni, Reference - CAR-2014-03-005: Remotely Launched Executables via Services - MITREni, Reference - CAR-2014-03-006: RunDLL32.exe monitoring - MITREni, Reference - CAR-2014-04-003: Powershell Execution - MITREni, Reference - CAR-2014-05-001: RPC Activity - MITREni, Reference - CAR-2014-05-002: Services launching Cmd - MITREni, Reference - CAR-2014-07-001: Service Search Path Interception - MITREni, Reference - CAR-2014-11-002: Outlier Parents of Cmd - MITREni, Reference - CAR-2014-11-003: Debuggers for Accessibility Applications - MITREni, Reference - CAR-2014-11-005: Remote Registry - MITREni, Reference - CAR-2014-11-006: Windows Remote Management (WinRM) - MITREni, Reference - CAR-2014-11-007: Remote Windows Management Instrumentation (WMI) over RPC - MITREni, Reference - CAR-2014-11-008: Command Launched from WinLogon - MITREni, Reference - CAR-2014-12-001: Remotely Launched Executables via WMI - MITREni, Reference - CAR-2015-04-001: Remotely Scheduled Tasks via AT - MITREni, Reference - CAR-2015-04-002: Remotely Scheduled Tasks via Schtasks - MITREni, Reference - CAR-2015-07-001: All Logins Since Last Boot - MITREni, Reference - CAR-2016-03-001: Host Discovery Commands - MITREni, Reference - CAR-2016-03-002: Create Remote Process via WMIC - MITREni, Reference - CAR-2016-04-002: User Activity from Clearing Event Logs - MITREni, Reference - CAR-2016-04-003: User Activity from Stopping Windows Defensive Services - MITREni, Reference - CAR-2016-04-004: Successful Local Account Loginni, Reference - CAR-2016-04-005: Remote Desktop Logon - MITREni, Reference - CAR-2019-04-001: UAC Bypass - MITREni, Reference - CAR-2019-04-002: Generic Regsvr32 - MITREni, Reference - CAR-2019-04-003: Squiblydoo - MITREni, Reference - CAR-2019-04-004: Credential Dumping via Mimikatz - MITREni, Reference - CAR-2019-07-001: Access Permission Modification - MITREni, Reference - CAR-2019-07-002: Lsass Process Dump via Procdump - MITREni, Reference - CAR-2019-08-001: Credential Dumping via Windows Task Manager - MITREni, Reference - CAR-2019-08-002: Active Directory Dumping via NTDSUtil - MITREni, Reference - CAR-2020-04-001: Shadow Copy Deletion - MITREni, Reference - CAR-2020-05-001: MiniDump of LSASS - MITREni, Reference - CAR-2020-05-003: Rare LolBAS Command Lines - MITREni, Reference - CAR-2020-08-001: NTFS Alternate Data Stream Execution - System Utilities - MITREni, Reference - CAR-2020-09-001: Scheduled Task - FileAccess - MITREni, Reference - CAR-2020-09-002: Component Object Model Hijacking - MITREni, Reference - CAR-2020-09-003: Indicator Blocking - Driver Unloaded - MITREni, Reference - CAR-2020-09-004: Credentials in Files & Registry - MITREni, Reference - CAR-2020-09-005: AppInit DLLs - MITREni, Reference - CAR-2020-11-001: Boot or Logon Initialization Scripts - MITREni, Reference - CAR-2020-11-002: Local Network Sniffing - MITREni, Reference - CAR-2020-11-003: DLL Injection with Mavinject - MITREni, Reference - CAR-2020-11-004: Processes Started From Irregular Parent - MITREni, Reference - CAR-2020-11-005: Clear Powershell Console Command History - MITREni, Reference - CAR-2020-11-006: Local Permission Group Discovery - MITREni, Reference - CAR-2020-11-007: Network Share Connection Removal - MITREni, Reference - CAR-2020-11-008: MSBuild and msxsl - MITREni, Reference - CAR-2020-11-009: Compiled HTML Access - MITREni, Reference - CAR-2020-11-010: CMSTP - MITREni, Reference - CAR-2020-11-011: Registry Edit from Screensaverni, Reference - CAR-2021-01-002: Unusually Long Command Line Strings - MITREni, Reference - CAR-2021-01-003: Clearing Windows Logs with Wevtutil - MITREni, Reference - CAR-2021-01-004: Unusual Child Process for Spoolsv.Exe or Connhost.Exe - MITREni, Reference - CAR-2021-01-006: Unusual Child Process spawned using DDE exploit - MITREni, Reference - CAR-2021-01-007: Detecting Tampering of Windows Defender Command Prompt - MITREni, Reference - CAR-2021-01-008: Disable UAC - MITREni, Reference - CAR-2021-01-009: Detecting Shadow Copy Deletion via Vssadmin.exe - MITREni, Reference - CAR-2021-02-001: Webshell-Indicative Process Tree - MITREni, Reference - CAR-2021-02-002: Get System Elevation - MITREni, Reference - CAR-2021-04-001: Common Windows Process Masquerading - MITREni, Reference - CAR-2021-05-001: Attempt To Add Certificate To Untrusted Store - MITREni, Reference - CAR-2021-05-002: Batch File Write to System32 - MITREni, Reference - CAR-2021-05-003: BCDEdit Failure Recovery Modification - MITREni, Reference - CAR-2021-05-004: BITS Job Persistence - MITREni, Reference - CAR-2021-05-005: BITSAdmin Download File - MITREni, Reference - CAR-2021-05-006: CertUtil Download With URLCache and Split Arguments - MITREni, Reference - CAR-2021-05-007: CertUtil Download With VerifyCtl and Split Arguments - MITREni, Reference - CAR-2021-05-008: Certutil exe certificate extraction - MITREni, Reference - CAR-2021-05-009: CertUtil With Decode Argument - MITREni, Reference - CAR-2021-05-010: Create local admin accounts using net exe - MITREni, Reference - CAR-2021-05-011: Create Remote Thread into LSASS - MITREni

External Proxyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1090.002

has super-classes
Proxyc
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

External Remote Servicesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1133

has super-classes
Initial Access Techniquec
Persistence Techniquec
producesop some Authenticationc
producesop some Authorizationc
producesop some Network Sessionc
is also defined as
named individual

Extra Window Memory Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.011

has super-classes
Process Injectionc

Extra Window Memory Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1181

has super-classes
Defense Evasion Techniquec
Privilege Escalation Techniquec

Fallback Channelsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1008

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

Fast Flux DNSc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1568.001

has super-classes
Dynamic Resolutionc

Fast Symbolic Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FastSymbolicLink

is defined by
http://dbpedia.org/resource/Symbolic_link#Storage_of_symbolic_links
has super-classes
Symbolic Linkc
Unix Linkc
is disjoint with
Slow Symbolic Linkc

Feature Assessmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FeatureAssessment

has super-classes
Assessmentc
has sub-classes
Admin Feature Assessmentc, Defensive Technique Assessmentc

Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#File

has super-classes
Resourcec
containsop some File Sectionc
may-containop some Filec
may-containop some URLc
has sub-classes
Archive Filec, Certificate Filec, Configuration Filec, Container Imagec, Database Filec, Document Filec, Executable Filec, Log Filec, NTFS Linkc, Object Filec, Operating System Filec, Password Filec, Shortcut Filec, Software Library Filec, Symbolic Linkc
is also defined as
named individual

File Access Pattern Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileAccessPatternAnalysis

has super-classes
Process Analysisc
analyzesop some Local Resource Accessc
is also defined as
named individual

File Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileAnalysis

has super-classes
Defensive Techniquec
analyzesop some Filec
enablesop some Detectc
has sub-classes
Dynamic Analysisc, Emulated File Analysisc, File Content Rulesc, File Hashingc
has members
Dynamic Analysisni, Emulated File Analysisni, File Content Rulesni, File Hashingni
is also defined as
named individual

File and Directory Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1083

has super-classes
Discovery Techniquec
accessesop some Directoryc
accessesop some Filec
is also defined as
named individual

File and Directory Permissions Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1222

has super-classes
Defense Evasion Techniquec
modifiesop some Access Control Configurationc
has sub-classes
Linux and Mac File and Directory Permissions Modificationc, Windows File and Directory Permissions Modificationc
is also defined as
named individual

File Carvingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileCarving

has super-classes
Network Traffic Analysisc
analyzesop some File Transfer Network Trafficc
is also defined as
named individual

File Content Rulesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileContentRules

has super-classes
File Analysisc
is also defined as
named individual

File Creation Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileCreationAnalysis

has super-classes
System Call Analysisc
analyzesop some Create Filec
is also defined as
named individual

File Deletionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.004

has super-classes
Indicator Removal on Hostc
deletesop some Filec
may-modifyop some Filec
is also defined as
named individual

File Deletionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1107

has super-classes
Defense Evasion Techniquec

File Encryptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileEncryption

has super-classes
Platform Hardeningc
encryptsop some Filec
is also defined as
named individual

File Evictionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileEviction

has super-classes
Defensive Techniquec
enablesop some Evictc
has sub-classes
File Removalc
has members
File Removalni
is also defined as
named individual

File Hashc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileHash

has super-classes
Identifierc
identifiesop some Filec
is also defined as
named individual

File Hash Reputation Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileHashReputationAnalysis

has super-classes
Identifier Reputation Analysisc
analyzesop some File Hashc
is also defined as
named individual

File Hashingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileHashing

has super-classes
File Analysisc
is also defined as
named individual

File Path Open Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FilePathOpenFunction

has super-classes
Subroutinec
accessesop some Filec
invokesop some Open Filec
is also defined as
named individual

File Removalc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileRemoval

has super-classes
File Evictionc
deletesop some Filec
may-accessop some File Serverc
has sub-classes
Email Removalc
has members
Email Removalni
is also defined as
named individual

File Sectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileSection

has super-classes
Digital Artifactc
has sub-classes
Image Segmentc, Resource Forkc
is also defined as
named individual

File Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileServer

has super-classes
Serverc
is also defined as
named individual

File Share Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileShareService

has super-classes
Network Servicec

File Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileSystem

has super-classes
Digital Artifactc
containsop some Directoryc
containsop some Filec
containsop some File System Linkc
containsop some File System Metadatac
is also defined as
named individual

File System Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileSystemLink

has super-classes
Digital Artifactc
has sub-classes
Hard Linkc, NTFS Linkc, Symbolic Linkc, Unix Linkc
is also defined as
named individual

File System Metadatac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileSystemMetadata

has super-classes
Metadatac
is also defined as
named individual

File System Permissions Weaknessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1044

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

File System Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileSystemSensor

has super-classes
Endpoint Sensorc
monitorsop some Filec
is also defined as
named individual

File Transfer Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileTransferNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Internet File Transfer Trafficc, Intranet File Transfer Trafficc, Outbound Internet File Transfer Trafficc
is also defined as
named individual

File Transfer Protocolsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071.002

has super-classes
Application Layer Protocolc
producesop some Outbound Internet File Transfer Trafficc
is also defined as
named individual

Finger Print Scanner Input Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FingerPrintScannerInputDevice

is defined by
http://dbpedia.org/resource/Fingerprint#Fingerprint_sensors
has super-classes
Image Scanner Input Devicec

Firewallc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Firewall

has super-classes
Network Nodec
has sub-classes
Application Layer Firewallc

Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Firmware

has super-classes
Softwarec
has sub-classes
Microcodec, Peripheral Firmwarec, System Firmwarec
is also defined as
named individual

Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1592.003

has super-classes
Gather Victim Host Informationc

Firmware Behavior Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FirmwareBehaviorAnalysis

has super-classes
Platform Monitoringc
analyzesop some Firmwarec
is also defined as
named individual

Firmware Corruptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1495

has super-classes
Impact Techniquec

Firmware Embedded Monitoring Codec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FirmwareEmbeddedMonitoringCode

has super-classes
Platform Monitoringc
analyzesop some Firmwarec
is also defined as
named individual

Firmware Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FirmwareSensor

has super-classes
Endpoint Sensorc
monitorsop some Firmwarec
is also defined as
named individual

Firmware Verificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FirmwareVerification

has super-classes
Platform Monitoringc
verifiesop some Firmwarec
has sub-classes
Peripheral Firmware Verificationc, System Firmware Verificationc
has members
Peripheral Firmware Verificationni, System Firmware Verificationni
is also defined as
named individual

First-stage Boot Loaderc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#First-stageBootLoader

has super-classes
Boot Loaderc

Flash Memoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FlashMemory

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Secondary Storagec

Forced Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1187

has super-classes
Credential Access Techniquec
may-modifyop some Windows Shortcut Filec
modifiesop some Authentication Logc
producesop some Authenticationc
is also defined as
named individual

Forge Web Credentialsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1606

has super-classes
Credential Access Techniquec
has sub-classes
SAML Tokensc, Web Cookiesc

Forward Proxy Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ForwardProxyServer

is defined by
http://dbpedia.org/resource/Open_proxy
has super-classes
Proxy Serverc

Forward Resolution Domain Denylistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ForwardResolutionDomainDenylisting

has super-classes
DNS Denylistingc
blocksop some Outbound Internet DNS Lookup Trafficc
has sub-classes
Hierarchical Domain Denylistingc, Homoglyph Denylistingc
has members
Hierarchical Domain Denylistingni, Homoglyph Denylistingni
is also defined as
named individual

Forward Resolution IP Denylistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ForwardResolutionIPDenylisting

has super-classes
DNS Denylistingc
blocksop some Inbound Internet DNS Response Trafficc
is also defined as
named individual

Free Memoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FreeMemory

has super-classes
System Callc
deletesop some Memory Blockc
is also defined as
named individual

Gatekeeper Bypassc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1144

has super-classes
Defense Evasion Techniquec

Gatekeeper Bypassc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.001

has super-classes
Subvert Trust Controlsc
modifiesop some File System Metadatac
is also defined as
named individual

Gather Victim Host Informationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1592

has super-classes
Reconnaissance Techniquec
has sub-classes
Client Configurationsc, Firmwarec, Hardwarec, Softwarec

Gather Victim Identity Informationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1589

has super-classes
Reconnaissance Techniquec
has sub-classes
Credentialsc, Email Addressesc, Employee Namesc

Gather Victim Network Informationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1590

has super-classes
Reconnaissance Techniquec
has sub-classes
DNSc, Domain Propertiesc, IP Addressesc, Network Security Appliancesc, Network Topologyc, Network Trust Dependenciesc

Gather Victim Org Informationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1591

has super-classes
Reconnaissance Techniquec
has sub-classes
Business Relationshipsc, Determine Physical Locationsc, Identify Business Tempoc, Identify Rolesc

Get Open Socketsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetOpenSockets

has super-classes
System Callc
enumeratesop some Pipec
is also defined as
named individual

Get Open Windowsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetOpenWindows

has super-classes
System Callc
has members
get foreground windowni
is also defined as
named individual

Get Running Processesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetRunningProcesses

has super-classes
System Callc
is also defined as
named individual

Get Screen Capturec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetScreenCapture

has super-classes
System Callc
is also defined as
named individual

Get System Config Valuec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetSystemConfigValue

has super-classes
System Config System Callc
readsop some System Configuration Database Recordc
has sub-classes
Get System Network Config Valuec
has members
reg open key ani, reg open key ex ani, reg open key ex wni, reg open key transacted ani, reg open key transacted wni, reg open key wni
is also defined as
named individual

Get System Network Config Valuec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetSystemNetworkConfigValue

has super-classes
Get System Config Valuec
is also defined as
named individual

Get System Timec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetSystemTime

has super-classes
System Callc
is also defined as
named individual

Global User Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GlobalUserAccount

has super-classes
Domain User Accountc
is also defined as
named individual

Golden Ticketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1558.001

has super-classes
Steal or Forge Kerberos Ticketsc
forgesop some Kerberos Ticket Granting Ticketc
is also defined as
named individual

Graphical User Interfacec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GraphicalUserInterface

has super-classes
User Interfacec
is also defined as
named individual

Graphics Card Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GraphicsCardFirmware

has super-classes
Peripheral Firmwarec

Graphics Processing Unitc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GraphicsProcessingUnit

has super-classes
Processorc

Group Policyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GroupPolicy

has super-classes
Access Control Configurationc
is also defined as
named individual

Group Policy Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1615

has super-classes
Discovery Techniquec
readsop some Group Policyc
is also defined as
named individual

Group Policy Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1484

has super-classes
Defense Evasion Techniquec
Privilege Escalation Techniquec
modifiesop some Group Policyc
has sub-classes
Domain Trust Modificationc, Group Policy Modificationc
is also defined as
named individual

Group Policy Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1484.001

has super-classes
Group Policy Modificationc

Group Policy Preferencesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.006

has super-classes
Unsecured Credentialsc
accessesop some Group Policyc
is also defined as
named individual

GUI Input Capturec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1056.002

has super-classes
Input Capturec
accessesop some Graphical User Interfacec
is also defined as
named individual

Guidancec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Guidance

has super-classes
Policyc

Guideline Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GuidelineReference

has super-classes
Policy Referencec
has members
Reference - Audit User Account Managementni, Reference - Digital Identity Guidelines 800-63-3ni, Reference - NIST Special Publication 800-160 Volume 1 - System Security Engineeringni, Reference - NIST Special Publication 800-37 Revision 2 - Risk Management Framework for Information Systems and Organizationsni, Reference - NIST Special Publication 800-53A Revision 5 - Assessing Security and Privacy Controls in Information Systems and Organizationsni, Reference - NISTIR 8011 Volume 1 - Automation Support for Security Control Assessmentsni, Reference - Platform Firmware Resiliency Guidelines - NISTni, Reference - Red Hat Enterprise Linux 8 Security Technical Implementation Guideni, Reference - Securing Web Transactionsni, Reference - Securing Web Transactions TLS Server Certificate Management - Appendix A Passive Inspectionni, Reference - Windows 10 STIGni

Hard Disk Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HardDiskFirmware

has super-classes
Peripheral Firmwarec

Hard Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HardLink

is defined by
http://dbpedia.org/resource/Hard_link
has super-classes
File System Linkc
has sub-classes
NTFS Hard Linkc, Unix Hard Linkc

Hardenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Harden

has super-classes
Defensive Tacticc
is also defined as
named individual

Hardwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1592.001

has super-classes
Gather Victim Host Informationc

Hardware Additionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1200

has super-classes
Initial Access Techniquec
connectsop some Hardware Devicec
is also defined as
named individual

Hardware Component Inventoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HardwareComponentInventory

has super-classes
Asset Inventoryc
inventoriesop some Hardware Devicec
is also defined as
named individual

Hardware Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HardwareDevice

has super-classes
Digital Artifactc
Physical Artifactc
has sub-classes
Input Devicec, Memory Management Unit Componentc, Output Devicec, Primary Storagec, Processorc, Processor Componentc, Removable Media Devicec, Secondary Storagec, Security Tokenc, Tertiary Storagec
is also defined as
named individual

Hardware Driverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HardwareDriver

has super-classes
Digital Artifactc
drivesop some Hardware Devicec
has sub-classes
Display Device Driverc
is also defined as
named individual

Hardware-based Process Isolationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Hardware-basedProcessIsolation

has super-classes
Execution Isolationc
isolatesop some Processc
restrictsop some Create Processc
is also defined as
named individual

Heap Segmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HeapSegment

has super-classes
Process Segmentc

Hidden File Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.005

has super-classes
Hide Artifactsc
may-modifyop some System Configuration Databasec
modifiesop some Storagec
is also defined as
named individual

Hidden Files and Directoriesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1158

has super-classes
Defense Evasion Techniquec
Persistence Techniquec

Hidden Files and Directoriesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.001

has super-classes
Hide Artifactsc
modifiesop some File System Metadatac
is also defined as
named individual

Hidden Usersc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1147

has super-classes
Defense Evasion Techniquec

Hidden Usersc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.002

has super-classes
Hide Artifactsc
modifiesop some User Init Configuration Filec
is also defined as
named individual

Hidden Windowc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1143

has super-classes
Defense Evasion Techniquec

Hidden Windowc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.003

has super-classes
Hide Artifactsc
may-modifyop some Property List Filec
may-modifyop some System Configuration Databasec
is also defined as
named individual

Hide Artifactsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564

has super-classes
Defense Evasion Techniquec
has sub-classes
Email Hiding Rulesc, Hidden File Systemc, Hidden Files and Directoriesc, Hidden Usersc, Hidden Windowc, NTFS File Attributesc, Process Argument Spoofingc, Resource Forkingc, Run Virtual Instancec, VBA Stompingc

Hierarchical Domain Denylistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HierarchicalDomainDenylisting

has super-classes
Forward Resolution Domain Denylistingc
is also defined as
named individual

Hijack Execution Flowc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574

has super-classes
Defense Evasion Techniquec
Persistence Techniquec
Privilege Escalation Techniquec
has sub-classes
COR_PROFILERc, DLL Search Order Hijackingc, DLL Side-Loadingc, Dylib Hijackingc, Executable Installer File Permissions Weaknessc, KernelCallbackTablec, LD_PRELOADc, Path Interception by PATH Environment Variablec, Path Interception by Search Order Hijackingc, Path Interception by Unquoted Pathc, Services File Permissions Weaknessc, Services Registry Permissions Weaknessc

HISTCONTROLc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1148

has super-classes
Defense Evasion Techniquec

Homoglyph Denylistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HomoglyphDenylisting

has super-classes
Forward Resolution Domain Denylistingc
is also defined as
named individual

Homoglyph Detectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HomoglyphDetection

has super-classes
Identifier Analysisc
analyzesop some Emailc
analyzesop some URLc
is also defined as
named individual

Hookingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1179

has super-classes
Credential Access Techniquec
Persistence Techniquec
Privilege Escalation Techniquec

Hostc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Host

has super-classes
Network Nodec
containsop some Applicationc
containsop some Operating Systemc
runsop some Operating Systemc
has sub-classes
Client Computerc, Serverc
is also defined as
named individual

Host Configuration Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HostConfigurationSensor

has super-classes
Endpoint Sensorc
monitorsop some Application Configurationc
monitorsop some Operating System Configurationc
is also defined as
named individual

Host-based Firewallc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Host-basedFirewall

has super-classes
System Softwarec
is also defined as
named individual

Hostnamec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Hostname

has super-classes
Identifierc
identifiesop some Hostc
is also defined as
named individual

HTML Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HTMLFile

has super-classes
Document Filec

HTML Smugglingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.006

has super-classes
Obfuscated Files or Informationc
createsop some JavaScript Blobc
hidesop some Digital Artifactc
is also defined as
named individual

Human Input Device Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HumanInputDeviceFirmware

has super-classes
Peripheral Firmwarec

Identifierc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Identifier

has super-classes
Digital Artifactc
has sub-classes
Domain Namec, File Hashc, Hostnamec, IP Addressc, URLc
is in domain of
addressesop
is in range of
addressed-byop
is also defined as
named individual

Identifier Activity Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IdentifierActivityAnalysis

has super-classes
Identifier Analysisc
is also defined as
named individual

Identifier Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IdentifierAnalysis

has super-classes
Defensive Techniquec
analyzesop some Identifierc
enablesop some Detectc
has sub-classes
Homoglyph Detectionc, Identifier Activity Analysisc, Identifier Reputation Analysisc, URL Analysisc
has members
Homoglyph Detectionni, Identifier Activity Analysisni, Identifier Reputation Analysisni, URL Analysisni
is also defined as
named individual

Identifier Reputation Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IdentifierReputationAnalysis

has super-classes
Identifier Analysisc
has sub-classes
Domain Name Reputation Analysisc, File Hash Reputation Analysisc, IP Reputation Analysisc, URL Reputation Analysisc
has members
Domain Name Reputation Analysisni, File Hash Reputation Analysisni, IP Reputation Analysisni, URL Reputation Analysisni
is also defined as
named individual

Identify Business Tempoc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1591.003

has super-classes
Gather Victim Org Informationc

Identify Rolesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1591.004

has super-classes
Gather Victim Org Informationc

IIS Componentsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.004

has super-classes
Server Software Componentc
addsop some Softwarec
is also defined as
named individual

Image Code Segmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImageCodeSegment

has super-classes
Image Segmentc
containsop some Subroutinec
has members
AMD64 Code Segmentni, ARM32 Code Segmentni, X86 Code Segmentni
is also defined as
named individual

Image Data Segmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImageDataSegment

has super-classes
Image Segmentc
is also defined as
named individual

Image File Execution Options Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1183

has super-classes
Defense Evasion Techniquec
Persistence Techniquec
Privilege Escalation Techniquec

Image File Execution Options Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.012

has super-classes
Event Triggered Executionc
modifiesop some System Configuration Databasec
is also defined as
named individual

Image Scanner Input Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImageScannerInputDevice

is defined by
http://dbpedia.org/resource/Image_scanner
has super-classes
Video Input Devicec
has sub-classes
Barcode Scanner Input Devicec, Finger Print Scanner Input Devicec

Image Segmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImageSegment

has super-classes
Binary Segmentc
File Sectionc
has sub-classes
Image Code Segmentc, Image Data Segmentc

Impactc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Impact

has super-classes
Offensive Tacticc
is also defined as
named individual

Impact Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImpactTechnique

has super-classes
Offensive Techniquec
enablesop some Impactc
has sub-classes
Account Access Removalc, Data Destructionc, Data Encrypted for Impactc, Data Manipulationc, Defacementc, Disk Content Wipec, Disk Structure Wipec, Disk Wipec, Endpoint Denial of Servicec, Firmware Corruptionc, Inhibit System Recoveryc, Network Denial of Servicec, Resource Hijackingc, Runtime Data Manipulationc, Service Stopc, Stored Data Manipulationc, System Shutdown/Rebootc, Transmitted Data Manipulationc
is also defined as
named individual

Impair Command History Loggingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.003

has super-classes
Impair Defensesc
may-modifyop some User Init Scriptc
may-modifyop some Windows Registry Keyc
modifiesop some Process Environment Variablec
is also defined as
named individual

Impair Defensesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562

has super-classes
Defense Evasion Techniquec
has sub-classes
Disable Cloud Logsc, Disable Windows Event Loggingc, Disable or Modify Cloud Firewallc, Disable or Modify System Firewallc, Disable or Modify Toolsc, Downgrade Attackc, Impair Command History Loggingc, Indicator Blockingc, Safe Mode Bootc

Impersonate Userc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImpersonateUser

has super-classes
System Callc
forgesop some User Accountc
has members
Impersonate Userni
is also defined as
named individual

Implant Container Imagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1525

has super-classes
Persistence Techniquec
addsop some Container Imagec
is also defined as
named individual

Import Library Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImportLibraryFunction

has super-classes
Subroutinec
loadsop some Shared Library Filec
is also defined as
named individual

Improper Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-287

has super-classes
Weaknessc
weakness ofop some Authentication Functionc
is also defined as
named individual

Improper Control of Generation of Code ('Code Injection')c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-94

has super-classes
Weaknessc
may be weakness ofop some Eval Functionc
may be weakness ofop some User Input Functionc
is also defined as
named individual

Improper Input Validationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-20

has super-classes
Weaknessc
weakness ofop some User Input Functionc
is also defined as
named individual

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-22

has super-classes
Weaknessc
weakness ofop some User Input Functionc
is also defined as
named individual

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-79

has super-classes
Weaknessc
weakness ofop some User Input Functionc
is also defined as
named individual

Improper Neutralization of Special Elements used in a Command ('Command Injection')c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-77

has super-classes
Weaknessc
weakness ofop some User Input Functionc
is also defined as
named individual

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-78

has super-classes
Weaknessc
may be weakness ofop some Eval Functionc
may be weakness ofop some Process Start Functionc
may be weakness ofop some User Input Functionc
is also defined as
named individual

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-89

has super-classes
Weaknessc
weakness ofop some User Input Functionc
is also defined as
named individual

Improper Restriction of Operations within the Bounds of a Memory Bufferc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-119

has super-classes
Weaknessc
weakness ofop some Raw Memory Access Functionc
is also defined as
named individual

Improper Restriction of XML External Entity Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-611

has super-classes
Weaknessc
weakness ofop some External Content Inclusion Functionc
is also defined as
named individual

In-memory Password Storec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#In-memoryPasswordStore

has super-classes
Password Storec
is also defined as
named individual

Inbound Internet DNS Response Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InboundInternetDNSResponseTraffic

has super-classes
Inbound Internet Network Trafficc
is also defined as
named individual

Inbound Internet Mail Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InboundInternetMailTraffic

has super-classes
Inbound Internet Network Trafficc
Inbound Network Trafficc
Mail Network Trafficc
is also defined as
named individual

Inbound Internet Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InboundInternetNetworkTraffic

has super-classes
Inbound Network Trafficc
Internet Network Trafficc
producesop some Network Trafficc
has sub-classes
Inbound Internet DNS Response Trafficc, Inbound Internet Mail Trafficc
is also defined as
named individual

Inbound Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InboundNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Inbound Internet Mail Trafficc, Inbound Internet Network Trafficc
is also defined as
named individual

Inbound Session Volume Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InboundSessionVolumeAnalysis

has super-classes
Network Traffic Analysisc
analyzesop some Inbound Internet Network Trafficc
is also defined as
named individual

Inbound Traffic Filteringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InboundTrafficFiltering

has super-classes
Network Traffic Filteringc
filtersop some Inbound Network Trafficc
is also defined as
named individual

Incorrect Default Permissionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-276

has super-classes
Weaknessc
weakness ofop some Application Installerc
is also defined as
named individual

Indicator Blockingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1054

has super-classes
Defense Evasion Techniquec

Indicator Blockingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.006

has super-classes
Impair Defensesc

Indicator Removal from Toolsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.005

has super-classes
Obfuscated Files or Informationc

Indicator Removal from Toolsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1066

has super-classes
Defense Evasion Techniquec

Indicator Removal on Hostc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070

has super-classes
Defense Evasion Techniquec
has sub-classes
Clear Command Historyc, Clear Linux or Mac System Logsc, Clear Windows Event Logsc, File Deletionc, Network Share Connection Removalc, Timestompc

Indirect Branch Call Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IndirectBranchCallAnalysis

has super-classes
Process Analysisc
is also defined as
named individual

Indirect Command Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1202

has super-classes
Defense Evasion Techniquec

Information Content Entityc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InformationContentEntity

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
D3FEND Catalog Thingc
archived-atdp some any u r i
has sub-classes
Catalogc, Documentc, External Knowledge Basec, Licensec, Source Codec
is in range of
citesop

Ingress Tool Transferc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1105

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

Inhibit System Recoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1490

has super-classes
Impact Techniquec

Init Scriptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InitScript

has super-classes
Executable Scriptc
has sub-classes
Network Init Script File Resourcec, User Init Scriptc

Initial Accessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InitialAccess

has super-classes
Offensive Tacticc
is also defined as
named individual

Initial Access Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InitialAccessTechnique

has super-classes
Offensive Techniquec
enablesop some Initial Accessc
has sub-classes
Drive-by Compromisec, Exploit Public-Facing Applicationc, External Remote Servicesc, Hardware Additionsc, Phishingc, Replication Through Removable Mediac, Spearphishing Attachmentc, Spearphishing Linkc, Spearphishing via Servicec, Supply Chain Compromisec, Trusted Relationshipc, Valid Accountsc
is also defined as
named individual

Input Capturec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1056

has super-classes
Collection Techniquec
Credential Access Techniquec
has sub-classes
Credential API Hookingc, GUI Input Capturec, Keyloggingc, Web Portal Capturec

Input Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InputDevice

has super-classes
Hardware Devicec
Local Resourcec
has sub-classes
Audio Input Devicec, Keyboard Input Devicec, Mouse Input Devicec, Video Input Devicec
is also defined as
named individual

Input Device Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InputDeviceAnalysis

has super-classes
Operating System Monitoringc
analyzesop some Input Devicec
is also defined as
named individual

Input Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InputFunction

has super-classes
Subroutinec
has sub-classes
User Input Functionc

Input Promptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1141

has super-classes
Credential Access Techniquec

Install Digital Certificatec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1608.003

has super-classes
Stage Capabilitiesc

Install Root Certificatec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1130

has super-classes
Defense Evasion Techniquec

Install Root Certificatec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.004

has super-classes
Subvert Trust Controlsc
modifiesop some Certificate Trust Storec
is also defined as
named individual

InstallUtilc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1118

has super-classes
Defense Evasion Techniquec
Execution Techniquec

InstallUtil Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.004

has super-classes
Signed Binary Proxy Executionc

Instant Messaging Clientc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InstantMessagingClient

is defined by
https://dbpedia.org/wiki/Instant_messaging
has super-classes
Collaborative Softwarec

Integer Overflow or Wraparoundc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-190

has super-classes
Weaknessc
weakness ofop some Mathematical Functionc
is also defined as
named individual

Integrated Honeynetc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntegratedHoneynet

has super-classes
Decoy Environmentc
spoofsop some Intranet Networkc
is also defined as
named individual

Integration Test Execution Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntegrationTestExecutionTool

has super-classes
Test Execution Toolc

Inter-Process Communication Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1559

has super-classes
Execution Techniquec
injectsop some Interprocess Communicationc
has sub-classes
Component Object Model Executionc, Dynamic Data Exchange Executionc, XPC Servicesc
is also defined as
named individual

Internal Defacementc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1491.001

has super-classes
Defacementc
modifiesop some Resourcec
is also defined as
named individual

Internal Proxyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1090.001

has super-classes
Proxyc
producesop some Intranet Network Trafficc
is also defined as
named individual

Internal Spearphishingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1534

has super-classes
Lateral Movement Techniquec
producesop some Emailc
is also defined as
named individual

Internet Articlec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InternetArticle

has super-classes
News Articlec
is also defined as
named individual

Internet Article Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InternetArticleReference

has super-classes
Technique Referencec
has members
Reference - Catia UAF Pluginni, Reference - Configure User Access Control and Permissionsni, Reference - Cyber Command System (CYCS)ni, Reference - Dagger Fact Sheetni, Reference - Decoy Personas for Safeguarding Online Identity Using Deception - MITREni, Reference - Detection of Malicious IDNHomoglyph Domainsni, Reference - FWTK - Firewall Toolkitni, Reference - How ASLR protects Linux systems from buffer overflow attacks - Network Worldni, Reference - How Does Antivirus Quarantine Work? - Safety Detectivesni, Reference - How to change registry values or permissions from a command line or a scriptni, Reference - How trust relationships work for resource forests in Azure Active Directory Domain Servicesni, Reference - MGT516: Managing Security Vulnerabilities: Enterprise and Cloudni, Reference - NIST RMF Quick Start Guide - Assess Step - Frequently Asked Questions (FAQ)ni, Reference - Overview of the seccomp sandboxni, Reference - Pointer Authentication Project Zeroni, Reference - Security Technologies: Stack Smashing Protection (StackGuard) - Red Hatni, Reference - Tenable Passive Network Monitoringni, Reference - The Pyramid of Pain - David Bianconi, Reference - What is NX/XD feature?ni, Reference - http://www.biometric-solutions.com/keystroke-dynamics.html - biometric-solutions.comni

Internet Connection Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1016.001

has super-classes
System Network Configuration Discoveryc

Internet DNS Lookupc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InternetDNSLookup

has super-classes
DNS Lookupc

Internet File Transfer Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InternetFileTransferTraffic

has super-classes
File Transfer Network Trafficc
Internet Network Trafficc

Internet Networkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InternetNetwork

is defined by
http://dbpedia.org/resource/Internetworking
has super-classes
Networkc

Internet Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InternetNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Inbound Internet Network Trafficc, Internet File Transfer Trafficc, Outbound Internet Network Trafficc
is also defined as
named individual

Interprocess Communicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InterprocessCommunication

has super-classes
Digital Artifactc
has sub-classes
Pipec
is also defined as
named individual

Intranet Administrative Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetAdministrativeNetworkTraffic

has super-classes
Administrative Network Trafficc
Intranet Network Trafficc
is also defined as
named individual

Intranet DNS Lookupc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetDNSLookup

has super-classes
DNS Lookupc

Intranet File Transfer Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetFileTransferTraffic

has super-classes
File Transfer Network Trafficc
Intranet Network Trafficc
is also defined as
named individual

Intranet IPC Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetIPCNetworkTraffic

has super-classes
IPC Network Trafficc
Intranet Network Trafficc
may-containop some Filec
is also defined as
named individual

Intranet Multicast Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetMulticastNetworkTraffic

has super-classes
Intranet Network Trafficc
is also defined as
named individual

Intranet Networkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetNetwork

has super-classes
Networkc
is also defined as
named individual

Intranet Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Intranet Administrative Network Trafficc, Intranet File Transfer Trafficc, Intranet IPC Network Trafficc, Intranet Multicast Network Trafficc, Intranet RPC Network Trafficc, Intranet Web Network Trafficc, Local Area Network Trafficc
is also defined as
named individual

Intranet RPC Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetRPCNetworkTraffic

has super-classes
Intranet Network Trafficc
RPC Network Trafficc

Intranet Web Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetWebNetworkTraffic

has super-classes
Intranet Network Trafficc
Web Network Trafficc
may-containop some Filec
is also defined as
named individual

Intrusion Detection Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntrusionDetectionSystem

is defined by
http://dbpedia.org/resource/Intrusion_detection_system
has super-classes
Digital Artifactc
has sub-classes
Intrusion Prevention Systemc

Intrusion Prevention Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntrusionPreventionSystem

is defined by
http://dbpedia.org/resource/Intrusion_detection_system#Intrusion_prevention
has super-classes
Intrusion Detection Systemc

Invalid Code Signaturec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.001

has super-classes
Masqueradingc
createsop some Executable Binaryc
is also defined as
named individual

IO Port Restrictionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IOPortRestriction

has super-classes
Execution Isolationc
filtersop some Input Devicec
filtersop some Removable Media Devicec
is also defined as
named individual

IP Addressc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IPAddress

has super-classes
Identifierc
identifiesop some Network Nodec
is also defined as
named individual

IP Addressesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1590.005

has super-classes
Gather Victim Network Informationc

IP Phonec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IPPhone

is defined by
http://dbpedia.org/resource/VoIP_phone
has super-classes
Personal Computerc

IP Reputation Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IPReputationAnalysis

has super-classes
Identifier Reputation Analysisc
analyzesop some IP Addressc
is also defined as
named individual

IPC Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IPCNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Intranet IPC Network Trafficc

IPC Traffic Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IPCTrafficAnalysis

has super-classes
Network Traffic Analysisc
analyzesop some Intranet IPC Network Trafficc
is also defined as
named individual

Isolatec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Isolate

has super-classes
Defensive Tacticc
is also defined as
named individual

Java Archivec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#JavaArchive

has super-classes
Archive Filec
Software Packagec

JavaScript Blobc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#JavaScriptBlob

has super-classes
Binary Large Objectc
is also defined as
named individual

JavaScript/JScriptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059.007

has super-classes
Command and Scripting Interpreter Executionc

Job Function Access Pattern Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#JobFunctionAccessPatternAnalysis

has super-classes
User Behavior Analysisc
analyzesop some Authorizationc
is also defined as
named individual

Journal Articlec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#JournalArticle

has super-classes
Academic Articlec

Junk Datac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1001.001

has super-classes
Data Obfuscationc

Kerberoastingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1208

has super-classes
Credential Access Techniquec

Kerberoastingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1558.003

has super-classes
Steal or Forge Kerberos Ticketsc
may-produceop some RPC Network Trafficc
is also defined as
named individual

Kerberos Ticketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#KerberosTicket

has super-classes
Access Tokenc
has sub-classes
Kerberos Ticket Granting Service Ticketc, Kerberos Ticket Granting Ticketc
is also defined as
named individual

Kerberos Ticket Granting Service Ticketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#KerberosTicketGrantingServiceTicket

has super-classes
Kerberos Ticketc

Kerberos Ticket Granting Ticketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#KerberosTicketGrantingTicket

has super-classes
Kerberos Ticketc
Ticket Granting Ticketc
is also defined as
named individual

Kernelc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Kernel

has super-classes
System Softwarec
containsop some Kernel Process Tablec
loadsop some Applicationc
managesop some Operating System Processc
managesop some User Processc
may-containop some Hardware Driverc
may-containop some Kernel Modulec
is also defined as
named individual

Kernel API Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#KernelAPISensor

has super-classes
Endpoint Sensorc
monitorsop some System Callc
is also defined as
named individual

Kernel Modulec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#KernelModule

has super-classes
Object Filec
is also defined as
named individual

Kernel Modules and Extensionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1215

has super-classes
Persistence Techniquec

Kernel Modules and Extensionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.006

has super-classes
Boot or Logon Autostart Executionc
modifiesop some Kernel Modulec
is also defined as
named individual

Kernel Process Tablec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#KernelProcessTable

has super-classes
Digital Artifactc
is also defined as
named individual

Kernel-based Process Isolationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Kernel-basedProcessIsolation

has super-classes
Execution Isolationc
has sub-classes
Mandatory Access Controlc, System Call Filteringc
has members
Mandatory Access Controlni, System Call Filteringni
is also defined as
named individual

KernelCallbackTablec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.013

has super-classes
Hijack Execution Flowc

Keyboard Input Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#KeyboardInputDevice

has super-classes
Input Devicec
is also defined as
named individual

Keychainc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1142

has super-classes
Credential Access Techniquec
accessesop some Encrypted Credentialc
is also defined as
named individual

Keychainc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555.001

has super-classes
Credentials from Password Storesc
accessesop some MacOS Keychainc
is also defined as
named individual

Keyloggingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1056.001

has super-classes
Input Capturec
accessesop some Keyboard Input Devicec
is also defined as
named individual

Kiosk Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#KioskComputer

is defined by
http://dbpedia.org/resource/Interactive_kiosk
has super-classes
Shared Computerc

Laptop Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LaptopComputer

is defined by
http://dbpedia.org/resource/Laptop
has super-classes
Personal Computerc

Latencyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Latency

has super-classes
D3FEND Thingc
has sub-classes
Analytic Latencyc, Eviction Latencyc

Lateral Movementc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LateralMovement

has super-classes
Offensive Tacticc
is also defined as
named individual

Lateral Movement Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LateralMovementTechnique

has super-classes
Offensive Techniquec
enablesop some Lateral Movementc
has sub-classes
Application Access Tokenc, Application Deployment Softwarec, Exploitation of Remote Servicesc, Internal Spearphishingc, Lateral Tool Transferc, Pass the Hashc, Pass the Ticketc, Remote Desktop Protocolc, Remote Service Session Hijackingc, Remote Servicesc, Replication Through Removable Mediac, SSH Hijackingc, Software Deployment Tools Executionc, Taint Shared Contentc, Use Alternate Authentication Materialc, Web Session Cookiec, Windows Admin Sharesc, Windows Remote Managementc
is also defined as
named individual

Lateral Tool Transferc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1570

has super-classes
Lateral Movement Techniquec
producesop some Intranet File Transfer Trafficc
is also defined as
named individual

Launch Agentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1159

has super-classes
Persistence Techniquec

Launch Agentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1543.001

has super-classes
Create or Modify System Processc
createsop some Property List Filec
is also defined as
named individual

Launch Daemonc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1160

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Launch Daemonc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1543.004

has super-classes
Create or Modify System Processc
modifiesop some Property List Filec
is also defined as
named individual

Launchctlc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1152

has super-classes
Defense Evasion Techniquec
Execution Techniquec
Persistence Techniquec

Launchctlc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1569.001

has super-classes
System Servicesc

Launchdc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053.004

has super-classes
Scheduled Task/Job Executionc
createsop some Property List Filec
is also defined as
named individual

LC_LOAD_DYLIB Additionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1161

has super-classes
Persistence Techniquec

LC_LOAD_DYLIB Additionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.006

has super-classes
Event Triggered Executionc
modifiesop some Executable Binaryc
is also defined as
named individual

LD_PRELOADc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.006

has super-classes
Hijack Execution Flowc
modifiesop some Operating System Configuration Filec
is also defined as
named individual

Legacy Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LegacySystem

has super-classes
Digital Systemc
is also defined as
named individual

Licensec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#License

has super-classes
Information Content Entityc
has sub-classes
Open Source Licensec, Proprietary Licensec

Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Link

has super-classes
Digital Artifactc
has sub-classes
Logical Linkc, Physical Linkc

Link Targetc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1608.005

has super-classes
Stage Capabilitiesc

Linux and Mac File and Directory Permissions Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1222.002

has super-classes
File and Directory Permissions Modificationc

ListPlantingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.015

has super-classes
Process Injectionc

LLMNR/NBT-NS Poisoning and Relayc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1171

has super-classes
Credential Access Techniquec

LLMNR/NBT-NS Poisoning and SMB Relayc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1557.001

has super-classes
Man-in-the-Middlec
producesop some Intranet Multicast Network Trafficc
is also defined as
named individual

Local Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1087.001

has super-classes
Create Accountc
createsop some Local User Accountc
is also defined as
named individual

Local Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1136.001

has super-classes
Create Accountc

Local Account Monitoringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalAccountMonitoring

has super-classes
User Behavior Analysisc
analyzesop some Local User Accountc
is also defined as
named individual

Local Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078.003

has super-classes
Valid Accountsc
usesop some Local User Accountc
is also defined as
named individual

Local Area Networkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalAreaNetwork

has super-classes
Networkc
may-containop some Hostc
is also defined as
named individual

Local Area Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalAreaNetworkTraffic

has super-classes
Intranet Network Trafficc
is also defined as
named individual

Local Authentication Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalAuthenticationService

has super-classes
Authentication Servicec
System Service Softwarec

Local Authorization Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalAuthorizationService

has super-classes
Authorization Servicec
System Service Softwarec

Local Data Stagingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1074.001

has super-classes
Data Stagedc
may-createop some Filec
may-invokeop some Create Filec
is also defined as
named individual

Local Email Collectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1114.001

has super-classes
Email Collectionc
readsop some Emailc
is also defined as
named individual

Local File Permissionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalFilePermissions

has super-classes
Platform Hardeningc
restrictsop some Directoryc
restrictsop some Filec
is also defined as
named individual

Local Groupsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1069.001

has super-classes
Permission Groups Discoveryc

Local Job Schedulingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1168

has super-classes
Execution Techniquec
Persistence Techniquec

Local Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalResource

has super-classes
Resourcec
has sub-classes
Input Devicec, Startup Directoryc, System Configuration Init Resourcec, User Logon Init Resourcec
is also defined as
named individual

Local Resource Accessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalResourceAccess

has super-classes
Resource Accessc
accessesop some Local Resourcec
is also defined as
named individual

Local User Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalUserAccount

has super-classes
User Accountc
is also defined as
named individual

Logc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Log

has super-classes
Digital Artifactc
has sub-classes
Authentication Logc, Authorization Logc, Event Logc, Packet Logc
is also defined as
named individual

Log Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LogFile

has super-classes
Filec
containsop some Logc
has sub-classes
Command History Log Filec, Operating System Log Filec
is also defined as
named individual

Log Message Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LogMessageFunction

has super-classes
Subroutinec

Logical Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LogicalLink

has super-classes
Linkc
has sub-classes
Application Layer Linkc, Data Link Linkc, Network Linkc, Transport Linkc
is also defined as
named individual

Logical Link Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LogicalLinkMapping

has super-classes
Network Mappingc
mapsop some Logical Linkc
mapsop some Networkc
mapsop some Network Nodec
has sub-classes
Active Logical Link Mappingc, Passive Logical Link Mappingc
has members
Active Logical Link Mappingni, Passive Logical Link Mappingni
is also defined as
named individual

Login Itemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1162

has super-classes
Persistence Techniquec

Login Itemsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.015

has super-classes
Boot or Logon Autostart Executionc
modifiesop some User Logon Init Resourcec
is also defined as
named individual

Login Sessionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LoginSession

has super-classes
Sessionc
has sub-classes
Remote Sessionc
is also defined as
named individual

Logon Script (Mac)c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.002

has super-classes
Boot or Logon Initialization Scriptsc
modifiesop some User Init Scriptc
is also defined as
named individual

Logon Script (Windows)c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.001

has super-classes
Boot or Logon Initialization Scriptsc
modifiesop some User Init Scriptc
is also defined as
named individual

Logon Userc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LogonUser

has super-classes
System Callc
authenticatesop some User Accountc
is also defined as
named individual

LSA Secretsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.004

has super-classes
OS Credential Dumpingc
may-accessop some Processc
may-accessop some System Password Databasec
is also defined as
named individual

LSASS Driverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1177

has super-classes
Execution Techniquec
Persistence Techniquec

LSASS Driverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.008

has super-classes
Boot or Logon Autostart Executionc
may-createop some Shared Library Filec
modifiesop some System Service Softwarec
is also defined as
named individual

LSASS Memoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.001

has super-classes
OS Credential Dumpingc
accessesop some Authentication Servicec
accessesop some Processc
is also defined as
named individual

MacOS Keychainc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MacOSKeychain

has super-classes
Password Storec
is also defined as
named individual

Mail Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MailNetworkTraffic

has super-classes
Network Trafficc
containsop some Emailc
has sub-classes
Inbound Internet Mail Trafficc
is also defined as
named individual

Mail Protocolsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071.003

has super-classes
Application Layer Protocolc
producesop some Outbound Internet Mail Trafficc
is also defined as
named individual

Mail Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MailServer

has super-classes
Serverc
runsop some Message Transfer Agentc
is also defined as
named individual

Mail Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MailService

has super-classes
Network Servicec
has sub-classes
Message Transfer Agentc

Make and Impersonate Tokenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.003

has super-classes
Access Token Manipulationc
copiesop some Access Tokenc
createsop some Login Sessionc
may-modifyop some Event Logc
is also defined as
named individual

Malicious File Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1204.002

has super-classes
User Executionc
executesop some Executable Filec
is also defined as
named individual

Malicious Imagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1204.003

has super-classes
User Executionc

Malicious Link Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1204.001

has super-classes
User Executionc
accessesop some URLc
producesop some Outbound Internet Web Trafficc
is also defined as
named individual

Malicious Shell Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1156

has super-classes
Persistence Techniquec

Malwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1587.001

has super-classes
Develop Capabilitiesc

Malwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1588.001

has super-classes
Obtain Capabilitiesc

Man in the Browserc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1185

has super-classes
Collection Techniquec
producesop some Web Network Trafficc
is also defined as
named individual

Man-in-the-Middlec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1557

has super-classes
Collection Techniquec
Credential Access Techniquec
producesop some Network Trafficc
has sub-classes
ARP Cache Poisoningc, DHCP Spoofingc, LLMNR/NBT-NS Poisoning and SMB Relayc
is also defined as
named individual

Mandatory Access Controlc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MandatoryAccessControl

has super-classes
Kernel-based Process Isolationc
isolatesop some Processc
restrictsop some Create Processc
is also defined as
named individual

Mark-of-the-Web Bypassc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.005

has super-classes
Subvert Trust Controlsc

Masquerade Task or Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.004

has super-classes
Masqueradingc
modifiesop some Task Schedulec
is also defined as
named individual

Masqueradingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036

has super-classes
Defense Evasion Techniquec
has sub-classes
Double File Extensionc, Invalid Code Signaturec, Masquerade Task or Servicec, Match Legitimate Name or Locationc, Rename System Utilitiesc, Right-to-Left Overridec, Space after Filenamec

Match Legitimate Name or Locationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.005

has super-classes
Masqueradingc
invokesop some Move Filec
may-createop some Filec
is also defined as
named individual

Mathematical Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MathematicalFunction

has super-classes
Subroutinec
is also defined as
named individual

Mavinjectc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.013

has super-classes
Signed Binary Proxy Executionc
invokesop some Create Threadc
modifiesop some Process Segmentc
is also defined as
named individual

Media Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MediaServer

is defined by
http://dbpedia.org/resource/Media_server
has super-classes
Serverc

Memory Addressc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryAddress

has super-classes
Digital Artifactc
addressesop some Memory Wordc
has sub-classes
Physical Addressc, Virtual Addressc
is also defined as
named individual

Memory Address Spacec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryAddressSpace

has super-classes
Address Spacec
containsop some Memory Addressc
has sub-classes
Virtual Memory Spacec
is also defined as
named individual

Memory Allocation Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryAllocationFunction

has super-classes
Subroutinec
invokesop some Allocate Memoryc
is also defined as
named individual

Memory Blockc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryBlock

has super-classes
Memory Extentc
containsop some Memory Wordc
may-containop some Recordc
has sub-classes
Pagec, Page Framec, Tertiary Storagec
is also defined as
named individual

Memory Boundary Trackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryBoundaryTracking

has super-classes
Operating System Monitoringc
analyzesop some Process Code Segmentc
is also defined as
named individual

Memory Extentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryExtent

has super-classes
Digital Artifactc
has sub-classes
Memory Blockc, Memory Poolc, Memory Wordc

Memory Free Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryFreeFunction

has super-classes
Subroutinec
invokesop some Free Memoryc
is also defined as
named individual

Memory Management Unitc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryManagementUnit

has super-classes
Processor Componentc
containsop some Translation Lookaside Bufferc
createsop some Virtual Addressc
managesop some Page Tablec
managesop some Storagec
is also defined as
named individual

Memory Management Unit Componentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryManagementUnitComponent

has super-classes
Hardware Devicec
has sub-classes
Translation Lookaside Bufferc

Memory Poolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryPool

has super-classes
Memory Extentc
containsop some Memory Blockc
is also defined as
named individual

Memory Protection Unitc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryProtectionUnit

has super-classes
Processor Componentc
is also defined as
named individual

Memory Wordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryWord

has super-classes
Memory Extentc
is also defined as
named individual

Message Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MessageAnalysis

has super-classes
Defensive Techniquec
enablesop some Detectc
has sub-classes
Sender MTA Reputation Analysisc, Sender Reputation Analysisc
has members
Sender MTA Reputation Analysisni, Sender Reputation Analysisni
is also defined as
named individual

Message Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MessageAuthentication

has super-classes
Message Hardeningc
authenticatesop some User to User Messagec
is also defined as
named individual

Message Encryptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MessageEncryption

has super-classes
Message Hardeningc
encryptsop some User to User Messagec
is also defined as
named individual

Message Hardeningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MessageHardening

has super-classes
Defensive Techniquec
enablesop some Hardenc
has sub-classes
Message Authenticationc, Message Encryptionc, Transfer Agent Authenticationc
has members
Message Authenticationni, Message Encryptionni, Transfer Agent Authenticationni
is also defined as
named individual

Message Transfer Agentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MessageTransferAgent

has super-classes
Mail Servicec
is also defined as
named individual

Metadatac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Metadata

is defined by
http://dbpedia.org/resource/Metadata
has super-classes
Digital Artifactc
has sub-classes
File System Metadatac

Microcodec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Microcode

is defined by
http://dbpedia.org/resource/Microcode
has super-classes
Firmwarec

Missing Authentication for Critical Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-306

has super-classes
Weaknessc

Missing Authorizationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-862

Broad and could apply to all resource accesses.
has super-classes
Weaknessc

MMCc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.014

has super-classes
Signed Binary Proxy Executionc
executesop some Commandc
may-addop some Softwarec
may-modifyop some System Configuration Databasec
is also defined as
named individual

Mobile Phonec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MobilePhone

is defined by
http://dbpedia.org/resource/Mobile_phone
has super-classes
Personal Computerc

Modelc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Model

has super-classes
Defensive Tacticc
is also defined as
named individual

Modemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Modem

is defined by
http://dbpedia.org/resource/Modem
has super-classes
Network Nodec
has sub-classes
Dial Up Modemc, Optical Modemc, Radio Modemc

Modify Authentication Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1556

has super-classes
Credential Access Techniquec
Defense Evasion Techniquec
modifiesop some Authentication Servicec
has sub-classes
Domain Controller Authenticationc, Network Device Authenticationc, Password Filter DLLc, Pluggable Authentication Modulesc, Reversible Encryptionc
is also defined as
named individual

Modify Cloud Compute Infrastructurec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1578

has super-classes
Defense Evasion Techniquec
has sub-classes
Create Cloud Instancec, Create Snapshotc, Delete Cloud Instancec, Revert Cloud Instancec

Modify Existing Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1031

has super-classes
Persistence Techniquec

Modify Registryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1112

has super-classes
Defense Evasion Techniquec
modifiesop some Windows Registryc
is also defined as
named individual

Modify System Imagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1601

has super-classes
Defense Evasion Techniquec
has sub-classes
Downgrade System Imagec, Patch System Imagec

Monitoringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Monitoring

is defined by
http://wordnet-rdf.princeton.edu/id/00881724-n
has super-classes
D3FEND Thingc

Mouse Input Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MouseInputDevice

is defined by
http://dbpedia.org/resource/Computer_mouse
has super-classes
Input Devicec

Move Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MoveFile

has super-classes
System Callc
modifiesop some File System Metadatac
is also defined as
named individual

MSBuildc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1127.001

has super-classes
Trusted Developer Utilities Proxy Executionc
modifiesop some Compiler Configuration Filec
runsop some Compilerc
is also defined as
named individual

Mshtac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1170

has super-classes
Defense Evasion Techniquec
Execution Techniquec

Mshta Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.005

has super-classes
Signed Binary Proxy Executionc

Msiexec Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.007

has super-classes
Signed Binary Proxy Executionc

Multi-factor Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Multi-factorAuthentication

has super-classes
Credential Hardeningc
authenticatesop some User Accountc
is also defined as
named individual

Multi-Factor Authentication Request Generationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1621

has super-classes
Credential Access Techniquec

Multi-hop Proxyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1090.003

has super-classes
Proxyc
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

Multi-hop Proxyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1188

has super-classes
Command and Control Techniquec

Multi-Stage Channelsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1104

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

Multilayer Encryptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1079

has super-classes
Command and Control Techniquec

Multimedia Document Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MultimediaDocumentFile

has super-classes
Document Filec
is also defined as
named individual

Native API Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1106

has super-classes
Execution Techniquec
invokesop some System Callc
is also defined as
named individual

Netsh Helper DLLc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1128

has super-classes
Persistence Techniquec

Netsh Helper DLLc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.007

has super-classes
Event Triggered Executionc
modifiesop some System Configuration Database Recordc
producesop some Processc
is also defined as
named individual

Networkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Network

has super-classes
Digital Artifactc
has sub-classes
Internet Networkc, Intranet Networkc, Local Area Networkc, Wide Area Networkc
is also defined as
named individual

Network Address Translation Traversalc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1599.001

has super-classes
Network Boundary Bridgingc

Network Agentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CollectorAgent

has super-classes
Softwarec
is also defined as
named individual

Network Boundary Bridgingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1599

has super-classes
Defense Evasion Techniquec
has sub-classes
Network Address Translation Traversalc

Network Card Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkCardFirmware

has super-classes
Peripheral Firmwarec

Network Denial of Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1498

has super-classes
Impact Techniquec
has sub-classes
Direct Network Floodc, Reflection Amplificationc, Service Exhaustion Floodc

Network Device Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1556.004

has super-classes
Modify Authentication Processc

Network Device CLIc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059.008

has super-classes
Command and Scripting Interpreter Executionc

Network Device Configuration Dumpc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1602.002

has super-classes
Data from Configuration Repositoryc

Network Directory Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkDirectoryResource

has super-classes
Network File Share Resourcec
containsop some Directoryc
is also defined as
named individual

Network File Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkFileResource

has super-classes
Network File Share Resourcec
containsop some Filec
has sub-classes
Network Init Script File Resourcec, Web File Resourcec
is also defined as
named individual

Network File Share Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkFileShareResource

has super-classes
Network Resourcec
has sub-classes
Network Directory Resourcec, Network File Resourcec
is also defined as
named individual

Network Flowc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkFlow

has super-classes
Digital Artifactc
summarizesop some Network Trafficc
is also defined as
named individual

Network Flow Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkFlowSensor

has super-classes
Network Sensorc
monitorsop some Network Flowc
is also defined as
named individual

Network Init Script File Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkInitScriptFileResource

has super-classes
Init Scriptc
Network File Resourcec
is also defined as
named individual

Network Isolationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkIsolation

has super-classes
Defensive Techniquec
enablesop some Isolatec
has sub-classes
Broadcast Domain Isolationc, DNS Allowlistingc, DNS Denylistingc, Encrypted Tunnelsc, Network Traffic Filteringc
has members
Broadcast Domain Isolationni, DNS Allowlistingni, DNS Denylistingni, Encrypted Tunnelsni, Network Traffic Filteringni
is also defined as
named individual

Network Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkLink

has super-classes
Logical Linkc

Network Logon Scriptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.003

has super-classes
Boot or Logon Initialization Scriptsc
modifiesop some Network Init Script File Resourcec
is also defined as
named individual

Network Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkMapping

has super-classes
Defensive Techniquec
enablesop some Modelc
has sub-classes
Logical Link Mappingc, Network Traffic Policy Mappingc, Network Vulnerability Assessmentc, Physical Link Mappingc
has members
Logical Link Mappingni, Network Traffic Policy Mappingni, Network Vulnerability Assessmentni, Physical Link Mappingni
is also defined as
named individual

Network Nodec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkNode

has super-classes
Digital Artifactc
runsop some Operating Systemc
has sub-classes
Firewallc, Hostc, Modemc, Proxy Serverc, RF Nodec, Routerc, Switchc, Wireless Access Pointc
is also defined as
named individual

Network Node Inventoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkNodeInventory

has super-classes
Asset Inventoryc
inventoriesop some Network Nodec
is also defined as
named individual

Network Packetc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkPackets

has super-classes
Network Trafficc
is also defined as
named individual

Network Printerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkPrinter

is defined by
http://dbpedia.org/resource/Printer_(computing)
has super-classes
Shared Computerc

Network Protocol Analyzerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkProtocolAnalyzer

has super-classes
Network Sensorc
monitorsop some Network Trafficc
is also defined as
named individual

Network Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkResource

has super-classes
Remote Resourcec
has sub-classes
Network File Share Resourcec, Serverc
is in range of
accessesop
is also defined as
named individual

Network Resource Accessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkResourceAccess

has super-classes
Resource Accessc
accessesop some Network Resourcec
accessesop some Resourcec
has sub-classes
Web Resource Accessc
is also defined as
named individual

Network Security Appliancesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1590.006

has super-classes
Gather Victim Network Informationc

Network Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkSensor

has super-classes
Sensorc
has sub-classes
Network Flow Sensorc, Network Protocol Analyzerc

Network Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkService

is defined by
http://dbpedia.org/resource/Network_service
has super-classes
Service Application Processc
has sub-classes
Authorization Servicec, Directory Servicec, File Share Servicec, Mail Servicec, Remote Authentication Servicec

Network Service Scanningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1046

has super-classes
Discovery Techniquec

Network Sessionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkSession

has super-classes
Network Trafficc
containsop some Network Packetc
has sub-classes
Remote Commandc, Remote Terminal Sessionc
is also defined as
named individual

Network Share Connection Removalc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.005

has super-classes
Indicator Removal on Hostc
unmountsop some Network File Share Resourcec
is also defined as
named individual

Network Share Connection Removalc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1126

has super-classes
Defense Evasion Techniquec

Network Share Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1135

has super-classes
Discovery Techniquec

Network Sniffingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1040

has super-classes
Credential Access Techniquec
Discovery Techniquec
may-produceop some DNS Lookupc
is also defined as
named individual

Network Topologyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1590.004

has super-classes
Gather Victim Network Informationc

Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTraffic

has super-classes
Digital Artifactc
may-containop some Domain Namec
originates-fromop some Physical Locationc
has sub-classes
Administrative Network Trafficc, DNS Network Trafficc, File Transfer Network Trafficc, IPC Network Trafficc, Inbound Network Trafficc, Internet Network Trafficc, Intranet Network Trafficc, Mail Network Trafficc, Network Packetc, Network Sessionc, Outbound Network Trafficc, RPC Network Trafficc, Web Network Trafficc
is also defined as
named individual

Network Traffic Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficAnalysis

has super-classes
Defensive Techniquec
enablesop some Detectc
has sub-classes
Administrative Network Activity Analysisc, Byte Sequence Emulationc, Certificate Analysisc, Client-server Payload Profilingc, Connection Attempt Analysisc, DNS Traffic Analysisc, File Carvingc, IPC Traffic Analysisc, Inbound Session Volume Analysisc, Network Traffic Community Deviationc, Per Host Download-Upload Ratio Analysisc, Protocol Metadata Anomaly Detectionc, RPC Traffic Analysisc, Relay Pattern Analysisc, Remote Terminal Session Detectionc
has members
Administrative Network Activity Analysisni, Byte Sequence Emulationni, Certificate Analysisni, Client-server Payload Profilingni, Connection Attempt Analysisni, DNS Traffic Analysisni, File Carvingni, IPC Traffic Analysisni, Inbound Session Volume Analysisni, Network Traffic Community Deviationni, Per Host Download-Upload Ratio Analysisni, Protocol Metadata Anomaly Detectionni, RPC Traffic Analysisni, Relay Pattern Analysisni, Remote Terminal Session Detectionni
is also defined as
named individual

Network Traffic Analysis Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficAnalysisSoftware

has super-classes
Developer Applicationc
is also defined as
named individual

Network Traffic Community Deviationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficCommunityDeviation

has super-classes
Network Traffic Analysisc
analyzesop some Network Trafficc
is also defined as
named individual

Network Traffic Filteringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficFiltering

has super-classes
Network Isolationc
filtersop some Network Trafficc
has sub-classes
Inbound Traffic Filteringc, Outbound Traffic Filteringc
has members
Inbound Traffic Filteringni, Outbound Traffic Filteringni
is also defined as
named individual

Network Traffic Policy Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficPolicyMapping

has super-classes
Network Mappingc
mapsop some Access Control Configurationc
queriesop some Network Agentc
is also defined as
named individual

Network Trust Dependenciesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1590.003

has super-classes
Gather Victim Network Informationc

Network Vulnerability Assessmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkVulnerabilityAssessment

has super-classes
Network Mappingc
evaluatesop some Networkc
identifiesop some vulnerabilityc
is also defined as
named individual

New Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1050

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

News Articlec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NewsArticle

has super-classes
Articlec
has sub-classes
Internet Articlec

NIST Controlc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NISTControl

has super-classes
External Controlc
member-ofop some NIST SP 800-53 Control Catalogc
has members
AC-17(8)ni, AC-2(1)ni, AC-2(13)ni, AC-2(2)ni, AC-2(3)ni, AC-2(4)ni, AC-2(5)ni, AC-2(6)ni, AC-2(7)ni, AC-2(9)ni, AC-23ni, AC-24ni, AC-24(1)ni, AC-24(2)ni, AC-3ni, AC-3(11)ni, AC-3(13)ni, AC-3(3)ni, AC-3(7)ni, AC-3(8)ni, AC-4ni, AC-4(1)ni, AC-4(10)ni, AC-4(11)ni, AC-4(12)ni, AC-4(13)ni, AC-4(14)ni, AC-4(15)ni, AC-4(17)ni, AC-4(19)ni, AC-4(20)ni, AC-4(21)ni, AC-4(26)ni, AC-4(27)ni, AC-4(28)ni, AC-4(29)ni, AC-4(3)ni, AC-4(30)ni, AC-4(32)ni, AC-4(4)ni, AC-4(5)ni, AC-4(6)ni, AC-4(8)ni, AC-5ni, AC-6ni, AC-6(1)ni, AC-6(10)ni, AC-6(3)ni, AC-6(4)ni, AC-6(5)ni, AC-6(6)ni, AC-6(9)ni, AC-7ni, AC-7(3)ni, AC-7(4)ni, AU-10(5)ni, AU-14(2)ni, AU-15ni, AU-2ni, AU-2(1)ni, AU-2(2)ni, AU-3ni, AU-4ni, CM-14ni, CM-5ni, CM-5(1)ni, CM-5(3)ni, CM-5(5)ni, CM-5(6)ni, CM-6(3)ni, IA-2(1)ni, IA-2(2)ni, IA-2(4)ni, IA-2(6)ni, IR-4(12)ni, IR-4(13)ni, MA-3(3)ni, MA-3(4)ni, MA-3(5)ni, MA-3(6)ni, MA-4(1)ni, MA-6ni, MA-6(1)ni, MA-6(2)ni, MA-6(3)ni, RA-3(3)ni, RA-3(4)ni, RA-5ni, RA-5(2)ni, RA-5(3)ni, RA-5(4)ni, RA-5(5)ni, RA-5(6)ni, RA-5(7)ni, SA-10(1)ni, SA-10(3)ni, SA-10(4)ni, SA-10(5)ni, SA-10(6)ni, SA-11(1)ni, SA-11(8)ni, SA-8(18)ni, SA-8(22)ni, SC-2ni, SC-2(1)ni, SC-3ni, SC-3(1)ni, SI-2(4)ni, SI-2(5)ni, SI-2(6)ni, SI-3ni, SI-3(10)ni, SI-3(4)ni, SI-3(8)ni, SI-4ni, SI-4(2)ni, SI-4(4)ni

NIST SP 800-53 Control Catalogc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NISTSP800-53ControlCatalog

has super-classes
Control Catalogc
has-memberop some NIST Controlc
has members
NIST SP 800-53 R3ni, NIST SP 800-53 R4ni, NIST SP 800-53 R5ni

Non-Application Layer Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1095

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

Non-Standard Encodingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1132.002

has super-classes
Data Encodingc

Non-Standard Portc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1571

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

NTDSc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.003

has super-classes
OS Credential Dumpingc
accessesop some Encrypted Credentialc
is also defined as
named individual

NTFS File Attributesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1096

has super-classes
Defense Evasion Techniquec

NTFS File Attributesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.004

has super-classes
Hide Artifactsc
modifiesop some File System Metadatac
is also defined as
named individual

NTFS Hard Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NTFSHardLink

is defined by
http://dbpedia.org/resource/NTFS_links
has super-classes
Hard Linkc
NTFS Linkc

NTFS Junction Pointc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NTFSJunctionPoint

is defined by
http://dbpedia.org/resource/NTFS_links
has super-classes
NTFS Linkc
Symbolic Linkc

NTFS Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NTFSLink

has super-classes
Filec
File System Linkc
has sub-classes
NTFS Hard Linkc, NTFS Junction Pointc, NTFS Symbolic Linkc

NTFS Symbolic Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NTFSSymbolicLink

is defined by
http://dbpedia.org/resource/NTFS_links
has super-classes
NTFS Linkc
Symbolic Linkc

NULL Pointer Dereferencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-476

has super-classes
Weaknessc
weakness ofop some Pointer Dereferencing Functionc
is also defined as
named individual

Obfuscated Files or Informationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027

has super-classes
Defense Evasion Techniquec
has sub-classes
Binary Paddingc, Compile After Deliveryc, HTML Smugglingc, Indicator Removal from Toolsc, Software Packingc, Steganographyc

Object Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ObjectFile

has super-classes
Filec
has sub-classes
Kernel Modulec, Shared Library Filec
is also defined as
named individual

Obtain Capabilitiesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1588

has super-classes
Resource Development Techniquec
has sub-classes
Code Signing Certificatesc, Digital Certificatesc, Exploitsc, Malwarec, Toolc, Vulnerabilitiesc

Odbcconf Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.008

has super-classes
Signed Binary Proxy Executionc

Offensive Tacticc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OffensiveTactic

is defined by
https://attack.mitre.org/docs/ATTACK_Design_and_Philosophy_March_2020.pdf
has super-classes
ATTACK Thingc
enabled-byop some Offensive Techniquec
has sub-classes
Collectionc, Command And Controlc, Credential Accessc, Defense Evasionc, Discoveryc, Executionc, Exfiltrationc, Impactc, Initial Accessc, Lateral Movementc, Persistencec, Privilege Escalationc, Resource Developmentc, reconnaissancec
has members
Collectionni, Command And Controlni, Credential Accessni, Defense Evasionni, Discoveryni, Executionni, Exfiltrationni, Impactni, Initial Accessni, Lateral Movementni, Persistenceni, Privilege Escalationni

Offensive Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OffensiveTechnique

is defined by
https://attack.mitre.org/docs/ATTACK_Design_and_Philosophy_March_2020.pdf
has super-classes
ATTACK Thingc
Techniquec
enablesop some Offensive Tacticc
has sub-classes
Collection Techniquec, Command and Control Techniquec, Credential Access Techniquec, Defense Evasion Techniquec, Discovery Techniquec, Execution Techniquec, Exfiltration Techniquec, Impact Techniquec, Initial Access Techniquec, Lateral Movement Techniquec, Persistence Techniquec, Privilege Escalation Techniquec, Reconnaissance Techniquec, Resource Development Techniquec
is in domain of
attack-id, attack-kb-annotation
is in range of
may-be-tactically-associated-withop

Office Applicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OfficeApplication

has super-classes
User Applicationc
is also defined as
named individual

Office Application Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OfficeApplicationFile

has super-classes
Document Filec
is also defined as
named individual

Office Application Startupc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137

has super-classes
Persistence Techniquec
has sub-classes
Add-insc, Office Template Macrosc, Office Testc, Outlook Formsc, Outlook Home Pagec, Outlook Rulesc

Office Template Macrosc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.001

has super-classes
Office Application Startupc
may-addop some Executable Scriptc
may-modifyop some Executable Scriptc
may-modifyop some System Configuration Database Recordc
is also defined as
named individual

Office Testc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.002

has super-classes
Office Application Startupc
modifiesop some System Configuration Database Recordc
is also defined as
named individual

One-time Passwordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#One-timePassword

has super-classes
Credential Hardeningc
authenticatesop some User Accountc
use-limitsop some Passwordc
is also defined as
named individual

One-Way Communicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1102.003

has super-classes
Web Servicec

Open Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OpenFile

has super-classes
System Callc
accessesop some Filec
is also defined as
named individual

Open Source Licensec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OpenSourceLicense

has super-classes
Licensec

Open-source Developerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Open-sourceDeveloper

has super-classes
Product Developerc

Operating Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystem

has super-classes
Digital Artifactc
containsop some Kernelc
containsop some System Service Softwarec
may-containop some Operating System Configuration Componentc
is also defined as
named individual

Operating System Configurationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemConfiguration

has super-classes
Configuration Resourcec
has sub-classes
Operating System Configuration Componentc
is also defined as
named individual

Operating System Configuration Componentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemConfigurationComponent

has super-classes
Operating System Configurationc
has sub-classes
System Configuration Database Recordc, System Firewall Configurationc, System Init Configurationc
is also defined as
named individual

Operating System Configuration Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemConfigurationFile

has super-classes
Configuration Filec
Operating System Filec
is also defined as
named individual

Operating System Executable Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemExecutableFile

has super-classes
Operating System Filec
is also defined as
named individual

Operating System Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemFile

has super-classes
Filec
has sub-classes
Operating System Configuration Filec, Operating System Executable Filec, Operating System Log Filec, Operating System Shared Library Filec
is also defined as
named individual

Operating System Log Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemLogFile

has super-classes
Log Filec
Operating System Filec
is also defined as
named individual

Operating System Monitoringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemMonitoring

has super-classes
Platform Monitoringc
has sub-classes
Endpoint Health Beaconc, Input Device Analysisc, Memory Boundary Trackingc, Scheduled Job Analysisc, System Daemon Monitoringc, System File Analysisc, System Init Config Analysisc, User Session Init Config Analysisc
has members
Endpoint Health Beaconni, Input Device Analysisni, Memory Boundary Trackingni, Scheduled Job Analysisni, System Daemon Monitoringni, System File Analysisni, System Init Config Analysisni, User Session Init Config Analysisni
is also defined as
named individual

Operating System Packaging Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemPackagingTool

has super-classes
Software Packaging Toolc

Operating System Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemProcess

has super-classes
Processc
has sub-classes
System Init Processc, Task Scheduler Processc
is also defined as
named individual

Operating System Shared Library Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemSharedLibraryFile

has super-classes
Operating System Filec
Shared Library Filec
is also defined as
named individual

Operational Activity Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperationalActivityMapping

has super-classes
Defensive Techniquec
enablesop some Modelc
has sub-classes
Access Modelingc, Operational Dependency Mappingc, Operational Risk Assessmentc, Organization Mappingc
has members
Access Modelingni, Operational Dependency Mappingni, Operational Risk Assessmentni, Organization Mappingni
is also defined as
named individual

Operational Dependency Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperationalDependencyMapping

has super-classes
Operational Activity Mappingc
mapsop some Dependencyc
mapsop some Organizational Activityc
is also defined as
named individual

Operational Risk Assessmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperationalRiskAssessment

has super-classes
Operational Activity Mappingc
evaluatesop some Organizationc
identifiesop some vulnerabilityc
is also defined as
named individual

Operations Center Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperationsCenterComputer

is defined by
http://dbpedia.org/resource/Mainframe_computer
has super-classes
Shared Computerc

Optical Modemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OpticalModem

is defined by
http://dbpedia.org/resource/Modem#Optical_modem
has super-classes
Modemc

Orchestration Controllerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OrchestrationController

has super-classes
Orchestration Serverc
containsop some Container Orchestration Softwarec
is also defined as
named individual

Orchestration Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OrchestrationServer

has super-classes
Serverc
has sub-classes
Orchestration Controllerc, Orchestration Workerc

Orchestration Workerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OrchestrationWorker

has super-classes
Orchestration Serverc

Organizationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Organization

has super-classes
Agentc
has-memberop some Personc
has sub-classes
Providerc
has members
DISA FSOni
is also defined as
named individual

Organization Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OrganizationMapping

has super-classes
Operational Activity Mappingc
mapsop some Dependencyc
mapsop some Organizationc
mapsop some Personc
may-mapop some Organizational Activityc
is also defined as
named individual

Organizational Activityc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OrganizationalActivity

has super-classes
Activityc
is also defined as
named individual

OS Credential Dumpingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003

has super-classes
Credential Access Techniquec
accessesop some Credentialc
has sub-classes
/etc/passwd and /etc/shadowc, Cached Domain Credentialsc, DCSyncc, LSA Secretsc, LSASS Memoryc, NTDSc, Proc Filesystemc, Security Account Managerc
is also defined as
named individual

OS Exhaustion Floodc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1499.001

has super-classes
Endpoint Denial of Servicec

Out-of-bounds Readc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-125

has super-classes
Weaknessc
weakness ofop some Raw Memory Access Functionc
is also defined as
named individual

Out-of-bounds Writec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-787

has super-classes
Weaknessc
weakness ofop some Raw Memory Access Functionc
is also defined as
named individual

Outbound Internet DNS Lookup Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetDNSLookupTraffic

has super-classes
DNS Network Trafficc
Outbound Internet Network Trafficc
Outbound Network Trafficc
may-containop some DNS Lookupc
is also defined as
named individual

Outbound Internet Encrypted Remote Terminal Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetEncryptedRemoteTerminalTraffic

has super-classes
Outbound Internet Encrypted Trafficc
is also defined as
named individual

Outbound Internet Encrypted Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetEncryptedTraffic

has super-classes
Outbound Internet Network Trafficc
has sub-classes
Outbound Internet Encrypted Remote Terminal Trafficc, Outbound Internet Encrypted Web Trafficc
is also defined as
named individual

Outbound Internet Encrypted Web Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetEncryptedWebTraffic

has super-classes
Outbound Internet Encrypted Trafficc
Outbound Internet Web Trafficc
is also defined as
named individual

Outbound Internet File Transfer Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetFileTransferTraffic

has super-classes
File Transfer Network Trafficc
Outbound Internet Network Trafficc
Outbound Network Trafficc
containsop some Filec
is also defined as
named individual

Outbound Internet Mail Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetMailTraffic

has super-classes
Outbound Internet Network Trafficc
is also defined as
named individual

Outbound Internet Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetNetworkTraffic

has super-classes
Internet Network Trafficc
Outbound Network Trafficc
has sub-classes
Outbound Internet DNS Lookup Trafficc, Outbound Internet Encrypted Trafficc, Outbound Internet File Transfer Trafficc, Outbound Internet Mail Trafficc, Outbound Internet RPC Trafficc, Outbound Internet Web Trafficc
is also defined as
named individual

Outbound Internet RPC Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetRPCTraffic

has super-classes
Outbound Internet Network Trafficc
Outbound Network Trafficc
RPC Network Trafficc

Outbound Internet Web Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetWebTraffic

has super-classes
Outbound Internet Network Trafficc
Web Network Trafficc
may-containop some URLc
has sub-classes
Outbound Internet Encrypted Web Trafficc
is also defined as
named individual

Outbound Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Outbound Internet DNS Lookup Trafficc, Outbound Internet File Transfer Trafficc, Outbound Internet Network Trafficc, Outbound Internet RPC Trafficc
is also defined as
named individual

Outbound Traffic Filteringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundTrafficFiltering

has super-classes
Network Traffic Filteringc
filtersop some Outbound Network Trafficc
is also defined as
named individual

Outlook Formsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.003

has super-classes
Office Application Startupc
addsop some Office Application Filec
is also defined as
named individual

Outlook Home Pagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.004

has super-classes
Office Application Startupc
modifiesop some Application Configuration Databasec
is also defined as
named individual

Outlook Rulesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.005

has super-classes
Office Application Startupc
modifiesop some Application Configuration Databasec
is also defined as
named individual

Output Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutputDevice

is defined by
http://dbpedia.org/resource/Output_device
has super-classes
Hardware Devicec
has sub-classes
Display Adapterc

Packet Logc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PacketLog

has super-classes
Logc
recordsop some Network Sessionc
is also defined as
named individual

Pagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Page

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Memory Blockc

Page Framec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PageFrame

has super-classes
Memory Blockc
contained-byop some Primary Storagec
is also defined as
named individual

Page Tablec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PageTable

has super-classes
Digital Artifactc
containsop some Physical Addressc
containsop some Virtual Addressc
is also defined as
named individual

Parent PID Spoofingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.004

has super-classes
Access Token Manipulationc
invokesop some Create Processc
is also defined as
named individual

Parent PID Spoofingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1502

has super-classes
Defense Evasion Techniquec
Privilege Escalation Techniquec

Parent Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ParentProcess

is defined by
http://dbpedia.org/resource/Parent_process
has super-classes
Processc

Partitionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Partition

has super-classes
Digital Artifactc
is also defined as
named individual

Partition Tablec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PartitionTable

has super-classes
Digital Artifactc
addressesop some Partitionc
is also defined as
named individual

Pass the Hashc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1075

has super-classes
Lateral Movement Techniquec

Pass The Hashc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550.002

has super-classes
Use Alternate Authentication Materialc
createsop some Authenticationc
is also defined as
named individual

Pass the Ticketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1097

has super-classes
Lateral Movement Techniquec

Pass The Ticketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550.003

has super-classes
Use Alternate Authentication Materialc
createsop some Authenticationc
is also defined as
named individual

Passive Certificate Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PassiveCertificateAnalysis

has super-classes
Certificate Analysisc
has members
Passive Certificate Analysisni
is also defined as
named individual

Passive Logical Link Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PassiveLogicalLinkMapping

has super-classes
Logical Link Mappingc
is also defined as
named individual

Passive Physical Link Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PassivePhysicalLinkMapping

has super-classes
Physical Link Mappingc
is disjoint with
Active Physical Link Mappingc
is also defined as
named individual

Passwordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Password

has super-classes
Credentialc
has sub-classes
Encrypted Passwordc
is also defined as
named individual

Password Crackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1110.002

has super-classes
Brute Forcec
accessesop some Passwordc
is also defined as
named individual

Password Databasec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PasswordDatabase

has super-classes
Databasec
has sub-classes
Password Filec, Password Storec, System Password Databasec

Password Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PasswordFile

has super-classes
Filec
Password Databasec
is also defined as
named individual

Password Filter DLLc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1174

has super-classes
Credential Access Techniquec

Password Filter DLLc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1556.002

has super-classes
Modify Authentication Processc
createsop some Shared Library Filec
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Password Guessingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1110.001

has super-classes
Brute Forcec
accessesop some Passwordc
modifiesop some Authentication Logc
producesop some Authenticationc
is also defined as
named individual

Password Managerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PasswordManager

is defined by
http://dbpedia.org/resource/Password_manager
has super-classes
Applicationc

Password Managersc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555.005

has super-classes
Credentials from Password Storesc

Password Policy Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1201

has super-classes
Discovery Techniquec

Password Sprayingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1110.003

has super-classes
Brute Forcec
accessesop some Passwordc
may-createop some Intranet Administrative Network Trafficc
modifiesop some Authentication Logc
producesop some Authenticationc
is also defined as
named individual

Password Storec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PasswordStore

has super-classes
Password Databasec
has sub-classes
In-memory Password Storec, MacOS Keychainc
is also defined as
named individual

Patch System Imagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1601.001

has super-classes
Modify System Imagec

Patentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Patent

has super-classes
Documentc
is also defined as
named individual

Patent Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PatentReference

has super-classes
Technique Referencec
has members
Reference - Account monitoring - Forescout Technologiesni, Reference - Active firewall system and methodology - McAfee LLCni, Reference - Advanced device matching systemni, Reference - Anomaly Detection Using Adaptive Behavioral Profiles - Securonix Incni, Reference - Anti-tamper system with self-adjusting guards - ARXAN TECHNOLOGIES Incni, Reference - Apparatus for to provide content to and query a reverse domain name system server - Barrracuda Networksni, Reference - Approaches for securing an internet endpoint using fine-grained operating system virtualization - Bromium, Inc.ni, Reference - Architecture of transparent network security for application containers - Neuvector Incni, Reference - Automated computer vulnerability resolution systemni, Reference - Automatically generating network resource groups and assigning customized decoy policies thereto - Illusive Networks Ltdni, Reference - Automatically generating rules for connection security - Microsoftni, Reference - Biometric Challenge-Response Authentication - Accentureni, Reference - Broadcast isolation and level 3 network switch - Hewlett Packard Enterprise Development LPni, Reference - Computational modeling and classification of data streams - Crowdstrike Incni, Reference - Computer Worm Defense System and Method - FireEye Incni, Reference - Computer motherboard having peripheral security functionsni, Reference - Computer-implemented methods and systems for identifying visually similar text character strings - Greathorn Incni, Reference - Computing apparatus with automatic integrity reference generation and maintenance - Tripwire, Inc.ni, Reference - Content extractor and analysis system - Bit 9 Inc, Carbon Black Incni, Reference - Data processing and scanning systems for generating and populating a data inventoryni, Reference - Database for receiving, storing and compiling information about email messagesni, Reference - Deception-Based Responses to Security Attacks - Crowdstrike Incni, Reference - Decoy Network-Based Service for Deceiving Attackers - Amazon Technologiesni, Reference - Decoy and deceptive data object technology - Cymmetria Incni, Reference - Decoy and deceptive data object technology - Cymmetria, Inc.ni, Reference - Detecting network reconnaissance by tracking intranet dark-net communications - VECTRA NETWORKS Incni, Reference - Detecting script-based malware - Crowdstrike Incni, Reference - Deterministic method for detecting and blocking of exploits on interpreted code - K2 Cyber Security Incni, Reference - Distributed meta-information query in a network - Bit 9 Incni, Reference - Domain age registration alert - Inc Rapid7 Inc RAPID7 Incni, Reference - Dynamic selection and generation of a virtual clone for detonation of suspicious content within a honey network - Palo Alto Networks Incni, Reference - Embedding contexts for on-line threats into response policy zones - Verisign Incni, Reference - End-to-end certificate pinningni, Reference - File-modifying malware detection - Crowdstrike Incni, Reference - Finding phishing sitesni, Reference - Firewall for interent access - Secure Computing LLCni, Reference - Firewall for processing a connectionless network packet - National Security Agencyni, Reference - Firewall for processing connection-oriented and connectionless datagrams over a connection-oriented network - National Security Agencyni, Reference - Firewalls that filter based upon protocol commands - Intel Corpni, Reference - Firmware Embedded Monitoring Code Red Balloonni, Reference - Firmware Verification Eclypsiumni, Reference - Firmware Verification Trapezoidni, Reference - Framework for notifying a directory service of authentication events processed outside the directory service - Oracle International Corpni, Reference - Guards for application in software tamperproofing - Purdue Research Foundationni, Reference - Hardware-assisted system and method for detecting and analyzing system calls made to an operting system kernel - Endgame Incni, Reference - Heuristic botnet detection - Palo Alto Networks Incni, Reference - Host intrusion prevention system using software and user behavior analysis - Sophos Ltdni, Reference - Identification and extraction of key forensics indicators of compromise using subject-specific filesystem viewsni, Reference - Identification of traceroute nodes and associated devicesni, Reference - Identification of visual international domain name collisions - Verisign Incni, Reference - Identifying a denial-of-service attack in a cloud-based proxy service - Cloudfare Inc.ni, Reference - Inferential exploit attempt detection - Crowdstrike Incni, Reference - Instant process termination tool to recover control of an information handling system - Dell Products LPni, Reference - Integrity assurance through early loading in the boot phase - Crowdstrike Incni, Reference - Intrusion detection using a heartbeat - Sophos Ltdni, Reference - Isolation of applications within a virtual machine - Bromium, Inc.ni, Reference - Malicious relay detection on networks - VECTRA NETWORKS Incni, Reference - Malware analysis system - Palo Alto Networks Incni, Reference - Malware detection in event loops - Crowdstrike Incni, Reference - Malware detection using local computational models - Crowdstrike Incni, Reference - Method and Apparatus for Detecting Malicious Websites - Endgame Incni, Reference - Method and Apparatus for Network Fraud Detection and Remediation Through Analytics - Idaptive LLCni, Reference - Method and apparatus for increasing the speed at which computer viruses are detected - McAfee LLCni, Reference - Method and apparatus for utilizing a token for resource access - Rsa Security Inc.ni, Reference - Method and system for UDP flood attack detection - Riorey LLCni, Reference - Method and system for controlling communication portsni, Reference - Method and system for detecting algorithm-generated domains - VECTRA NETWORKS Incni, Reference - Method and system for detecting external control of compromised hosts - VECTRA NETWORKS Incni, Reference - Method and system for detecting malicious payloads - Vectra Networks Incni, Reference - Method and system for detecting restricted content associated with retrieved content - Sophos Ltdni, Reference - Method and system for detecting suspicious administrative activity - Vectra Networks Incni, Reference - Method and system for detecting threats using metadata vectors - VECTRA NETWORKS Incni, Reference - Method and system for detecting threats using passive cluster mapping - Vectra Networks Incni, Reference - Method and system for providing software updates to local machinesni, Reference - Method for controlling computer network security - Checkpoint Software Technologies Ltdni, Reference - Method for file encryptionni, Reference - Method using kernel mode assistance for the detection and removal of threats which are actively preventing detection and removal from a running system - Symantec Corporationni, Reference - Mock attack cybersecurity training system and methods - WOMBAT SECURITY TECHNOLOGIES Incni, Reference - Modeling user access to computer resources - Daedalus Group LLC (formerly IBM)ni, Reference - Modification of a Server to Mimic a Deception Mechanism - Acalvio Technologies Incni, Reference - Network firewall with proxy - Secure Computing LLCni, Reference - Open source intelligence deceptions - Illusive Networks Ltdni, Reference - Post sandbox methods and systems for detecting and blocking zero-day exploits via api call validation - K2 Cyber Security Incni, Reference - Preventing execution of task scheduled malware - McAfee LLCni, Reference - Privacy and security systems and methods of useni, Reference - Private virtual local area network isolation - Cisco Technology Incni, Reference - Protected computing environment - Microsoft Technology Licensing LLCni, Reference - Protecting against distributed denial of service attacks - Cisco Technology Inc.ni, Reference - Protecting against distributed network flood attacks - Juniper Networks Inc.ni, Reference - RPC call interception - Crowdstrike Incni, Reference - Reputation of an entity associated with a content itemni, Reference - Secure caching of server credentials - Dell Products LPni, Reference - Security System with Methodology for Interprocess Communication Control - Check Point Software Tech Incni, Reference - Security vulnerability information aggregationni, Reference - Sinkholing bad network domains by registering the bad network domains on the internet - Palo Alto Networks Incni, Reference - Software vulnerability graph databaseni, Reference - Supply chain cyber-deception - Cymmetria, Inc.ni, Reference - Synchronizing a honey network configuration to reflect a target network environment - Palo Alto Networks Incni, Reference - System and Method for Detection of a Change in Behavior in the Use of a Website Through Vector Velocity Analysis - Silver Tail Systemsni, Reference - System and Method for Network Security Including Detection of Attacks Through Partner Websites - EMC IP Holding Co LLCni, Reference - System and Method for Process Hollowing Detection - Carbon Black Incni, Reference - System and a method for identifying the presence of malware and ransomware using mini-traps set at network endpoints - Fidelis Cybersecurity Solutions Incni, Reference - System and method for detecting homoglyph attacks with a siamese convolutional neural network - Endgame Incni, Reference - System and method for detecting malware injected into memory of a computing device - Endgame Incni, Reference - System and method for identifying the presence of malware using mini-traps set at network endpoints - Fidelis Cybersecurity Solutions Incni, Reference - System and method for internet security - Cylance Incni, Reference - System and method for managed security assessment and mitigationni, Reference - System and method for providing an actively invalidated client-side network resource cache - IMVUni, Reference - System and method for scanning remote services to locate stored objects with malwareni, Reference - System and method for validating in-memory integrity of executable files to identify malicious activity - Endgame Incni, Reference - System and method for vulnerability risk analysisni, Reference - System and method thereof for identifying and responding to security incidents based on preemptive forensics - Palo Alto Networks Incni, Reference - System and methods thereof for causality identification and attributions determination of processes in a network - Palo Alto Networks IncCyber Secdo Ltdni, Reference - System and methods thereof for detection of persistent threats in a computerized environment background - Palo Alto Networks IncCyber Secdo Ltdni, Reference - System and methods thereof for identification of suspicious system processes - Palo Alto Networks Incni, Reference - System and methods thereof for logical identification of malicious threats across a plurality of end-point devices (epd) communicatively connected by a network - Palo Alto Networks IncCyber Secdo Ltdni, Reference - System and methods thereof for preventing ransomware from encrypting data elements stored in a memory of a computer-based system - Palo Alto Networks Incni, Reference - System for detecting threats using scenario-based tracking of internal and external network traffic - VECTRA NETWORKS Incni, Reference - System for implementing threat detection using daily network traffic community outliers - VECTRA NETWORKS Incni, Reference - System for implementing threat detection using threat and risk assessment of asset-actor interactions - VECTRA NETWORKS Incni, Reference - System, method, and computer program product for detecting and assessing security risks in a network - Exabeam Incni, Reference - Systems and methods for detecting and/or handling targeted attacks in the email channel - Graphus Incni, Reference - Systems and methods for detecting credential theft - Symantec Corpni, Reference - Tamper proof mutating software - ARXAN TECHNOLOGIES Incni, Reference - Techniques for impeding and detecting network threats - Verisign Incni, Reference - Threat detection for return oriented programming - Crowdstrike Incni, Reference - Threat detection through the accumulated detection of threat characteristics - Sophos Ltdni, Reference - Tokenless biometric transaction authorization method and systemni, Reference - Trusted Communications With Child Processes - Microsoft Technology Licensing LLCni, Reference - USB filter for hub malicious code prevention systemni, Reference - Use of an application controller to monitor and control software file and application environments - Sophos Ltdni, Reference - Using spanning tree protocol (STP) to enhance layer-2 topology mapsni, Reference - Virtualized process isolation - Advanced Micro Devices Incni

Path Interception by PATH Environment Variablec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.007

has super-classes
Hijack Execution Flowc
createsop some Executable Filec
is also defined as
named individual

Path Interception by Search Order Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.008

has super-classes
Hijack Execution Flowc
createsop some Executable Filec
is also defined as
named individual

Path Interception by Unquoted Pathc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.009

has super-classes
Hijack Execution Flowc
createsop some Executable Filec
is also defined as
named individual

Per Host Download-Upload Ratio Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PerHostDownload-UploadRatioAnalysis

has super-classes
Network Traffic Analysisc
analyzesop some Network Trafficc
is also defined as
named individual

Peripheral Device Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1120

has super-classes
Discovery Techniquec

Peripheral Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PeripheralFirmware

has super-classes
Firmwarec
has sub-classes
Graphics Card Firmwarec, Hard Disk Firmwarec, Human Input Device Firmwarec, Network Card Firmwarec, Peripheral Hub Firmwarec
is also defined as
named individual

Peripheral Firmware Verificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PeripheralFirmwareVerification

has super-classes
Firmware Verificationc
verifiesop some Peripheral Firmwarec
is also defined as
named individual

Peripheral Hub Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PeripheralHubFirmware

has super-classes
Peripheral Firmwarec

Permission Groups Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1069

has super-classes
Discovery Techniquec
has sub-classes
Cloud Groupsc, Domain Groupsc, Local Groupsc

Persistencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Persistence

has super-classes
Offensive Tacticc
is also defined as
named individual

Persistence Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PersistenceTechnique

has super-classes
Offensive Techniquec
enablesop some Persistencec
has sub-classes
Accessibility Featuresc, Account Manipulationc, AppCert DLLsc, AppInit DLLsc, Application Shimmingc, Authentication Packagec, BITS Jobsc, Boot or Logon Autostart Executionc, Boot or Logon Initialization Scriptsc, Bootkitc, Browser Extensionsc, Change Default File Associationc, Component Firmwarec, Component Object Model Hijackingc, Compromise Client Software Binaryc, Create Accountc, Create or Modify System Processc, DLL Search Order Hijackingc, Dylib Hijackingc, Emondc, Event Triggered Executionc, External Remote Servicesc, File System Permissions Weaknessc, Hidden Files and Directoriesc, Hijack Execution Flowc, Hookingc, Image File Execution Options Injectionc, Implant Container Imagec, Kernel Modules and Extensionsc, LC_LOAD_DYLIB Additionc, LSASS Driverc, Launch Agentc, Launch Daemonc, Launchctlc, Local Job Schedulingc, Login Itemc, Malicious Shell Modificationc, Modify Existing Servicec, Netsh Helper DLLc, New Servicec, Office Application Startupc, Plist Modificationc, Port Monitorsc, PowerShell Profilec, Pre-OS Bootc, Rc.commonc, Re-opened Applicationsc, Registry Run Keys / Startup Folderc, SIP and Trust Provider Hijackingc, Scheduled Task/Job Executionc, Screensaverc, Security Support Providerc, Server Software Componentc, Service Registry Permissions Weaknessc, Setuid and Setgidc, Shortcut Modificationc, Startup Itemsc, System Firmwarec, Systemd Servicec, Time Providersc, Traffic Signalingc, Trapc, Valid Accountsc, Web Shellc, Windows Management Instrumentation Event Subscriptionc, Winlogon Helper DLLc
is also defined as
named individual

Personc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Person

has super-classes
Agentc
namedp some string
is also defined as
named individual

Personal Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PersonalComputer

is defined by
http://dbpedia.org/resource/Personal_computer
has super-classes
Client Computerc
has sub-classes
Desktop Computerc, IP Phonec, Laptop Computerc, Mobile Phonec, Tablet Computerc

Phishingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1566

has super-classes
Initial Access Techniquec
has sub-classes
Spearphishing Attachmentc, Spearphishing Linkc, Spearphishing Via Servicec

Phishing for Informationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1598

has super-classes
Reconnaissance Techniquec
has sub-classes
Spearphishing Attachmentc, Spearphishing Linkc, Spearphishing Servicec

Physical Addressc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PhysicalAddress

has super-classes
Memory Addressc
is also defined as
named individual

Physical Artifactc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PhysicalArtifact

has super-classes
Artifactc
Physical Objectc
has sub-classes
Hardware Devicec

Physical Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PhysicalLink

has super-classes
Linkc
is also defined as
named individual

Physical Link Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PhysicalLinkMapping

has super-classes
Network Mappingc
mapsop some Network Nodec
mapsop some Physical Linkc
has sub-classes
Active Physical Link Mappingc, Passive Physical Link Mappingc
has members
Active Physical Link Mappingni, Passive Physical Link Mappingni
is also defined as
named individual

Physical Locationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PhysicalLocation

has super-classes
Digital Artifactc
is also defined as
named individual

Physical Objectc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PhysicalObject

has super-classes
D3FEND Thingc
has-locationop some Physical Locationc
has sub-classes
Physical Artifactc

Pipec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Pipe

has super-classes
Interprocess Communicationc
is also defined as
named individual

Platformc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Platform

has super-classes
Digital Artifactc
containsop some Firmwarec
containsop some Hardware Devicec
containsop some Operating Systemc
is also defined as
named individual

Platform Hardeningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PlatformHardening

has super-classes
Defensive Techniquec
enablesop some Hardenc
has sub-classes
Bootloader Authenticationc, Disk Encryptionc, Driver Load Integrity Checkingc, File Encryptionc, Local File Permissionsc, RF Shieldingc, Software Updatec, System Configuration Permissionsc, TPM Boot Integrityc
has members
Bootloader Authenticationni, Disk Encryptionni, Driver Load Integrity Checkingni, Executable Allowlistingni, File Encryptionni, Local File Permissionsni, RF Shieldingni, Software Updateni, System Configuration Permissionsni, TPM Boot Integrityni
is also defined as
named individual

Platform Monitoringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PlatformMonitoring

has super-classes
Defensive Techniquec
enablesop some Detectc
has sub-classes
Firmware Behavior Analysisc, Firmware Embedded Monitoring Codec, Firmware Verificationc, Operating System Monitoringc
has members
Firmware Behavior Analysisni, Firmware Embedded Monitoring Codeni, Firmware Verificationni, Operating System Monitoringni
is also defined as
named individual

Plist File Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1647

has super-classes
Defense Evasion Techniquec

Plist Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1150

has super-classes
Defense Evasion Techniquec
Persistence Techniquec
Privilege Escalation Techniquec

Plist Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.011

has super-classes
Boot or Logon Autostart Executionc
modifiesop some Application Configuration Filec
is also defined as
named individual

Pluggable Authentication Modulesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1556.003

has super-classes
Modify Authentication Processc
may-modifyop some Operating System Configuration Filec
may-modifyop some Operating System Shared Library Filec
is also defined as
named individual

Pointerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Pointer

has super-classes
Digital Artifactc
has sub-classes
Saved Instruction Pointerc
is also defined as
named individual

Pointer Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PointerAuthentication

has super-classes
Application Hardeningc
authenticatesop some Pointerc
is also defined as
named individual

Pointer Dereferencing Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PointerDereferencingFunction

has super-classes
Subroutinec
addressesop some Memory Blockc
addressesop some Pointerc
is also defined as
named individual

Policyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Policy

has super-classes
Documentc
has sub-classes
Guidancec

Policy Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PolicyReference

has super-classes
Technique Referencec
has sub-classes
Guideline Referencec

Port Knockingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1205.001

has super-classes
Traffic Signalingc
producesop some Network Trafficc
is also defined as
named individual

Port Monitorsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1013

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Port Monitorsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.010

has super-classes
Boot or Logon Autostart Executionc
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Portable Executable Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.002

has super-classes
Process Injectionc
may-addop some Object Filec
is also defined as
named individual

Portfolio Assessmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PortfolioAssessment

has super-classes
Assessmentc
has-evidenceop some Capability Assessmentc

POSIX Symbolic Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#POSIXSymbolicLink

is defined by
http://dbpedia.org/resource/Symbolic_link
has super-classes
Symbolic Linkc
Unix Linkc

PowerShellc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1086

has super-classes
Execution Techniquec

PowerShell Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059.001

has super-classes
Command and Scripting Interpreter Executionc

PowerShell Profilec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1504

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

PowerShell Profilec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.013

has super-classes
Event Triggered Executionc
modifiesop some PowerShell Profile Scriptc
is also defined as
named individual

PowerShell Profile Scriptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PowerShellProfileScript

has super-classes
User Init Scriptc
is also defined as
named individual

Pre-OS Bootc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1542

has super-classes
Defense Evasion Techniquec
Persistence Techniquec
has sub-classes
Bootkitc, Component Firmwarec, ROMMONkitc, System Firmwarec, TFTP Bootc

Primary Storagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PrimaryStorage

has super-classes
Hardware Devicec
Storagec
containsop some Page Framec
containsop some Process Segmentc
has sub-classes
Processor Cache Memoryc, Processor Registerc, RAMc, ROMc
is also defined as
named individual

Print Processorsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.012

has super-classes
Boot or Logon Autostart Executionc

Print Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PrintServer

is defined by
http://dbpedia.org/resource/Print_server
has super-classes
Serverc

Private Keyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PrivateKey

has super-classes
Asymmetric Keyc
is also defined as
named individual

Private Keysc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1145

has super-classes
Credential Access Techniquec

Private Keysc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.004

has super-classes
Unsecured Credentialsc
accessesop some Private Keyc
is also defined as
named individual

Privilege Escalationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PrivilegeEscalation

has super-classes
Offensive Tacticc
is also defined as
named individual

Privilege Escalation Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PrivilegeEscalationTechnique

has super-classes
Offensive Techniquec
enablesop some Privilege Escalationc
has sub-classes
Abuse Elevation Control Mechanismc, Access Token Manipulationc, Accessibility Featuresc, AppCert DLLsc, AppInit DLLsc, Application Shimmingc, Boot or Logon Autostart Executionc, Boot or Logon Initialization Scriptsc, Bypass User Account Controlc, Create Accountc, Create or Modify System Processc, DLL Search Order Hijackingc, Dylib Hijackingc, Elevated Execution with Promptc, Emondc, Escape to Hostc, Event Triggered Executionc, Exploitation for Privilege Escalationc, Extra Window Memory Injectionc, File System Permissions Weaknessc, Group Policy Modificationc, Hijack Execution Flowc, Hookingc, Image File Execution Options Injectionc, Launch Daemonc, New Servicec, Parent PID Spoofingc, Plist Modificationc, Port Monitorsc, PowerShell Profilec, Process Injectionc, SID-History Injectionc, Scheduled Task/Job Executionc, Service Registry Permissions Weaknessc, Setuid and Setgidc, Startup Itemsc, Sudoc, Sudo Cachingc, Valid Accountsc, Web Shellc
is also defined as
named individual

Privileged User Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PrivilegedUserAccount

is defined by
https://www.ssh.com/iam/user/privileged-account
has super-classes
User Accountc

Proc Filesystemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.007

has super-classes
OS Credential Dumpingc
accessesop some Operating System Filec
accessesop some Process Imagec
is also defined as
named individual

Proc Memoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.009

has super-classes
Process Injectionc
accessesop some Operating System Filec
may-modifyop some Operating System Filec
is also defined as
named individual

procedurec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Procedure

has super-classes
D3FEND Thingc
implementsop some Techniquec
startop some stepc
has sub-classes
Use Case Procedurec
has members
Procedure 1 - T1134.001 Access Token Manipulationni

Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Process

has super-classes
Digital Artifactc
containsop some Process Imagec
instructed-byop some Softwarec
may-executeop some Threadc
process-image-pathop some Executable Binaryc
process-userop some User Accountc
usesop some Resourcec
process-command-line-argumentsdp some string
process-environmental-variablesdp some string
process-identifierdp some integer
process-security-contextdp some string
has sub-classes
Child Processc, Operating System Processc, Parent Processc, User Processc
is in domain of
process-security-contextdp
has members
BSD Processni, Linux Processni, Windows Processni, iOS Processni, macOS Processni
is also defined as
named individual

Process Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessAnalysis

has super-classes
Defensive Techniquec
enablesop some Detectc
has sub-classes
Database Query String Analysisc, File Access Pattern Analysisc, Indirect Branch Call Analysisc, Process Code Segment Verificationc, Process Self-Modification Detectionc, Process Spawn Analysisc, Script Execution Analysisc, Shadow Stack Comparisonsc, System Call Analysisc
has members
Database Query String Analysisni, File Access Pattern Analysisni, Indirect Branch Call Analysisni, Process Code Segment Verificationni, Process Self-Modification Detectionni, Process Spawn Analysisni, Script Execution Analysisni, Shadow Stack Comparisonsni, System Call Analysisni
is also defined as
named individual

Process Argument Spoofingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.010

has super-classes
Hide Artifactsc

Process Code Segmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessCodeSegment

has super-classes
Process Segmentc
containsop some Subroutinec
may-containop some Process Segmentc
has members
AMD64 Code Segmentni, ARM32 Code Segmentni, X86 Code Segmentni
is also defined as
named individual

Process Code Segment Verificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessCodeSegmentVerification

has super-classes
Process Analysisc
verifiesop some Process Code Segmentc
is also defined as
named individual

Process Data Segmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessDataSegment

has super-classes
Process Segmentc

Process Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1057

has super-classes
Discovery Techniquec
may-invokeop some Create Processc
may-invokeop some Get Running Processesc
is also defined as
named individual

Process Doppelgängingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.013

has super-classes
Process Injectionc
invokesop some Create Processc
is also defined as
named individual

Process Doppelgängingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1186

has super-classes
Defense Evasion Techniquec

Process Environment Variablec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessEnvironmentVariable

has super-classes
Application Configurationc
is also defined as
named individual

Process Evictionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessEviction

has super-classes
Defensive Techniquec
enablesop some Evictc
has sub-classes
Process Suspensionc, Process Terminationc
has members
Process Suspensionni, Process Terminationni
is also defined as
named individual

Process Hollowingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.012

has super-classes
Process Injectionc
modifiesop some Process Code Segmentc
is also defined as
named individual

Process Hollowingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1093

has super-classes
Defense Evasion Techniquec

Process Imagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessImage

has super-classes
Digital Artifactc
containsop some Process Segmentc
is also defined as
named individual

Process Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055

has super-classes
Defense Evasion Techniquec
Privilege Escalation Techniquec
has sub-classes
Asynchronous Procedure Callc, Dynamic-link Library Injectionc, Extra Window Memory Injectionc, ListPlantingc, Portable Executable Injectionc, Proc Memoryc, Process Doppelgängingc, Process Hollowingc, Ptrace System Callsc, Thread Execution Hijackingc, Thread Local Storagec, VDSO Hijackingc

Process Lineage Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessLineageAnalysis

has super-classes
Process Spawn Analysisc
analyzesop some Processc
analyzesop some Process Treec
is also defined as
named individual

Process Segmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessSegment

has super-classes
Binary Segmentc
has sub-classes
Heap Segmentc, Process Code Segmentc, Process Data Segmentc, Stack Segmentc
is also defined as
named individual

Process Segment Execution Preventionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessSegmentExecutionPrevention

has super-classes
Application Hardeningc
neutralizesop some Process Segmentc
is also defined as
named individual

Process Self-Modification Detectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessSelf-ModificationDetection

has super-classes
Process Analysisc
analyzesop some Processc
is also defined as
named individual

Process Spawn Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessSpawnAnalysis

has super-classes
Process Analysisc
analyzesop some Create Processc
analyzesop some Processc
has sub-classes
Process Lineage Analysisc
has members
Process Lineage Analysisni
is also defined as
named individual

Process Start Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessStartFunction

has super-classes
Subroutinec
invokesop some Create Processc
is also defined as
named individual

Process Suspensionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessSuspension

has super-classes
Process Evictionc
suspendsop some Processc
is also defined as
named individual

Process Terminationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessTermination

has super-classes
Process Evictionc
terminatesop some Processc
is also defined as
named individual

Process Treec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessTree

has super-classes
Digital Artifactc
containsop some Processc
is also defined as
named individual

Processorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Processor

has super-classes
Hardware Devicec
has sub-classes
Central Processing Unitc, Graphics Processing Unitc

Processor Cache Memoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CacheMemory

has super-classes
Primary Storagec
accessed-byop some Central Processing Unitc
may-containop some Process Segmentc
modifiesop some Processor Cache Memoryc
is also defined as
named individual

Processor Componentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessorComponent

has super-classes
Hardware Devicec
has sub-classes
Memory Management Unitc, Memory Protection Unitc

Processor Registerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessorRegister

has super-classes
Primary Storagec
contained-byop some Central Processing Unitc
is also defined as
named individual

Productc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Product

has super-classes
Capability Implementationc
has sub-classes
Appliancec, Software Productc

Product Developerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProductDeveloper

has super-classes
Providerc
producesop some Productc
has sub-classes
Open-source Developerc

Property List Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PropertyListFile

has super-classes
Configuration Filec
is also defined as
named individual

Propositionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Proposition

is defined by
http://semanticscience.org/resource/SIO_000256
has super-classes
D3FEND Catalog Thingc
has sub-classes
Statementc

Proprietary Licensec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProprietaryLicense

has super-classes
Licensec

Protocol Impersonationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1001.003

has super-classes
Data Obfuscationc

Protocol Metadata Anomaly Detectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProtocolMetadataAnomalyDetection

has super-classes
Network Traffic Analysisc
analyzesop some Network Trafficc
is also defined as
named individual

Protocol Tunnelingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1572

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

Providerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Provider

has super-classes
Organizationc
producesop some Capability Implementationc
has sub-classes
Product Developerc, Service Providerc, Vendorc

Proxyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1090

has super-classes
Command and Control Techniquec
has sub-classes
Domain Frontingc, External Proxyc, Internal Proxyc, Multi-hop Proxyc

Proxy Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProxyServer

is defined by
http://dbpedia.org/resource/Proxy_server
has super-classes
Network Nodec
Serverc
has sub-classes
Forward Proxy Serverc, Reverse Proxy Serverc

Ptrace System Callsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.008

has super-classes
Process Injectionc
invokesop some System Callc
is also defined as
named individual

Public Keyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PublicKey

has super-classes
Asymmetric Keyc
is also defined as
named individual

PubPrn Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1216.001

has super-classes
Signed Script Proxy Executionc

Purchase Technical Datac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1597.002

has super-classes
Search Closed Sourcesc

Python Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059.006

has super-classes
Command and Scripting Interpreter Executionc

Python Packagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PythonPackage

has super-classes
Software Packagec

Python Script Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PythonScriptFile

has super-classes
Executable Scriptc

Query Registryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1012

has super-classes
Discovery Techniquec
accessesop some System Configuration Databasec
may-invokeop some Get System Config Valuec
is also defined as
named individual

Radio Modemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RadioModem

is defined by
http://dbpedia.org/resource/Modem#Radio
has super-classes
Modemc

RAMc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RAM

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Primary Storagec

Raw Memory Access Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RawMemoryAccessFunction

has super-classes
Subroutinec
accessesop some Memory Blockc
is also defined as
named individual

Rc.commonc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.004

has super-classes
Boot or Logon Initialization Scriptsc
modifiesop some System Init Scriptc
is also defined as
named individual

Rc.commonc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1163

has super-classes
Persistence Techniquec

RDP Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1563.002

has super-classes
Remote Service Session Hijackingc
accessesop some RDP Sessionc
is also defined as
named individual

RDP Sessionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RDPSession

has super-classes
Remote Sessionc
is also defined as
named individual

Re-opened Applicationsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1164

has super-classes
Persistence Techniquec

Re-opened Applicationsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.007

has super-classes
Boot or Logon Autostart Executionc
modifiesop some Application Configuration Filec
is also defined as
named individual

Read Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReadFile

has super-classes
System Callc
readsop some Filec
is also defined as
named individual

reconnaissancec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reconnaissance

has super-classes
Offensive Tacticc
is also defined as
named individual

Reconnaissance Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReconnaissanceTechnique

has super-classes
Offensive Techniquec
enablesop some reconnaissancec
has sub-classes
Active Scanningc, Gather Victim Host Informationc, Gather Victim Identity Informationc, Gather Victim Network Informationc, Gather Victim Org Informationc, Phishing for Informationc, Search Closed Sourcesc, Search Open Technical Databasesc, Search Open Websites/Domainsc, Search Victim-Owned Websitesc
is also defined as
named individual

Recordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Record

has super-classes
Digital Artifactc
has sub-classes
Boot Recordc, Configuration Database Recordc, DNS Recordc, System Utilization Recordc
is also defined as
named individual

Reduce Key Spacec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1600.001

has super-classes
Weaken Encryptionc

Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference

has super-classes
D3FEND Thingc
is in domain of
d3fend-kb-reference-annotation, kb-abstract, kb-author, kb-mitre-analysis, kb-reference-ofop, kb-reference-titledp

Reference Typec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReferenceType

has super-classes
D3FEND Thingc
has members
Bookni, Internet Articleni, Marketing Materialni, Patentni, Source Codeni, User Manualni

Reflection Amplificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1498.002

has super-classes
Network Denial of Servicec
producesop some Inbound Internet Network Trafficc
is also defined as
named individual

Reflective Code Loadingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1620

has super-classes
Defense Evasion Techniquec
modifiesop some Process Segmentc
is also defined as
named individual

Registry Run Keys / Startup Folderc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1060

has super-classes
Persistence Techniquec

Registry Run Keys / Startup Folderc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.001

has super-classes
Boot or Logon Autostart Executionc
may-modifyop some System Configuration Init Database Recordc
may-modifyop some User Startup Script Filec
is also defined as
named individual

Regsvcs/Regasmc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1121

has super-classes
Defense Evasion Techniquec
Execution Techniquec

Regsvcs/Regasm Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.009

has super-classes
Signed Binary Proxy Executionc

Regsvr32c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1117

has super-classes
Defense Evasion Techniquec
Execution Techniquec

Regsvr32 Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.010

has super-classes
Signed Binary Proxy Executionc

Relay Pattern Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RelayPatternAnalysis

has super-classes
Network Traffic Analysisc
analyzesop some Outbound Internet Network Trafficc
is also defined as
named individual

Remote Access Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1219

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Network Trafficc
is also defined as
named individual

Remote Authentication Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteAuthenticationService

has super-classes
Authentication Servicec
Network Servicec

Remote Authorization Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteAuthorizationService

has super-classes
Authorization Servicec

Remote Commandc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteCommand

has super-classes
Commandc
Network Sessionc
has sub-classes
Remote Database Queryc, Remote Procedure Callc

Remote Data Stagingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1074.002

has super-classes
Data Stagedc
modifiesop some Network Resourcec
is also defined as
named individual

Remote Database Queryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteDatabaseQuery

has super-classes
Database Queryc
Remote Commandc

Remote Desktop Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021.001

has super-classes
Remote Servicesc
createsop some RDP Sessionc
producesop some Administrative Network Trafficc
is also defined as
named individual

Remote Desktop Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1076

has super-classes
Lateral Movement Techniquec

Remote Email Collectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1114.002

has super-classes
Email Collectionc
accessesop some Mail Serverc
is also defined as
named individual

Remote Procedure Callc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteProcedureCall

is defined by
http://dbpedia.org/resource/Remote_procedure_call
has super-classes
Remote Commandc

Remote Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteResource

has super-classes
Resourcec
has sub-classes
Network Resourcec

Remote Service Session Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1563

has super-classes
Lateral Movement Techniquec
accessesop some Remote Sessionc
producesop some Administrative Network Trafficc
has sub-classes
RDP Hijackingc, SSH Hijackingc
is also defined as
named individual

Remote Servicesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021

has super-classes
Lateral Movement Techniquec
producesop some Intranet Network Trafficc
has sub-classes
Distributed Component Object Modelc, Remote Desktop Protocolc, SMB/Windows Admin Sharesc, SSHc, VNCc, Windows Remote Managementc
is also defined as
named individual

Remote Sessionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteSession

has super-classes
Login Sessionc
has sub-classes
RDP Sessionc, SSH Sessionc
is also defined as
named individual

Remote System Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1018

has super-classes
Discovery Techniquec
may-accessop some Operating System Configuration Filec
may-invokeop some Create Processc
may-invokeop some Create Socketc
producesop some Network Trafficc
is also defined as
named individual

Remote Terminal Sessionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteTerminalSession

has super-classes
Network Sessionc

Remote Terminal Session Detectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteTerminalSessionDetection

has super-classes
Network Traffic Analysisc
analyzesop some Network Trafficc
is also defined as
named individual

Removable Media Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemovableMediaDevice

has super-classes
Hardware Devicec
is also defined as
named individual

Rename System Utilitiesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.003

has super-classes
Masqueradingc
may-createop some Executable Filec
may-modifyop some Operating System Executable Filec
is also defined as
named individual

Replication Through Removable Mediac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1091

has super-classes
Initial Access Techniquec
Lateral Movement Techniquec
executesop some Removable Media Devicec
is also defined as
named individual

Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Resource

has super-classes
Digital Artifactc
has sub-classes
Configuration Resourcec, Filec, Local Resourcec, Remote Resourcec
is in domain of
addressed-byop
is in range of
addressesop
is also defined as
named individual

Resource Accessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ResourceAccess

has super-classes
Digital Eventc
User Actionc
has sub-classes
Local Resource Accessc, Network Resource Accessc
is also defined as
named individual

Resource Access Pattern Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ResourceAccessPatternAnalysis

has super-classes
User Behavior Analysisc
analyzesop some Authenticationc
analyzesop some Authorizationc
is also defined as
named individual

Resource Developmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ResourceDevelopment

has super-classes
Offensive Tacticc

Resource Development Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ResourceDevelopmentTechnique

has super-classes
Offensive Techniquec
enablesop some reconnaissancec
has sub-classes
Acquire Infrastructurec, Compromise Accountsc, Compromise Infrastructurec, Develop Capabilitiesc, Establish Accountsc, Obtain Capabilitiesc, Stage Capabilitiesc
is also defined as
named individual

Resource Forkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ResourceFork

has super-classes
File Sectionc
is also defined as
named individual

Resource Forkingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.009

has super-classes
Hide Artifactsc
may-createop some Resource Forkc
may-modifyop some Resource Forkc
is also defined as
named individual

Resource Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1496

has super-classes
Impact Techniquec

Reverse Proxy Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReverseProxyServer

is defined by
http://dbpedia.org/resource/Reverse_proxy
has super-classes
Proxy Serverc

Reverse Resolution Domain Denylistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReverseResolutionDomainDenylisting

has super-classes
DNS Denylistingc
blocksop some Inbound Internet DNS Response Trafficc
is also defined as
named individual

Reverse Resolution IP Denylistingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReverseResolutionIPDenylisting

has super-classes
DNS Denylistingc
blocksop some Outbound Internet DNS Lookup Trafficc
is also defined as
named individual

Reversible Encryptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1556.005

has super-classes
Modify Authentication Processc

Revert Cloud Instancec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1536

has super-classes
Defense Evasion Techniquec

Revert Cloud Instancec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1578.004

has super-classes
Modify Cloud Compute Infrastructurec

RF Nodec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RFNode

has super-classes
Network Nodec
has sub-classes
RF Receiverc, RF Transceiverc, RF Transmitterc

RF Receiverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RFReceiver

has super-classes
RF Nodec

RF Shieldingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RFShielding

has super-classes
Platform Hardeningc
is also defined as
named individual

RF Transceiverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RFTransceiver

has super-classes
RF Nodec
has sub-classes
Wireless Access Pointc

RF Transmitterc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RFTransmitter

has super-classes
RF Nodec

Right-to-Left Overridec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.002

has super-classes
Masqueradingc
modifiesop some File System Metadatac
is also defined as
named individual

Rogue Domain Controllerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1207

has super-classes
Defense Evasion Techniquec
modifiesop some System Configuration Databasec
producesop some Intranet Administrative Network Trafficc
is also defined as
named individual

ROMc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ROM

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Primary Storagec

ROMMONkitc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1542.004

has super-classes
Pre-OS Bootc

Rootkitc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1014

has super-classes
Defense Evasion Techniquec
may-modifyop some Boot Sectorc
may-modifyop some Firmwarec
may-modifyop some Kernelc
may-modifyop some Kernel Modulec
may-modifyop some Shared Library Filec
is also defined as
named individual

Routerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Router

is defined by
http://dbpedia.org/resource/Router_(computing)
has super-classes
Network Nodec
has sub-classes
Wireless Routerc

RPC Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RPCNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Intranet RPC Network Trafficc, Outbound Internet RPC Trafficc
is also defined as
named individual

RPC Traffic Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RPCTrafficAnalysis

has super-classes
Network Traffic Analysisc
analyzesop some RPC Network Trafficc
is also defined as
named individual

Run Virtual Instancec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.006

has super-classes
Hide Artifactsc
createsop some Filec
executesop some Virtualization Softwarec
may-addop some Virtualization Softwarec
may-createop some Directoryc
is also defined as
named individual

Rundll32c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1085

has super-classes
Defense Evasion Techniquec
Execution Techniquec

Rundll32 Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.011

has super-classes
Signed Binary Proxy Executionc
invokesop some Create Processc
loadsop some Shared Library Filec
is also defined as
named individual

Runtime Data Manipulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1494

has super-classes
Impact Techniquec

Runtime Data Manipulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1565.003

has super-classes
Data Manipulationc
may-modifyop some Executable Filec
is also defined as
named individual

Safe Mode Bootc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.009

has super-classes
Impair Defensesc
disablesop some Endpoint Sensorc
disablesop some System Configuration Init Database Recordc
may-modifyop some Endpoint Health Beaconc
is also defined as
named individual

SAML Tokensc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1606.002

has super-classes
Forge Web Credentialsc

Saved Instruction Pointerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SavedInstructionPointer

has super-classes
Pointerc
Stack Componentc

Scan Databasesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1596.005

has super-classes
Search Open Technical Databasesc

Scanning IP Blocksc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1595.001

has super-classes
Active Scanningc

Scheduled Job Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ScheduledJobAnalysis

has super-classes
Operating System Monitoringc
analyzesop some Task Schedulec
is also defined as
named individual

Scheduled Task/Job Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053

has super-classes
Execution Techniquec
Persistence Techniquec
Privilege Escalation Techniquec
invokesop some Create Processc
modifiesop some Task Schedulec
has sub-classes
At (Linux) Executionc, At (Windows) Executionc, Container Orchestration Jobc, Cron Executionc, Launchdc, Schtasks Executionc, Systemd Timersc
is also defined as
named individual

Scheduled Transferc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1029

has super-classes
Exfiltration Techniquec
producesop some Internet Network Trafficc
is also defined as
named individual

Schtasks Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053.005

has super-classes
Scheduled Task/Job Executionc

Screen Capturec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1113

has super-classes
Collection Techniquec
may-accessop some Display Serverc
may-invokeop some Get Screen Capturec
is also defined as
named individual

Screensaverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1180

has super-classes
Persistence Techniquec

Screensaverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.002

has super-classes
Event Triggered Executionc
createsop some Executable Filec
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Script Application Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ScriptApplicationProcess

has super-classes
Application Processc
interpretsop some Executable Scriptc
is also defined as
named individual

Script Execution Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ScriptExecutionAnalysis

has super-classes
Process Analysisc
analyzesop some Script Application Processc
is also defined as
named individual

Search Closed Sourcesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1597

has super-classes
Reconnaissance Techniquec
has sub-classes
Purchase Technical Datac, Threat Intel Vendorsc

Search Enginesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1593.002

has super-classes
Search Open Websites/Domainsc

Search Open Technical Databasesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1596

has super-classes
Reconnaissance Techniquec
has sub-classes
CDNsc, DNS/Passive DNSc, Digital Certificatesc, Scan Databasesc, WHOISc

Search Open Websites/Domainsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1593

has super-classes
Reconnaissance Techniquec
has sub-classes
Search Enginesc, Social Mediac

Search Victim-Owned Websitesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1594

has super-classes
Reconnaissance Techniquec

Second-stage Boot Loaderc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Second-stageBootLoader

has super-classes
Boot Loaderc

Secondary Storagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SecondaryStorage

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Hardware Devicec
Storagec
has sub-classes
Cloud Storagec, Flash Memoryc, Tertiary Storagec

Security Account Managerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.002

has super-classes
OS Credential Dumpingc
may-accessop some Authentication Servicec
may-accessop some Processc
may-accessop some System Password Databasec
is also defined as
named individual

Security Software Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1063

has super-classes
Discovery Techniquec

Security Software Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1518.001

has super-classes
Software Discoveryc
may-accessop some File System Metadatac
may-accessop some Kernel Process Tablec
may-accessop some System Configuration Database Recordc
may-accessop some System Firewall Configurationc
may-invokeop some Get Running Processesc
is also defined as
named individual

Security Support Providerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1101

has super-classes
Persistence Techniquec

Security Support Providerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.005

has super-classes
Boot or Logon Autostart Executionc
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Security Tokenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SecurityToken

has super-classes
Hardware Devicec
containsop some Access Tokenc
is also defined as
named individual

Securityd Memoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1167

has super-classes
Credential Access Techniquec

Securityd Memoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555.002

has super-classes
Credentials from Password Storesc
accessesop some In-memory Password Storec
is also defined as
named individual

Segment Address Offset Randomizationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SegmentAddressOffsetRandomization

has super-classes
Application Hardeningc
obfuscatesop some Process Segmentc
is also defined as
named individual

Sender MTA Reputation Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SenderMTAReputationAnalysis

has super-classes
Message Analysisc
analyzesop some Emailc
is also defined as
named individual

Sender Reputation Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SenderReputationAnalysis

has super-classes
Message Analysisc
analyzesop some Emailc
is also defined as
named individual

Sensorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Sensor

has super-classes
D3FEND Thingc
Digital Artifactc
has sub-classes
Cloud Service Sensorc, Endpoint Sensorc, Network Sensorc

Serialization Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SerializationFunction

has super-classes
Subroutinec

Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Server

has super-classes
Hostc
Network Resourcec
managesop some Service Application Processc
runsop some Service Applicationc
has sub-classes
Authentication Serverc, Computing Serverc, DNS Serverc, Database Serverc, File Serverc, Mail Serverc, Media Serverc, Orchestration Serverc, Print Serverc, Proxy Serverc, VPN Serverc, Web Serverc
is also defined as
named individual

Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1583.004

has super-classes
Acquire Infrastructurec

Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1584.004

has super-classes
Compromise Infrastructurec

Server Software Componentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505

has super-classes
Persistence Techniquec
has sub-classes
IIS Componentsc, SQL Stored Proceduresc, Terminal Services DLLc, Transport Agentc, Web Shellc

Server-Side Request Forgery (SSRF)c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-918

has super-classes
Weaknessc
weakness ofop some User Input Functionc
is also defined as
named individual

Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Service

has super-classes
Capability Implementationc
has sub-classes
Software Servicec

Service Applicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ServiceApplication

has super-classes
Applicationc
has sub-classes
Container Orchestration Softwarec, Container Runtimec, Credential Management Systemc, Software Deployment Toolc, Virtualization Softwarec, Web Server Applicationc
is also defined as
named individual

Service Application Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ServiceApplicationProcess

has super-classes
Application Processc
has sub-classes
Authentication Servicec, Authorization Servicec, Network Servicec
is also defined as
named individual

Service Binary Verificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ServiceBinaryVerification

has super-classes
System File Analysisc
verifiesop some Service Applicationc
is also defined as
named individual

Service Dependencyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ServiceDependency

has super-classes
Dependencyc
is also defined as
named individual

Service Dependency Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ServiceDependencyMapping

has super-classes
System Mappingc
mapsop some Service Dependencyc
is also defined as
named individual

Service Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1035

has super-classes
Execution Techniquec

Service Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1569.002

has super-classes
System Servicesc

Service Exhaustion Floodc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1499.002

has super-classes
Network Denial of Servicec
producesop some Inbound Internet Network Trafficc
is also defined as
named individual

Service Providerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ServiceProvider

has super-classes
Providerc
providesop some Servicec

Service Registry Permissions Weaknessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1058

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Service Stopc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1489

has super-classes
Impact Techniquec

Services File Permissions Weaknessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.010

has super-classes
Hijack Execution Flowc
modifiesop some Service Applicationc
is also defined as
named individual

Services Registry Permissions Weaknessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.011

has super-classes
Hijack Execution Flowc
modifiesop some System Configuration Init Database Recordc
is also defined as
named individual

Sessionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Session

is defined by
http://dbpedia.org/resource/Session_(computer_science)
has super-classes
Digital Artifactc
has sub-classes
Login Sessionc

Session Cookiec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SessionCookie

has super-classes
Credentialc
is also defined as
named individual

Session Duration Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SessionDurationAnalysis

has super-classes
User Behavior Analysisc
analyzesop some Authenticationc
analyzesop some Authorizationc
is also defined as
named individual

Set System Config Valuec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SetSystemConfigValue

has super-classes
System Config System Callc
modifiesop some System Configuration Database Recordc
has members
reg set key value ani, reg set key value wni, reg set value ani, reg set value ex ani, reg set value ex wni, reg set value wni
is also defined as
named individual

Setuid and Setgidc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1166

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Setuid and Setgidc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1548.001

has super-classes
Abuse Elevation Control Mechanismc
modifiesop some Access Control Configurationc
is also defined as
named individual

Shadow Stackc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ShadowStack

has super-classes
Digital Artifactc
copy-ofop some Call Stackc
is also defined as
named individual

Shadow Stack Comparisonsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ShadowStackComparisons

has super-classes
Process Analysisc
analyzesop some Stack Framec
is also defined as
named individual

Shared Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SharedComputer

has super-classes
Client Computerc
has sub-classes
Kiosk Computerc, Network Printerc, Operations Center Computerc, Thin Client Computerc

Shared Library Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SharedLibraryFile

has super-classes
Object Filec
has sub-classes
Operating System Shared Library Filec
is also defined as
named individual

Shared Modules Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1129

has super-classes
Execution Techniquec

Shared Resource Access Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SharedResourceAccessFunction

has super-classes
Subroutinec
accessesop some Resourcec
is also defined as
named individual

Sharepointc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1213.002

has super-classes
Data from Information Repositoriesc
accessesop some Web File Resourcec
is also defined as
named individual

Shimc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Shim

has super-classes
Softwarec
has sub-classes
Application Shimc
is also defined as
named individual

Shim Databasec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ShimDatabase

has super-classes
Application Configuration Databasec
is also defined as
named individual

Shortcut Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ShortcutFile

has super-classes
Filec
has sub-classes
Windows Shortcut Filec

Shortcut Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1023

has super-classes
Persistence Techniquec

Shortcut Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.009

has super-classes
Boot or Logon Autostart Executionc
may-modifyop some Symbolic Linkc
may-modifyop some User Startup Script Filec
is also defined as
named individual

SID-History Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.005

has super-classes
Access Token Manipulationc
modifiesop some Access Control Configurationc
is also defined as
named individual

SID-History Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1178

has super-classes
Privilege Escalation Techniquec

Signed Binary Proxy Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218

has super-classes
Defense Evasion Techniquec
Execution Techniquec
has sub-classes
CMSTPc, Compiled HTML Filec, Control Panel Executionc, InstallUtil Executionc, MMCc, Mavinjectc, Mshta Executionc, Msiexec Executionc, Odbcconf Executionc, Regsvcs/Regasm Executionc, Regsvr32 Executionc, Rundll32 Executionc, Verclsidc

Signed Script Proxy Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1216

has super-classes
Defense Evasion Techniquec
Execution Techniquec
has sub-classes
PubPrn Executionc

Silver Ticketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1558.002

has super-classes
Steal or Forge Kerberos Ticketsc

SIP and Trust Provider Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1198

has super-classes
Defense Evasion Techniquec
Persistence Techniquec

SIP and Trust Provider Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.003

has super-classes
Subvert Trust Controlsc
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Slow Symbolic Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SlowSymbolicLink

has super-classes
Symbolic Linkc
Unix Linkc
has sub-classes
Aliasc
is disjoint with
Fast Symbolic Linkc

SMB/Windows Admin Sharesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021.002

has super-classes
Remote Servicesc

SNMP (MIB Dump)c back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1602.001

has super-classes
Data from Configuration Repositoryc

Social Mediac back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1593.001

has super-classes
Search Open Websites/Domainsc

Social Media Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1585.001

has super-classes
Establish Accountsc

Social Media Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1586.001

has super-classes
Compromise Accountsc

Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Software

has super-classes
Digital Artifactc
containsop some Executable Filec
implementsop some Subroutinec
instructsop some Processc
has sub-classes
Applicationc, Firmwarec, Network Agentc, Shimc, Software Libraryc, Software Patchc, Subroutinec, System Service Softwarec, System Softwarec, Utility Softwarec
is also defined as
named individual

Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1592.002

has super-classes
Gather Victim Host Informationc

Software Artifact Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareArtifactServer

has super-classes
Artifact Serverc

Software Deployment Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareDeploymentTool

has super-classes
Service Applicationc
is also defined as
named individual

Software Deployment Tools Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1072

has super-classes
Execution Techniquec
Lateral Movement Techniquec
addsop some Filec
executesop some Software Deployment Toolc
installsop some Softwarec
is also defined as
named individual

Software Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1518

has super-classes
Discovery Techniquec
has sub-classes
Security Software Discoveryc

Software Inventoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareInventory

has super-classes
Asset Inventoryc
inventoriesop some Softwarec
is also defined as
named individual

Software Libraryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareLibrary

has super-classes
Softwarec
containsop some Software Library Filec
is also defined as
named individual

Software Library Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareLibraryFile

has super-classes
Filec
containsop some Subroutinec
may-containop some Executable Binaryc
may-containop some Executable Scriptc
is also defined as
named individual

Software Packagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwarePackage

has super-classes
Digital Artifactc
has sub-classes
Java Archivec, Python Packagec

Software Packaging Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwarePackagingTool

has super-classes
Build Toolc
has sub-classes
Container Build Toolc, Operating System Packaging Toolc

Software Packingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.002

has super-classes
Obfuscated Files or Informationc
obfuscatesop some Executable Filec
is also defined as
named individual

Software Packingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1045

has super-classes
Defense Evasion Techniquec

Software Patchc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwarePatch

is defined by
http://dbpedia.org/resource/Patch_(computing)
has super-classes
Softwarec

Software Productc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareProduct

has super-classes
Productc

Software Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareService

has super-classes
Servicec

Software Updatec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareUpdate

has super-classes
Platform Hardeningc
updatesop some Softwarec
is also defined as
named individual

Source Codec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SourceCode

has super-classes
Information Content Entityc
is also defined as
named individual

Source Code Analyzer Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SourceCodeAnalyzerTool

has super-classes
Static Analysis Toolc

Source Code Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SourceCodeReference

has super-classes
Technique Referencec
has members
Reference - Muninni, Reference - OS Query Windows User Collection Codeni

Space after Filenamec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.006

has super-classes
Masqueradingc
createsop some Filec
is also defined as
named individual

Space after Filenamec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1151

has super-classes
Defense Evasion Techniquec
Execution Techniquec

Spearphishing Attachmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1193

has super-classes
Initial Access Techniquec

Spearphishing Attachmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1566.001

has super-classes
Phishingc
producesop some Emailc
producesop some Inbound Internet Mail Trafficc
is also defined as
named individual

Spearphishing Attachmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1598.002

has super-classes
Phishing for Informationc

Spearphishing Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1192

has super-classes
Initial Access Techniquec

Spearphishing Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1566.002

has super-classes
Phishingc
producesop some Emailc
producesop some Inbound Internet Mail Trafficc
producesop some URLc
is also defined as
named individual

Spearphishing Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1598.003

has super-classes
Phishing for Informationc

Spearphishing Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1598.001

has super-classes
Phishing for Informationc

Spearphishing via Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1194

has super-classes
Initial Access Techniquec

Spearphishing Via Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1566.003

has super-classes
Phishingc
producesop some Filec
producesop some URLc
is also defined as
named individual

Specificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Specification

has super-classes
Documentc

Specification Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SpecificationReference

has super-classes
Technique Referencec
has members
Reference - An Architecture for Describing Simple Network Management Protocol (SNMP) Management Frameworksni, Reference - DNS Whitelist (DNSWL) Email Authentication Method Extensionni, Reference - IEEE Standard for Local and Metropolitan Area Networks - Station and Media Access Control Connectivity Discoveryni, Reference - LUKS1 On-Disk Format SpecificationVersion 1.2.3ni, Reference - Pointer Authentication on ARMv8.3ni, Reference - PsSuspend - Microsoftni, Reference - RFC 2289 - A One-Time Password Systemni, Reference - RFC 6376: DomainKeys Identified Mail (DKIM) Signatures - IETFni, Reference - RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email - IETFni, Reference - RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) - IETFni, Reference - RFC 7642: System for Cross-domain Identity Management: Definitions, Overview, Concepts, and Requirementsni, Reference - Revoke a previously issued verifiable credential - Microsoftni, Reference - Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.1ni, Reference - Security Architecture for the Internet Protocolni, Reference - TCG Trusted Attestation Protocol Use Cases for TPM Families 1.2 and 2.0 and DICEni, Reference - TPM 2.0 Library Specification - Trusted Computing Group, Incorporatedni, Reference - Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilitiesni, Reference - Trusted Attestation Protocol Use Casesni, Reference - UEFI Platform Initialization (PI) Specificationni, Reference - Unified Architecture Framework (UAF)ni, Reference - Web Authentication: An API for accessing Public Key Credentials Level 2ni, Reference - Web-Based Enterprise Managementni, Reference - Windows Management Infrastructure (MI)ni, Reference - Windows Management Instrumentation (WMI)ni

SQL Stored Proceduresc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.001

has super-classes
Server Software Componentc
createsop some Stored Procedurec
invokesop some Create Processc
is also defined as
named individual

SSHc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021.004

has super-classes
Remote Servicesc
createsop some SSH Sessionc
producesop some Administrative Network Trafficc
is also defined as
named individual

SSH Authorized Keysc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098.004

has super-classes
Account Manipulationc

SSH Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1184

has super-classes
Lateral Movement Techniquec

SSH Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1563.001

has super-classes
Remote Service Session Hijackingc
accessesop some SSH Sessionc
is also defined as
named individual

SSH Sessionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SSHSession

has super-classes
Remote Sessionc
is also defined as
named individual

Stack Componentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StackComponent

has super-classes
Digital Artifactc
has sub-classes
Saved Instruction Pointerc, Stack Framec, Stack Frame Canaryc

Stack Framec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StackFrame

has super-classes
Stack Componentc
may-containop some Pointerc
may-containop some Stack Frame Canaryc
is also defined as
named individual

Stack Frame Canaryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StackFrameCanary

has super-classes
Stack Componentc
is also defined as
named individual

Stack Frame Canary Validationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StackFrameCanaryValidation

has super-classes
Application Hardeningc
validatesop some Stack Framec
has members
GNU GCC StackGuardni, Microsoft VCCLCompilerTool BufferSecurityCheckni
is also defined as
named individual

Stack Segmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StackSegment

has super-classes
Process Segmentc
containsop some Stack Framec
is also defined as
named individual

Stage Capabilitiesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1608

has super-classes
Resource Development Techniquec
has sub-classes
Drive-by Targetc, Install Digital Certificatec, Link Targetc, Upload Malwarec, Upload Toolc

Standalone Honeynetc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StandaloneHoneynet

has super-classes
Decoy Environmentc
spoofsop some Intranet Networkc
is also defined as
named individual

Standard Cryptographic Protocolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1032

has super-classes
Command and Control Techniquec

Standard Encodingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1132.001

has super-classes
Data Encodingc

Startup Directoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StartupDirectory

has super-classes
Directoryc
Local Resourcec

Startup Itemsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.005

has super-classes
Boot or Logon Initialization Scriptsc
modifiesop some System Startup Directoryc
is also defined as
named individual

Startup Itemsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1165

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Statementc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Statement

is defined by
http://semanticscience.org/resource/SIO_001183
has super-classes
Propositionc
has sub-classes
Capability Feature Claimc

Static Analysis Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StaticAnalysisTool

is defined by
http://dbpedia.org/resource/Static_program_analysis
has super-classes
Code Analyzerc
has sub-classes
Source Code Analyzer Toolc

Steal Application Access Tokenc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1528

has super-classes
Credential Access Techniquec
accessesop some Access Tokenc
is also defined as
named individual

Steal or Forge Kerberos Ticketsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1558

has super-classes
Credential Access Techniquec
may-accessop some Kerberos Ticketc
may-createop some Kerberos Ticketc
has sub-classes
AS-REP Roastingc, Golden Ticketc, Kerberoastingc, Silver Ticketc
is also defined as
named individual

Steal Web Session Cookiec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1539

has super-classes
Credential Access Techniquec
accessesop some Session Cookiec
is also defined as
named individual

Steganographyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1001.002

has super-classes
Data Obfuscationc

Steganographyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.003

has super-classes
Obfuscated Files or Informationc

stepc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Step

has super-classes
D3FEND Thingc
endop some stepc
forkop some stepc
may-be-associated-withop some Artifactc
nextop some stepc
has sub-classes
Use Case Stepc
has members
Step 1 - Copy Tokenni, Step 2 - Impersonate Userni

Storagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Storage

has super-classes
Digital Artifactc
may-containop some File Systemc
has sub-classes
Primary Storagec, Secondary Storagec
is also defined as
named individual

Stored Data Manipulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1492

has super-classes
Impact Techniquec

Stored Data Manipulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1565.001

has super-classes
Data Manipulationc
modifiesop some Filec
is also defined as
named individual

Stored Procedurec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StoredProcedure

has super-classes
Subroutinec
is also defined as
named individual

String Format Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StringFormatFunction

has super-classes
Subroutinec

Strong Password Policyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StrongPasswordPolicy

has super-classes
Credential Hardeningc
strengthensop some Passwordc
strengthensop some User Accountc
is also defined as
named individual

Subroutinec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine

has super-classes
Softwarec
has sub-classes
Authentication Functionc, Console Output Functionc, Copy Memory Functionc, Deserialization Functionc, Eval Functionc, Exception Handlerc, External Content Inclusion Functionc, File Path Open Functionc, Import Library Functionc, Input Functionc, Log Message Functionc, Mathematical Functionc, Memory Allocation Functionc, Memory Free Functionc, Pointer Dereferencing Functionc, Process Start Functionc, Raw Memory Access Functionc, Serialization Functionc, Shared Resource Access Functionc, Stored Procedurec, String Format Functionc, Thread Start Functionc
is also defined as
named individual

Subvert Trust Controlsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553

has super-classes
Defense Evasion Techniquec
has sub-classes
Code Signingc, Code Signing Policy Modificationc, Gatekeeper Bypassc, Install Root Certificatec, Mark-of-the-Web Bypassc, SIP and Trust Provider Hijackingc

Sudoc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1169

has super-classes
Privilege Escalation Techniquec

Sudo and Sudo Cachingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1548.003

has super-classes
Abuse Elevation Control Mechanismc
may-modifyop some Event Logc
modifiesop some Operating System Configuration Filec
is also defined as
named individual

Sudo Cachingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1206

has super-classes
Privilege Escalation Techniquec

Supply Chain Compromisec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1195

has super-classes
Initial Access Techniquec
modifiesop some Digital Artifactc
has sub-classes
Compromise Hardware Supply Chainc, Compromise Software Dependencies and Development Toolsc, Compromise Software Supply Chainc
is also defined as
named individual

Suspend Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SuspendProcess

has super-classes
System Callc
evictsop some Processc
is also defined as
named individual

Switchc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Switch

is defined by
http://dbpedia.org/resource/Network_switch
has super-classes
Network Nodec

Symbolic Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SymbolicLink

has super-classes
Filec
File System Linkc
addressesop some Filec
has sub-classes
Fast Symbolic Linkc, NTFS Junction Pointc, NTFS Symbolic Linkc, POSIX Symbolic Linkc, Slow Symbolic Linkc
is also defined as
named individual

Symmetric Cryptographyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1573.001

has super-classes
Encrypted Channelc
createsop some Outbound Internet Encrypted Trafficc
is also defined as
named individual

Symmetric Keyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SymmetricKey

has super-classes
Cryptographic Keyc

Systemc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#System

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Artifactc
has sub-classes
Digital Systemc

System Callc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemCall

has super-classes
Digital Artifactc
Digital Eventc
executesop some Subroutinec
has sub-classes
Allocate Memoryc, Authenticate Userc, Connect Socketc, Copy Tokenc, Create Filec, Create Processc, Create Socketc, Create Threadc, Free Memoryc, Get Open Socketsc, Get Open Windowsc, Get Running Processesc, Get Screen Capturec, Get System Timec, Impersonate Userc, Logon Userc, Move Filec, Open Filec, Read Filec, Suspend Processc, System Config System Callc, Terminate Processc, Trace Processc, Write Filec
is also defined as
named individual

System Call Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemCallAnalysis

has super-classes
Process Analysisc
analyzesop some System Callc
has sub-classes
File Creation Analysisc
has members
File Creation Analysisni
is also defined as
named individual

System Call Filteringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemCallFiltering

has super-classes
Kernel-based Process Isolationc
filtersop some System Callc
is also defined as
named individual

System Checksc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1497.001

has super-classes
Virtualization/Sandbox Evasionc

System Config System Callc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemConfigSystemCall

has super-classes
System Callc
has sub-classes
Get System Config Valuec, Set System Config Valuec

System Configuration Databasec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemConfigurationDatabase

has super-classes
Databasec
containsop some System Configuration Database Recordc
has sub-classes
Windows Registryc
is also defined as
named individual

System Configuration Database Recordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemConfigurationDatabaseRecord

has super-classes
Configuration Database Recordc
Operating System Configuration Componentc
has sub-classes
System Configuration Init Database Recordc, Windows Registry Keyc
is also defined as
named individual

System Configuration Init Database Recordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemConfigurationInitDatabaseRecord

has super-classes
System Configuration Database Recordc
System Configuration Init Resourcec
System Init Configurationc
is also defined as
named individual

System Configuration Init Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemConfigurationInitResource

has super-classes
Local Resourcec
has sub-classes
System Configuration Init Database Recordc, System Init Scriptc, System Startup Directoryc

System Configuration Permissionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemConfigurationPermissions

has super-classes
Platform Hardeningc
restrictsop some System Configuration Databasec
restrictsop value Operating System Configuration
is also defined as
named individual

System Daemon Monitoringc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemDaemonMonitoring

has super-classes
Operating System Monitoringc
monitorsop some Operating System Processc
is also defined as
named individual

System Dependencyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemDependency

has super-classes
Dependencyc
is also defined as
named individual

System Dependency Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemDependencyMapping

has super-classes
System Mappingc
mapsop some System Dependencyc
is also defined as
named individual

System File Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemFileAnalysis

has super-classes
Operating System Monitoringc
analyzesop some Operating System Filec
has sub-classes
Service Binary Verificationc
has members
Service Binary Verificationni
is also defined as
named individual

System Firewall Configurationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemFirewallConfiguration

has super-classes
Operating System Configuration Componentc
configuresop some Host-based Firewallc
is also defined as
named individual

System Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemFirmware

has super-classes
Firmwarec
is also defined as
named individual

System Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1019

has super-classes
Persistence Techniquec

System Firmwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1542.001

has super-classes
Pre-OS Bootc
modifiesop some System Firmwarec
is also defined as
named individual

System Firmware Verificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemFirmwareVerification

has super-classes
Firmware Verificationc
verifiesop some System Firmwarec
is also defined as
named individual

System Information Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1082

has super-classes
Discovery Techniquec
may-accessop some Decoy Artifactc
may-invokeop some Create Processc
is also defined as
named individual

System Init Config Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemInitConfigAnalysis

has super-classes
Operating System Monitoringc
analyzesop some System Init Configurationc
is also defined as
named individual

System Init Configurationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemInitConfiguration

has super-classes
Operating System Configuration Componentc
has sub-classes
System Configuration Init Database Recordc, System Init Scriptc, System Startup Directoryc
is also defined as
named individual

System Init Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemInitProcess

has super-classes
Operating System Processc

System Init Scriptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemInitScript

has super-classes
Executable Scriptc
System Configuration Init Resourcec
System Init Configurationc
is also defined as
named individual

System Language Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1614.001

has super-classes
System Location Discoveryc
queriesop some System Configuration Databasec
is also defined as
named individual

System Location Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1614

has super-classes
Discovery Techniquec
accessesop some Configuration Resourcec
has sub-classes
System Language Discoveryc
is also defined as
named individual

System Mappingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemMapping

has super-classes
Defensive Techniquec
enablesop some Modelc
has sub-classes
Data Exchange Mappingc, Service Dependency Mappingc, System Dependency Mappingc, System Vulnerability Assessmentc
has members
Data Exchange Mappingni, Service Dependency Mappingni, System Dependency Mappingni, System Vulnerability Assessmentni
is also defined as
named individual

System Network Configuration Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1016

has super-classes
Discovery Techniquec
may-executeop some Executable Scriptc
may-invokeop some Create Processc
may-invokeop some Get System Network Config Valuec
has sub-classes
Internet Connection Discoveryc
is also defined as
named individual

System Network Connections Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1049

has super-classes
Discovery Techniquec
may-invokeop some Get Open Socketsc
is also defined as
named individual

System Owner/User Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1033

has super-classes
Discovery Techniquec
may-accessop some Directory Servicec
may-accessop some Get System Config Valuec
may-accessop some Password Filec
may-accessop some Process Segmentc
may-invokeop some Copy Tokenc
may-invokeop some Create Processc
is also defined as
named individual

System Password Databasec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemPasswordDatabase

has super-classes
Password Databasec
is also defined as
named individual

System Service Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1007

has super-classes
Discovery Techniquec
may-invokeop some Create Processc
may-invokeop some Get Running Processesc
is also defined as
named individual

System Service Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemServiceSoftware

has super-classes
Softwarec
containsop some Operating System Filec
has sub-classes
Local Authentication Servicec, Local Authorization Servicec, Task Scheduler Softwarec
is also defined as
named individual

System Servicesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1569

has super-classes
Execution Techniquec
has sub-classes
Launchctlc, Service Executionc

System Shutdown/Rebootc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1529

has super-classes
Impact Techniquec

System Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemSoftware

has super-classes
Softwarec
has sub-classes
Host-based Firewallc, Kernelc

System Startup Directoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemStartupDirectory

has super-classes
Directoryc
System Configuration Init Resourcec
System Init Configurationc
is also defined as
named individual

System Time Applicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemTimeApplication

has super-classes
Utility Softwarec
is also defined as
named individual

System Time Discoveryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1124

has super-classes
Discovery Techniquec
may-invokeop some Create Processc
may-invokeop some Get System Timec
is also defined as
named individual

System Utilization Recordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemUtilizationRecord

has super-classes
Recordc

System Vulnerability Assessmentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemVulnerabilityAssessment

has super-classes
System Mappingc
evaluatesop some Digital Systemc
identifiesop some vulnerabilityc
is also defined as
named individual

Systemd Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1501

has super-classes
Persistence Techniquec

Systemd Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1543.002

has super-classes
Create or Modify System Processc
may-createop some Operating System Configuration Filec
may-modifyop some Operating System Configuration Filec
is also defined as
named individual

Systemd Timersc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053.006

has super-classes
Scheduled Task/Job Executionc

Tablet Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TabletComputer

is defined by
http://dbpedia.org/resource/Tablet_computer
has super-classes
Personal Computerc

Taint Shared Contentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1080

has super-classes
Lateral Movement Techniquec
modifiesop some Network Resourcec
is also defined as
named individual

Target Audiencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TargetAudience

has super-classes
D3FEND Use Case Thingc
is disjoint with
D3FEND Use Casec, Use Case Goalc, Use Case Prerequisitec, Use Case Procedurec, Use Case Stepc

Task Schedulec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TaskSchedule

has super-classes
Digital Artifactc
is also defined as
named individual

Task Scheduler Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TaskSchedulerProcess

has super-classes
Operating System Processc

Task Scheduler Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TaskSchedulerSoftware

has super-classes
System Service Softwarec

Techniquec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Technique

has super-classes
D3FEND Thingc
associated-withop some Digital Artifactc
implemented-byop some procedurec
has sub-classes
Defensive Techniquec, Offensive Techniquec
is in domain of
kb-article
is in range of
kb-reference-ofop
has members
Defensive Techniqueni

Technique Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TechniqueReference

has super-classes
D3FEND Thingc
kb-reference-ofop some Defensive Techniquec
has-linkdp some any u r i
kb-reference-titledp some string
has sub-classes
Academic Paper Referencec, Book Referencec, External Knowledge Basec, Internet Article Referencec, Patent Referencec, Policy Referencec, Source Code Referencec, Specification Referencec, User Manual Referencec
has members
Reference - Certificate Transparencyni, Reference - Certificate and Public Key Pinningni, Reference - FWTK Documentation - fwtk.orgni, Reference - StreamingPhishni, Reference - Use Rkill to Stop Malware Processes - ghacks.netni

Template Injectionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1221

has super-classes
Defense Evasion Techniquec

Terminal Services DLLc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.005

has super-classes
Server Software Componentc

Terminate Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TerminateProcess

has super-classes
System Callc
terminatesop some Processc
is also defined as
named individual

Tertiary Storagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TertiaryStorage

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Hardware Devicec
Memory Blockc
Secondary Storagec

Test Execution Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TestExecutionTool

is defined by
http://dbpedia.org/resource/Test_execution_engine
has super-classes
Developer Applicationc
has sub-classes
Integration Test Execution Toolc, Unit Test Execution Toolc

TFTP Bootc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1542.005

has super-classes
Pre-OS Bootc

Thin Client Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ThinClientComputer

is defined by
http://dbpedia.org/resource/Thin_client
has super-classes
Shared Computerc
has sub-classes
Zero Client Computerc

Threadc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Thread

has super-classes
Digital Artifactc
is also defined as
named individual

Thread Execution Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.003

has super-classes
Process Injectionc
invokesop some System Callc
may-addop some Executable Binaryc
is also defined as
named individual

Thread Local Storagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.005

has super-classes
Process Injectionc
invokesop some System Callc
is also defined as
named individual

Thread Start Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ThreadStartFunction

has super-classes
Subroutinec
executesop some Threadc
is also defined as
named individual

Threat Intel Vendorsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1597.001

has super-classes
Search Closed Sourcesc

Ticket Granting Ticketc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TicketGrantingTicket

is defined by
http://dbpedia.org/resource/Ticket_Granting_Ticket
has super-classes
Access Tokenc
has sub-classes
Kerberos Ticket Granting Ticketc

Time Based Evasionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1497.003

has super-classes
Virtualization/Sandbox Evasionc
may-invokeop some Get System Timec
may-runop some System Time Applicationc
is also defined as
named individual

Time Providersc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1209

has super-classes
Persistence Techniquec

Time Providersc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.003

has super-classes
Boot or Logon Autostart Executionc
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Timestompc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.006

has super-classes
Indicator Removal on Hostc
forgesop some File System Metadatac
is also defined as
named individual

Timestompc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1099

has super-classes
Defense Evasion Techniquec

Token Impersonation/Theftc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.001

has super-classes
Access Token Manipulationc
copiesop some Access Tokenc
is also defined as
named individual

Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1588.002

has super-classes
Obtain Capabilitiesc

TPM Boot Integrityc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TPMBootIntegrity

has super-classes
Platform Hardeningc
is also defined as
named individual

Trace Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TraceProcess

has super-classes
System Callc
monitorsop some Processc
is also defined as
named individual

Traffic Duplicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1020.001

has super-classes
Automated Exfiltrationc

Traffic Signalingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1205

has super-classes
Command and Control Techniquec
Defense Evasion Techniquec
Persistence Techniquec
producesop some Network Trafficc
has sub-classes
Port Knockingc
is also defined as
named individual

Transfer Agent Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TransferAgentAuthentication

has super-classes
Message Hardeningc
is also defined as
named individual

Transfer Data to Cloud Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1537

has super-classes
Exfiltration Techniquec

Translation Lookaside Bufferc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TranslationLookasideBuffer

has super-classes
Memory Management Unit Componentc
is also defined as
named individual

Transmitted Data Manipulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1493

has super-classes
Impact Techniquec

Transmitted Data Manipulationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1565.002

has super-classes
Data Manipulationc
may-modifyop some Network Trafficc
is also defined as
named individual

Transport Agentc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.002

has super-classes
Server Software Componentc
addsop some Message Transfer Agentc
modifiesop some Mail Serverc
is also defined as
named individual

Transport Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TransportLink

has super-classes
Logical Linkc

Trapc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1154

has super-classes
Execution Techniquec
Persistence Techniquec

Trapc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.005

has super-classes
Event Triggered Executionc
executesop some Commandc
may-createop some Executable Scriptc
may-modifyop some Executable Scriptc
modifiesop some Event Logc
is also defined as
named individual

Trust Storec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TrustStore

has super-classes
Digital Artifactc
has sub-classes
Certificate Trust Storec

Trusted Developer Utilities Proxy Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1127

has super-classes
Defense Evasion Techniquec
has sub-classes
MSBuildc

Trusted Relationshipc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1199

has super-classes
Initial Access Techniquec
createsop some Login Sessionc
producesop some Intranet Network Trafficc
is also defined as
named individual

Two-Factor Authentication Interceptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1111

has super-classes
Credential Access Techniquec
may-accessop some Security Tokenc
is also defined as
named individual

Uncommonly Used Portc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1065

has super-classes
Command and Control Techniquec

Uncontrolled Resource Consumptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-400

has super-classes
Weaknessc

Unit Test Execution Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UnitTestExecutionTool

has super-classes
Test Execution Toolc

Unix Hard Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UnixHardLink

is defined by
http://dbpedia.org/resource/Hard_link
has super-classes
Hard Linkc
Unix Linkc

Unix Linkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UnixLink

has super-classes
File System Linkc
has sub-classes
Fast Symbolic Linkc, POSIX Symbolic Linkc, Slow Symbolic Linkc, Unix Hard Linkc

Unix Shell Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059.004

has super-classes
Command and Scripting Interpreter Executionc

Unrestricted Upload of File with Dangerous Typec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-434

has super-classes
Weaknessc
weakness ofop some User Input Functionc
is also defined as
named individual

Unsecured Credentialsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552

has super-classes
Credential Access Techniquec
accessesop some Credentialc
has sub-classes
Bash Historyc, Cloud Instance Metadata APIc, Container APIc, Credentials in Filesc, Credentials in Registryc, Group Policy Preferencesc, Private Keysc
is also defined as
named individual

Unused/Unsupported Cloud Regionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1535

has super-classes
Defense Evasion Techniquec

Upload Malwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1608.001

has super-classes
Stage Capabilitiesc

Upload Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1608.002

has super-classes
Stage Capabilitiesc

URLc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#URL

has super-classes
Identifierc
addressesop some Resourcec
has members
HTTP URLni, HTTPS URLni, Web Socket URLni
is also defined as
named individual

URL Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#URLAnalysis

has super-classes
Identifier Analysisc
analyzesop some URLc
is also defined as
named individual

URL Reputation Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#URLReputationAnalysis

has super-classes
Identifier Reputation Analysisc
analyzesop some URLc
is also defined as
named individual

Use After Freec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-416

has super-classes
Weaknessc

Use Alternate Authentication Materialc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550

has super-classes
Defense Evasion Techniquec
Lateral Movement Techniquec
accessesop some Authentication Servicec
has sub-classes
Application Access Tokenc, Pass The Hashc, Pass The Ticketc, Web Session Cookiec
is also defined as
named individual

Use Case Goalc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UseCaseGoal

has super-classes
D3FEND Use Case Thingc
is disjoint with
D3FEND Use Casec, Target Audiencec, Use Case Prerequisitec, Use Case Procedurec, Use Case Stepc

Use Case Prerequisitec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UseCasePrerequisite

has super-classes
D3FEND Use Case Thingc
is disjoint with
D3FEND Use Casec, Target Audiencec, Use Case Goalc, Use Case Procedurec, Use Case Stepc

Use Case Procedurec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UseCaseProcedure

has super-classes
D3FEND Use Case Thingc
procedurec
is disjoint with
D3FEND Use Casec, Target Audiencec, Use Case Goalc, Use Case Prerequisitec, Use Case Stepc

Use Case Stepc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UseCaseStep

has super-classes
D3FEND Use Case Thingc
stepc
is disjoint with
D3FEND Use Casec, Target Audiencec, Use Case Goalc, Use Case Prerequisitec, Use Case Procedurec

Use of Hard-coded Credentialsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-798

has super-classes
Weaknessc
weakness ofop some Authentication Functionc
is also defined as
named individual

Userc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#User

has super-classes
Digital Artifactc
has-accountop some User Accountc
is also defined as
named individual

User Accountc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserAccount

has super-classes
Digital Artifactc
has sub-classes
Cloud User Accountc, Default User Accountc, Domain User Accountc, Local User Accountc, Privileged User Accountc
has members
LDIF Recordni
is also defined as
named individual

User Account Permissionsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserAccountPermissions

has super-classes
Credential Hardeningc
restrictsop some User Accountc
is also defined as
named individual

User Actionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserAction

has super-classes
Digital Artifactc
Digital Eventc
has sub-classes
Authenticationc, Authorizationc, Resource Accessc
is also defined as
named individual

User Activity Based Checksc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1497.002

has super-classes
Virtualization/Sandbox Evasionc

User Applicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserApplication

has super-classes
Applicationc
has sub-classes
Application Installerc, Browserc, Browser Extensionc, Collaborative Softwarec, Developer Applicationc, Office Applicationc

User Behaviorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserBehavior

has super-classes
Digital Artifactc
containsop some User Actionc
is also defined as
named individual

User Behavior Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserBehaviorAnalysis

has super-classes
Defensive Techniquec
enablesop some Detectc
has sub-classes
Authentication Event Thresholdingc, Authorization Event Thresholdingc, Credential Compromise Scope Analysisc, Domain Account Monitoringc, Job Function Access Pattern Analysisc, Local Account Monitoringc, Resource Access Pattern Analysisc, Session Duration Analysisc, User Data Transfer Analysisc, User Geolocation Logon Pattern Analysisc, Web Session Activity Analysisc
has members
Authentication Event Thresholdingni, Authorization Event Thresholdingni, Credential Compromise Scope Analysisni, Domain Account Monitoringni, Job Function Access Pattern Analysisni, Local Account Monitoringni, Resource Access Pattern Analysisni, Session Duration Analysisni, User Data Transfer Analysisni, User Geolocation Logon Pattern Analysisni, Web Session Activity Analysisni
is also defined as
named individual

User Data Transfer Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserDataTransferAnalysis

has super-classes
User Behavior Analysisc
analyzesop some Resource Accessc
is also defined as
named individual

User Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1204

has super-classes
Execution Techniquec
has sub-classes
Malicious File Executionc, Malicious Imagec, Malicious Link Executionc

User Geolocation Logon Pattern Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserGeolocationLogonPatternAnalysis

has super-classes
User Behavior Analysisc
analyzesop some Network Trafficc
is also defined as
named individual

User Init Configuration Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserInitConfigurationFile

has super-classes
Configuration Filec
User Logon Init Resourcec
is also defined as
named individual

User Init Scriptc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserInitScript

has super-classes
Executable Scriptc
Init Scriptc
User Logon Init Resourcec
has sub-classes
PowerShell Profile Scriptc
is also defined as
named individual

User Input Functionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction

has super-classes
Input Functionc
is also defined as
named individual

User Interfacec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserInterface

is defined by
http://dbpedia.org/resource/User_interface
has super-classes
Digital Artifactc
has sub-classes
Command Line Interfacec, Graphical User Interfacec

User Logon Init Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserLogonInitResource

has super-classes
Local Resourcec
has sub-classes
User Init Configuration Filec, User Init Scriptc, User Startup Directoryc, User Startup Script Filec
is also defined as
named individual

User Manualc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserManual

has super-classes
Documentc
is also defined as
named individual

User Manual Referencec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserManualReference

has super-classes
Technique Referencec
has members
Reference - /DYNAMICBASE (Use address space layout randomization) - Microsoft Docsni, Reference - /GS (Buffer Security Check) - Microsoft Docsni, Reference - /SAFESEH (Image has Safe Exception Handlers) - Microsoft Docsni, Reference - Cisco ASR 9000 Series Aggregation Services Routers - Access List Commandsni, Reference - File and Folder Permissionsni, Reference - Libre NMS - Network Map Extensionni, Reference - Libre NMS - Oxidized Extensionni, Reference - Mitigate threats by using Windows 10 security features: Data Execution Prevention - Microsoftni, Reference - Qualys Network Passive Sensor Getting Started Guideni, Reference - Registry Key Security and Access Rightsni, Reference - Reverse DNS Blocking - Barracuda Networksni, Reference - SNMP - Network Auto-Discoveryni, Reference - Tivoli Application Dependency Discovery Manager 7.3.0 - Dependencies between resourcesni, Reference - Use DNS Policy for Applying Filters on DNS Queriesni

User Processc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserProcess

has super-classes
Processc
has sub-classes
Application Processc
is also defined as
named individual

User Session Init Config Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserSessionInitConfigAnalysis

has super-classes
Operating System Monitoringc
analyzesop some User Init Configuration Filec
is also defined as
named individual

User Startup Directoryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserStartupDirectory

has super-classes
User Logon Init Resourcec
containsop some User Startup Script Filec
is also defined as
named individual

User Startup Script Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserStartupScriptFile

has super-classes
Executable Scriptc
User Logon Init Resourcec
is also defined as
named individual

User to User Messagec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserToUserMessage

has super-classes
Digital Artifactc
has-recipientop some User Accountc
has-senderop some User Accountc
is also defined as
named individual

Utility Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UtilitySoftware

is defined by
http://dbpedia.org/resource/Utility_software
has super-classes
Softwarec
has sub-classes
System Time Applicationc

Valid Accountsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078

has super-classes
Defense Evasion Techniquec
Initial Access Techniquec
Persistence Techniquec
Privilege Escalation Techniquec
producesop some Authenticationc
producesop some Authorizationc
usesop some User Accountc
has sub-classes
Cloud Accountsc, Default Accountsc, Domain Accountsc, Local Accountsc
is also defined as
named individual

VBA Stompingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.007

has super-classes
Hide Artifactsc
modifiesop some Office Application Filec
is also defined as
named individual

VBScript Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059.005

has super-classes
Command and Scripting Interpreter Executionc

VDSO Hijackingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.014

has super-classes
Process Injectionc
accessesop some Shared Library Filec
invokesop some System Callc
is also defined as
named individual

Vendorc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Vendor

has super-classes
Providerc
sellsop some Capability Implementationc

Verclsidc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.012

has super-classes
Signed Binary Proxy Executionc

Version Control Toolc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#VersionControlTool

is defined by
http://dbpedia.org/resource/Version_control
has super-classes
Developer Applicationc

Video Capturec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1125

has super-classes
Collection Techniquec
accessesop some Video Input Devicec
is also defined as
named individual

Video Input Devicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#VideoInputDevice

has super-classes
Input Devicec
has sub-classes
Image Scanner Input Devicec
is also defined as
named individual

Virtual Addressc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#VirtualAddress

has super-classes
Memory Addressc
is also defined as
named individual

Virtual Memory Spacec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#VirtualMemorySpace

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-classes
Memory Address Spacec

Virtual Private Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1583.003

has super-classes
Acquire Infrastructurec

Virtual Private Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1584.003

has super-classes
Compromise Infrastructurec

Virtualization Softwarec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#VirtualizationSoftware

has super-classes
Service Applicationc
is also defined as
named individual

Virtualization/Sandbox Evasionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1497

has super-classes
Defense Evasion Techniquec
has sub-classes
System Checksc, Time Based Evasionc, User Activity Based Checksc

VNCc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021.005

has super-classes
Remote Servicesc

Volumec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Volume

has super-classes
Digital Artifactc
is also defined as
named individual

Volume Boot Recordc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#VolumeBootRecord

has super-classes
Boot Recordc
is also defined as
named individual

VPN Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#VPNServer

is defined by
https://www.techopedia.com/definition/30750/vpn-server
has super-classes
Serverc

Vulnerabilitiesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1588.006

has super-classes
Obtain Capabilitiesc

vulnerabilityc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Vulnerability

has super-classes
D3FEND Thingc
is also defined as
named individual

Vulnerability Scanningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1595.002

has super-classes
Active Scanningc

Weaken Encryptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1600

has super-classes
Defense Evasion Techniquec
has sub-classes
Disable Crypto Hardwarec, Reduce Key Spacec

Weaknessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Weakness

has super-classes
D3FEND Thingc
has sub-classes
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')c, Cross-Site Request Forgery (CSRF)c, Deserialization of Untrusted Datac, Improper Authenticationc, Improper Control of Generation of Code ('Code Injection')c, Improper Input Validationc, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')c, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')c, Improper Neutralization of Special Elements used in a Command ('Command Injection')c, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')c, Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')c, Improper Restriction of Operations within the Bounds of a Memory Bufferc, Improper Restriction of XML External Entity Referencec, Incorrect Default Permissionsc, Integer Overflow or Wraparoundc, Missing Authentication for Critical Functionc, Missing Authorizationc, NULL Pointer Dereferencec, Out-of-bounds Readc, Out-of-bounds Writec, Server-Side Request Forgery (SSRF)c, Uncontrolled Resource Consumptionc, Unrestricted Upload of File with Dangerous Typec, Use After Freec, Use of Hard-coded Credentialsc
is in domain of
may be weakness ofop
is in range of
may have weaknessop

Web Application Firewallc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebApplicationFirewall

is defined by
http://dbpedia.org/resource/Web_application_firewall
has super-classes
Application Layer Firewallc

Web Application Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebApplicationServer

is defined by
http://dbpedia.org/resource/Application_server
has super-classes
Web Serverc

Web Authenticationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebAuthentication

has super-classes
Authenticationc
may-createop some Session Cookiec
has sub-classes
Cloud Service Authenticationc
is also defined as
named individual

Web Cookiesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1606.001

has super-classes
Forge Web Credentialsc

Web File Resourcec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebFileResource

has super-classes
Network File Resourcec
addressed-byop some URLc
is also defined as
named individual

Web Network Trafficc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebNetworkTraffic

has super-classes
Network Trafficc
has sub-classes
Intranet Web Network Trafficc, Outbound Internet Web Trafficc
is also defined as
named individual

Web Portal Capturec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1056.003

has super-classes
Input Capturec
modifiesop some Web Server Applicationc
is also defined as
named individual

Web Protocolsc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071.001

has super-classes
Application Layer Protocolc
may-transferop some Certificate Filec
producesop some Outbound Internet Web Trafficc
is also defined as
named individual

Web Resource Accessc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebResourceAccess

has super-classes
Network Resource Accessc
is also defined as
named individual

Web Script Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebScriptFile

has super-classes
Executable Scriptc
is also defined as
named individual

Web Serverc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebServer

has super-classes
Serverc
has sub-classes
Artifact Serverc, Web Application Serverc
is also defined as
named individual

Web Server Applicationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebServerApplication

has super-classes
Service Applicationc
is also defined as
named individual

Web Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1102

has super-classes
Command and Control Techniquec
producesop some Outbound Internet Web Trafficc
has sub-classes
Bidirectional Communicationc, Dead Drop Resolverc, One-Way Communicationc
is also defined as
named individual

Web Servicesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1583.006

has super-classes
Acquire Infrastructurec

Web Servicesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1584.006

has super-classes
Compromise Infrastructurec

Web Session Activity Analysisc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebSessionActivityAnalysis

has super-classes
User Behavior Analysisc
analyzesop some Web Resource Accessc
is also defined as
named individual

Web Session Cookiec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1506

has super-classes
Defense Evasion Techniquec
Lateral Movement Techniquec

Web Session Cookiec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550.004

has super-classes
Use Alternate Authentication Materialc
addsop some Session Cookiec
producesop some Web Network Trafficc
is also defined as
named individual

Web Shellc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1100

has super-classes
Persistence Techniquec
Privilege Escalation Techniquec

Web Shellc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.003

has super-classes
Server Software Componentc
addsop some Web Script Filec
modifiesop some Web Serverc
producesop some Processc
is also defined as
named individual

WHOISc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1596.002

has super-classes
Search Open Technical Databasesc

Wide Area Networkc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WideAreaNetwork

is defined by
http://dbpedia.org/resource/Local_area_network
has super-classes
Networkc

Windows Admin Sharesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1077

has super-classes
Lateral Movement Techniquec

Windows Command Shell Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059.003

has super-classes
Command and Scripting Interpreter Executionc

Windows Credential Managerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555.004

has super-classes
Credentials from Password Storesc

Windows File and Directory Permissions Modificationc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1222.001

has super-classes
File and Directory Permissions Modificationc

Windows Management Instrumentation Event Subscriptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1084

has super-classes
Persistence Techniquec

Windows Management Instrumentation Event Subscriptionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.003

has super-classes
Event Triggered Executionc
modifiesop some Event Logc
producesop some Intranet Administrative Network Trafficc
is also defined as
named individual

Windows Management Instrumentation Executionc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1047

has super-classes
Execution Techniquec
may-createop some Intranet Administrative Network Trafficc
may-invokeop some Create Processc
is also defined as
named individual

Windows Registryc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WindowsRegistry

has super-classes
System Configuration Databasec
is also defined as
named individual

Windows Registry Keyc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WindowsRegistryKey

has super-classes
System Configuration Database Recordc
windows-registry-keydp some string
windows-registry-valuedp some string
is also defined as
named individual

Windows Remote Managementc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021.006

has super-classes
Remote Servicesc

Windows Remote Managementc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1028

has super-classes
Execution Techniquec
Lateral Movement Techniquec

Windows Servicec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1543.003

has super-classes
Create or Modify System Processc
modifiesop some System Configuration Databasec
is also defined as
named individual

Windows Shortcut Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WindowsShortcutFile

has super-classes
Shortcut Filec
is also defined as
named individual

Winlogon Helper DLLc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1004

has super-classes
Persistence Techniquec

Winlogon Helper DLLc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.004

has super-classes
Boot or Logon Autostart Executionc
modifiesop some System Configuration Database Recordc
is also defined as
named individual

Wireless Access Pointc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WirelessAccessPoint

is defined by
http://dbpedia.org/resource/Wireless_access_point
has super-classes
Network Nodec
RF Transceiverc
has sub-classes
Wireless Routerc

Wireless Routerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WirelessRouter

is defined by
http://dbpedia.org/resource/Wireless_router
has super-classes
Routerc
Wireless Access Pointc

Wordlist Scanningc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1595.003

has super-classes
Active Scanningc

Write Filec back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WriteFile

has super-classes
System Callc
modifiesop some Filec
is also defined as
named individual

XDG Autostart Entriesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.013

has super-classes
Boot or Logon Autostart Executionc

XPC Servicesc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1559.003

has super-classes
Inter-Process Communication Executionc

XSL Script Processingc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1220

has super-classes
Defense Evasion Techniquec
addsop some Filec
interpretsop some Executable Scriptc
invokesop some Create Processc
is also defined as
named individual

Zero Client Computerc back to ToC or Class ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ZeroClientComputer

is defined by
http://dbpedia.org/resource/Thin_client#Zero_client
has super-classes
Thin Client Computerc

Object Properties

abusesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#abuses

is defined by
http://wordnet-rdf.princeton.edu/id/01163606-v
has super-properties
usesop

accessed-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#accessed-by

has super-properties
associated-withop
may-be-accessed-byop
is inverse of
accessesop

accessesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#accesses

is defined by
http://wordnet-rdf.princeton.edu/id/02673854-n
has super-properties
associated-withop
may-accessop
has sub-properties
executesop, modifiesop, readsop, writesop
has range
Network Resourcec
is inverse of
accessed-byop

addressed-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#addressed-by

has super-properties
associated-withop
has domain
Resourcec
has range
Identifierc
is inverse of
addressesop

addressesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#addresses

has super-properties
associated-withop
has domain
Identifierc
has range
Resourcec
is inverse of
addressed-byop

addsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#adds

has super-properties
associated-withop
may-addop

analyzesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#analyzes

is defined by
http://wordnet-rdf.princeton.edu/id/00738221-v
has super-properties
associated-withop
detectsop
has sub-properties
verifiesop

assessed-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#assessed-by

has super-properties
d3fend-catalog-object-propertyop
is inverse of
assessesop

assessesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#assesses

associated-withop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#associated-with

attached-toop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#attached-to

is defined by
http://wordnet-rdf.princeton.edu/id/01980375-s
has super-properties
associated-withop

attack-may-be-countered-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#attack-may-be-countered-by

authenticatesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#authenticates

is defined by
http://wordnet-rdf.princeton.edu/id/01980375-s
has super-properties
associated-withop
hardensop

authorop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#author

has super-properties
creatorop

authorizesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#authorizes

is defined by
http://wordnet-rdf.princeton.edu/id/00804987-v
has super-properties
associated-withop
hardensop

blocksop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#blocks

is defined by
http://wordnet-rdf.princeton.edu/id/01480024-v
has super-properties
countersop
filtersop

broaderop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#broader

has super-properties
semantic-relationop

broader-transitiveop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#broader-transitive

has super-properties
semantic-relationop

cited-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#cited-by

has super-properties
d3fend-catalog-object-propertyop
is inverse of
citesop

citesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#cites

claimed-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#claimed-by

has super-properties
d3fend-catalog-object-propertyop
is inverse of
claimsop

claimsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#claims

has super-properties
d3fend-catalog-object-propertyop
has sub-properties
featuresop
is inverse of
claimed-byop

configuresop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#configures

has super-properties
associated-withop
hardensop

connectsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#connects

is defined by
http://wordnet-rdf.princeton.edu/id/01071413-v
has super-properties
associated-withop

contained-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#contained-by

has characteristics : transitive

has super-properties
associated-withop
may-be-contained-byop
is inverse of
containsop

containsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#contains

is defined by
http://wordnet-rdf.princeton.edu/id/02639021-v

has characteristics : transitive

has super-properties
associated-withop
may-containop
is inverse of
contained-byop

contributorop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#contributor

has super-properties
d3fend-catalog-object-propertyop
has sub-properties
creatorop, evaluatorop, submitterop, validatorop
has range
thingc

copiesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#copies

is defined by
http://wordnet-rdf.princeton.edu/id/01738810-v
has super-properties
createsop

copy-ofop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#copy-of

has super-properties
associated-withop

countersop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#counters

has super-properties
d3fend-catalog-object-propertyop
may-counterop
has sub-properties
blocksop, deceivesop, detectsop, evictsop, hardensop

created-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#created-by

has super-properties
associated-withop
may-be-created-byop
is inverse of
createsop

createsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#creates

is defined by
http://wordnet-rdf.princeton.edu/id/01630392-v
has super-properties
associated-withop
may-createop
has sub-properties
copiesop, forgesop
is inverse of
created-byop

creatorop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#creator

has super-properties
contributorop
has sub-properties
authorop

d3fend general object propertyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-general-object-property

has super-properties
d3fend object propertyop
has sub-properties
has procedureop

d3fend object propertyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-object-property

d3fend process object propertyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-process-object-property

has super-properties
d3fend object propertyop
has sub-properties
endop, forkop, nextop, startop

d3fend use case object propertyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-use-case-object-property

has super-properties
d3fend object propertyop
has sub-properties
has audienceop, has goalop, has prerequisiteop

d3fend-catalog-object-propertyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-catalog-object-property

d3fend-kb-object-propertyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-kb-object-property

has super-properties
d3fend object propertyop
has sub-properties
has contributionop, has contributorop, kb-referenceop, kb-reference-ofop

d3fend-tactical-verb-propertyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-tactical-verb-property

has super-properties
d3fend object propertyop
has sub-properties
deceives-withop, detectsop, evictsop, hardensop, isolatesop
has domain
Defensive Techniquec
has range
Artifactc

deceivesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#deceives

has super-properties
countersop

deceives-withop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#deceives-with

has super-properties
d3fend-tactical-verb-propertyop
has sub-properties
spoofsop

deletesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#deletes

is defined by
http://wordnet-rdf.princeton.edu/id/01001860-v
has super-properties
evictsop
modifiesop

dependentop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#dependent

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-properties
associated-withop

depends-onop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#dependsOn

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-properties
associated-withop
is inverse of
has-dependentop

detectsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#detects

has super-properties
countersop
d3fend-tactical-verb-propertyop
has sub-properties
analyzesop, monitorsop

disablesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#disables

is defined by
http://wordnet-rdf.princeton.edu/id/00513267-v
has super-properties
evictsop
may-disableop
modifiesop

drivesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#drives

is defined by
http://wordnet-rdf.princeton.edu/id/01184038-v
has super-properties
associated-withop

employed-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#employed-by

is defined by
http://wordnet-rdf.princeton.edu/id/01161188-v
has super-properties
associated-withop
is inverse of
employsop

employsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#employs

has super-properties
associated-withop
is inverse of
employed-byop

enabled-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#enabled-by

is defined by
http://wordnet-rdf.princeton.edu/id/00513958-v
has super-properties
associated-withop
is inverse of
enablesop

enablesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#enables

is defined by
http://wordnet-rdf.princeton.edu/id/00513958-v
has super-properties
associated-withop
is inverse of
enabled-byop

encryptsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#encrypts

is defined by
http://wordnet-rdf.princeton.edu/id/00996121-v
has super-properties
associated-withop
hardensop

endop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#end

has super-properties
d3fend process object propertyop

enumeratesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#enumerates

has super-properties
readsop

evaluated-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#evaluated-by

has super-properties
associated-withop
is inverse of
evaluatesop

evaluatesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#evaluates

has super-properties
associated-withop
may evaluateop
is inverse of
evaluated-byop

evaluatorop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#evaluator

has super-properties
contributorop

evictsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#evicts

has super-properties
countersop
d3fend-tactical-verb-propertyop
may-evictop
has sub-properties
deletesop, disablesop, obfuscatesop, suspendsop, terminatesop

exactlyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#exactly

has super-properties
semantic-relationop

executesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#executes

is defined by
http://wordnet-rdf.princeton.edu/id/02569242-v
has super-properties
accessesop
may-executeop
runsop
has sub-properties
injectsop, interpretsop, invokesop

expected-latencyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#expected-latency

has super-properties
latencyop
has range
latencyop some Latencyc

extendsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#extends

is defined by
http://wordnet-rdf.princeton.edu/id/00541315-v
has super-properties
modifiesop

featuresop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#features

has super-properties
claimsop
has domain
Capability Feature Claimc
has range
Capability Featurec

filtersop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#filters

is defined by
http://wordnet-rdf.princeton.edu/id/01461293-v
has super-properties
associated-withop
isolatesop
has sub-properties
blocksop

forgesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#forges

has super-properties
createsop

forkop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#fork

has super-properties
d3fend process object propertyop

hardensop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#hardens

has audienceop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-audience

has super-properties
d3fend use case object propertyop

has contributionop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-contribution

has super-properties
d3fend-kb-object-propertyop

has contributorop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-contributor

has super-properties
d3fend-kb-object-propertyop

has goalop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-goal

has super-properties
d3fend use case object propertyop

has prerequisiteop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-prerequisite

has super-properties
d3fend use case object propertyop

has procedureop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-procedure

has super-properties
d3fend general object propertyop

has weaknessop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-weakness

has super-properties
may have weaknessop

has-accountop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-account

has super-properties
ownsop

has-dependentop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-dependent

has super-properties
associated-withop
is inverse of
depends-onop

has-evidenceop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-evidence

has super-properties
d3fend-catalog-object-propertyop

has-featureop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-feature

has super-properties
d3fend-catalog-object-propertyop

has-implementationop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-implementation

has super-properties
d3fend-catalog-object-propertyop

has-locationop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-location

is defined by
http://wordnet-rdf.princeton.edu/id/02133811-s
has super-properties
associated-withop

has-memberop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-member

has super-properties
d3fend-catalog-object-propertyop
is inverse of
member-ofop

has-recipientop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-recipient

is defined by
http://www.ontologyrepository.com/CommonCoreOntologies/has_recipient
has super-properties
associated-withop

has-senderop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-sender

is defined by
http://www.ontologyrepository.com/CommonCoreOntologies/has_sender
has super-properties
associated-withop

hidesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#hides

has super-properties
associated-withop
has range
Digital Artifactc

identified byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#identified-by

has super-properties
associated-withop
is inverse of
identified byop, identified byop

identifiesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#identifies

has super-properties
associated-withop

impairsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#impairs

has super-properties
associated-withop

implemented-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#implemented-by

has super-properties
d3fend-catalog-object-propertyop
has range
Capability Implementationc
is inverse of
implementsop

implementsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#implements

has super-properties
d3fend-catalog-object-propertyop
has domain
Capability Implementationc
is inverse of
implemented-byop

injectsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#injects

has super-properties
executesop

installsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#installs

is defined by
http://wordnet-rdf.princeton.edu/id/01572394-v
has super-properties
associated-withop

instructed-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#instructed-by

has super-properties
associated-withop

instructsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#instructs

has super-properties
associated-withop

interpretsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#interprets

has super-properties
executesop
may-interpretop

inventoried-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#inventoried-by

has super-properties
associated-withop
is inverse of
inventoriesop

inventoriesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#inventories

has super-properties
associated-withop
is inverse of
inventoried-byop

invoked-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#invoked-by

has super-properties
associated-withop
may-be-invoked-byop
is inverse of
invokesop

invokesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#invokes

is defined by
http://wordnet-rdf.princeton.edu/id/06599393-n
has super-properties
executesop
may-invokeop
is inverse of
invoked-byop

isolatesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#isolates

is defined by
http://wordnet-rdf.princeton.edu/id/00496744-v
has super-properties
associated-withop
d3fend-tactical-verb-propertyop
has sub-properties
filtersop

kb-referenceop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#kb-reference

has super-properties
d3fend-kb-object-propertyop
is inverse of
kb-reference-ofop

kb-reference-ofop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#kb-reference-of

has super-properties
d3fend-kb-object-propertyop
has domain
Referencec
has range
Techniquec
is inverse of
kb-referenceop

latencyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#latency

has super-properties
d3fend-catalog-object-propertyop
has sub-properties
expected-latencyop
has range
latencyop some Latencyc

licenseop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#license

has super-properties
d3fend-catalog-object-propertyop
has range
licenseop some Licensec

limitsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#limits

is defined by
http://wordnet-rdf.princeton.edu/id/13781154-n
has super-properties
restrictsop
has sub-properties
use-limitsop

loaded-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#loaded-by

has super-properties
associated-withop
is inverse of
loadsop

loadsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#loads

is defined by
http://wordnet-rdf.princeton.edu/id/02236692-v
has super-properties
associated-withop
is inverse of
loaded-byop

managesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#manages

is defined by
http://wordnet-rdf.princeton.edu/id/02447914-v
has super-properties
associated-withop

mapped-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#mapped-by

has super-properties
associated-withop
is inverse of
mapsop

mapsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#maps

has super-properties
may-mapop
is inverse of
mapped-byop

may be weakness ofop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-weakness-of

has super-properties
may-be-associated-withop
has sub-properties
weakness ofop
has domain
Weaknessc
has range
Artifactc

may evaluateop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-evaluate

has super-properties
may-be-associated-withop
has sub-properties
evaluatesop

may have weaknessop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-have-weakness

has super-properties
may-be-associated-withop
has sub-properties
has weaknessop
has domain
Artifactc
has range
Weaknessc

may-accessop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-access

has super-properties
may-be-associated-withop
has sub-properties
accessesop
is inverse of
may-be-accessed-byop

may-addop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-add

has super-properties
may-be-associated-withop
has sub-properties
addsop

may-be-accessed-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-accessed-by

has super-properties
may-be-associated-withop
has sub-properties
accessed-byop
is inverse of
may-accessop

may-be-associated-withop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-associated-with

may-be-contained-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-contained-by

has characteristics : transitive

has super-properties
may-be-associated-withop
has sub-properties
contained-byop
is inverse of
may-containop

may-be-created-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-created-by

has super-properties
may-be-associated-withop
has sub-properties
created-byop
is inverse of
may-createop

may-be-deceived-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-deceived-by

has super-properties
attack-may-be-countered-byop
is inverse of
may-deceiveop

may-be-detected-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-detected-by

has super-properties
attack-may-be-countered-byop
is inverse of
may-detectop

may-be-evicted-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-evicted-by

has super-properties
attack-may-be-countered-byop
is inverse of
may-evictop

may-be-hardened-against-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-hardened-against-by

has super-properties
attack-may-be-countered-byop
is inverse of
may-hardenop

may-be-invoked-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-invoked-by

has super-properties
may-be-associated-withop
has sub-properties
invoked-byop
is inverse of
may-invokeop

may-be-isolated-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-isolated-by

has super-properties
attack-may-be-countered-byop
is inverse of
may-isolateop

may-be-modified-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-modified-by

has super-properties
may-be-associated-withop
has sub-properties
modified-byop
is inverse of
may-modifyop

may-be-tactically-associated-withop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-tactically-associated-with

may-containop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-contain

has characteristics : transitive

has super-properties
may-be-associated-withop
has sub-properties
containsop
is inverse of
may-be-contained-byop

may-counterop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-counter

has super-properties
may-be-associated-withop
has sub-properties
countersop, may-evictop

may-counter-attackop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-counter-attack

has super-properties
may-be-tactically-associated-withop
has sub-properties
may-deceiveop, may-detectop, may-evictop, may-hardenop, may-isolateop

may-createop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-create

has super-properties
may-be-associated-withop
has sub-properties
createsop
is inverse of
may-be-created-byop

may-deceiveop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-deceive

has super-properties
may-counter-attackop
is inverse of
may-be-deceived-byop

may-detectop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-detect

has super-properties
may-counter-attackop
is inverse of
may-be-detected-byop

may-disableop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-disable

has super-properties
may-evictop
has sub-properties
disablesop

may-evictop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-evict

has super-properties
may-counterop
may-counter-attackop
has sub-properties
evictsop, may-disableop
is inverse of
may-be-evicted-byop

may-executeop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-execute

has super-properties
may-be-associated-withop
has sub-properties
executesop

may-hardenop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-harden

has super-properties
may-counter-attackop
is inverse of
may-be-hardened-against-byop

may-interpretop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-interpret

has super-properties
may-be-associated-withop
has sub-properties
interpretsop

may-invokeop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-invoke

has super-properties
may-be-associated-withop
has sub-properties
invokesop
is inverse of
may-be-invoked-byop

may-isolateop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-isolate

has super-properties
may-counter-attackop
is inverse of
may-be-isolated-byop

may-mapop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-map

has super-properties
may-be-associated-withop
has sub-properties
mapsop

may-modifyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-modify

has super-properties
may-be-associated-withop
has sub-properties
modifiesop, modifies-partop
is inverse of
may-be-modified-byop

may-produceop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-produce

has super-properties
may-be-associated-withop
has sub-properties
producesop

may-queryop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-query

has super-properties
may-be-associated-withop
has sub-properties
queriesop

may-runop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-run

has super-properties
may-be-associated-withop
has sub-properties
runsop

may-transferop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#may-transfer

has super-properties
may-be-associated-withop

member-ofop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#member-of

has super-properties
d3fend-catalog-object-propertyop
is inverse of
has-memberop

modified-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#modified-by

has super-properties
associated-withop
may-be-modified-byop
is inverse of
modifiesop

modifiesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#modifies

is defined by
http://wordnet-rdf.princeton.edu/id/00126072-v
has super-properties
accessesop
associated-withop
may-modifyop
has sub-properties
deletesop, disablesop, extendsop, obfuscatesop, updatesop
is inverse of
modified-byop

modifies-partop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#modifies-part

has super-properties
may-modifyop
has sub-property chains
modifiesop o containsop

monitorsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#monitors

is defined by
http://wordnet-rdf.princeton.edu/id/02167732-v
has super-properties
associated-withop
detectsop

narrowerop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#narrower

has super-properties
semantic-relationop

narrower-transitiveop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#narrower-transitive

has super-properties
semantic-relationop

neutralizesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#neutralizes

is defined by
http://wordnet-rdf.princeton.edu/id/00471015-v
has super-properties
associated-withop
hardensop

nextop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#next

has super-properties
d3fend process object propertyop

obfuscatesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#obfuscates

is defined by
http://wordnet-rdf.princeton.edu/id/00942245-v
has super-properties
evictsop
modifiesop

originates-fromop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#originates-from

is defined by
http://wordnet-rdf.princeton.edu/id/02749218-v
has super-properties
associated-withop

ownsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#owns

is defined by
http://wordnet-rdf.princeton.edu/id/02209474-v
has super-properties
associated-withop
has sub-properties
has-accountop

process-ancestorop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-ancestor

has characteristics : transitive

has super-properties
process-propertyop
has sub-properties
process-parentop

process-image-pathop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-image-path

has super-properties
process-propertyop

process-parentop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-parent

has super-properties
process-ancestorop

process-propertyop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-property

has super-properties
associated-withop
has sub-properties
process-ancestorop, process-image-pathop, process-userop

process-userop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-user

has super-properties
process-propertyop

produced-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#produced-by

has super-properties
associated-withop
is inverse of
producesop

producerop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#producer

has super-properties
d3fend-catalog-object-propertyop
is inverse of
producesop

producesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#produces

is defined by
http://wordnet-rdf.princeton.edu/id/01625832-v

providerop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#provider

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-properties
associated-withop

providesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#provides

has super-properties
d3fend-catalog-object-propertyop

publisherop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#publisher

has super-properties
d3fend-catalog-object-propertyop
is inverse of
publishesop

publishesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#publishes

has super-properties
d3fend-catalog-object-propertyop
is inverse of
publisherop

queriesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#queries

has super-properties
associated-withop
may-queryop

readsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#reads

has super-properties
accessesop
has sub-properties
enumeratesop

recorded-inop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#recorded-in

has super-properties
associated-withop

recordsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#records

is defined by
http://wordnet-rdf.princeton.edu/id/01002259-v
has super-properties
associated-withop

relatedop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#related

is defined by
http://www.w3.org/2004/02/skos/core#related
has super-properties
semantic-relationop

restrictsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#restricts

is defined by
http://wordnet-rdf.princeton.edu/id/00234091-v
has super-properties
associated-withop
has sub-properties
limitsop

runsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#runs

has super-properties
associated-withop
may-runop
has sub-properties
executesop

sellerop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#seller

has super-properties
d3fend-catalog-object-propertyop
is inverse of
sellsop

sellsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#sells

has super-properties
d3fend-catalog-object-propertyop
is inverse of
sellerop

semantic-relationop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#semantic-relation

has super-properties
associated-withop
has sub-properties
broaderop, broader-transitiveop, exactlyop, narrowerop, narrower-transitiveop, relatedop

spoofsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#spoofs

has super-properties
associated-withop
deceives-withop

startop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#start

has super-properties
d3fend process object propertyop

strengthensop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#strengthens

is defined by
http://wordnet-rdf.princeton.edu/id/00165779-v
has super-properties
associated-withop
hardensop

submitterop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#submitter

has super-properties
contributorop

summarizesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#summarizes

is defined by
http://wordnet-rdf.princeton.edu/id/02758570-v
has super-properties
associated-withop

suspendsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#suspends

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
has super-properties
evictsop

terminatesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#terminates

is defined by
http://wordnet-rdf.princeton.edu/id/00353480-v
has super-properties
associated-withop
evictsop

unmountsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#unmounts

has super-properties
associated-withop

updatesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#updates

has super-properties
hardensop
modifiesop

use-limitsop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#use-limits

has super-properties
limitsop

used-byop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#used-by

has super-properties
associated-withop
is inverse of
usesop

usesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#uses

is defined by
http://wordnet-rdf.princeton.edu/id/01161188-v
has super-properties
associated-withop
has sub-properties
abusesop
is inverse of
used-byop

validatesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#validates

is defined by
http://wordnet-rdf.princeton.edu/id/00669142-v
has super-properties
associated-withop
hardensop

validatorop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#validator

has super-properties
contributorop

verifiesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#verifies

is defined by
http://wordnet-rdf.princeton.edu/id/00666401-v
has super-properties
analyzesop
associated-withop

weakness ofop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of

has super-properties
may be weakness ofop

writesop back to ToC or Object Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#writes

has super-properties
accessesop

Data Properties

archived-atdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#archived-at

has super-properties
d3fend-catalog-data-propertydp
has range
any u r i

attack-kb-data-propertydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#attack-kb-data-property

has super-properties
top data property

capec-iddp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#capec-id

has super-properties
d3fend-kb-data-propertydp

commentsdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#comments

has characteristics : functional

has super-properties
d3fend-catalog-data-propertydp
has domain
Capability Feature Claimc
has range
string

confidencedp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#confidence

has super-properties
d3fend-catalog-data-propertydp

control-namedp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#control-name

d3fend-artifact-data-propertydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-artifact-data-property

d3fend-catalog-data-propertydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-catalog-data-property

d3fend-commentdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-comment

has super-properties
d3fend-kb-data-propertydp

d3fend-data-propertydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-data-property

d3fend-display-propertydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-display-property

has super-properties
d3fend-data-propertydp

d3fend-external-control-data-propertydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-external-control-data-property

has super-properties
d3fend-data-propertydp
has sub-properties
control-namedp, d3fend-catalog-data-propertydp, versiondp

d3fend-iddp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-id

has super-properties
d3fend-kb-data-propertydp

d3fend-kb-data-propertydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-kb-data-property

has super-properties
d3fend-data-propertydp
has sub-properties
capec-iddp, d3fend-commentdp, d3fend-iddp, has-linkdp, kb-reference-titledp

datedp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#date

has super-properties
d3fend-data-propertydp
has sub-properties
date availabledp, date createddp, date issueddp, date modifieddp, date publisheddp, date validdp
has range
date time

date availabledp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#available

has super-properties
datedp
has range
date time

date createddp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#created

has super-properties
datedp
has range
date time

date issueddp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#issued

has super-properties
datedp
has range
date time

date modifieddp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#modified

has super-properties
datedp
has range
date time

date publisheddp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#published

has super-properties
datedp
has range
date time

date validdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#valid

has super-properties
datedp
has range
date time

expectation ratingdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#expectation-rating

has super-properties
d3fend-catalog-data-propertydp

has-linkdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#has-link

has super-properties
d3fend-kb-data-propertydp
has range
any u r i

identifierdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#identifier

has super-properties
d3fend-catalog-data-propertydp
has range
string

kb-reference-titledp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#kb-reference-title

has super-properties
d3fend-kb-data-propertydp
has domain
Referencec
has range
string

namedp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#name

has super-properties
d3fend-catalog-data-propertydp

operating-systemdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#operating-system

has super-properties
d3fend-catalog-data-propertydp
has domain
Capability Implementationc
has range
string

process-command-line-argumentsdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-command-line-arguments

has super-properties
process-data-propertydp

process-data-propertydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-data-property

process-environmental-variablesdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-environmental-variables

has super-properties
process-data-propertydp

process-identifierdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-identifier

has super-properties
process-data-propertydp

process-security-contextdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#process-security-context

has super-properties
process-data-propertydp
has domain
Processc

ratingdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#rating

has characteristics : functional

has super-properties
d3fend-catalog-data-propertydp

stagedp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#stage

has characteristics : functional

has super-properties
d3fend-catalog-data-propertydp

textdp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#text

has super-properties
d3fend-catalog-data-propertydp

titledp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#title

has super-properties
d3fend-catalog-data-propertydp
has range
string

versiondp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#version

has characteristics : functional

has super-properties
d3fend-catalog-data-propertydp
d3fend-external-control-data-propertydp
has domain
Capability Implementationc or Control Catalogc
has range
integer or string

windows-registry-data-propertydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#windows-registry-data-property

windows-registry-keydp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#windows-registry-key

has super-properties
windows-registry-data-propertydp

windows-registry-valuedp back to ToC or Data Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#windows-registry-value

has super-properties
windows-registry-data-propertydp

Named Individuals

.bash_profile and .bashrcni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.004

has facts
modifiesop User Init Configuration File
is also defined as
class

/etc/passwd and /etc/shadowni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.008

has facts
accessesop Encrypted Credential
accessesop Password File
is also defined as
class

AC-17(8)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-17_8

belongs to
NIST Controlc
has facts
broaderop Executable Denylisting
control-namedp "Remote Access | Disable Nonsecure Network Protocols"
member-ofop NIST SP 800-53 R5

AC-2(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-2_1

belongs to
NIST Controlc
has facts
broaderop Account Locking
broaderop Multi-factor Authentication
control-namedp "Account Management | Automated System Account Management"
member-ofop NIST SP 800-53 R5

AC-2(13)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-2_13

belongs to
NIST Controlc
has facts
control-namedp "Account Management | Disable Accounts for High-risk Individuals"
member-ofop NIST SP 800-53 R5
narrowerop Account Locking

AC-2(2)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-2_2

belongs to
NIST Controlc
has facts
broaderop Account Locking
control-namedp "Account Management | Automated Temporary and Emergency Account Management"
member-ofop NIST SP 800-53 R5

AC-2(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-2_3

belongs to
NIST Controlc
has facts
broaderop Account Locking
control-namedp "Account Management | Disable Accounts"
member-ofop NIST SP 800-53 R5

AC-2(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-2_4

belongs to
NIST Controlc
has facts
control-namedp "Account Management | Automated Audit Actions"
member-ofop NIST SP 800-53 R5
relatedop Domain Account Monitoring

AC-2(5)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-2_5

belongs to
NIST Controlc
has facts
control-namedp "Account Management | Inactivity Logout"
member-ofop NIST SP 800-53 R5
relatedop Account Locking

AC-2(6)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-2_6

belongs to
NIST Controlc
has facts
broaderop Mandatory Access Control
control-namedp "Account Management | Dynamic Privilege Management"
member-ofop NIST SP 800-53 R5

AC-2(7)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-2_7

belongs to
NIST Controlc
has facts
control-namedp "Account Management | Privileged User Accounts"
member-ofop NIST SP 800-53 R5
narrowerop User Account Permissions

AC-2(9)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-2_9

belongs to
NIST Controlc
has facts
control-namedp "Account Management | Restrictions on Use of Shared and Group Accounts"
member-ofop NIST SP 800-53 R5
narrowerop Mandatory Access Control
narrowerop User Account Permissions

AC-23ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-23

belongs to
NIST Controlc
has facts
control-namedp "Data Mining Protection"
member-ofop NIST SP 800-53 R5
narrowerop Job Function Access Pattern Analysis
narrowerop Local Account Monitoring
narrowerop Resource Access Pattern Analysis
narrowerop User Data Transfer Analysis

AC-24ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-24

belongs to
NIST Controlc
has facts
control-namedp "Access Control Decisions"
member-ofop NIST SP 800-53 R5
narrowerop Mandatory Access Control

AC-24(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-24_1

belongs to
NIST Controlc
has facts
control-namedp "Access Control Decisions | Transmit Access Authorization Information"
member-ofop NIST SP 800-53 R5
narrowerop Mandatory Access Control
narrowerop User Account Permissions

AC-24(2)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-24_2

belongs to
NIST Controlc
has facts
control-namedp "Access Control Decisions | No User or Process Identity"
member-ofop NIST SP 800-53 R5
narrowerop Mandatory Access Control
narrowerop User Account Permissions

AC-3ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-3

belongs to
NIST Controlc
has facts
control-namedp "Access Enforcement"
member-ofop NIST SP 800-53 R5
narrowerop Executable Allowlisting
narrowerop Executable Denylisting
narrowerop Mandatory Access Control

AC-3(11)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-3_11

belongs to
NIST Controlc
has facts
control-namedp "Access Enforcement | Restrict Access to Specific Information Types"
member-ofop NIST SP 800-53 R5
narrowerop Mandatory Access Control

AC-3(13)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-3_13

belongs to
NIST Controlc
has facts
control-namedp "Access Enforcement | Attribute-based Access Control"
member-ofop NIST SP 800-53 R5
narrowerop Mandatory Access Control

AC-3(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-3_3

belongs to
NIST Controlc
has facts
control-namedp "Access Enforcement | Mandatory Access Control"
exactlyop Mandatory Access Control
member-ofop NIST SP 800-53 R5

AC-3(7)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-3_7

belongs to
NIST Controlc
has facts
control-namedp "Access Enforcement | Role-based Access Control"
member-ofop NIST SP 800-53 R5
narrowerop Mandatory Access Control

AC-3(8)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-3_8

belongs to
NIST Controlc
has facts
control-namedp "Access Enforcement | Revocation of Access Authorizations"
member-ofop NIST SP 800-53 R5
narrowerop Mandatory Access Control
narrowerop System Call Filtering

AC-4ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_1

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Object Security and Privacy Attributes"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(10)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_10

belongs to
NIST Controlc
has facts
broaderop Inbound Traffic Filtering
broaderop Outbound Traffic Filtering
control-namedp "Information Flow Enforcement | Enable and Disable Security or Privacy Policy Filters"
member-ofop NIST SP 800-53 R5

AC-4(11)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_11

belongs to
NIST Controlc
has facts
broaderop Inbound Traffic Filtering
broaderop Outbound Traffic Filtering
control-namedp "Information Flow Enforcement | Configuration of Security or Privacy Policy Filters"
member-ofop NIST SP 800-53 R5

AC-4(12)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_12

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Data Type Identifiers"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(13)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_13

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Decomposition into Policy-relevant Subcomponents"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(14)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_14

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Security or Privacy Policy Filter Constraints"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(15)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_15

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Detection of Unsanctioned Information"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(17)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_17

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Domain Authentication"
member-ofop NIST SP 800-53 R5
narrowerop Domain Trust Policy

AC-4(19)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_19

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Validation of Metadata"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(20)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_20

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Approved Solutions"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(21)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_21

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Physical or Logical Separation of Information Flows"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(26)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_26

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Audit Filtering Actions"
member-ofop NIST SP 800-53 R5
narrowerop File Content Rules

AC-4(27)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_27

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Redundant/independent Filtering Mechanisms"
exactlyop Inbound Traffic Filtering
exactlyop Outbound Traffic Filtering
member-ofop NIST SP 800-53 R5

AC-4(28)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_28

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Linear Filter Pipelines"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(29)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_29

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Filter Orchestration Engines"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_3

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Dynamic Information Flow Control"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(30)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_30

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Filter Mechanisms Using Multiple Processes"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(32)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_32

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Process Requirements for Information Transfer"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_4

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Flow Control of Encrypted Information"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(5)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_5

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Embedded Data Types"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(6)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_6

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Metadata"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-4(8)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-4_8

belongs to
NIST Controlc
has facts
control-namedp "Information Flow Enforcement | Security and Privacy Policy Filters"
member-ofop NIST SP 800-53 R5
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering

AC-5ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-5

belongs to
NIST Controlc
has facts
broaderop Local File Permissions
broaderop Mandatory Access Control
broaderop User Account Permissions
control-namedp "Separation of Duties"
member-ofop NIST SP 800-53 R5

AC-6ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-6

belongs to
NIST Controlc
has facts
broaderop Local File Permissions
broaderop Mandatory Access Control
broaderop User Account Permissions
control-namedp "Least Privilege"
member-ofop NIST SP 800-53 R5

AC-6(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-6_1

belongs to
NIST Controlc
has facts
control-namedp "Least Privilege | Authorize Access to Security Functions"
exactlyop System Configuration Permissions
member-ofop NIST SP 800-53 R5

AC-6(10)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-6_10

belongs to
NIST Controlc
has facts
control-namedp "Least Privilege | Prohibit Non-privileged Users from Executing Privileged Functions"
member-ofop NIST SP 800-53 R5
narrowerop Local File Permissions
narrowerop Mandatory Access Control
narrowerop System Configuration Permissions

AC-6(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-6_3

belongs to
NIST Controlc
has facts
control-namedp "Least Privilege | Network Access to Privileged Commands"
exactlyop System Configuration Permissions
member-ofop NIST SP 800-53 R5

AC-6(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-6_4

belongs to
NIST Controlc
has facts
control-namedp "Least Privilege | Separate Processing Domains"
member-ofop NIST SP 800-53 R5
narrowerop Hardware-based Process Isolation

AC-6(5)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-6_5

belongs to
NIST Controlc
has facts
control-namedp "Least Privilege | Privileged Accounts"
member-ofop NIST SP 800-53 R5
narrowerop Local File Permissions
narrowerop Mandatory Access Control
narrowerop System Configuration Permissions

AC-6(6)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-6_6

belongs to
NIST Controlc
has facts
control-namedp "Least Privilege | Privileged Access by Non-organizational Users"
member-ofop NIST SP 800-53 R5
narrowerop Local File Permissions
narrowerop Mandatory Access Control
narrowerop System Configuration Permissions

AC-6(9)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-6_9

belongs to
NIST Controlc
has facts
broaderop Local Account Monitoring
broaderop User Behavior Analysis
control-namedp "Least Privilege | Log Use of Privileged Functions"
member-ofop NIST SP 800-53 R5

AC-7ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-7

belongs to
NIST Controlc
has facts
control-namedp "Unsuccessful Logon Attempts"
exactlyop Account Locking
member-ofop NIST SP 800-53 R5

AC-7(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-7_3

belongs to
NIST Controlc
has facts
control-namedp "Unsuccessful Logon Attempts | Biometric Attempt Limiting"
member-ofop NIST SP 800-53 R5
narrowerop Account Locking

AC-7(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AC-7_4

belongs to
NIST Controlc
has facts
broaderop Account Locking
control-namedp "Unsuccessful Logon Attempts | Use of Alternate Authentication Factor"
member-ofop NIST SP 800-53 R5

Access Modelingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AccessModeling

belongs to
Operational Activity Mappingc
has facts
d3fend-iddp "D3-AM"
kb-referenceop Reference - RFC 7642: System for Cross-domain Identity Management: Definitions, Overview, Concepts, and Requirements
mapsop Access Control Configuration
mapsop User Account
is also defined as
class

Accessibility Featuresni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.008

has facts
may-createop Intranet Administrative Network Traffic
may-modifyop Executable Binary
may-modifyop System Configuration Database Record
is also defined as
class

Account Access Removalni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1531

has facts
modifiesop User Account
is also defined as
class

Account Lockingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AccountLocking

belongs to
Credential Evictionc
has facts
date createddp "2020-08-05T00:00:00"^^date time
d3fend-iddp "D3-AL"
disablesop User Account
kb-referenceop Reference - Account monitoring - Forescout Technologies
kb-referenceop Reference - Framework for notifying a directory service of authentication events processed outside the directory service - Oracle International Corp
is also defined as
class

Account Manipulationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098

has facts
modifiesop User Account
is also defined as
class

Account Use Policiesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1036

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "D3-AZET may be related (is potentially related though not called out in ATT&CK definition.)"
relatedop Account Locking
relatedop Authentication Cache Invalidation
relatedop Authentication Event Thresholding

Active Certificate Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ActiveCertificateAnalysis

belongs to
Active Certificate Analysisc
Certificate Analysisc
has facts
date createddp "2020-08-05T00:00:00"^^date time
d3fend-iddp "D3-ACA"
kb-referenceop Reference - Securing Web Transactions
is also defined as
class

Active Directory Configurationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1015

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "M1015 scope is broad, touches on an wide variety of techniques in D3FEND."
relatedop Authentication Cache Invalidation
relatedop Domain Trust Policy
relatedop User Account Permissions

Active Logical Link Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ActiveLogicalLinkMapping

belongs to
Logical Link Mappingc
has facts
d3fend-iddp "D3-ALLM"
kb-referenceop Reference - Identification of traceroute nodes and associated devices
kb-referenceop Reference - SNMP - Network Auto-Discovery
may-queryop Network Agent
is also defined as
class

Active Physical Link Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ActivePhysicalLinkMapping

belongs to
Physical Link Mappingc
is disjoint with
Passive Physical Link Mapping
has facts
d3fend-iddp "D3-APLM"
kb-referenceop Reference - Identification of traceroute nodes and associated devices
kb-referenceop Reference - Using spanning tree protocol (STP) to enhance layer-2 topology maps
may-queryop Network Agent
is also defined as
class

Add Office 365 Global Administrator Roleni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098.003

has facts
modifiesop Global User Account
is also defined as
class

Add-insni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.006

has facts
addsop Software
may-modifyop System Configuration Database
modifiesop Office Application
is also defined as
class

Additional Azure Service Principal Credentialsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098.001

has facts
createsop Credential
producesop Intranet Administrative Network Traffic
is also defined as
class

Administrative Network Activity Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AdministrativeNetworkActivityAnalysis

belongs to
Network Traffic Analysisc
has facts
analyzesop Intranet Administrative Network Traffic
date createddp "2020-08-05T00:00:00"^^date time
d3fend-iddp "D3-ANAA"
kb-referenceop Reference - Method and system for detecting suspicious administrative activity - Vectra Networks Inc
kb-referenceop Reference - CAR-2014-11-005: Remote Registry - MITRE
kb-referenceop Reference - CAR-2014-11-006: Windows Remote Management (WinRM) - MITRE
is also defined as
class

Adobe PDF File 1.3ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AdobePDFFile1.3

belongs to
Document Filec
has facts
may-containop Javascript File

Allocate Memoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AllocateMemory

has facts
createsop Memory Block
is also defined as
class

AMD64 Code Segmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AMD64CodeSegment

belongs to
Image Code Segmentc
Process Code Segmentc

Antivirus/Antimalwareni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1049

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "Process Analysis and subclasses."
relatedop File Content Rules
relatedop File Hashing
relatedop Process Analysis

AppCert DLLsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.009

has facts
invokesop Create Process
loadsop Shared Library File
modifiesop System Configuration Database Record
is also defined as
class

AppInit DLLsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.010

has facts
invokesop Create Process
loadsop Shared Library File
modifiesop System Configuration Database Record
is also defined as
class

Applicationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Application

has facts
may-containop Application Configuration
is also defined as
class

Application Access Tokenni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550.001

has facts
may-produceop Network Traffic
usesop Access Token
is also defined as
class

Application Configuration Databaseni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationConfigurationDatabase

has facts
containsop Application Configuration Database Record
is also defined as
class

Application Configuration Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationConfigurationFile

has facts
containsop Application Configuration
is also defined as
class

Application Configuration Hardeningni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationConfigurationHardening

belongs to
Application Hardeningc
has facts
d3fend-iddp "D3-ACH"
hardensop Application Configuration
kb-referenceop Reference - Red Hat Enterprise Linux 8 Security Technical Implementation Guide
kb-referenceop Reference - Windows 10 STIG
is also defined as
class

Application Developer Guidanceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1013

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "A future release of D3FEND will define a taxonomy of Source Code Hardening Techniques."

Application Hardeningni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationHardening

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-AH"
enablesop Harden
is also defined as
class

Application Inventory Sensorni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationInventorySensor

has facts
monitorsop Application
is also defined as
class

Application Isolation and Sandboxingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1048

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp ""Sandboxing" is often used to describe a detection environment which includes some forms of analysis (see D3-DA.)" Many forms of isolation (e.g., quarantining) are more static in nature and simply limit software's access to system resources."
relatedop Dynamic Analysis
relatedop Hardware-based Process Isolation
relatedop Mandatory Access Control
relatedop System Call Filtering

Application Layer Protocolni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071

has facts
may-transferop Certificate File
producesop Outbound Internet Network Traffic
is also defined as
class

Application Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ApplicationProcess

has facts
runsop Application
is also defined as
class

Application Shimmingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.011

has facts
createsop Shim
modifiesop Shim Database
is also defined as
class

Application Window Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1010

has facts
may-invokeop Create Process
may-invokeop Get Open Windows
is also defined as
class

Archive Collected Datani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1560

has facts
createsop Archive File
is also defined as
class

Archive via Custom Methodni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1560.003

has facts
createsop Custom Archive File
is also defined as
class

Archive via Libraryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1560.002

has facts
createsop Archive File
is also defined as
class

Archive via Utilityni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1560.001

has facts
createsop Archive File
is also defined as
class

ARM32 Code Segmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ARM32CodeSegment

belongs to
Image Code Segmentc
Process Code Segmentc

ASCII Domain Nameni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ASCIIDomainName

belongs to
Domain Namec

Asset Inventoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AssetInventory

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-AI"
enablesop Model
is also defined as
class

Asset Vulnerability Enumerationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AssetVulnerabilityEnumeration

belongs to
Asset Inventoryc
has facts
d3fend-iddp "D3-AVE"
evaluatesop Digital Artifact
identifiesop vulnerability
kb-referenceop Reference - Automated computer vulnerability resolution system
kb-referenceop Reference - Security vulnerability information aggregation
kb-referenceop Reference - System and method for vulnerability risk analysis
is also defined as
class

Asymmetric Cryptographyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1573.002

has facts
createsop Outbound Internet Encrypted Traffic
may-transferop Certificate File
is also defined as
class

Asynchronous Procedure Callni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.004

has facts
may-invokeop Create Process
is also defined as
class

AU-10(5)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AU-10_5

belongs to
NIST Controlc
has facts
broaderop Driver Load Integrity Checking
control-namedp "Non-repudiation | Digital Signatures"
member-ofop NIST SP 800-53 R5

AU-14(2)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AU-14_2

belongs to
NIST Controlc
has facts
control-namedp "Session Audit | Capture and Record Content"
member-ofop NIST SP 800-53 R5
narrowerop Local Account Monitoring

AU-15ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AU-15

belongs to
NIST Controlc
has facts
control-namedp "Alternate Audit Logging Capability"
member-ofop NIST SP 800-53 R5
narrowerop Local Account Monitoring

AU-2ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AU-2

belongs to
NIST Controlc
has facts
control-namedp "Event Logging"
exactlyop Local Account Monitoring
member-ofop NIST SP 800-53 R5

AU-2(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AU-2_1

belongs to
NIST Controlc
has facts
control-namedp "Event Logging | Compilation of Audit Records from Multiple Sources"
exactlyop Local Account Monitoring
member-ofop NIST SP 800-53 R5

AU-2(2)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AU-2_2

belongs to
NIST Controlc
has facts
control-namedp "Event Logging | Selection of Audit Events by Component"
exactlyop Local Account Monitoring
member-ofop NIST SP 800-53 R5

AU-3ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AU-3

belongs to
NIST Controlc
has facts
control-namedp "Content of Audit Records"
exactlyop Local Account Monitoring
member-ofop NIST SP 800-53 R5

AU-4ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_AU-4

belongs to
NIST Controlc
has facts
control-namedp "Audit Log Storage Capacity"
member-ofop NIST SP 800-53 R5
narrowerop Local Account Monitoring

Audio Captureni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1123

has facts
accessesop Audio Input Device
is also defined as
class

Auditni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1047

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "M1047 scope is broad, touches on an wide variety of techniques in d3fend."
relatedop Domain Account Monitoring
relatedop Local Account Monitoring
relatedop System File Analysis

Authenticate Userni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticateUser

has facts
authenticatesop User Account
is also defined as
class

Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Authentication

belongs to
Authenticationc
has facts
authenticatesop User
may-createop Intranet Network Traffic
originates-fromop Physical Location
is also defined as
class

Authentication Cache Invalidationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationCacheInvalidation

belongs to
Credential Evictionc
has facts
d3fend-iddp "D3-ANCI"
deletesop Credential
kb-referenceop Reference - Secure caching of server credentials - Dell Products LP
kb-referenceop Reference - System and method for providing an actively invalidated client-side network resource cache - IMVU
is also defined as
class

Authentication Event Thresholdingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationEventThresholding

belongs to
User Behavior Analysisc
has facts
analyzesop Authentication
date createddp "2020-08-05T00:00:00"^^date time
d3fend-iddp "D3-ANET"
kb-referenceop Reference - Method and Apparatus for Network Fraud Detection and Remediation Through Analytics - Idaptive LLC
kb-referenceop Reference - CAR-2013-02-008: Simultaneous Logins on a Host - MITRE
kb-referenceop Reference - CAR-2013-02-012: User Logged in to Multiple Hosts - MITRE
kb-referenceop Reference - CAR-2013-10-001: User Login Activity Monitoring - MITRE
kb-referenceop Reference - System, method, and computer program product for detecting and assessing security risks in a network - Exabeam Inc
is also defined as
class

Authentication Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationFunction

has facts
authenticatesop User Account
is also defined as
class

Authentication Logni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationLog

has facts
recordsop Authentication
is also defined as
class

Authentication Packageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.002

has facts
modifiesop System Configuration Database Record
is also defined as
class

Authorizationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Authorization

has facts
authorizesop Network Resource Access
is also defined as
class

Authorization Event Thresholdingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthorizationEventThresholding

belongs to
User Behavior Analysisc
has facts
analyzesop Authorization
date createddp "2020-08-05T00:00:00"^^date time
d3fend-iddp "D3-AZET"
kb-referenceop Reference - Method and Apparatus for Network Fraud Detection and Remediation Through Analytics - Idaptive LLC
kb-referenceop Reference - CAR-2013-09-003: SMB Session Setups - MITRE
kb-referenceop Reference - CAR-2013-02-012: User Logged in to Multiple Hosts - MITRE
kb-referenceop Reference - System, method, and computer program product for detecting and assessing security risks in a network - Exabeam Inc
is also defined as
class

Authorization Logni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#AuthorizationLog

has facts
recordsop Network Resource Access
is also defined as
class

Automated Collectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1119

has facts
accessesop File
is also defined as
class

Automated Exfiltrationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1020

has facts
producesop Internet Network Traffic
is also defined as
class

Bash Historyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.003

has facts
accessesop Command History Log File
is also defined as
class

Bash Script Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BashScriptFile

belongs to
Executable Scriptc

Behavior Prevention on Endpointni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1040

belongs to
ATTACK Mitigationc
has facts
relatedop Authentication Event Thresholding
relatedop Authorization Event Thresholding
relatedop Job Function Access Pattern Analysis
relatedop Resource Access Pattern Analysis
relatedop Session Duration Analysis
relatedop User Data Transfer Analysis
relatedop User Geolocation Logon Pattern Analysis
relatedop Web Session Activity Analysis

Binary Paddingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.001

has facts
modifiesop Executable Binary
is also defined as
class

Biometric Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BiometricAuthentication

belongs to
Credential Hardeningc
has facts
authenticatesop User Account
d3fend-iddp "D3-BAN"
kb-referenceop Biometric Authentication
kb-referenceop Reference - Tokenless biometric transaction authorization method and system
kb-referenceop Reference - http://www.biometric-solutions.com/keystroke-dynamics.html - biometric-solutions.com
is also defined as
class

BITS Jobsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1197

has facts
may-produceop Intranet IPC Network Traffic
may-produceop Intranet Web Network Traffic
may-produceop Outbound Internet Web Traffic
is also defined as
class

Block Deviceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BlockDevice

has facts
containsop Boot Sector
containsop Partition
containsop Partition Table
may-containop Volume
is also defined as
class

Bookni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Book

belongs to
Reference Typec

Boot Integrityni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1046

belongs to
ATTACK Mitigationc
has facts
relatedop Bootloader Authentication
relatedop TPM Boot Integrity

Bootkitni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1542.003

has facts
may-modifyop Boot Loader
may-modifyop Boot Sector
may-modifyop Volume Boot Record
is also defined as
class

Bootloader Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BootloaderAuthentication

belongs to
Platform Hardeningc
has facts
authenticatesop Boot Loader
d3fend-iddp "D3-BA"
kb-referenceop Reference - UEFI Platform Initialization (PI) Specification
is also defined as
class

Broadcast Domain Isolationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BroadcastDomainIsolation

belongs to
Network Isolationc
has facts
d3fend-iddp "D3-BDI"
filtersop Local Area Network Traffic
kb-referenceop Reference - Broadcast isolation and level 3 network switch - Hewlett Packard Enterprise Development LP
kb-referenceop Reference - Private virtual local area network isolation - Cisco Technology Inc
is also defined as
class

Browserni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Browser

has facts
may-containop Browser Extension
is also defined as
class

Browser Extensionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BrowserExtension

has facts
extendsop Browser
is also defined as
class

Browser Extensionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1176

has facts
modifiesop Browser Extension
is also defined as
class

BSD Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#BSDProcess

belongs to
Processc

Bypass User Access Controlni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1548.002

has facts
executesop Executable File
invokesop Create Process
may-modifyop System Configuration Database Record
is also defined as
class

Byte Sequence Emulationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ByteSequenceEmulation

belongs to
Network Traffic Analysisc
has facts
d3fend-iddp "D3-BSE"
kb-referenceop Reference - Network-Based Buffer Overflow Detection by Exploit Code Analysis - Information Security Research Centre
kb-referenceop Reference - Network-level polymorphic shellcode detection using emulation
is also defined as
class

Cached Domain Credentialsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.005

has facts
accessesop Encrypted Credential
may-modifyop Log
is also defined as
class

Call Stackni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CallStack

has facts
containsop Stack Frame
is also defined as
class

CCI Catalog v2022-04-05ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCICatalog_v2022-04-05

belongs to
Control Correlation Identifier Catalogc
has facts
archived-atdp "https://public.cyber.mil/stigs/cci/"^^any u r i
has-memberop CCI-000015
has-memberop CCI-000016
has-memberop CCI-000017
has-memberop CCI-000018
has-memberop CCI-000020
has-memberop CCI-000022
has-memberop CCI-000025
has-memberop CCI-000027
has-memberop CCI-000029
has-memberop CCI-000030
has-memberop CCI-000032
has-memberop CCI-000034
has-memberop CCI-000035
has-memberop CCI-000037
has-memberop CCI-000040
has-memberop CCI-000044
has-memberop CCI-000047
has-memberop CCI-000056
has-memberop CCI-000057
has-memberop CCI-000058
has-memberop CCI-000060
has-memberop CCI-000066
has-memberop CCI-000067
has-memberop CCI-000068
has-memberop CCI-000071
has-memberop CCI-000139
has-memberop CCI-000143
has-memberop CCI-000144
has-memberop CCI-000162
has-memberop CCI-000163
has-memberop CCI-000164
has-memberop CCI-000185
has-memberop CCI-000186
has-memberop CCI-000187
has-memberop CCI-000192
has-memberop CCI-000193
has-memberop CCI-000194
has-memberop CCI-000195
has-memberop CCI-000196
has-memberop CCI-000197
has-memberop CCI-000198
has-memberop CCI-000199
has-memberop CCI-000200
has-memberop CCI-000205
has-memberop CCI-000213
has-memberop CCI-000218
has-memberop CCI-000219
has-memberop CCI-000226
has-memberop CCI-000346
has-memberop CCI-000352
has-memberop CCI-000374
has-memberop CCI-000381
has-memberop CCI-000382
has-memberop CCI-000386
has-memberop CCI-000417
has-memberop CCI-000663
has-memberop CCI-000764
has-memberop CCI-000765
has-memberop CCI-000766
has-memberop CCI-000767
has-memberop CCI-000768
has-memberop CCI-000771
has-memberop CCI-000772
has-memberop CCI-000774
has-memberop CCI-000776
has-memberop CCI-000804
has-memberop CCI-000831
has-memberop CCI-000877
has-memberop CCI-000880
has-memberop CCI-000884
has-memberop CCI-000888
has-memberop CCI-001009
has-memberop CCI-001019
has-memberop CCI-001067
has-memberop CCI-001069
has-memberop CCI-001082
has-memberop CCI-001083
has-memberop CCI-001084
has-memberop CCI-001085
has-memberop CCI-001086
has-memberop CCI-001087
has-memberop CCI-001089
has-memberop CCI-001090
has-memberop CCI-001092
has-memberop CCI-001094
has-memberop CCI-001096
has-memberop CCI-001100
has-memberop CCI-001109
has-memberop CCI-001111
has-memberop CCI-001115
has-memberop CCI-001117
has-memberop CCI-001118
has-memberop CCI-001124
has-memberop CCI-001125
has-memberop CCI-001127
has-memberop CCI-001128
has-memberop CCI-001133
has-memberop CCI-001144
has-memberop CCI-001145
has-memberop CCI-001146
has-memberop CCI-001147
has-memberop CCI-001150
has-memberop CCI-001166
has-memberop CCI-001169
has-memberop CCI-001170
has-memberop CCI-001178
has-memberop CCI-001185
has-memberop CCI-001199
has-memberop CCI-001200
has-memberop CCI-001210
has-memberop CCI-001211
has-memberop CCI-001233
has-memberop CCI-001237
has-memberop CCI-001239
has-memberop CCI-001242
has-memberop CCI-001262
has-memberop CCI-001297
has-memberop CCI-001305
has-memberop CCI-001310
has-memberop CCI-001350
has-memberop CCI-001352
has-memberop CCI-001356
has-memberop CCI-001368
has-memberop CCI-001372
has-memberop CCI-001373
has-memberop CCI-001374
has-memberop CCI-001376
has-memberop CCI-001377
has-memberop CCI-001399
has-memberop CCI-001400
has-memberop CCI-001401
has-memberop CCI-001403
has-memberop CCI-001404
has-memberop CCI-001405
has-memberop CCI-001414
has-memberop CCI-001424
has-memberop CCI-001425
has-memberop CCI-001426
has-memberop CCI-001427
has-memberop CCI-001428
has-memberop CCI-001436
has-memberop CCI-001452
has-memberop CCI-001453
has-memberop CCI-001454
has-memberop CCI-001493
has-memberop CCI-001494
has-memberop CCI-001495
has-memberop CCI-001496
has-memberop CCI-001499
has-memberop CCI-001555
has-memberop CCI-001556
has-memberop CCI-001557
has-memberop CCI-001574
has-memberop CCI-001589
has-memberop CCI-001619
has-memberop CCI-001632
has-memberop CCI-001662
has-memberop CCI-001668
has-memberop CCI-001677
has-memberop CCI-001682
has-memberop CCI-001683
has-memberop CCI-001684
has-memberop CCI-001685
has-memberop CCI-001686
has-memberop CCI-001695
has-memberop CCI-001744
has-memberop CCI-001749
has-memberop CCI-001762
has-memberop CCI-001764
has-memberop CCI-001767
has-memberop CCI-001774
has-memberop CCI-001811
has-memberop CCI-001812
has-memberop CCI-001813
has-memberop CCI-001855
has-memberop CCI-001858
has-memberop CCI-001936
has-memberop CCI-001937
has-memberop CCI-001941
has-memberop CCI-001953
has-memberop CCI-001954
has-memberop CCI-001957
has-memberop CCI-001991
has-memberop CCI-002005
has-memberop CCI-002009
has-memberop CCI-002010
has-memberop CCI-002015
has-memberop CCI-002016
has-memberop CCI-002041
has-memberop CCI-002145
has-memberop CCI-002165
has-memberop CCI-002169
has-memberop CCI-002178
has-memberop CCI-002179
has-memberop CCI-002201
has-memberop CCI-002205
has-memberop CCI-002207
has-memberop CCI-002211
has-memberop CCI-002218
has-memberop CCI-002233
has-memberop CCI-002235
has-memberop CCI-002238
has-memberop CCI-002262
has-memberop CCI-002263
has-memberop CCI-002264
has-memberop CCI-002272
has-memberop CCI-002277
has-memberop CCI-002281
has-memberop CCI-002282
has-memberop CCI-002283
has-memberop CCI-002284
has-memberop CCI-002289
has-memberop CCI-002290
has-memberop CCI-002302
has-memberop CCI-002306
has-memberop CCI-002307
has-memberop CCI-002308
has-memberop CCI-002309
has-memberop CCI-002322
has-memberop CCI-002346
has-memberop CCI-002347
has-memberop CCI-002353
has-memberop CCI-002355
has-memberop CCI-002357
has-memberop CCI-002358
has-memberop CCI-002359
has-memberop CCI-002361
has-memberop CCI-002363
has-memberop CCI-002364
has-memberop CCI-002381
has-memberop CCI-002382
has-memberop CCI-002384
has-memberop CCI-002385
has-memberop CCI-002394
has-memberop CCI-002397
has-memberop CCI-002400
has-memberop CCI-002403
has-memberop CCI-002409
has-memberop CCI-002411
has-memberop CCI-002420
has-memberop CCI-002421
has-memberop CCI-002422
has-memberop CCI-002423
has-memberop CCI-002425
has-memberop CCI-002426
has-memberop CCI-002460
has-memberop CCI-002462
has-memberop CCI-002463
has-memberop CCI-002464
has-memberop CCI-002465
has-memberop CCI-002466
has-memberop CCI-002467
has-memberop CCI-002468
has-memberop CCI-002470
has-memberop CCI-002475
has-memberop CCI-002476
has-memberop CCI-002530
has-memberop CCI-002531
has-memberop CCI-002533
has-memberop CCI-002536
has-memberop CCI-002546
has-memberop CCI-002605
has-memberop CCI-002607
has-memberop CCI-002613
has-memberop CCI-002614
has-memberop CCI-002617
has-memberop CCI-002618
has-memberop CCI-002630
has-memberop CCI-002631
has-memberop CCI-002661
has-memberop CCI-002662
has-memberop CCI-002684
has-memberop CCI-002688
has-memberop CCI-002689
has-memberop CCI-002690
has-memberop CCI-002691
has-memberop CCI-002710
has-memberop CCI-002711
has-memberop CCI-002712
has-memberop CCI-002715
has-memberop CCI-002716
has-memberop CCI-002717
has-memberop CCI-002718
has-memberop CCI-002723
has-memberop CCI-002724
has-memberop CCI-002726
has-memberop CCI-002729
has-memberop CCI-002740
has-memberop CCI-002743
has-memberop CCI-002746
has-memberop CCI-002748
has-memberop CCI-002749
has-memberop CCI-002771
has-memberop CCI-002824
has-memberop CCI-002883
has-memberop CCI-002890
has-memberop CCI-002891
has-memberop CCI-003014
has-memberop CCI-003123
versiondp "2022-04-05"

CCI-000015ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000015_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Account Locking
broaderop Domain Account Monitoring
broaderop Local Account Monitoring
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-05-13T00:00:00"^^date time

CCI-000016ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000016_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2009-05-13T00:00:00"^^date time

CCI-000017ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000017_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2009-05-13T00:00:00"^^date time

CCI-000018ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000018_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Domain Account Monitoring
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-05-13T00:00:00"^^date time

CCI-000020ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000020_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000022ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000022_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-05-13T00:00:00"^^date time

CCI-000025ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000025_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000027ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000027_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-05-13T00:00:00"^^date time

CCI-000029ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000029_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-05-13T00:00:00"^^date time

CCI-000030ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000030_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-05-13T00:00:00"^^date time

CCI-000032ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000032_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000034ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000034_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Inbound Traffic Filtering
broaderop Outbound Traffic Filtering
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-05-13T00:00:00"^^date time

CCI-000035ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000035_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Inbound Traffic Filtering
broaderop Outbound Traffic Filtering
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000037ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000037_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Local File Permissions
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000040ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000040_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Authorization Event Thresholding
broaderop Local Account Monitoring
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000044ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000044_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000047ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000047_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000056ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000056_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000057ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000057_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2009-05-19T00:00:00"^^date time

CCI-000058ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000058_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2009-05-19T00:00:00"^^date time

CCI-000060ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000060_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2009-05-19T00:00:00"^^date time

CCI-000066ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000066_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Remote Terminal Session Detection
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000067ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000067_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Remote Terminal Session Detection
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000068ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000068_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Encrypted Tunnels
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000071ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000071_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Remote Terminal Session Detection
date publisheddp "2009-05-19T00:00:00"^^date time

CCI-000139ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000139_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Daemon Monitoring
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000143ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000143_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Daemon Monitoring
date publisheddp "2009-05-20T00:00:00"^^date time

CCI-000144ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000144_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Daemon Monitoring
date publisheddp "2009-05-20T00:00:00"^^date time

CCI-000162ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000162_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Credential Hardening
date publisheddp "2009-05-22T00:00:00"^^date time

CCI-000163ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000163_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Platform Hardening
narrowerop System Configuration Permissions
date publisheddp "2009-05-22T00:00:00"^^date time

CCI-000164ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000164_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Platform Hardening
date publisheddp "2009-05-22T00:00:00"^^date time

CCI-000185ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000185_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Credential Hardening
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000186ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000186_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Credential Hardening
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000187ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000187_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Credential Hardening
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000192ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000192_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000193ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000193_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000194ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000194_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000195ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000195_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000196ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000196_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000197ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000197_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000198ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000198_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000199ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000199_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-09-15T00:00:00"^^date time

CCI-000200ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000200_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-05-22T00:00:00"^^date time

CCI-000205ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000205_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2009-05-22T00:00:00"^^date time

CCI-000213ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000213_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Biometric Authentication
broaderop Certificate-based Authentication
broaderop Multi-factor Authentication
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000218ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000218_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000219ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000219_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000226ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000226_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Execution Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-14T00:00:00"^^date time

CCI-000346ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000346_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Local File Permissions
narrowerop Mandatory Access Control
narrowerop User Account Permissions
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000352ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000352_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Allowlisting
narrowerop Executable Denylisting
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000374ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000374_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Operating System Monitoring
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000381ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000381_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Platform Hardening
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000382ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000382_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Platform Hardening
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000386ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000386_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Executable Denylisting
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000417ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000417_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Execution Isolation
broaderop Network Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000663ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000663_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Execution Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-000764ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000764_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Biometric Authentication
broaderop Certificate-based Authentication
broaderop Multi-factor Authentication
broaderop One-time Password
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000765ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000765_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Multi-factor Authentication
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000766ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000766_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Multi-factor Authentication
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000767ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000767_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Multi-factor Authentication
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000768ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000768_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Multi-factor Authentication
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000771ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000771_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Multi-factor Authentication
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000772ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000772_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Multi-factor Authentication
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000774ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000774_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop One-time Password
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000776ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000776_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop One-time Password
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000804ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000804_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Biometric Authentication
broaderop Certificate-based Authentication
broaderop Multi-factor Authentication
broaderop One-time Password
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-17T00:00:00"^^date time

CCI-000831ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000831_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Credential Eviction
broaderop Process Eviction
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000877ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000877_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Biometric Authentication
broaderop Certificate-based Authentication
broaderop Multi-factor Authentication
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000880ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000880_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Operating System Monitoring
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000884ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000884_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Credential Hardening
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-000888ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-000888_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Encrypted Tunnels
date publisheddp "2009-09-18T00:00:00"^^date time

CCI-001009ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001009_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop File Encryption
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001019ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001019_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Disk Encryption
narrowerop File Encryption
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001067ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001067_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Platform Hardening
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001069ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001069_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Allowlisting
narrowerop Executable Denylisting
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001082ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001082_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Local File Permissions
broaderop Mandatory Access Control
broaderop System Configuration Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001083ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001083_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Local File Permissions
narrowerop Mandatory Access Control
narrowerop System Configuration Permissions
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001084ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001084_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Configuration Permissions
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001085ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001085_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Hardware-based Process Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001086ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001086_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Configuration Permissions
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001087ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001087_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Configuration Permissions
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001089ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001089_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Configuration Permissions
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001090ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001090_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Network Traffic Filtering
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001092ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001092_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001094ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001094_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001096ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001096_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Local File Permissions
narrowerop System Configuration Permissions
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001100ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001100_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001109ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001109_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Inbound Traffic Filtering
exactlyop Outbound Traffic Filtering
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001111ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001111_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001115ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001115_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001117ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001117_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001118ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001118_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Network Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001124ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001124_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Broadcast Domain Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001125ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001125_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001127ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001127_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Encrypted Tunnels
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001128ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001128_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Encrypted Tunnels
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001133ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001133_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Session Duration Analysis
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001144ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001144_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Disk Encryption
narrowerop File Encryption
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001145ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001145_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Disk Encryption
narrowerop File Encryption
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001146ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001146_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Disk Encryption
narrowerop File Encryption
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001147ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001147_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Disk Encryption
narrowerop File Encryption
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001150ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001150_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Remote Terminal Session Detection
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001166ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001166_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Dynamic Analysis
broaderop Emulated File Analysis
broaderop File Content Rules
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001169ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001169_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Denylisting
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001170ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001170_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Denylisting
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001178ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001178_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001185ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001185_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Authentication Cache Invalidation
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001199ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001199_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Disk Encryption
broaderop File Content Rules
broaderop File Encryption
broaderop File Hashing
broaderop Local File Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001200ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001200_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Disk Encryption
narrowerop File Encryption
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001210ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001210_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Driver Load Integrity Checking
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001211ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001211_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Application Configuration Hardening
date publisheddp "2009-09-21T00:00:00"^^date time

CCI-001233ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001233_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Software Update
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001237ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001237_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Software Update
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001239ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001239_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Analysis
broaderop Network Traffic Analysis
broaderop Platform Monitoring
broaderop Process Analysis
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001242ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001242_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Dynamic Analysis
broaderop Emulated File Analysis
broaderop File Content Rules
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001262ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001262_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001297ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001297_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Driver Load Integrity Checking
broaderop File Hashing
broaderop Pointer Authentication
broaderop TPM Boot Integrity
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001305ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001305_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Message Authentication
broaderop Sender MTA Reputation Analysis
broaderop Sender Reputation Analysis
broaderop Transfer Agent Authentication
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001310ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001310_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Database Query String Analysis
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001350ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001350_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop File Encryption
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001352ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001352_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001356ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001356_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Authentication Event Thresholding
exactlyop Authorization Event Thresholding
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001368ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001368_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001372ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001372_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001373ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001373_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001374ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001374_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001376ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001376_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001377ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001377_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001399ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001399_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001400ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001400_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001401ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001401_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-22T00:00:00"^^date time

CCI-001403ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001403_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Domain Account Monitoring
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-24T00:00:00"^^date time

CCI-001404ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001404_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Domain Account Monitoring
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-24T00:00:00"^^date time

CCI-001405ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001405_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Domain Account Monitoring
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-24T00:00:00"^^date time

CCI-001414ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001414_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-24T00:00:00"^^date time

CCI-001424ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001424_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-25T00:00:00"^^date time

CCI-001425ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001425_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-25T00:00:00"^^date time

CCI-001426ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001426_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-25T00:00:00"^^date time

CCI-001427ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001427_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-25T00:00:00"^^date time

CCI-001428ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001428_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-25T00:00:00"^^date time

CCI-001436ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001436_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2009-09-25T00:00:00"^^date time

CCI-001452ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001452_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2009-05-25T00:00:00"^^date time

CCI-001453ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001453_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Encrypted Tunnels
member-ofop CCI Catalog v2022-04-05
date publisheddp "2009-09-29T00:00:00"^^date time

CCI-001454ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001454_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Remote Terminal Session Detection
date publisheddp "2009-09-29T00:00:00"^^date time

CCI-001493ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001493_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
date publisheddp "2009-09-29T00:00:00"^^date time

CCI-001494ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001494_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Platform Hardening
narrowerop System Configuration Permissions
date publisheddp "2009-09-29T00:00:00"^^date time

CCI-001495ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001495_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Platform Hardening
date publisheddp "2009-09-29T00:00:00"^^date time

CCI-001496ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001496_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop File Encryption
date publisheddp "2009-09-29T00:00:00"^^date time

CCI-001499ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001499_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Configuration Permissions
narrowerop User Account Permissions
date publisheddp "2009-09-29T00:00:00"^^date time

CCI-001555ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001555_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2010-05-11T00:00:00"^^date time

CCI-001556ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001556_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2010-05-11T00:00:00"^^date time

CCI-001557ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001557_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Network Traffic Analysis
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2010-05-11T00:00:00"^^date time

CCI-001574ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001574_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2010-05-11T00:00:00"^^date time

CCI-001589ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001589_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Operating System Monitoring
date publisheddp "2010-05-12T00:00:00"^^date time

CCI-001619ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001619_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2010-05-12T00:00:00"^^date time

CCI-001632ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001632_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Encrypted Tunnels
member-ofop CCI Catalog v2022-04-05
date publisheddp "2010-05-12T00:00:00"^^date time

CCI-001662ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001662_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Dynamic Analysis
narrowerop Emulated File Analysis
narrowerop File Content Rules
date publisheddp "2010-05-12T00:00:00"^^date time

CCI-001668ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001668_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Analysis
broaderop Network Traffic Analysis
broaderop Platform Monitoring
broaderop Process Analysis
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2010-05-12T00:00:00"^^date time

CCI-001677ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001677_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Message Authentication
broaderop Sender MTA Reputation Analysis
broaderop Sender Reputation Analysis
broaderop Transfer Agent Authentication
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2010-05-12T00:00:00"^^date time

CCI-001682ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001682_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2011-05-03T00:00:00"^^date time

CCI-001683ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001683_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Account Monitoring
date publisheddp "2011-05-03T00:00:00"^^date time

CCI-001684ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001684_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Account Monitoring
date publisheddp "2011-05-03T00:00:00"^^date time

CCI-001685ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001685_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Account Monitoring
date publisheddp "2011-05-03T00:00:00"^^date time

CCI-001686ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001686_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Account Monitoring
date publisheddp "2011-05-03T00:00:00"^^date time

CCI-001695ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001695_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Denylisting
date publisheddp "2011-10-07T00:00:00"^^date time

CCI-001744ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001744_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Operating System Monitoring
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-02-28T00:00:00"^^date time

CCI-001749ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001749_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Allowlisting
narrowerop Executable Denylisting
date publisheddp "2013-02-28T00:00:00"^^date time

CCI-001762ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001762_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Configuration Permissions
date publisheddp "2013-02-28T00:00:00"^^date time

CCI-001764ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001764_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Executable Allowlisting
broaderop Executable Denylisting
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-02-28T00:00:00"^^date time

CCI-001767ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001767_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Denylisting
date publisheddp "2013-02-28T00:00:00"^^date time

CCI-001774ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001774_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Allowlisting
date publisheddp "2013-02-28T00:00:00"^^date time

CCI-001811ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001811_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop File Analysis
date publisheddp "2013-03-01T00:00:00"^^date time

CCI-001812ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001812_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Allowlisting
narrowerop Executable Denylisting
date publisheddp "2013-03-01T00:00:00"^^date time

CCI-001813ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001813_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-03-01T00:00:00"^^date time

CCI-001855ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001855_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Daemon Monitoring
date publisheddp "2013-03-14T00:00:00"^^date time

CCI-001858ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001858_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Daemon Monitoring
date publisheddp "2013-03-14T00:00:00"^^date time

CCI-001936ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001936_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Multi-factor Authentication
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-001937ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001937_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Multi-factor Authentication
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-001941ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001941_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop One-time Password
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-001953ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001953_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Biometric Authentication
broaderop Certificate-based Authentication
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-001954ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001954_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Biometric Authentication
narrowerop Certificate-based Authentication
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-001957ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001957_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop One-time Password
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-001991ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-001991_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Certificate-based Authentication
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-002005ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002005_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Biometric Authentication
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-002009ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002009_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Biometric Authentication
narrowerop Certificate-based Authentication
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-002010ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002010_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Biometric Authentication
narrowerop Certificate-based Authentication
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-002015ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002015_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Biometric Authentication
narrowerop Certificate-based Authentication
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-002016ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002016_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Biometric Authentication
narrowerop Certificate-based Authentication
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-002041ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002041_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Strong Password Policy
date publisheddp "2013-05-03T00:00:00"^^date time

CCI-002145ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002145_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop User Account Permissions
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002165ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002165_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002169ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002169_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002178ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002178_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
narrowerop System Call Filtering
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002179ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002179_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
narrowerop System Call Filtering
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002201ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002201_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002205ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002205_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002207ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002207_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002211ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002211_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002218ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002218_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002233ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002233_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Denylisting
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002235ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002235_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
narrowerop System Configuration Permissions
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002238ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002238_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Account Locking
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002262ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002262_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002263ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002263_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002264ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002264_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002272ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002272_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002277ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002277_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002281ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002281_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002282ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002282_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002283ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002283_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002284ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002284_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002289ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002289_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002290ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002290_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002302ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002302_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002306ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002306_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop System Configuration Permissions
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002307ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002307_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop System Configuration Permissions
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002308ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002308_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop System Configuration Permissions
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002309ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002309_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop System Configuration Permissions
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002322ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002322_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Remote Terminal Session Detection
date publisheddp "2013-06-24T00:00:00"^^date time

CCI-002346ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002346_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Database Query String Analysis
broaderop Disk Encryption
broaderop File Encryption
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-25T00:00:00"^^date time

CCI-002347ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002347_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Access Pattern Analysis
broaderop Input Device Analysis
broaderop Resource Access Pattern Analysis
broaderop User Data Transfer Analysis
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-25T00:00:00"^^date time

CCI-002353ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002353_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-25T00:00:00"^^date time

CCI-002355ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002355_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Mandatory Access Control
broaderop User Account Permissions
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-06-25T00:00:00"^^date time

CCI-002357ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002357_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
narrowerop User Account Permissions
date publisheddp "2013-06-25T00:00:00"^^date time

CCI-002358ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002358_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
narrowerop User Account Permissions
date publisheddp "2013-06-25T00:00:00"^^date time

CCI-002359ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002359_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Mandatory Access Control
narrowerop User Account Permissions
date publisheddp "2013-06-25T00:00:00"^^date time

CCI-002361ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002361_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Process Termination
date publisheddp "2013-06-26T00:00:00"^^date time

CCI-002363ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002363_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Process Termination
date publisheddp "2013-06-26T00:00:00"^^date time

CCI-002364ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002364_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Process Termination
date publisheddp "2013-06-26T00:00:00"^^date time

CCI-002381ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002381_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Hardware-based Process Isolation
broaderop Kernel-based Process Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002382ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002382_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Hardware-based Process Isolation
broaderop Kernel-based Process Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002384ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002384_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Network Traffic Filtering
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002385ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002385_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002394ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002394_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop System Configuration Permissions
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002397ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002397_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002400ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002400_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Outbound Traffic Filtering
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002403ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002403_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002409ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002409_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
narrowerop Outbound Traffic Filtering
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002411ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002411_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Hardware-based Process Isolation
broaderop IO Port Restriction
broaderop Kernel-based Process Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002420ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002420_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Encrypted Tunnels
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002421ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002421_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Encrypted Tunnels
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002422ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002422_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Encrypted Tunnels
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002423ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002423_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Encrypted Tunnels
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002425ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002425_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Encrypted Tunnels
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002426ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002426_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Encrypted Tunnels
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002460ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002460_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Denylisting
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002462ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002462_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002463ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002463_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002464ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002464_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002465ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002465_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002466ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002466_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Domain Trust Policy
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002467ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002467_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop DNS Traffic Analysis
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002468ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002468_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop DNS Traffic Analysis
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002470ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002470_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Certificate-based Authentication
narrowerop Certificate Pinning
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002475ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002475_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Disk Encryption
narrowerop File Encryption
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002476ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002476_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Disk Encryption
narrowerop File Encryption
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002530ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002530_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Hardware-based Process Isolation
broaderop Kernel-based Process Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002531ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002531_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Hardware-based Process Isolation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002533ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002533_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Kernel-based Process Isolation
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002536ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002536_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop RF Shielding
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002546ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002546_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop IO Port Restriction
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-02T00:00:00"^^date time

CCI-002605ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002605_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Software Update
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002607ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002607_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Software Update
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002613ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002613_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Software Update
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002614ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002614_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Software Update
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002617ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002617_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Software Update
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002618ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002618_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Software Update
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002630ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002630_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Script Execution Analysis
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002631ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002631_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Script Execution Analysis
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002661ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002661_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Inbound Traffic Filtering
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002662ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002662_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Outbound Traffic Filtering
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002684ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002684_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Network Traffic Analysis
broaderop Platform Monitoring
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002688ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002688_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Content Rules
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002689ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002689_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Content Rules
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002690ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002690_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Content Rules
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002691ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002691_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Content Rules
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002710ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002710_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Driver Load Integrity Checking
broaderop File Hashing
broaderop Pointer Authentication
broaderop TPM Boot Integrity
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002711ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002711_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop TPM Boot Integrity
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002712ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002712_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Driver Load Integrity Checking
broaderop File Hashing
broaderop Pointer Authentication
broaderop TPM Boot Integrity
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002715ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002715_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Driver Load Integrity Checking
narrowerop File Hashing
narrowerop Pointer Authentication
narrowerop TPM Boot Integrity
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002716ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002716_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Hashing
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002717ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002717_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Hashing
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002718ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002718_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop File Hashing
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002723ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002723_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Driver Load Integrity Checking
narrowerop File Hashing
narrowerop Pointer Authentication
narrowerop TPM Boot Integrity
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002724ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002724_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Driver Load Integrity Checking
narrowerop File Hashing
narrowerop Pointer Authentication
narrowerop TPM Boot Integrity
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002726ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002726_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Driver Load Integrity Checking
broaderop TPM Boot Integrity
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002729ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002729_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Driver Load Integrity Checking
broaderop TPM Boot Integrity
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002740ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002740_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Executable Allowlisting
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002743ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002743_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Sender MTA Reputation Analysis
broaderop Sender Reputation Analysis
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002746ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002746_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Database Query String Analysis
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002748ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002748_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Database Query String Analysis
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002749ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002749_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Database Query String Analysis
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002771ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002771_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Outbound Traffic Filtering
date publisheddp "2013-07-11T00:00:00"^^date time

CCI-002824ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002824_v2022-04-05

belongs to
CCI Controlc
has facts
broaderop Dead Code Elimination
broaderop Process Segment Execution Prevention
broaderop Segment Address Offset Randomization
broaderop Stack Frame Canary Validation
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-07-12T00:00:00"^^date time

CCI-002883ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002883_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop User Account Permissions
date publisheddp "2013-07-22T00:00:00"^^date time

CCI-002890ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002890_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Encrypted Tunnels
date publisheddp "2013-07-22T00:00:00"^^date time

CCI-002891ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-002891_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Remote Terminal Session Detection
date publisheddp "2013-07-22T00:00:00"^^date time

CCI-003014ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-003014_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
exactlyop Mandatory Access Control
member-ofop CCI Catalog v2022-04-05
date publisheddp "2013-08-30T00:00:00"^^date time

CCI-003123ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CCI-003123_v2022-04-05

belongs to
CCI Controlc
has facts
contributorop DISA FSO
member-ofop CCI Catalog v2022-04-05
narrowerop Encrypted Tunnels
date publisheddp "2013-09-24T00:00:00"^^date time

Central Processing Unitni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CentralProcessingUnit

has facts
containsop Processor Register
may-containop Processor Cache Memory
may-containop Memory Management Unit
may-containop Memory Protection Unit
is also defined as
class

Certificateni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Certificate

has facts
containsop Identifier
containsop Public Key
is also defined as
class

Certificate Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CertificateAnalysis

belongs to
Certificate Analysisc
Network Traffic Analysisc
has facts
analyzesop Certificate File
d3fend-iddp "D3-CA"
kb-referenceop Reference - Securing Web Transactions
is also defined as
class

Certificate Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CertificateFile

has facts
containsop Certificate
is also defined as
class

Certificate Pinningni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CertificatePinning

belongs to
Credential Hardeningc
has facts
authenticatesop Public Key
d3fend-iddp "D3-CP"
kb-referenceop Reference - Certificate and Public Key Pinning
kb-referenceop Reference - End-to-end certificate pinning
is also defined as
class

Certificate Trust Storeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CertificateTrustStore

has facts
containsop Certificate
is also defined as
class

Certificate-based Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Certificate-basedAuthentication

belongs to
Credential Hardeningc
has facts
d3fend-iddp "D3-CBAN"
kb-referenceop Reference - Tokenless biometric transaction authorization method and system
is also defined as
class

Change Default File Associationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.001

has facts
modifiesop System Configuration Database Record
is also defined as
class

Clear Command Historyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.003

has facts
modifiesop Command History Log
is also defined as
class

Clear Linux or Mac System Logsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.002

has facts
modifiesop Operating System Log File
is also defined as
class

Clear Windows Event Logsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.001

has facts
modifiesop Event Log
is also defined as
class

Client-server Payload Profilingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Client-serverPayloadProfiling

belongs to
Network Traffic Analysisc
has facts
analyzesop Network Traffic
d3fend-iddp "D3-CSPP"
kb-referenceop Reference - Method and system for detecting malicious payloads - Vectra Networks Inc
is also defined as
class

Clipboard Datani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1115

has facts
readsop Clipboard
is also defined as
class

Cloud Accountni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1087.004

has facts
createsop Cloud User Account
is also defined as
class

Cloud Accountsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078.004

has facts
usesop Cloud User Account
is also defined as
class

Cloud Instance Metadata APIni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.005

has facts
accessesop Cloud Instance Metadata
is also defined as
class

Cloud Service Dashboardni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1538

has facts
accessesop Cloud Configuration
is also defined as
class

Cloud Service Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1526

has facts
readsop Cloud Configuration
is also defined as
class

Cloud Service Sensorni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CloudServiceSensor

has facts
monitorsop Cloud Service Authentication
monitorsop Cloud Service Authorization
is also defined as
class

Cloud Storage Object Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1619

has facts
accessesop Cloud Storage
is also defined as
class

CM-14ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_CM-14

belongs to
NIST Controlc
has facts
control-namedp "Signed Components"
member-ofop NIST SP 800-53 R5
relatedop Driver Load Integrity Checking
relatedop Message Authentication

CM-5ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_CM-5

belongs to
NIST Controlc
has facts
control-namedp "Access Restrictions for Change"
member-ofop NIST SP 800-53 R5
narrowerop Executable Allowlisting
narrowerop Executable Denylisting
narrowerop Local Account Monitoring
narrowerop Mandatory Access Control

CM-5(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_CM-5_1

belongs to
NIST Controlc
has facts
control-namedp "Access Restrictions for Change | Automated Access Enforcement and Audit Records"
member-ofop NIST SP 800-53 R5
narrowerop Local Account Monitoring

CM-5(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_CM-5_3

belongs to
NIST Controlc
has facts
control-namedp "Access Restrictions for Change | Signed Components"
member-ofop NIST SP 800-53 R5
narrowerop Local Account Monitoring
narrowerop System Configuration Permissions

CM-5(5)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_CM-5_5

belongs to
NIST Controlc
has facts
control-namedp "Access Restrictions for Change | Privilege Limitation for Production and Operation"
member-ofop NIST SP 800-53 R5
narrowerop Local Account Monitoring
narrowerop System Configuration Permissions

CM-5(6)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_CM-5_6

belongs to
NIST Controlc
has facts
control-namedp "Access Restrictions for Change | Limit Library Privileges"
member-ofop NIST SP 800-53 R5
narrowerop Local Account Monitoring
narrowerop System Configuration Permissions

CM-6(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_CM-6_3

belongs to
NIST Controlc
has facts
broaderop Application Configuration Hardening
control-namedp "Configuration Settings | Unauthorized Change Detection"
member-ofop NIST SP 800-53 R5

CMSTPni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.003

has facts
invokesop Create Process
may-produceop Network Traffic
is also defined as
class

Code Repositoriesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1213.003

has facts
readsop Code Repository
is also defined as
class

Code Repositoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CodeRepository

has facts
containsop Source Code
is also defined as
class

Code Signingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1045

belongs to
ATTACK Mitigationc
has facts
relatedop Driver Load Integrity Checking
relatedop Executable Allowlisting
relatedop Service Binary Verification

Code Signingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.002

has facts
enablesop Defense Evasion
is also defined as
class

Collectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Collection

belongs to
Offensive Tacticc
is also defined as
class

Collection Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CollectionTechnique

has facts
enablesop Collection
is also defined as
class

Command And Controlni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CommandAndControl

belongs to
Offensive Tacticc
is also defined as
class

Command and Control Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CommandAndControlTechnique

has facts
enablesop Command And Control
is also defined as
class

Command and Scripting Interpreter Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1059

has facts
executesop Executable Script
is also defined as
class

Command History Log Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CommandHistoryLogFile

has facts
containsop Command History Log
is also defined as
class

Communication Through Removable Mediani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1092

has facts
modifiesop Removable Media Device
is also defined as
class

Compile After Deliveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.004

has facts
createsop Executable File
is also defined as
class

Compiled HTML Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.001

has facts
invokesop Create File
invokesop Create Process
is also defined as
class

Compilerni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Compiler

has facts
readsop Compiler Configuration File
is also defined as
class

Component Firmwareni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1542.002

has facts
modifiesop Firmware
is also defined as
class

Component Object Model Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.015

has facts
loadsop Executable Binary
modifiesop System Configuration Database
is also defined as
class

Compromise Client Software Binaryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1554

has facts
modifiesop Client Application
is also defined as
class

Compromise Hardware Supply Chainni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1195.003

has facts
modifiesop Hardware Device
is also defined as
class

Compromise Software Dependencies and Development Toolsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1195.001

has facts
modifiesop Software
is also defined as
class

Compromise Software Supply Chainni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1195.002

has facts
modifiesop Software
is also defined as
class

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-362

has facts
weakness ofop Shared Resource Access Function
is also defined as
class

Configuration Databaseni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConfigurationDatabase

has facts
containsop Configuration Database Record
is also defined as
class

Configuration Inventoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConfigurationInventory

belongs to
Asset Inventoryc
has facts
d3fend-iddp "D3-CI"
inventoriesop Configuration Resource
kb-referenceop Reference - Web-Based Enterprise Management
kb-referenceop Reference - Windows Management Infrastructure (MI)
kb-referenceop Reference - Windows Management Instrumentation (WMI)
is also defined as
class

Confluenceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1213.001

has facts
accessesop Web File Resource
is also defined as
class

Connect Socketni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConnectSocket

has facts
connectsop Pipe
is also defined as
class

Connected Honeynetni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConnectedHoneynet

belongs to
Decoy Environmentc
has facts
d3fend-iddp "D3-CHN"
kb-referenceop Reference - Modification of a Server to Mimic a Deception Mechanism - Acalvio Technologies Inc
spoofsop Local Area Network
is also defined as
class

Connection Attempt Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ConnectionAttemptAnalysis

belongs to
Network Traffic Analysisc
has facts
analyzesop Intranet Network Traffic
d3fend-iddp "D3-CAA"
kb-referenceop Reference - Detecting network reconnaissance by tracking intranet dark-net communications - VECTRA NETWORKS Inc
is also defined as
class

Container Runtimeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ContainerRuntime

has facts
runsop Container Image
is also defined as
class

Control Panel Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.002

has facts
invokesop Create Process
may-modifyop System Configuration Database Record
is also defined as
class

Copy Memory Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CopyMemoryFunction

has facts
copiesop Memory Block
is also defined as
class

Copy Tokenni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CopyToken

belongs to
Copy Tokenc
has facts
copiesop Access Token
is also defined as
class

COR_PROFILERni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.012

has facts
addsop Shared Library File
modifiesop System Configuration Database Record
is also defined as
class

Create Accountni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1136

has facts
createsop User Account
is also defined as
class

Create Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CreateFile

has facts
createsop File
is also defined as
class

Create Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CreateProcess

has facts
createsop Process
is also defined as
class

Create Process with Tokenni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.002

has facts
copiesop Access Token
may-modifyop Event Log
is also defined as
class

Create Socketni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CreateSocket

has facts
createsop Pipe
is also defined as
class

Create Threadni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CreateThread

has facts
createsop Thread
is also defined as
class

Credentialni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Credential

has facts
authenticatesop User Account
is also defined as
class

Credential Accessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialAccess

belongs to
Offensive Tacticc
is also defined as
class

Credential Access Protectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1043

belongs to
ATTACK Mitigationc
has facts
relatedop Hardware-based Process Isolation

Credential Access Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialAccessTechnique

has facts
accessesop Credential
enablesop Credential Access
may-accessop Password File
may-invokeop Create Process
is also defined as
class

Credential API Hookingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1056.004

has facts
may-modifyop Process Code Segment
is also defined as
class

Credential Compromise Scope Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialCompromiseScopeAnalysis

belongs to
User Behavior Analysisc
has facts
analyzesop Credential
d3fend-iddp "D3-CCSA"
kb-referenceop Reference - CAR-2015-07-001: All Logins Since Last Boot - MITRE
kb-referenceop Reference - Systems and methods for detecting credential theft - Symantec Corp
is also defined as
class

Credential Evictionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialEviction

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-CE"
enablesop Evict
is also defined as
class

Credential Hardeningni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialHardening

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-CH"
enablesop Harden
is also defined as
class

Credential Revokingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialRevoking

belongs to
Credential Evictionc
has facts
d3fend-iddp "D3-CR"
deletesop Credential
kb-referenceop Reference - Revoke a previously issued verifiable credential - Microsoft
is also defined as
class

Credential Stuffingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1110.004

has facts
may-createop Intranet Administrative Network Traffic
modifiesop Authentication Log
producesop Authentication
is also defined as
class

Credential Transmission Scopingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CredentialTransmissionScoping

belongs to
Credential Hardeningc
has facts
d3fend-iddp "D3-CTS"
kb-referenceop Reference - Web Authentication: An API for accessing Public Key Credentials Level 2
restrictsop Credential
is also defined as
class

Credentials from Password Storesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555

has facts
accessesop Password Store
may-accessop Database File
is also defined as
class

Credentials from Web Browsersni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555.003

has facts
accessesop Database File
may-accessop In-memory Password Store
may-invokeop Read File
is also defined as
class

Credentials in Filesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.001

has facts
accessesop File
is also defined as
class

Credentials in Registryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.002

has facts
accessesop System Configuration Database
is also defined as
class

Cross-Site Request Forgery (CSRF)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-352

has facts
weakness ofop User Input Function
is also defined as
class

Data Backupni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1053

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "Comprehensive IT disaster recovery plans are outside the current scope of D3FEND."

Data Encodingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1132

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

Data Exchange Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DataExchangeMapping

belongs to
System Mappingc
has facts
d3fend-iddp "D3-DEM"
kb-referenceop Reference - Catia UAF Plugin
kb-referenceop Reference - Tivoli Application Dependency Discovery Manager 7.3.0 - Dependencies between resources
kb-referenceop Reference - Unified Architecture Framework (UAF)
mapsop Data Dependency
is also defined as
class

Data from Information Repositoriesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1213

has facts
accessesop Resource
is also defined as
class

Data from Local Systemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1005

has facts
accessesop File
accessesop Local Resource
is also defined as
class

Data from Network Shared Driveni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1039

has facts
accessesop Network File Share Resource
is also defined as
class

Data from Removable Mediani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1025

has facts
accessesop Removable Media Device
is also defined as
class

Data Inventoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DataInventory

belongs to
Asset Inventoryc
has facts
d3fend-iddp "D3-DI"
inventoriesop Database
inventoriesop Document File
inventoriesop Email
inventoriesop Multimedia Document File
kb-referenceop Reference - Data processing and scanning systems for generating and populating a data inventory
is also defined as
class

Data Obfuscationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1001

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

Data Stagedni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1074

has facts
readsop Resource
is also defined as
class

Data Transfer Size Limitsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1030

has facts
producesop Internet Network Traffic
is also defined as
class

Database Query String Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DatabaseQueryStringAnalysis

belongs to
Process Analysisc
has facts
analyzesop Database Query
d3fend-iddp "D3-DQSA"
kb-referenceop Reference - System and method for internet security - Cylance Inc
is also defined as
class

Database Serverni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DatabaseServer

has facts
containsop Database
is also defined as
class

DCSyncni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.006

has facts
may-modifyop Event Log
producesop Intranet Administrative Network Traffic
is also defined as
class

Dead Code Eliminationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DeadCodeElimination

belongs to
Application Hardeningc
has facts
d3fend-iddp "D3-DCE"
kb-referenceop Reference - Dead code elimination
is also defined as
class

Deceiveni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Deceive

belongs to
Defensive Tacticc
is also defined as
class

Decoy Artifactni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyArtifact

has facts
may-containop Digital Artifact
is also defined as
class

Decoy Environmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyEnvironment

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-DE"
enablesop Deceive
managesop Decoy Artifact
is also defined as
class

Decoy Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyFile

belongs to
Decoy Objectc
has facts
d3fend-iddp "D3-DF"
kb-referenceop Reference - Open source intelligence deceptions - Illusive Networks Ltd
kb-referenceop Reference - System and a method for identifying the presence of malware and ransomware using mini-traps set at network endpoints - Fidelis Cybersecurity Solutions Inc
kb-referenceop Reference - System and methods thereof for preventing ransomware from encrypting data elements stored in a memory of a computer-based system - Palo Alto Networks Inc
kb-referenceop Reference - Supply chain cyber-deception - Cymmetria, Inc.
spoofsop File
is also defined as
class

Decoy Network Resourceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyNetworkResource

belongs to
Decoy Objectc
has facts
d3fend-iddp "D3-DNR"
kb-referenceop Reference - Automatically generating network resource groups and assigning customized decoy policies thereto - Illusive Networks Ltd
kb-referenceop Reference - Deception-Based Responses to Security Attacks - Crowdstrike Inc
kb-referenceop Reference - Dynamic selection and generation of a virtual clone for detonation of suspicious content within a honey network - Palo Alto Networks Inc
kb-referenceop Reference - System and method for identifying the presence of malware using mini-traps set at network endpoints - Fidelis Cybersecurity Solutions Inc
spoofsop Network Resource
is also defined as
class

Decoy Objectni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyObject

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-DO"
enablesop Deceive
is also defined as
class

Decoy Personani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyPersona

belongs to
Decoy Objectc
has facts
d3fend-iddp "D3-DP"
kb-referenceop Reference - Decoy Personas for Safeguarding Online Identity Using Deception - MITRE
kb-referenceop Reference - Decoy and deceptive data object technology - Cymmetria, Inc.
spoofsop User
is also defined as
class

Decoy Public Releaseni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyPublicRelease

belongs to
Decoy Objectc
has facts
d3fend-iddp "D3-DPR"
kb-referenceop Reference - Mock attack cybersecurity training system and methods - WOMBAT SECURITY TECHNOLOGIES Inc
is also defined as
class

Decoy Session Tokenni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoySessionToken

belongs to
Decoy Objectc
has facts
d3fend-iddp "D3-DST"
kb-referenceop Reference - Decoy and deceptive data object technology - Cymmetria Inc
spoofsop Access Token
is also defined as
class

Decoy User Credentialni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DecoyUserCredential

belongs to
Decoy Objectc
has facts
d3fend-iddp "D3-DUC"
kb-referenceop Reference - Decoy and deceptive data object technology - Cymmetria Inc
kb-referenceop Reference - Decoy Network-Based Service for Deceiving Attackers - Amazon Technologies
kb-referenceop Reference - System and method for identifying the presence of malware using mini-traps set at network endpoints - Fidelis Cybersecurity Solutions Inc
spoofsop Credential
is also defined as
class

Default Accountsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078.001

has facts
usesop Default User Account
is also defined as
class

Defense Evasionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefenseEvasion

belongs to
Offensive Tacticc
is also defined as
class

Defense Evasion Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefenseEvasionTechnique

has facts
enablesop Defense Evasion
is also defined as
class

Defensive Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DefensiveTechnique

belongs to
Techniquec
is also defined as
class

Deobfuscate/Decode Files or Informationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1140

has facts
invokesop Create Process
may-addop Executable File
may-modifyop Event Log
is also defined as
class

Dependencyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Dependency

has facts
dependentop D3FEND Thing
providerop D3FEND Thing
is also defined as
class

Deserialization of Untrusted Datani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-502

has facts
may be weakness ofop User Input Function
weakness ofop Deserialization Function
is also defined as
class

Detectni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Detect

belongs to
Defensive Tacticc
is also defined as
class

Direct Network Floodni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1498.001

has facts
createsop Inbound Internet Network Traffic
is also defined as
class

Direct Volume Accessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1006

has facts
accessesop Volume
is also defined as
class

Directoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Directory

has facts
may-containop File
is also defined as
class

DISA FSOni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DISA_FSO

belongs to
Organizationc

Disable or Modify System Firewallni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.004

has facts
modifiesop System Firewall Configuration
is also defined as
class

Disable or Modify Toolsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.001

has facts
disablesop Operating System Process
is also defined as
class

Disable or Remove Feature or Programni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1042

belongs to
ATTACK Mitigationc
has facts
relatedop Application Configuration Hardening
relatedop Executable Denylisting
relatedop Mandatory Access Control

Disable Windows Event Loggingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.002

has facts
may-modifyop Application Configuration
may-modifyop Operating System Configuration Component
is also defined as
class

Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Discovery

belongs to
Offensive Tacticc
is also defined as
class

Discovery Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DiscoveryTechnique

has facts
enablesop Discovery
is also defined as
class

Disk Content Wipeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1561.001

has facts
may-modifyop Boot Sector
may-modifyop Partition
may-modifyop Partition Table
may-modifyop Volume
modifiesop Block Device
is also defined as
class

Disk Encryptionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DiskEncryption

belongs to
Platform Hardeningc
has facts
d3fend-iddp "D3-DENCR"
encryptsop Storage
kb-referenceop Reference - LUKS1 On-Disk Format SpecificationVersion 1.2.3
is also defined as
class

Disk Structure Wipeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1561.002

has facts
may-modifyop Boot Sector
may-modifyop Partition Table
is also defined as
class

Display Device Driverni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DisplayDeviceDriver

has facts
drivesop Display Adapter
is also defined as
class

DLL Search Order Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.001

has facts
may-createop Shared Library File
is also defined as
class

DLL Side-Loadingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.002

has facts
may-createop Shared Library File
may-modifyop Shared Library File
is also defined as
class

DNSni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071.004

has facts
producesop Outbound Internet DNS Lookup Traffic
is also defined as
class

DNS Allowlistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSAllowlisting

belongs to
Network Isolationc
has facts
blocksop Outbound Internet DNS Lookup Traffic
d3fend-iddp "D3-DNSAL"
kb-referenceop Reference - DNS Whitelist (DNSWL) Email Authentication Method Extension
is also defined as
class

DNS Denylistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSDenylisting

belongs to
Network Isolationc
has facts
blocksop DNS Network Traffic
d3fend-iddp "D3-DNSDL"
kb-referenceop Reference - Use DNS Policy for Applying Filters on DNS Queries
is also defined as
class

DNS Traffic Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DNSTrafficAnalysis

belongs to
Network Traffic Analysisc
has facts
analyzesop Outbound Internet DNS Lookup Traffic
d3fend-iddp "D3-DNSTA"
kb-referenceop Reference - Domain age registration alert - Inc Rapid7 Inc RAPID7 Inc
kb-referenceop Reference - Heuristic botnet detection - Palo Alto Networks Inc
kb-referenceop Reference - Method and system for detecting algorithm-generated domains - VECTRA NETWORKS Inc
kb-referenceop Reference - Predicting Domain Generation Algorithms with Long Short-Term Memory Networks
kb-referenceop Reference - Sinkholing bad network domains by registering the bad network domains on the internet - Palo Alto Networks Inc
may-containop DNS Lookup
is also defined as
class

Do Not Mitigateni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1055

belongs to
ATTACK Mitigationc

Document Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DocumentFile

has facts
may-containop Executable Script
is also defined as
class

Domain Accountni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1087.002

has facts
createsop Domain User Account
is also defined as
class

Domain Account Monitoringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainAccountMonitoring

belongs to
User Behavior Analysisc
has facts
d3fend-iddp "D3-DAM"
kb-referenceop Reference - Audit User Account Management
monitorsop Domain User Account
is also defined as
class

Domain Accountsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078.002

has facts
usesop Domain User Account
is also defined as
class

Domain Frontingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1090.004

has facts
producesop Outbound Internet Encrypted Web Traffic
is also defined as
class

Domain Nameni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainName

has facts
identifiesop IP Address
is also defined as
class

Domain Name Reputation Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainNameReputationAnalysis

belongs to
Identifier Reputation Analysisc
has facts
analyzesop Domain Name
d3fend-iddp "D3-DNRA"
kb-referenceop Reference - Database for receiving, storing and compiling information about email messages
kb-referenceop Reference - Finding phishing sites
is also defined as
class

Domain Registrationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainRegistration

has facts
may-containop Domain Name
is also defined as
class

Domain Trust Policyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DomainTrustPolicy

belongs to
Credential Hardeningc
has facts
d3fend-iddp "D3-DTP"
kb-referenceop Reference - How trust relationships work for resource forests in Azure Active Directory Domain Services
restrictsop Directory Service
restrictsop Domain Account
is also defined as
class

Double File Extensionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.007

has facts
modifiesop File System Metadata
is also defined as
class

Downgrade Attackni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.010

has facts
accessesop Legacy System
is also defined as
class

Drive-by Compromiseni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1189

has facts
modifiesop Process Segment
producesop Outbound Internet Network Traffic
producesop URL
is also defined as
class

Driver Load Integrity Checkingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DriverLoadIntegrityChecking

belongs to
Platform Hardeningc
has facts
authenticatesop Hardware Driver
d3fend-iddp "D3-DLIC"
kb-referenceop Reference - Integrity assurance through early loading in the boot phase - Crowdstrike Inc
kb-referenceop Reference - Protected computing environment - Microsoft Technology Licensing LLC
is also defined as
class

Dylib Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.004

has facts
may-createop Shared Library File
may-modifyop Shared Library File
is also defined as
class

Dynamic Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#DynamicAnalysis

belongs to
File Analysisc
has facts
analyzesop Document File
analyzesop Executable File
d3fend-iddp "D3-DA"
kb-referenceop Reference - Malware analysis system - Palo Alto Networks Inc
kb-referenceop Reference - Use of an application controller to monitor and control software file and application environments - Sophos Ltd
is also defined as
class

Dynamic Resolutionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1568

has facts
producesop Outbound Internet DNS Lookup Traffic
is also defined as
class

Dynamic-link Library Injectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.001

has facts
addsop Shared Library File
invokesop System Call
loadsop Shared Library File
is also defined as
class

Elevated Execution with Promptni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1548.004

has facts
createsop System Configuration Database
invokesop System Call
is also defined as
class

Emailni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Email

has facts
may-containop File
may-containop URL
is also defined as
class

Email Attachmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EmailAttachment

has facts
attached-toop Email
is also defined as
class

Email Collectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1114

has facts
accessesop Resource
is also defined as
class

Email Forwarding Ruleni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1114.003

has facts
modifiesop Application Configuration
is also defined as
class

Email Hiding Rulesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.008

has facts
may-createop Email Rule
may-modifyop Email Rule
modifiesop Application Configuration
is also defined as
class

Email Removalni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EmailRemoval

belongs to
File Removalc
has facts
d3fend-iddp "D3-ER"
deletesop Email
kb-referenceop Reference - System and method for scanning remote services to locate stored objects with malware
may-accessop Mail Server
is also defined as
class

Emondni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.014

has facts
may-createop Property List File
may-modifyop Property List File
modifiesop Configuration Resource
is also defined as
class

Emulated File Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EmulatedFileAnalysis

belongs to
File Analysisc
has facts
analyzesop Document File
analyzesop Executable File
d3fend-iddp "D3-EFA"
kb-referenceop Reference - Network-level polymorphic shellcode detection using emulation
is also defined as
class

Enclaveni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Enclave

has facts
may-containop Local Area Network
is also defined as
class

Encrypt Sensitive Informationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1041

belongs to
ATTACK Mitigationc
has facts
relatedop Disk Encryption
relatedop Encrypted Tunnels
relatedop File Encryption
relatedop Message Encryption

Encrypted Channelni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1573

has facts
producesop Outbound Internet Encrypted Traffic
is also defined as
class

Encrypted Tunnelsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EncryptedTunnels

belongs to
Network Isolationc
has facts
d3fend-iddp "D3-ET"
isolatesop Intranet Network
kb-referenceop Reference - Security Architecture for the Internet Protocol
is also defined as
class

Endpoint Health Beaconni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EndpointHealthBeacon

belongs to
Operating System Monitoringc
has facts
d3fend-iddp "D3-EHB"
kb-referenceop Reference - Intrusion detection using a heartbeat - Sophos Ltd
is also defined as
class

Environment Variable Permissionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1039

belongs to
ATTACK Mitigationc
has facts
relatedop Application Configuration Hardening
relatedop System File Analysis

Eval Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#EvalFunction

has facts
invokesop Subroutine
is also defined as
class

Evictni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Evict

belongs to
Defensive Tacticc
is also defined as
class

Exception Handler Pointer Validationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExceptionHandlerPointerValidation

belongs to
Application Hardeningc
has facts
d3fend-iddp "D3-EHPV"
kb-referenceop Reference - /SAFESEH (Image has Safe Exception Handlers) - Microsoft Docs
validatesop Pointer
is also defined as
class

Exchange Email Delegate Permissionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1098.002

has facts
modifiesop Domain User Account
is also defined as
class

Executable Allowlistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutableAllowlisting

belongs to
Platform Hardeningc
has facts
blocksop Executable File
d3fend-iddp "D3-EAL"
kb-referenceop Reference - Enhancing Network Security By Preventing User-Initiated Malware Execution - MITRE
kb-referenceop Reference - Computing apparatus with automatic integrity reference generation and maintenance - Tripwire, Inc.
restrictsop Create Process
is also defined as
class

Executable Binaryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutableBinary

has facts
containsop Image Code Segment
containsop Image Data Segment
may-interpretop Executable Script
is also defined as
class

Executable Denylistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutableDenylisting

belongs to
Execution Isolationc
has facts
blocksop Executable File
d3fend-iddp "D3-EDL"
kb-referenceop Reference - Method and apparatus for increasing the speed at which computer viruses are detected - McAfee LLC
kb-referenceop Reference - Content extractor and analysis system - Bit 9 Inc, Carbon Black Inc
restrictsop Create Process
is also defined as
class

Executable Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutableFile

has facts
containsop Subroutine
is also defined as
class

Executable Installer File Permissions Weaknessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.005

has facts
modifiesop Service Application
is also defined as
class

Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Execution

belongs to
Offensive Tacticc
is also defined as
class

Execution Isolationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutionIsolation

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-EI"
enablesop Isolate
is also defined as
class

Execution Preventionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1038

belongs to
ATTACK Mitigationc
has facts
relatedop Driver Load Integrity Checking
relatedop Executable Allowlisting
relatedop Executable Denylisting
relatedop Process Segment Execution Prevention

Execution Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExecutionTechnique

has facts
enablesop Execution
is also defined as
class

Exfiltrationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Exfiltration

belongs to
Offensive Tacticc
is also defined as
class

Exfiltration Over Alternative Protocolni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1048

has facts
producesop Internet Network Traffic
is also defined as
class

Exfiltration Over Asymmetric Encrypted Non-C2 Protocolni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1048.002

has facts
may-transferop Certificate File
producesop Outbound Internet Encrypted Traffic
is also defined as
class

Exfiltration Over C2 Channelni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1041

has facts
may-transferop Certificate File
producesop Internet Network Traffic
is also defined as
class

Exfiltration Over Other Network Mediumni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1011

has facts
producesop Internet Network Traffic
is also defined as
class

Exfiltration Over Symmetric Encrypted Non-C2 Protocolni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1048.001

has facts
producesop Outbound Internet Encrypted Traffic
is also defined as
class

Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocolni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1048.003

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

Exfiltration over USBni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1052.001

has facts
modifiesop Removable Media Device
is also defined as
class

Exfiltration Over Web Serviceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1567

has facts
producesop Outbound Internet Web Traffic
is also defined as
class

Exfiltration Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ExfiltrationTechnique

has facts
enablesop Exfiltration
is also defined as
class

Exfiltration to Cloud Storageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1567.002

has facts
producesop Outbound Internet Encrypted Web Traffic
is also defined as
class

Exfiltration to Code Repositoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1567.001

has facts
may-produceop Outbound Internet Encrypted Remote Terminal Traffic
may-produceop Outbound Internet Encrypted Web Traffic
is also defined as
class

Exploit Protectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1050

belongs to
ATTACK Mitigationc
has facts
relatedop Application Hardening
relatedop Exception Handler Pointer Validation
relatedop Inbound Traffic Filtering
relatedop Shadow Stack Comparisons

Exploit Public-Facing Applicationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1190

has facts
injectsop Database Query
modifiesop Process Segment
producesop Inbound Internet Network Traffic
is also defined as
class

Exploitation for Client Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1203

has facts
modifiesop Process Code Segment
modifiesop Stack Frame
is also defined as
class

Exploitation for Credential Accessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1212

has facts
may-accessop Authentication Service
may-accessop Credential Management System
may-modifyop Process Code Segment
may-modifyop Stack Frame
is also defined as
class

Exploitation for Defense Evasionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1211

has facts
may-modifyop Process Code Segment
may-modifyop Stack Frame
is also defined as
class

Exploitation for Privilege Escalationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1068

has facts
enablesop Privilege Escalation
may-modifyop Stack Frame
modifiesop Process Code Segment
is also defined as
class

Exploitation of Remote Servicesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1210

has facts
may-modifyop Process Code Segment
may-modifyop Process Segment
may-modifyop Stack Frame
producesop Intranet Network Traffic
is also defined as
class

Exploitation of Transient Instruction Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CAPEC-663

belongs to
Common Attack Patternc
has facts
capec-iddp "CAPEC-553"
is also defined as
class

External Defacementni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1491.002

has facts
modifiesop Network Resource
is also defined as
class

External Proxyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1090.002

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

External Remote Servicesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1133

has facts
producesop Authentication
producesop Authorization
producesop Network Session
is also defined as
class

Fallback Channelsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1008

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#File

has facts
containsop File Section
may-containop File
may-containop URL
is also defined as
class

File Access Pattern Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileAccessPatternAnalysis

belongs to
Process Analysisc
has facts
analyzesop Local Resource Access
d3fend-iddp "D3-FAPA"
kb-referenceop Reference - File-modifying malware detection - Crowdstrike Inc
is also defined as
class

File Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileAnalysis

belongs to
Defensive Techniquec
has facts
analyzesop File
d3fend-iddp "D3-FA"
enablesop Detect
is also defined as
class

File and Directory Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1083

has facts
accessesop Directory
accessesop File
is also defined as
class

File and Directory Permissions Modificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1222

has facts
modifiesop Access Control Configuration
is also defined as
class

File Carvingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileCarving

belongs to
Network Traffic Analysisc
has facts
analyzesop File Transfer Network Traffic
d3fend-iddp "D3-FC"
kb-referenceop Reference - Computer Worm Defense System and Method - FireEye Inc
is also defined as
class

File Content Rulesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileContentRules

belongs to
File Analysisc
has facts
d3fend-iddp "D3-FCR"
kb-referenceop Reference - Computational modeling and classification of data streams - Crowdstrike Inc
kb-referenceop Reference - Detecting script-based malware - Crowdstrike Inc
kb-referenceop Reference - Distributed meta-information query in a network - Bit 9 Inc
kb-referenceop Reference - System and methods thereof for logical identification of malicious threats across a plurality of end-point devices (epd) communicatively connected by a network - Palo Alto Networks IncCyber Secdo Ltd
is also defined as
class

File Creation Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileCreationAnalysis

belongs to
System Call Analysisc
has facts
analyzesop Create File
d3fend-iddp "D3-FCA"
kb-referenceop Reference - CAR-2019-07-002: Lsass Process Dump via Procdump - MITRE
kb-referenceop Reference - CAR-2020-09-001: Scheduled Task - FileAccess - MITRE
is also defined as
class

File Deletionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.004

has facts
deletesop File
may-modifyop File
is also defined as
class

File Encryptionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileEncryption

belongs to
Platform Hardeningc
has facts
d3fend-iddp "D3-FE"
encryptsop File
kb-referenceop Reference - Method for file encryption
is also defined as
class

File Evictionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileEviction

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-FEV"
enablesop Evict
is also defined as
class

File Hashni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileHash

has facts
identifiesop File
is also defined as
class

File Hash Reputation Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileHashReputationAnalysis

belongs to
Identifier Reputation Analysisc
has facts
analyzesop File Hash
d3fend-iddp "D3-FHRA"
kb-referenceop Reference - Reputation of an entity associated with a content item
is also defined as
class

File Hashingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileHashing

belongs to
File Analysisc
has facts
d3fend-iddp "D3-FH"
kb-referenceop Reference - Munin
is also defined as
class

File Path Open Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FilePathOpenFunction

has facts
accessesop File
invokesop Open File
is also defined as
class

File Removalni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileRemoval

belongs to
File Evictionc
has facts
d3fend-iddp "D3-FR"
deletesop File
kb-referenceop Reference - How Does Antivirus Quarantine Work? - Safety Detectives
may-accessop File Server
is also defined as
class

File Systemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileSystem

has facts
containsop Directory
containsop File
containsop File System Link
containsop File System Metadata
is also defined as
class

File System Sensorni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FileSystemSensor

has facts
monitorsop File
is also defined as
class

File Transfer Protocolsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071.002

has facts
producesop Outbound Internet File Transfer Traffic
is also defined as
class

Filter Network Trafficni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1037

belongs to
ATTACK Mitigationc
has facts
relatedop Network Isolation

Firmware Behavior Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FirmwareBehaviorAnalysis

belongs to
Platform Monitoringc
has facts
analyzesop Firmware
d3fend-iddp "D3-FBA"
kb-referenceop Reference - Firmware Behavior Analysis ConFirm
kb-referenceop Reference - Firmware Behavior Analysis VIPER
is also defined as
class

Firmware Embedded Monitoring Codeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FirmwareEmbeddedMonitoringCode

belongs to
Platform Monitoringc
has facts
analyzesop Firmware
d3fend-iddp "D3-FEMC"
kb-referenceop Reference - Firmware Embedded Monitoring Code Red Balloon
kb-referenceop Reference - Firmware Embedded Monitoring Code Symbiotes
is also defined as
class

Firmware Sensorni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FirmwareSensor

has facts
monitorsop Firmware
is also defined as
class

Firmware Verificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FirmwareVerification

belongs to
Platform Monitoringc
has facts
d3fend-iddp "D3-FV"
kb-referenceop Reference - Firmware Verification Eclypsium
kb-referenceop Reference - Firmware Verification Trapezoid
kb-referenceop Reference - Platform Firmware Resiliency Guidelines - NIST
verifiesop Firmware
is also defined as
class

Forced Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1187

has facts
may-modifyop Windows Shortcut File
modifiesop Authentication Log
producesop Authentication
is also defined as
class

Forward Resolution Domain Denylistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ForwardResolutionDomainDenylisting

belongs to
DNS Denylistingc
has facts
blocksop Outbound Internet DNS Lookup Traffic
d3fend-iddp "D3-FRDDL"
kb-referenceop Reference - Use DNS Policy for Applying Filters on DNS Queries
is also defined as
class

Forward Resolution IP Denylistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ForwardResolutionIPDenylisting

belongs to
DNS Denylistingc
has facts
blocksop Inbound Internet DNS Response Traffic
d3fend-iddp "D3-FRIDL"
kb-referenceop Reference - Use DNS Policy for Applying Filters on DNS Queries
is also defined as
class

FQDN Domain Nameni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FQDNDomainName

belongs to
Domain Namec

Free Memoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#FreeMemory

has facts
deletesop Memory Block
is also defined as
class

Gatekeeper Bypassni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.001

has facts
modifiesop File System Metadata
is also defined as
class

get foreground windowni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetForegroundWindow

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl
belongs to
Get Open Windowsc

Get Open Socketsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetOpenSockets

has facts
enumeratesop Pipe
is also defined as
class

Get System Config Valueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GetSystemConfigValue

has facts
readsop System Configuration Database Record
is also defined as
class

GNU GCC StackGuardni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#GNUGCCStackGuard

belongs to
Stack Frame Canary Validationc

Golden Ticketni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1558.001

has facts
forgesop Kerberos Ticket Granting Ticket
is also defined as
class

Group Policy Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1615

has facts
readsop Group Policy
is also defined as
class

Group Policy Modificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1484

has facts
modifiesop Group Policy
is also defined as
class

Group Policy Preferencesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.006

has facts
accessesop Group Policy
is also defined as
class

GUI Input Captureni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1056.002

has facts
accessesop Graphical User Interface
is also defined as
class

Hardenni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Harden

belongs to
Defensive Tacticc
is also defined as
class

Hardware Additionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1200

has facts
connectsop Hardware Device
is also defined as
class

Hardware Component Inventoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HardwareComponentInventory

belongs to
Asset Inventoryc
has facts
d3fend-iddp "D3-HCI"
inventoriesop Hardware Device
kb-referenceop Reference - Advanced device matching system
is also defined as
class

Hardware Driverni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HardwareDriver

has facts
drivesop Hardware Device
is also defined as
class

Hardware-based Process Isolationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Hardware-basedProcessIsolation

belongs to
Execution Isolationc
has facts
d3fend-iddp "D3-HBPI"
isolatesop Process
kb-referenceop Reference - Virtualized process isolation - Advanced Micro Devices Inc
kb-referenceop Reference - Approaches for securing an internet endpoint using fine-grained operating system virtualization - Bromium, Inc.
kb-referenceop Reference - Isolation of applications within a virtual machine - Bromium, Inc.
restrictsop Create Process
is also defined as
class

Hidden File Systemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.005

has facts
may-modifyop System Configuration Database
modifiesop Storage
is also defined as
class

Hidden Files and Directoriesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.001

has facts
modifiesop File System Metadata
is also defined as
class

Hidden Usersni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.002

has facts
modifiesop User Init Configuration File
is also defined as
class

Hidden Windowni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.003

has facts
may-modifyop Property List File
may-modifyop System Configuration Database
is also defined as
class

Hierarchical Domain Denylistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HierarchicalDomainDenylisting

belongs to
Forward Resolution Domain Denylistingc
has facts
d3fend-iddp "D3-HDDL"
kb-referenceop Reference - Use DNS Policy for Applying Filters on DNS Queries
is also defined as
class

Homoglyph Denylistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HomoglyphDenylisting

belongs to
Forward Resolution Domain Denylistingc
has facts
d3fend-iddp "D3-HDL"
kb-referenceop Reference - Detection of Malicious IDNHomoglyph Domains
is also defined as
class

Homoglyph Detectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HomoglyphDetection

belongs to
Identifier Analysisc
has facts
analyzesop Email
analyzesop URL
d3fend-iddp "D3-HD"
kb-referenceop Reference - Computer-implemented methods and systems for identifying visually similar text character strings - Greathorn Inc
kb-referenceop Reference - System and method for detecting homoglyph attacks with a siamese convolutional neural network - Endgame Inc
is also defined as
class

Hostni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Host

has facts
containsop Application
containsop Operating System
runsop Operating System
is also defined as
class

Host Configuration Sensorni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HostConfigurationSensor

has facts
monitorsop Application Configuration
monitorsop Operating System Configuration
is also defined as
class

Hostnameni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Hostname

belongs to
Domain Namec
has facts
identifiesop Host
is also defined as
class

HTML Smugglingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.006

has facts
createsop JavaScript Blob
hidesop Digital Artifact
is also defined as
class

HTTP URLni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HTTPURL

belongs to
URLc

HTTPS URLni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#HTTPSURL

belongs to
URLc

IA-2(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_IA-2_1

belongs to
NIST Controlc
has facts
control-namedp "Identification and Authentication (organizational Users) | Multi-factor Authentication to Privileged Accounts"
member-ofop NIST SP 800-53 R5
narrowerop Multi-factor Authentication

IA-2(2)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_IA-2_2

belongs to
NIST Controlc
has facts
control-namedp "Identification and Authentication (organizational Users) | Multi-factor Authentication to Non-privileged Accounts"
member-ofop NIST SP 800-53 R5
narrowerop Multi-factor Authentication

IA-2(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_IA-2_4

belongs to
NIST Controlc
has facts
control-namedp "Identification and Authentication (organizational Users) | Local Access to Non-privileged Accounts"
member-ofop NIST SP 800-53 R5
narrowerop Local Account Monitoring

IA-2(6)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_IA-2_6

belongs to
NIST Controlc
has facts
control-namedp "Identification and Authentication (organizational Users) | Access to Accounts —separate Device"
member-ofop NIST SP 800-53 R5
narrowerop Multi-factor Authentication

Identifier Activity Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IdentifierActivityAnalysis

belongs to
Identifier Analysisc
has facts
kb-referenceop Reference - The Pyramid of Pain - David Bianco
is also defined as
class

Identifier Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IdentifierAnalysis

belongs to
Defensive Techniquec
has facts
analyzesop Identifier
d3fend-iddp "D3-ID"
enablesop Detect
is also defined as
class

Identifier Reputation Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IdentifierReputationAnalysis

belongs to
Identifier Analysisc
has facts
d3fend-iddp "D3-IRA"
kb-referenceop Reference - Finding phishing sites
is also defined as
class

IIS Componentsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.004

has facts
addsop Software
is also defined as
class

Image Code Segmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImageCodeSegment

has facts
containsop Subroutine
is also defined as
class

Image File Execution Options Injectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.012

has facts
modifiesop System Configuration Database
is also defined as
class

Impactni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Impact

belongs to
Offensive Tacticc
is also defined as
class

Impact Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImpactTechnique

has facts
enablesop Impact
is also defined as
class

Impair Command History Loggingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.003

has facts
may-modifyop User Init Script
may-modifyop Windows Registry Key
modifiesop Process Environment Variable
is also defined as
class

Impersonate Userni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImpersonateUser

belongs to
Impersonate Userc
has facts
forgesop User Account
is also defined as
class

Implant Container Imageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1525

has facts
addsop Container Image
is also defined as
class

Import Library Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ImportLibraryFunction

has facts
loadsop Shared Library File
is also defined as
class

Improper Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-287

has facts
weakness ofop Authentication Function
is also defined as
class

Improper Control of Generation of Code ('Code Injection')ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-94

has facts
may be weakness ofop Eval Function
may be weakness ofop User Input Function
is also defined as
class

Improper Input Validationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-20

has facts
weakness ofop User Input Function
is also defined as
class

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-22

has facts
weakness ofop User Input Function
is also defined as
class

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-79

has facts
weakness ofop User Input Function
is also defined as
class

Improper Neutralization of Special Elements used in a Command ('Command Injection')ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-77

has facts
weakness ofop User Input Function
is also defined as
class

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-78

has facts
may be weakness ofop Eval Function
may be weakness ofop Process Start Function
may be weakness ofop User Input Function
is also defined as
class

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-89

has facts
weakness ofop User Input Function
is also defined as
class

Improper Restriction of Operations within the Bounds of a Memory Bufferni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-119

has facts
weakness ofop Raw Memory Access Function
is also defined as
class

Improper Restriction of XML External Entity Referenceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-611

has facts
weakness ofop External Content Inclusion Function
is also defined as
class

Inbound Internet Network Trafficni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InboundInternetNetworkTraffic

has facts
producesop Network Traffic
is also defined as
class

Inbound Session Volume Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InboundSessionVolumeAnalysis

belongs to
Network Traffic Analysisc
has facts
analyzesop Inbound Internet Network Traffic
d3fend-iddp "D3-ISVA"
kb-referenceop Reference - Detecting DDoS Attack Using Snort
kb-referenceop Reference - Identifying a denial-of-service attack in a cloud-based proxy service - Cloudfare Inc.
kb-referenceop Reference - Method and system for UDP flood attack detection - Riorey LLC
kb-referenceop Reference - Protecting against distributed denial of service attacks - Cisco Technology Inc.
kb-referenceop Reference - Protecting against distributed network flood attacks - Juniper Networks Inc.
is also defined as
class

Inbound Traffic Filteringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InboundTrafficFiltering

belongs to
Network Traffic Filteringc
has facts
d3fend-iddp "D3-ITF"
filtersop Inbound Network Traffic
kb-referenceop Reference - Active firewall system and methodology - McAfee LLC
kb-referenceop Reference - Automatically generating rules for connection security - Microsoft
kb-referenceop Reference - FWTK - Firewall Toolkit
kb-referenceop Reference - Firewall for interent access - Secure Computing LLC
kb-referenceop Reference - Firewall for processing a connectionless network packet - National Security Agency
kb-referenceop Reference - Firewall for processing connection-oriented and connectionless datagrams over a connection-oriented network - National Security Agency
kb-referenceop Reference - Firewalls that filter based upon protocol commands - Intel Corp
kb-referenceop Reference - Method for controlling computer network security - Checkpoint Software Technologies Ltd
kb-referenceop Reference - Network firewall with proxy - Secure Computing LLC
is also defined as
class

Incorrect Default Permissionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-276

has facts
weakness ofop Application Installer
is also defined as
class

Indirect Branch Call Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IndirectBranchCallAnalysis

belongs to
Process Analysisc
has facts
d3fend-iddp "D3-IBCA"
kb-referenceop Reference - Indirect Branching Calls
is also defined as
class

Ingress Tool Transferni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1105

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

Initial Accessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InitialAccess

belongs to
Offensive Tacticc
is also defined as
class

Initial Access Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InitialAccessTechnique

has facts
enablesop Initial Access
is also defined as
class

Input Device Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InputDeviceAnalysis

belongs to
Operating System Monitoringc
has facts
analyzesop Input Device
d3fend-iddp "D3-IDA"
kb-referenceop Reference - http://www.biometric-solutions.com/keystroke-dynamics.html - biometric-solutions.com
kb-referenceop Reference - Continuous authentication by analysis of keyboard typing characteristics - Bradford Univ., UK
is also defined as
class

Install Root Certificateni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.004

has facts
modifiesop Certificate Trust Store
is also defined as
class

Integer Overflow or Wraparoundni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-190

has facts
weakness ofop Mathematical Function
is also defined as
class

Integrated Honeynetni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntegratedHoneynet

belongs to
Decoy Environmentc
has facts
d3fend-iddp "D3-IHN"
kb-referenceop Reference - Synchronizing a honey network configuration to reflect a target network environment - Palo Alto Networks Inc
spoofsop Intranet Network
is also defined as
class

Inter-Process Communication Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1559

has facts
injectsop Interprocess Communication
is also defined as
class

Internal Defacementni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1491.001

has facts
modifiesop Resource
is also defined as
class

Internal Proxyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1090.001

has facts
producesop Intranet Network Traffic
is also defined as
class

Internal Spearphishingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1534

has facts
producesop Email
is also defined as
class

Internationalized Domain Nameni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InternationalizedDomainName

belongs to
Domain Namec

Internet Articleni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#InternetArticle

belongs to
Reference Typec
is also defined as
class

Intranet IPC Network Trafficni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetIPCNetworkTraffic

has facts
may-containop File
is also defined as
class

Intranet Web Network Trafficni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IntranetWebNetworkTraffic

has facts
may-containop File
is also defined as
class

Invalid Code Signatureni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.001

has facts
createsop Executable Binary
is also defined as
class

IO Port Restrictionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IOPortRestriction

belongs to
Execution Isolationc
has facts
d3fend-iddp "D3-IOPR"
filtersop Input Device
filtersop Removable Media Device
kb-referenceop Reference - Computer motherboard having peripheral security functions
kb-referenceop Reference - Method and system for controlling communication ports
kb-referenceop Reference - USB filter for hub malicious code prevention system
is also defined as
class

iOS Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#iOSProcess

belongs to
Processc

IP Addressni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IPAddress

has facts
identifiesop Network Node
is also defined as
class

IP Reputation Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IPReputationAnalysis

belongs to
Identifier Reputation Analysisc
has facts
analyzesop IP Address
d3fend-iddp "D3-IPRA"
kb-referenceop Reference - Database for receiving, storing and compiling information about email messages
kb-referenceop Reference - Finding phishing sites
is also defined as
class

IPC Traffic Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#IPCTrafficAnalysis

belongs to
Network Traffic Analysisc
has facts
analyzesop Intranet IPC Network Traffic
d3fend-iddp "D3-IPCTA"
kb-referenceop Reference - CAR-2013-05-005: SMB Copy and Execution - MITRE
kb-referenceop Reference - CAR-2013-01-003: SMB Events Monitoring - MITRE
kb-referenceop Reference - CAR-2013-09-003: SMB Session Setups - MITRE
kb-referenceop Reference - CAR-2014-03-001: SMB Write Request - NamedPipes - MITRE
kb-referenceop Reference - CAR-2013-05-003: SMB Write Request - MITRE
kb-referenceop Reference - Security System with Methodology for Interprocess Communication Control - Check Point Software Tech Inc
kb-referenceop Reference - CAR-2015-04-001: Remotely Scheduled Tasks via AT - MITRE
is also defined as
class

IR-4(12)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_IR-4_12

belongs to
NIST Controlc
has facts
control-namedp "Incident Handling | Malicious Code and Forensic Analysis"
member-ofop NIST SP 800-53 R5
relatedop Dynamic Analysis

IR-4(13)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_IR-4_13

belongs to
NIST Controlc
has facts
control-namedp "Incident Handling | Behavior Analysis"
member-ofop NIST SP 800-53 R5
relatedop Decoy Environment
relatedop Decoy Object

Isolateni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Isolate

belongs to
Defensive Tacticc
is also defined as
class

Javascript Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#JavascriptFile

belongs to
Executable Scriptc

Job Function Access Pattern Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#JobFunctionAccessPatternAnalysis

belongs to
User Behavior Analysisc
has facts
analyzesop Authorization
d3fend-iddp "D3-JFAPA"
kb-referenceop Reference - Anomaly Detection Using Adaptive Behavioral Profiles - Securonix Inc
is also defined as
class

Kerberoastingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1558.003

has facts
may-produceop RPC Network Traffic
is also defined as
class

Kernelni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Kernel

has facts
containsop Kernel Process Table
loadsop Application
managesop Operating System Process
managesop User Process
may-containop Hardware Driver
may-containop Kernel Module
is also defined as
class

Kernel API Sensorni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#KernelAPISensor

has facts
monitorsop System Call
is also defined as
class

Kernel Modules and Extensionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.006

has facts
modifiesop Kernel Module
is also defined as
class

Kernel-based Process Isolationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Kernel-basedProcessIsolation

belongs to
Execution Isolationc
has facts
d3fend-iddp "D3-KBPI"
kb-referenceop Reference - Overview of the seccomp sandbox
is also defined as
class

Keychainni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1142

has facts
accessesop Encrypted Credential
is also defined as
class

Keychainni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555.001

has facts
accessesop MacOS Keychain
is also defined as
class

Keyloggingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1056.001

has facts
accessesop Keyboard Input Device
is also defined as
class

Lateral Movementni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LateralMovement

belongs to
Offensive Tacticc
is also defined as
class

Lateral Movement Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LateralMovementTechnique

has facts
enablesop Lateral Movement
is also defined as
class

Lateral Tool Transferni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1570

has facts
producesop Intranet File Transfer Traffic
is also defined as
class

Launch Agentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1543.001

has facts
createsop Property List File
is also defined as
class

Launch Daemonni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1543.004

has facts
modifiesop Property List File
is also defined as
class

Launchdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053.004

has facts
createsop Property List File
is also defined as
class

LC_LOAD_DYLIB Additionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.006

has facts
modifiesop Executable Binary
is also defined as
class

LD_PRELOADni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.006

has facts
modifiesop Operating System Configuration File
is also defined as
class

LDIF Recordni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LDIFRecord

belongs to
User Accountc

Limit Access to Resource Over Networkni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1035

belongs to
ATTACK Mitigationc
has facts
relatedop Network Isolation

Limit Hardware Installationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1034

belongs to
ATTACK Mitigationc
has facts
relatedop IO Port Restriction

Limit Software Installationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1033

belongs to
ATTACK Mitigationc
has facts
relatedop Executable Allowlisting
relatedop Executable Denylisting

Linux ELF File 32bitni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LinuxELFFile32bit

belongs to
Executable Binaryc

Linux ELF File 64bitni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LinuxELFFile64bit

belongs to
Executable Binaryc

Linux Execni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LinuxExec

belongs to
Create Processc

Linux Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LinuxProcess

belongs to
Processc

LLMNR/NBT-NS Poisoning and SMB Relayni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1557.001

has facts
producesop Intranet Multicast Network Traffic
is also defined as
class

Local Accountni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1087.001

has facts
createsop Local User Account
is also defined as
class

Local Account Monitoringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalAccountMonitoring

belongs to
User Behavior Analysisc
has facts
analyzesop Local User Account
d3fend-iddp "D3-LAM"
kb-referenceop Reference - Audit User Account Management
kb-referenceop Reference - CAR-2016-04-004: Successful Local Account Login
kb-referenceop Reference - OS Query Windows User Collection Code
is also defined as
class

Local Accountsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078.003

has facts
usesop Local User Account
is also defined as
class

Local Area Networkni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalAreaNetwork

has facts
may-containop Host
is also defined as
class

Local Data Stagingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1074.001

has facts
may-createop File
may-invokeop Create File
is also defined as
class

Local Email Collectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1114.001

has facts
readsop Email
is also defined as
class

Local File Permissionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalFilePermissions

belongs to
Platform Hardeningc
has facts
d3fend-iddp "D3-LFP"
kb-referenceop Reference - File and Folder Permissions
restrictsop Directory
restrictsop File
is also defined as
class

Local Resource Accessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LocalResourceAccess

has facts
accessesop Local Resource
is also defined as
class

Log Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LogFile

has facts
containsop Log
is also defined as
class

Logical Link Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LogicalLinkMapping

belongs to
Network Mappingc
has facts
d3fend-iddp "D3-LLM"
kb-referenceop Reference - Libre NMS - Network Map Extension
mapsop Logical Link
mapsop Network
mapsop Network Node
is also defined as
class

Login Itemsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.015

has facts
modifiesop User Logon Init Resource
is also defined as
class

Logon Script (Mac)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.002

has facts
modifiesop User Init Script
is also defined as
class

Logon Script (Windows)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.001

has facts
modifiesop User Init Script
is also defined as
class

Logon Userni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LogonUser

has facts
authenticatesop User Account
is also defined as
class

LSA Secretsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.004

has facts
may-accessop Process
may-accessop System Password Database
is also defined as
class

LSASS Driverni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.008

has facts
may-createop Shared Library File
modifiesop System Service Software
is also defined as
class

LSASS Memoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.001

has facts
accessesop Authentication Service
accessesop Process
is also defined as
class

Lua Script Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#LuaScriptFile

belongs to
Executable Scriptc

MA-3(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_MA-3_3

belongs to
NIST Controlc
has facts
control-namedp "Maintenance Tools | Prevent Unauthorized Removal"
member-ofop NIST SP 800-53 R5
narrowerop User Account Permissions

MA-3(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_MA-3_4

belongs to
NIST Controlc
has facts
control-namedp "Maintenance Tools | Restricted Tool Use"
member-ofop NIST SP 800-53 R5
narrowerop User Account Permissions

MA-3(5)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_MA-3_5

belongs to
NIST Controlc
has facts
control-namedp "Maintenance Tools | Execution with Privilege"
member-ofop NIST SP 800-53 R5
narrowerop User Account Permissions

MA-3(6)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_MA-3_6

belongs to
NIST Controlc
has facts
control-namedp "Maintenance Tools | Software Updates and Patches"
member-ofop NIST SP 800-53 R5
narrowerop Software Update

MA-4(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_MA-4_1

belongs to
NIST Controlc
has facts
control-namedp "Nonlocal Maintenance | Logging and Review"
member-ofop NIST SP 800-53 R5
narrowerop Local Account Monitoring

MA-6ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_MA-6

belongs to
NIST Controlc
has facts
control-namedp "Timely Maintenance"
member-ofop NIST SP 800-53 R5
narrowerop Software Update

MA-6(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_MA-6_1

belongs to
NIST Controlc
has facts
control-namedp "Timely Maintenance | Preventive Maintenance"
member-ofop NIST SP 800-53 R5
narrowerop Software Update

MA-6(2)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_MA-6_2

belongs to
NIST Controlc
has facts
control-namedp "Timely Maintenance | Predictive Maintenance"
member-ofop NIST SP 800-53 R5
narrowerop Software Update

MA-6(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_MA-6_3

belongs to
NIST Controlc
has facts
control-namedp "Timely Maintenance | Automated Support for Predictive Maintenance"
member-ofop NIST SP 800-53 R5
narrowerop Software Update

macOS Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#macOSProcess

belongs to
Processc

Mail Network Trafficni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MailNetworkTraffic

has facts
containsop Email
is also defined as
class

Mail Protocolsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071.003

has facts
producesop Outbound Internet Mail Traffic
is also defined as
class

Mail Serverni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MailServer

has facts
runsop Message Transfer Agent
is also defined as
class

Make and Impersonate Tokenni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.003

has facts
copiesop Access Token
createsop Login Session
may-modifyop Event Log
is also defined as
class

Malicious File Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1204.002

has facts
executesop Executable File
is also defined as
class

Malicious Link Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1204.001

has facts
accessesop URL
producesop Outbound Internet Web Traffic
is also defined as
class

Man in the Browserni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1185

has facts
producesop Web Network Traffic
is also defined as
class

Man-in-the-Middleni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1557

has facts
producesop Network Traffic
is also defined as
class

Mandatory Access Controlni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MandatoryAccessControl

belongs to
Kernel-based Process Isolationc
has facts
d3fend-iddp "D3-MAC"
isolatesop Process
kb-referenceop Reference - Analysis of the Windows Vista Security Model - Symantec Corporation
kb-referenceop Reference - Architecture of transparent network security for application containers - Neuvector Inc
restrictsop Create Process
is also defined as
class

Marketing Materialni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MarketingMaterial

belongs to
Reference Typec

Masquerade Task or Serviceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.004

has facts
modifiesop Task Schedule
is also defined as
class

Match Legitimate Name or Locationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.005

has facts
invokesop Move File
may-createop File
is also defined as
class

Mavinjectni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.013

has facts
invokesop Create Thread
modifiesop Process Segment
is also defined as
class

Memory Addressni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryAddress

has facts
addressesop Memory Word
is also defined as
class

Memory Address Spaceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryAddressSpace

has facts
containsop Memory Address
is also defined as
class

Memory Allocation Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryAllocationFunction

has facts
invokesop Allocate Memory
is also defined as
class

Memory Blockni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryBlock

has facts
containsop Memory Word
may-containop Record
is also defined as
class

Memory Boundary Trackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryBoundaryTracking

belongs to
Operating System Monitoringc
has facts
analyzesop Process Code Segment
d3fend-iddp "D3-MBT"
kb-referenceop Reference - Inferential exploit attempt detection - Crowdstrike Inc
is also defined as
class

Memory Free Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryFreeFunction

has facts
invokesop Free Memory
is also defined as
class

Memory Management Unitni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryManagementUnit

has facts
containsop Translation Lookaside Buffer
createsop Virtual Address
managesop Page Table
managesop Storage
is also defined as
class

Memory Poolni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryPool

has facts
containsop Memory Block
is also defined as
class

Message Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MessageAnalysis

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-MA"
enablesop Detect
is also defined as
class

Message Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MessageAuthentication

belongs to
Message Hardeningc
has facts
authenticatesop User to User Message
d3fend-iddp "D3-MAN"
kb-referenceop Reference - RFC 6376: DomainKeys Identified Mail (DKIM) Signatures - IETF
kb-referenceop Reference - Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.1
is also defined as
class

Message Encryptionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MessageEncryption

belongs to
Message Hardeningc
has facts
d3fend-iddp "D3-MENCR"
encryptsop User to User Message
kb-referenceop Reference - Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.1
is also defined as
class

Message Hardeningni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MessageHardening

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-MH"
enablesop Harden
is also defined as
class

Microsoft VCCLCompilerTool BufferSecurityCheckni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MicrosoftVCCLCompilerToolBufferSecurityCheck

belongs to
Stack Frame Canary Validationc

Microsoft Word DOC Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MicrosoftWordDOCFile

belongs to
Document Filec

Microsoft Word DOCB Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MicrosoftWordDOCBFile

belongs to
Document Filec

Microsoft Word DOCM Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MicrosoftWordDOCMFile

belongs to
Document Filec

Microsoft Word DOCX Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MicrosoftWordDOCXFile

belongs to
Document Filec

Microsoft Word DOT Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MicrosoftWordDOTFile

belongs to
Document Filec

Microsoft Word DOTM Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MicrosoftWordDOTMFile

belongs to
Document Filec

Microsoft Word DOTX Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MicrosoftWordDOTXFile

belongs to
Document Filec

Microsoft Word WBK Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MicrosoftWordWBKFile

belongs to
Document Filec

MMCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.014

has facts
executesop Command
may-addop Software
may-modifyop System Configuration Database
is also defined as
class

Modelni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Model

belongs to
Defensive Tacticc
is also defined as
class

Modify Authentication Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1556

has facts
modifiesop Authentication Service
is also defined as
class

Modify Registryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1112

has facts
modifiesop Windows Registry
is also defined as
class

Move Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MoveFile

has facts
modifiesop File System Metadata
is also defined as
class

MSBuildni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1127.001

has facts
modifiesop Compiler Configuration File
runsop Compiler
is also defined as
class

MSG Email Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#MSGEmailFile

belongs to
Emailc

Multi-factor Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1032

belongs to
ATTACK Mitigationc
has facts
relatedop Multi-factor Authentication

Multi-factor Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Multi-factorAuthentication

belongs to
Credential Hardeningc
has facts
authenticatesop User Account
d3fend-iddp "D3-MFA"
kb-referenceop Reference - Method and apparatus for utilizing a token for resource access - Rsa Security Inc.
is also defined as
class

Multi-hop Proxyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1090.003

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

Multi-Stage Channelsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1104

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

Native API Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1106

has facts
invokesop System Call
is also defined as
class

Netsh Helper DLLni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.007

has facts
modifiesop System Configuration Database Record
producesop Process
is also defined as
class

Network Directory Resourceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkDirectoryResource

has facts
containsop Directory
is also defined as
class

Network File Resourceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkFileResource

has facts
containsop File
is also defined as
class

Network Flowni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkFlow

has facts
summarizesop Network Traffic
is also defined as
class

Network Flow Sensorni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkFlowSensor

has facts
monitorsop Network Flow
is also defined as
class

Network Intrusion Preventionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1031

belongs to
ATTACK Mitigationc
has facts
relatedop Inbound Traffic Filtering
relatedop Network Traffic Analysis
relatedop Outbound Traffic Filtering

Network Isolationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkIsolation

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-NI"
enablesop Isolate
is also defined as
class

Network Logon Scriptni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.003

has facts
modifiesop Network Init Script File Resource
is also defined as
class

Network Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkMapping

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-NM"
enablesop Model
is also defined as
class

Network Nodeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkNode

has facts
runsop Operating System
is also defined as
class

Network Node Inventoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkNodeInventory

belongs to
Asset Inventoryc
has facts
d3fend-iddp "D3-NNI"
inventoriesop Network Node
kb-referenceop Reference - IEEE Standard for Local and Metropolitan Area Networks - Station and Media Access Control Connectivity Discovery
kb-referenceop Reference - Qualys Network Passive Sensor Getting Started Guide
kb-referenceop Reference - An Architecture for Describing Simple Network Management Protocol (SNMP) Management Frameworks
kb-referenceop Reference - Web-Based Enterprise Management
kb-referenceop Reference - Windows Management Infrastructure (MI)
kb-referenceop Reference - Windows Management Instrumentation (WMI)
is also defined as
class

Network Protocol Analyzerni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkProtocolAnalyzer

has facts
monitorsop Network Traffic
is also defined as
class

Network Resource Accessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkResourceAccess

has facts
accessesop Network Resource
accessesop Resource
is also defined as
class

Network Segmentationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1030

belongs to
ATTACK Mitigationc
has facts
relatedop Broadcast Domain Isolation
relatedop Encrypted Tunnels
relatedop Inbound Session Volume Analysis
relatedop Inbound Traffic Filtering

Network Sessionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkSession

has facts
containsop Network Packet
is also defined as
class

Network Share Connection Removalni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.005

has facts
unmountsop Network File Share Resource
is also defined as
class

Network Sniffingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1040

has facts
may-produceop DNS Lookup
is also defined as
class

Network Trafficni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTraffic

has facts
may-containop Domain Name
originates-fromop Physical Location
is also defined as
class

Network Traffic Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficAnalysis

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-NTA"
enablesop Detect
is also defined as
class

Network Traffic Analysis Softwareni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficAnalysisSoftware

belongs to
Digital Artifactc
is also defined as
class

Network Traffic Community Deviationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficCommunityDeviation

belongs to
Network Traffic Analysisc
has facts
analyzesop Network Traffic
d3fend-iddp "D3-NTCD"
kb-referenceop Reference - System for implementing threat detection using daily network traffic community outliers - VECTRA NETWORKS Inc
is also defined as
class

Network Traffic Filteringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficFiltering

belongs to
Network Isolationc
has facts
d3fend-iddp "D3-NTF"
filtersop Network Traffic
kb-referenceop Reference - Active firewall system and methodology - McAfee LLC
kb-referenceop Reference - Automatically generating rules for connection security - Microsoft
kb-referenceop Reference - FWTK - Firewall Toolkit
kb-referenceop Reference - Firewall for interent access - Secure Computing LLC
kb-referenceop Reference - Firewall for processing a connectionless network packet - National Security Agency
kb-referenceop Reference - Firewall for processing connection-oriented and connectionless datagrams over a connection-oriented network - National Security Agency
kb-referenceop Reference - Firewalls that filter based upon protocol commands - Intel Corp
kb-referenceop Reference - Method for controlling computer network security - Checkpoint Software Technologies Ltd
kb-referenceop Reference - Network firewall with proxy - Secure Computing LLC
is also defined as
class

Network Traffic Policy Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkTrafficPolicyMapping

belongs to
Network Mappingc
has facts
d3fend-iddp "D3-NTPM"
kb-referenceop Reference - Cisco ASR 9000 Series Aggregation Services Routers - Access List Commands
mapsop Access Control Configuration
queriesop Network Agent
is also defined as
class

Network Vulnerability Assessmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NetworkVulnerabilityAssessment

belongs to
Network Mappingc
has facts
d3fend-iddp "D3-NVA"
evaluatesop Network
identifiesop vulnerability
is also defined as
class

NIST SP 800-53 R3ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R3

belongs to
NIST SP 800-53 Control Catalogc
has facts
archived-atdp "https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2013-04-30"^^any u r i
versiondp "3"^^integer

NIST SP 800-53 R4ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R4

belongs to
NIST SP 800-53 Control Catalogc
has facts
archived-atdp "https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2013-04-30"^^any u r i
versiondp "4"^^integer

NIST SP 800-53 R5ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5

belongs to
NIST SP 800-53 Control Catalogc
has facts
archived-atdp "https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final"^^any u r i
has-memberop AC-17(8)
has-memberop AC-23
has-memberop AC-24
has-memberop AC-24(1)
has-memberop AC-24(2)
has-memberop AC-2(1)
has-memberop AC-2(13)
has-memberop AC-2(2)
has-memberop AC-2(3)
has-memberop AC-2(4)
has-memberop AC-2(5)
has-memberop AC-2(6)
has-memberop AC-2(7)
has-memberop AC-2(9)
has-memberop AC-3
has-memberop AC-3(11)
has-memberop AC-3(13)
has-memberop AC-3(3)
has-memberop AC-3(7)
has-memberop AC-3(8)
has-memberop AC-4
has-memberop AC-4(1)
has-memberop AC-4(10)
has-memberop AC-4(11)
has-memberop AC-4(12)
has-memberop AC-4(13)
has-memberop AC-4(14)
has-memberop AC-4(15)
has-memberop AC-4(17)
has-memberop AC-4(19)
has-memberop AC-4(20)
has-memberop AC-4(21)
has-memberop AC-4(26)
has-memberop AC-4(27)
has-memberop AC-4(28)
has-memberop AC-4(29)
has-memberop AC-4(3)
has-memberop AC-4(30)
has-memberop AC-4(32)
has-memberop AC-4(4)
has-memberop AC-4(5)
has-memberop AC-4(6)
has-memberop AC-4(8)
has-memberop AC-5
has-memberop AC-6
has-memberop AC-6(1)
has-memberop AC-6(10)
has-memberop AC-6(3)
has-memberop AC-6(4)
has-memberop AC-6(5)
has-memberop AC-6(6)
has-memberop AC-6(9)
has-memberop AC-7
has-memberop AC-7(3)
has-memberop AC-7(4)
has-memberop AU-10(5)
has-memberop AU-14(2)
has-memberop AU-15
has-memberop AU-2
has-memberop AU-2(1)
has-memberop AU-2(2)
has-memberop AU-3
has-memberop AU-4
has-memberop CM-14
has-memberop CM-5
has-memberop CM-5(1)
has-memberop CM-5(3)
has-memberop CM-5(5)
has-memberop CM-5(6)
has-memberop CM-6(3)
has-memberop IA-2(1)
has-memberop IA-2(2)
has-memberop IA-2(4)
has-memberop IA-2(6)
has-memberop IR-4(12)
has-memberop IR-4(13)
has-memberop MA-3(3)
has-memberop MA-3(4)
has-memberop MA-3(5)
has-memberop MA-3(6)
has-memberop MA-4(1)
has-memberop MA-6
has-memberop MA-6(1)
has-memberop MA-6(2)
has-memberop MA-6(3)
has-memberop RA-3(3)
has-memberop RA-3(4)
has-memberop RA-5
has-memberop RA-5(2)
has-memberop RA-5(3)
has-memberop RA-5(4)
has-memberop RA-5(5)
has-memberop RA-5(6)
has-memberop RA-5(7)
has-memberop SA-10(1)
has-memberop SA-10(3)
has-memberop SA-10(4)
has-memberop SA-10(5)
has-memberop SA-10(6)
has-memberop SA-11(1)
has-memberop SA-11(8)
has-memberop SA-8(18)
has-memberop SA-8(22)
has-memberop SC-2
has-memberop SC-2(1)
has-memberop SC-3
has-memberop SC-3(1)
has-memberop SI-2(4)
has-memberop SI-2(5)
has-memberop SI-2(6)
has-memberop SI-3
has-memberop SI-3(10)
has-memberop SI-3(4)
has-memberop SI-3(8)
has-memberop SI-4
has-memberop SI-4(2)
has-memberop SI-4(4)
versiondp "5"^^integer

Non-Application Layer Protocolni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1095

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

non-real-time-analyticni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#non-real-time-analytic

belongs to
Analytic Latencyc

non-real-time-evictionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#non-real-time-eviction

belongs to
Eviction Latencyc

Non-Standard Portni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1571

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

NTDSni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.003

has facts
accessesop Encrypted Credential
is also defined as
class

NTFS File Attributesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.004

has facts
modifiesop File System Metadata
is also defined as
class

NULL Pointer Dereferenceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-476

has facts
weakness ofop Pointer Dereferencing Function
is also defined as
class

Office Template Macrosni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.001

has facts
may-addop Executable Script
may-modifyop Executable Script
may-modifyop System Configuration Database Record
is also defined as
class

Office Testni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.002

has facts
modifiesop System Configuration Database Record
is also defined as
class

One-time Passwordni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#One-timePassword

belongs to
Credential Hardeningc
has facts
authenticatesop User Account
d3fend-iddp "D3-OTP"
kb-referenceop Reference - RFC 2289 - A One-Time Password System
use-limitsop Password
is also defined as
class

Open Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OpenFile

has facts
accessesop File
is also defined as
class

Operating Systemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystem

has facts
containsop Kernel
containsop System Service Software
may-containop Operating System Configuration Component
is also defined as
class

Operating System Configurationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1028

belongs to
ATTACK Mitigationc
has facts
relatedop Platform Hardening

Operating System Monitoringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperatingSystemMonitoring

belongs to
Platform Monitoringc
has facts
d3fend-iddp "D3-OSM"
enablesop Detect
kb-referenceop Reference - Host intrusion prevention system using software and user behavior analysis - Sophos Ltd
kb-referenceop Reference - CAR-2016-04-002: User Activity from Clearing Event Logs - MITRE
is also defined as
class

Operational Activity Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperationalActivityMapping

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-OAM"
enablesop Model
kb-referenceop Reference - Catia UAF Plugin
is also defined as
class

Operational Dependency Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperationalDependencyMapping

belongs to
Operational Activity Mappingc
has facts
d3fend-iddp "D3-ODM"
kb-referenceop Reference - Catia UAF Plugin
kb-referenceop Reference - Cyber Command System (CYCS)
kb-referenceop Reference - Dagger Fact Sheet
kb-referenceop Reference - Dagger: Modeling and visualization for mission impact situational awareness
kb-referenceop Reference - Mission Dependency Modeling for Cyber Situational Awareness
kb-referenceop Reference - Unified Architecture Framework (UAF)
mapsop Dependency
mapsop Organizational Activity
is also defined as
class

Operational Risk Assessmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OperationalRiskAssessment

belongs to
Operational Activity Mappingc
has facts
d3fend-iddp "D3-ORA"
evaluatesop Organization
identifiesop vulnerability
kb-referenceop Reference - MGT516: Managing Security Vulnerabilities: Enterprise and Cloud
kb-referenceop Reference - NIST RMF Quick Start Guide - Assess Step - Frequently Asked Questions (FAQ)
kb-referenceop Reference - NIST Special Publication 800-160 Volume 1 - System Security Engineering
kb-referenceop Reference - NIST Special Publication 800-37 Revision 2 - Risk Management Framework for Information Systems and Organizations
kb-referenceop Reference - NIST Special Publication 800-53A Revision 5 - Assessing Security and Privacy Controls in Information Systems and Organizations
kb-referenceop Reference - NISTIR 8011 Volume 1 - Automation Support for Security Control Assessments
is also defined as
class

Orchestration Controllerni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OrchestrationController

has facts
containsop Container Orchestration Software
is also defined as
class

Organization Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OrganizationMapping

belongs to
Operational Activity Mappingc
has facts
d3fend-iddp "D3-OM"
kb-referenceop Reference - Catia UAF Plugin
kb-referenceop Reference - Organizational Management in SAP ERP HCM
kb-referenceop Reference - Unified Architecture Framework (UAF)
mapsop Dependency
mapsop Organization
mapsop Person
may-mapop Organizational Activity
is also defined as
class

OS Credential Dumpingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003

has facts
accessesop Credential
is also defined as
class

Out-of-bounds Readni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-125

has facts
weakness ofop Raw Memory Access Function
is also defined as
class

Out-of-bounds Writeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-787

has facts
weakness ofop Raw Memory Access Function
is also defined as
class

Outbound Internet DNS Lookup Trafficni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetDNSLookupTraffic

has facts
may-containop DNS Lookup
is also defined as
class

Outbound Internet File Transfer Trafficni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetFileTransferTraffic

has facts
containsop File
is also defined as
class

Outbound Internet Web Trafficni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundInternetWebTraffic

has facts
may-containop URL
is also defined as
class

Outbound Traffic Filteringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#OutboundTrafficFiltering

belongs to
Network Traffic Filteringc
has facts
d3fend-iddp "D3-OTF"
filtersop Outbound Network Traffic
kb-referenceop Reference - Automatically generating rules for connection security - Microsoft
is also defined as
class

Outlook Formsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.003

has facts
addsop Office Application File
is also defined as
class

Outlook Home Pageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.004

has facts
modifiesop Application Configuration Database
is also defined as
class

Outlook Rulesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1137.005

has facts
modifiesop Application Configuration Database
is also defined as
class

Packet Logni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PacketLog

has facts
recordsop Network Session
is also defined as
class

Page Frameni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PageFrame

has facts
contained-byop Primary Storage
is also defined as
class

Page Tableni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PageTable

has facts
containsop Physical Address
containsop Virtual Address
is also defined as
class

Parent PID Spoofingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.004

has facts
invokesop Create Process
is also defined as
class

Partition Tableni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PartitionTable

has facts
addressesop Partition
is also defined as
class

Pass The Hashni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550.002

has facts
createsop Authentication
is also defined as
class

Pass The Ticketni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550.003

has facts
createsop Authentication
is also defined as
class

Passive Certificate Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PassiveCertificateAnalysis

belongs to
Certificate Analysisc
Passive Certificate Analysisc
has facts
d3fend-iddp "D3-PCA"
kb-referenceop Reference - Certificate Transparency
kb-referenceop Reference - StreamingPhish
is also defined as
class

Passive Logical Link Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PassiveLogicalLinkMapping

belongs to
Logical Link Mappingc
has facts
d3fend-iddp "D3-PLLM"
kb-referenceop Reference - Tenable Passive Network Monitoring
is also defined as
class

Passive Physical Link Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PassivePhysicalLinkMapping

belongs to
Physical Link Mappingc
is disjoint with
Active Physical Link Mapping
has facts
d3fend-iddp "D3-PPLM"
is also defined as
class

Password Crackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1110.002

has facts
accessesop Password
is also defined as
class

Password Filter DLLni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1556.002

has facts
createsop Shared Library File
modifiesop System Configuration Database Record
is also defined as
class

Password Guessingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1110.001

has facts
accessesop Password
modifiesop Authentication Log
producesop Authentication
is also defined as
class

Password Policiesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1027

belongs to
ATTACK Mitigationc
has facts
relatedop One-time Password
relatedop Strong Password Policy

Password Sprayingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1110.003

has facts
accessesop Password
may-createop Intranet Administrative Network Traffic
modifiesop Authentication Log
producesop Authentication
is also defined as
class

Patentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Patent

belongs to
Reference Typec
is also defined as
class

Path Interception by PATH Environment Variableni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.007

has facts
createsop Executable File
is also defined as
class

Path Interception by Search Order Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.008

has facts
createsop Executable File
is also defined as
class

Path Interception by Unquoted Pathni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.009

has facts
createsop Executable File
is also defined as
class

PE32 Executable Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PE32ExecutableFile

belongs to
Executable Binaryc

PE32+ Executable Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PE32PLUSExecutableFile

belongs to
Executable Binaryc

Per Host Download-Upload Ratio Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PerHostDownload-UploadRatioAnalysis

belongs to
Network Traffic Analysisc
has facts
analyzesop Network Traffic
d3fend-iddp "D3-PHDURA"
kb-referenceop Reference - System for detecting threats using scenario-based tracking of internal and external network traffic - VECTRA NETWORKS Inc
is also defined as
class

Peripheral Firmware Verificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PeripheralFirmwareVerification

belongs to
Firmware Verificationc
has facts
d3fend-iddp "D3-PFV"
kb-referenceop Reference - Firmware Verification Eclypsium
kb-referenceop Reference - Firmware Verification Trapezoid
verifiesop Peripheral Firmware
is also defined as
class

Persistenceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Persistence

belongs to
Offensive Tacticc
is also defined as
class

Persistence Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PersistenceTechnique

has facts
enablesop Persistence
is also defined as
class

Physical Link Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PhysicalLinkMapping

belongs to
Network Mappingc
has facts
d3fend-iddp "D3-PLM"
kb-referenceop Reference - Libre NMS - Network Map Extension
mapsop Network Node
mapsop Physical Link
is also defined as
class

Platformni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Platform

has facts
containsop Firmware
containsop Hardware Device
containsop Operating System
is also defined as
class

Platform Hardeningni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PlatformHardening

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-PH"
enablesop Harden
is also defined as
class

Platform Monitoringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PlatformMonitoring

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-PM"
enablesop Detect
is also defined as
class

Plist Modificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.011

has facts
modifiesop Application Configuration File
is also defined as
class

Pluggable Authentication Modulesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1556.003

has facts
may-modifyop Operating System Configuration File
may-modifyop Operating System Shared Library File
is also defined as
class

Pointer Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PointerAuthentication

belongs to
Application Hardeningc
has facts
authenticatesop Pointer
d3fend-iddp "D3-PAN"
kb-referenceop Reference - Pointer Authentication on ARMv8.3
kb-referenceop Reference - Pointer Authentication Project Zero
is also defined as
class

Pointer Dereferencing Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PointerDereferencingFunction

has facts
addressesop Memory Block
addressesop Pointer
is also defined as
class

Port Knockingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1205.001

has facts
producesop Network Traffic
is also defined as
class

Port Monitorsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.010

has facts
modifiesop System Configuration Database Record
is also defined as
class

Portable Executable Injectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.002

has facts
may-addop Object File
is also defined as
class

PowerShell Profileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.013

has facts
modifiesop PowerShell Profile Script
is also defined as
class

Powershell Script Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PowershellScriptFile

belongs to
Executable Scriptc

Pre-compromiseni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1056

belongs to
ATTACK Mitigationc
has facts
relatedop Decoy Environment
relatedop Decoy Object

Primary Storageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PrimaryStorage

has facts
containsop Page Frame
containsop Process Segment
is also defined as
class

Private Keysni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552.004

has facts
accessesop Private Key
is also defined as
class

Privilege Escalationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PrivilegeEscalation

belongs to
Offensive Tacticc
is also defined as
class

Privilege Escalation Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#PrivilegeEscalationTechnique

has facts
enablesop Privilege Escalation
is also defined as
class

Privileged Account Managementni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1026

belongs to
ATTACK Mitigationc
has facts
relatedop Domain Account Monitoring
relatedop Local Account Monitoring
relatedop Strong Password Policy

Privileged Process Integrityni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1025

belongs to
ATTACK Mitigationc
has facts
relatedop Bootloader Authentication
relatedop Driver Load Integrity Checking
relatedop Mandatory Access Control
relatedop Process Segment Execution Prevention

Proc Filesystemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.007

has facts
accessesop Operating System File
accessesop Process Image
is also defined as
class

Proc Memoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.009

has facts
accessesop Operating System File
may-modifyop Operating System File
is also defined as
class

Procedure 1 - T1134.001 Access Token Manipulationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#procedure-1

belongs to
procedurec
has facts
implementsop Token Impersonation/Theft
startop Step 1 - Copy Token

Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Process

has facts
containsop Process Image
instructed-byop Software
may-executeop Thread
process-image-pathop Executable Binary
process-userop User Account
usesop Resource
is also defined as
class

Process Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessAnalysis

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-PA"
enablesop Detect
is also defined as
class

Process Code Segmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessCodeSegment

has facts
containsop Subroutine
may-containop Process Segment
is also defined as
class

Process Code Segment Verificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessCodeSegmentVerification

belongs to
Process Analysisc
has facts
d3fend-iddp "D3-PCSV"
kb-referenceop Reference - Anti-tamper system with self-adjusting guards - ARXAN TECHNOLOGIES Inc
kb-referenceop Reference - Guards for application in software tamperproofing - Purdue Research Foundation
kb-referenceop Reference - System and method for detecting malware injected into memory of a computing device - Endgame Inc
kb-referenceop Reference - System and method for validating in-memory integrity of executable files to identify malicious activity - Endgame Inc
kb-referenceop Reference - Tamper proof mutating software - ARXAN TECHNOLOGIES Inc
kb-referenceop Reference - Threat detection through the accumulated detection of threat characteristics - Sophos Ltd
verifiesop Process Code Segment
is also defined as
class

Process Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1057

has facts
may-invokeop Create Process
may-invokeop Get Running Processes
is also defined as
class

Process Doppelgängingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.013

has facts
invokesop Create Process
is also defined as
class

Process Evictionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessEviction

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-PE"
enablesop Evict
is also defined as
class

Process Hollowingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.012

has facts
modifiesop Process Code Segment
is also defined as
class

Process Imageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessImage

has facts
containsop Process Segment
is also defined as
class

Process Lineage Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessLineageAnalysis

belongs to
Process Spawn Analysisc
has facts
analyzesop Process
analyzesop Process Tree
d3fend-iddp "D3-PLA"
kb-referenceop Reference - CAR-2014-11-008: Command Launched from WinLogon - MITRE
kb-referenceop Reference - CAR-2014-11-003: Debuggers for Accessibility Applications - MITRE
kb-referenceop Reference - CAR-2019-04-002: Generic Regsvr32 - MITRE
kb-referenceop Reference - CAR-2014-11-002: Outlier Parents of Cmd - MITRE
kb-referenceop Reference - CAR-2013-02-003: Processes Spawning cmd.exe - MITRE
kb-referenceop Reference - CAR-2013-04-002: Quick execution of a series of suspicious commands - MITRE
kb-referenceop Reference - CAR-2013-03-001: Reg.exe called from Command Shell - MITRE
kb-referenceop Reference - CAR-2014-12-001: Remotely Launched Executables via WMI - MITRE
kb-referenceop Reference - CAR-2013-09-005: Service Outlier Executables - MITRE
kb-referenceop Reference - CAR-2014-07-001: Service Search Path Interception - MITRE
kb-referenceop Reference - CAR-2014-05-002: Services launching Cmd - MITRE
kb-referenceop Reference - System and methods thereof for causality identification and attributions determination of processes in a network - Palo Alto Networks IncCyber Secdo Ltd
kb-referenceop Reference - System and methods thereof for identification of suspicious system processes - Palo Alto Networks Inc
kb-referenceop Reference - CAR-2019-04-001: UAC Bypass - MITRE
kb-referenceop Reference - CAR-2020-11-002: Local Network Sniffing - MITRE
kb-referenceop Reference - CAR-2020-11-004: Processes Started From Irregular Parent - MITRE
kb-referenceop Reference - CAR-2021-02-002: Get System Elevation - MITRE
kb-referenceop Reference - CAR-2021-05-003: BCDEdit Failure Recovery Modification - MITRE
is also defined as
class

Process Segment Execution Preventionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessSegmentExecutionPrevention

belongs to
Application Hardeningc
has facts
d3fend-iddp "D3-PSEP"
kb-referenceop Reference - Mitigate threats by using Windows 10 security features: Data Execution Prevention - Microsoft
kb-referenceop Reference - What is NX/XD feature?
neutralizesop Process Segment
is also defined as
class

Process Self-Modification Detectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessSelf-ModificationDetection

belongs to
Process Analysisc
has facts
analyzesop Process
d3fend-iddp "D3-PSMD"
kb-referenceop Reference - System and Method for Process Hollowing Detection - Carbon Black Inc
is also defined as
class

Process Spawn Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessSpawnAnalysis

belongs to
Process Analysisc
has facts
analyzesop Create Process
analyzesop Process
d3fend-iddp "D3-PSA"
kb-referenceop Reference - CAR-2019-08-002: Active Directory Dumping via NTDSUtil - MITRE
kb-referenceop Reference - CAR-2013-07-005: Command Line Usage of Archiving Software - MITRE
kb-referenceop Reference - CAR-2016-03-002: Create Remote Process via WMIC - MITRE
kb-referenceop Reference - CAR-2019-04-004: Credential Dumping via Mimikatz - MITRE
kb-referenceop Reference - CAR-2016-03-001: Host Discovery Commands - MITRE
kb-referenceop Reference - CAR-2019-07-002: Lsass Process Dump via Procdump - MITRE
kb-referenceop Reference - CAR-2014-04-003: Powershell Execution - MITRE
kb-referenceop Reference - CAR-2014-03-006: RunDLL32.exe monitoring - MITRE
kb-referenceop Reference - CAR-2019-04-003: Squiblydoo - MITRE
kb-referenceop Reference - CAR-2013-07-001: Suspicious Arguments - MITRE
kb-referenceop Reference - CAR-2013-05-002: Suspicious Run Locations - MITRE
kb-referenceop Reference - CAR-2020-04-001: Shadow Copy Deletion - MITRE
kb-referenceop Reference - CAR-2020-05-003: Rare LolBAS Command Lines - MITRE
kb-referenceop Reference - CAR-2020-08-001: NTFS Alternate Data Stream Execution - System Utilities - MITRE
kb-referenceop Reference - CAR-2020-09-003: Indicator Blocking - Driver Unloaded - MITRE
kb-referenceop Reference - CAR-2020-09-004: Credentials in Files & Registry - MITRE
kb-referenceop Reference - CAR-2020-11-001: Boot or Logon Initialization Scripts - MITRE
kb-referenceop Reference - CAR-2020-11-003: DLL Injection with Mavinject - MITRE
kb-referenceop Reference - CAR-2020-11-005: Clear Powershell Console Command History - MITRE
kb-referenceop Reference - CAR-2020-11-006: Local Permission Group Discovery - MITRE
kb-referenceop Reference - CAR-2020-11-007: Network Share Connection Removal - MITRE
kb-referenceop Reference - CAR-2020-11-008: MSBuild and msxsl - MITRE
kb-referenceop Reference - CAR-2020-11-009: Compiled HTML Access - MITRE
kb-referenceop Reference - CAR-2021-01-002: Unusually Long Command Line Strings - MITRE
kb-referenceop Reference - CAR-2021-01-003: Clearing Windows Logs with Wevtutil - MITRE
kb-referenceop Reference - CAR-2021-01-004: Unusual Child Process for Spoolsv.Exe or Connhost.Exe - MITRE
kb-referenceop Reference - CAR-2021-01-006: Unusual Child Process spawned using DDE exploit - MITRE
kb-referenceop Reference - CAR-2021-01-007: Detecting Tampering of Windows Defender Command Prompt - MITRE
kb-referenceop Reference - CAR-2021-01-008: Disable UAC - MITRE
kb-referenceop Reference - CAR-2021-01-009: Detecting Shadow Copy Deletion via Vssadmin.exe - MITRE
kb-referenceop Reference - CAR-2021-02-001: Webshell-Indicative Process Tree - MITRE
kb-referenceop Reference - CAR-2021-04-001: Common Windows Process Masquerading - MITRE
kb-referenceop Reference - CAR-2021-05-001: Attempt To Add Certificate To Untrusted Store - MITRE
kb-referenceop Reference - CAR-2021-05-002: Batch File Write to System32 - MITRE
kb-referenceop Reference - CAR-2021-05-003: BCDEdit Failure Recovery Modification - MITRE
kb-referenceop Reference - CAR-2021-05-004: BITS Job Persistence - MITRE
kb-referenceop Reference - CAR-2021-05-005: BITSAdmin Download File - MITRE
kb-referenceop Reference - CAR-2021-05-006: CertUtil Download With URLCache and Split Arguments - MITRE
kb-referenceop Reference - CAR-2021-05-007: CertUtil Download With VerifyCtl and Split Arguments - MITRE
kb-referenceop Reference - CAR-2021-05-008: Certutil exe certificate extraction - MITRE
kb-referenceop Reference - CAR-2021-05-009: CertUtil With Decode Argument - MITRE
kb-referenceop Reference - CAR-2021-05-010: Create local admin accounts using net exe - MITRE
is also defined as
class

Process Start Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessStartFunction

has facts
invokesop Create Process
is also defined as
class

Process Suspensionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessSuspension

belongs to
Process Evictionc
has facts
d3fend-iddp "D3-PS"
kb-referenceop Reference - PsSuspend - Microsoft
suspendsop Process
is also defined as
class

Process Terminationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessTermination

belongs to
Process Evictionc
has facts
d3fend-iddp "D3-PT"
kb-referenceop Reference - Instant process termination tool to recover control of an information handling system - Dell Products LP
kb-referenceop Reference - Malware detection using local computational models - Crowdstrike Inc
terminatesop Process
is also defined as
class

Process Treeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessTree

has facts
containsop Process
is also defined as
class

Processor Cache Memoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CacheMemory

has facts
accessed-byop Central Processing Unit
may-containop Process Segment
modifiesop Processor Cache Memory
is also defined as
class

Processor Registerni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessorRegister

has facts
contained-byop Central Processing Unit
is also defined as
class

Protocol Metadata Anomaly Detectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ProtocolMetadataAnomalyDetection

belongs to
Network Traffic Analysisc
has facts
analyzesop Network Traffic
d3fend-iddp "D3-PMAD"
kb-referenceop Reference - Method and system for detecting threats using metadata vectors - VECTRA NETWORKS Inc
kb-referenceop Reference - Method and system for detecting threats using passive cluster mapping - Vectra Networks Inc
kb-referenceop Reference - System for implementing threat detection using daily network traffic community outliers - VECTRA NETWORKS Inc
is also defined as
class

Protocol Tunnelingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1572

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

Ptrace System Callsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.008

has facts
invokesop System Call
is also defined as
class

Query Registryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1012

has facts
accessesop System Configuration Database
may-invokeop Get System Config Value
is also defined as
class

RA-3(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_RA-3_3

belongs to
NIST Controlc
has facts
broaderop File Analysis
broaderop Identifier Analysis
broaderop Message Analysis
broaderop Network Traffic Analysis
broaderop Platform Monitoring
broaderop Process Analysis
broaderop User Behavior Analysis
control-namedp "Risk Assessment | Dynamic Threat Awareness"
member-ofop NIST SP 800-53 R5

RA-3(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_RA-3_4

belongs to
NIST Controlc
has facts
control-namedp "Risk Assessment | Predictive Cyber Analytics"
member-ofop NIST SP 800-53 R5
narrowerop File Analysis
narrowerop Identifier Analysis
narrowerop Message Analysis
narrowerop Network Traffic Analysis
narrowerop Platform Monitoring
narrowerop Process Analysis
narrowerop User Behavior Analysis

RA-5ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_RA-5

belongs to
NIST Controlc
has facts
broaderop Network Traffic Analysis
control-namedp "Vulnerability Monitoring and Scanning"
member-ofop NIST SP 800-53 R5

RA-5(2)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_RA-5_2

belongs to
NIST Controlc
has facts
control-namedp "Vulnerability Monitoring and Scanning | Update Vulnerabilities to Be Scanned"
member-ofop NIST SP 800-53 R5
narrowerop Network Traffic Analysis

RA-5(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_RA-5_3

belongs to
NIST Controlc
has facts
control-namedp "Vulnerability Monitoring and Scanning | Breadth and Depth of Coverage"
member-ofop NIST SP 800-53 R5
narrowerop Network Traffic Analysis

RA-5(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_RA-5_4

belongs to
NIST Controlc
has facts
control-namedp "Vulnerability Monitoring and Scanning | Discoverable Information"
member-ofop NIST SP 800-53 R5
relatedop Decoy Environment
relatedop Decoy Object

RA-5(5)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_RA-5_5

belongs to
NIST Controlc
has facts
control-namedp "Vulnerability Monitoring and Scanning | Privileged Access"
member-ofop NIST SP 800-53 R5
narrowerop Platform Hardening

RA-5(6)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_RA-5_6

belongs to
NIST Controlc
has facts
control-namedp "Vulnerability Monitoring and Scanning | Automated Trend Analyses"
member-ofop NIST SP 800-53 R5
narrowerop Platform Hardening

RA-5(7)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_RA-5_7

belongs to
NIST Controlc
has facts
control-namedp "Vulnerability Monitoring and Scanning | Automated Detection and Notification of Unauthorized Components"
member-ofop NIST SP 800-53 R5
narrowerop Executable Allowlisting
narrowerop Executable Denylisting

Raw Memory Access Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RawMemoryAccessFunction

has facts
accessesop Memory Block
is also defined as
class

Rc.commonni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.004

has facts
modifiesop System Init Script
is also defined as
class

RDP Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1563.002

has facts
accessesop RDP Session
is also defined as
class

Re-opened Applicationsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.007

has facts
modifiesop Application Configuration File
is also defined as
class

Read Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReadFile

has facts
readsop File
is also defined as
class

real-time-analyticni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#real-time-analytic

belongs to
Analytic Latencyc

real-time-evictionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#real-time-eviction

belongs to
Eviction Latencyc

Reconnaissance Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReconnaissanceTechnique

has facts
enablesop reconnaissance
is also defined as
class

Reference - /DYNAMICBASE (Use address space layout randomization) - Microsoft Docsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DYNAMICBASE_UseAddressSpaceLayoutRandomization_MicrosoftDocs

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/cpp/build/reference/dynamicbase-use-address-space-layout-randomization?view=vs-2019"^^any u r i
kb-reference-ofop Segment Address Offset Randomization
kb-reference-titledp "/DYNAMICBASE (Use address space layout randomization)"

Reference - /GS (Buffer Security Check) - Microsoft Docsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-GS_BufferSecurityCheck_MicrosoftDocs

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/cpp/build/reference/gs-buffer-security-check?view=vs-2019"^^any u r i
kb-reference-ofop Stack Frame Canary Validation
kb-reference-titledp "/GS (Buffer Security Check)"

Reference - /SAFESEH (Image has Safe Exception Handlers) - Microsoft Docsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SAFESEH_ImageHasSafeExceptionHandlers_MicrosoftDocs

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/cpp/build/reference/safeseh-image-has-safe-exception-handlers?view=msvc-160"^^any u r i
kb-reference-ofop Exception Handler Pointer Validation
kb-reference-titledp "/SAFESEH (Image has Safe Exception Handlers)"

Reference - Account monitoring - Forescout Technologiesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AccountMonitoring_ForescoutTechnologies

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190205511A1"^^any u r i
kb-reference-ofop Account Locking
kb-reference-titledp "Account monitoring"

Reference - Active firewall system and methodology - McAfee LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ActiveFirewallSystemAndMethodology_McAfeeLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US6550012B1"^^any u r i
kb-reference-ofop Inbound Traffic Filtering
kb-reference-titledp "Active firewall system and methodology"

Reference - Advanced device matching systemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AdvancedDeviceMatchingSystem

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10892951B2/"^^any u r i
kb-reference-ofop Hardware Component Inventory
kb-reference-titledp "Advanced device matching system"

Reference - An Architecture for Describing Simple Network Management Protocol (SNMP) Management Frameworksni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RFC3411-AnArchitectureForDescribingSimpleNetworkManagementProtocolSNMPManagementFrameworks

belongs to
Specification Referencec
has facts
has-linkdp "https://https://datatracker.ietf.org/doc/html/rfc3411"^^any u r i
kb-reference-ofop Hardware Component Inventory
kb-reference-titledp "An Architecture for Describing Simple Network Management Protocol (SNMP) Management Frameworks"

Reference - Analysis of the Windows Vista Security Model - Symantec Corporationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AnalysisOfTheWindowsVistaSecurityModel_SymantecCorporation

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://web.archive.org/web/20140407025337/http://www.symantec.com/avcenter/reference/Windows_Vista_Security_Model_Analysis.pdf"^^any u r i
kb-reference-ofop Mandatory Access Control
kb-reference-titledp "Analysis of the Windows Vista Security Model"

Reference - Anomaly Detection Using Adaptive Behavioral Profiles - Securonix Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AnomalyDetectionUsingAdaptiveBehavioralProfiles_SecuronixInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160226901A1"^^any u r i
kb-reference-ofop Job Function Access Pattern Analysis
kb-reference-titledp "Anomaly Detection Using Adaptive Behavioral Profiles"

Reference - Anti-tamper system with self-adjusting guards - ARXAN TECHNOLOGIES Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Anti-tamperSystemWithSelf-adjustingGuards_ARXANTECHNOLOGIESInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20150052603A1"^^any u r i
kb-reference-ofop Process Code Segment Verification
kb-reference-titledp "Anti-tamper system with self-adjusting guards"

Reference - Apparatus for to provide content to and query a reverse domain name system server - Barrracuda Networksni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ApparatusForToProvideContentToAndQueryAReverseDomainNameSystemServer

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20100174829A1/en?oq=20100174829"^^any u r i
kb-reference-ofop Reverse Resolution Domain Denylisting
kb-reference-titledp "Apparatus for to provide content to and query a reverse domain name system server"

Reference - Approaches for securing an internet endpoint using fine-grained operating system virtualization - Bromium, Inc.ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ApproachesForSecuringAnInternetEndpointUsingFine-grainedOperatingSystemVirtualization_Bromium,Inc.

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20110296412A1"^^any u r i
kb-reference-ofop Hardware-based Process Isolation
kb-reference-titledp "Approaches for securing an internet endpoint using fine-grained operating system virtualization"

Reference - Architecture of transparent network security for application containers - Neuvector Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ArchitectureOfTransparentNetworkSecurityForApplicationContainers_NeuvectorInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170093922A1"^^any u r i
kb-reference-ofop Mandatory Access Control
kb-reference-titledp "Architecture of transparent network security for application containers"

Reference - Audit User Account Managementni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AuditUserAccountManagement

belongs to
Guideline Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-user-account-management"^^any u r i
kb-reference-ofop Domain Account Monitoring
kb-reference-ofop Local Account Monitoring
kb-reference-titledp "Audit User Account Management"

Reference - Automated computer vulnerability resolution systemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AutomatedComputerVulnerabilityResolutionSystem

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US7308712B2"^^any u r i
kb-reference-ofop Asset Vulnerability Enumeration
kb-reference-titledp "Automated computer vulnerability resolution system"

Reference - Automatically generating network resource groups and assigning customized decoy policies thereto - Illusive Networks Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AutomaticallyGeneratingNetworkResourceGroupsAndAssigningCustomizedDecoyPoliciesThereto_IllusiveNetworksLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170310689A1"^^any u r i
kb-reference-ofop Decoy Network Resource
kb-reference-titledp "Automatically generating network resource groups and assigning customized decoy policies thereto"

Reference - Automatically generating rules for connection security - Microsoftni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AutomaticallyGeneratingRulesForConnectionSecurity_Microsoft

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20120054825"^^any u r i
kb-reference-ofop Inbound Traffic Filtering
kb-reference-ofop Outbound Traffic Filtering
kb-reference-titledp "Automatically generating rules for connection security"

Reference - Biometric Challenge-Response Authentication - Accentureni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-BiometricChallenge-ResponseAuthentication-Accenture

belongs to
Patent Referencec
has facts
has-linkdp "https://www.patentguru.com/US2021110015A1"^^any u r i
kb-reference-ofop Multi-factor Authentication
kb-reference-titledp "Biometric Challenge-Response Authentication"

Reference - Broadcast isolation and level 3 network switch - Hewlett Packard Enterprise Development LPni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-BroadcastIsolationAndLevel3NetworkSwitch_HewlettPackardEnterpriseDevelopmentLP

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US5920699A"^^any u r i
kb-reference-ofop Broadcast Domain Isolation
kb-reference-titledp "Broadcast isolation and level 3 network switch"

Reference - CAR-2013-01-002: Autorun Differences - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AutorunDifferences_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-01-002/"^^any u r i
kb-reference-ofop System File Analysis
kb-reference-titledp "CAR-2013-01-002: Autorun Differences"

Reference - CAR-2013-01-003: SMB Events Monitoring - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SMBEventsMonitoring_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-01-003/"^^any u r i
kb-reference-ofop IPC Traffic Analysis
kb-reference-titledp "CAR-2013-01-003: SMB Events Monitoring"

Reference - CAR-2013-02-003: Processes Spawning cmd.exe - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ProcessesSpawningCmd.exe_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-02-003/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2013-02-003: Processes Spawning cmd.exe"

Reference - CAR-2013-02-008: Simultaneous Logins on a Host - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SimultaneousLoginsOnAHost_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-02-008/"^^any u r i
kb-reference-ofop Authentication Event Thresholding
kb-reference-titledp "CAR-2013-02-008: Simultaneous Logins on a Host"

Reference - CAR-2013-02-012: User Logged in to Multiple Hosts - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UserLoggedInToMultipleHosts_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-02-012/"^^any u r i
kb-reference-ofop Authentication Event Thresholding
kb-reference-ofop Authorization Event Thresholding
kb-reference-titledp "CAR-2013-02-012: User Logged in to Multiple Hosts"

Reference - CAR-2013-03-001: Reg.exe called from Command Shell - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Reg.exeCalledFromCommandShell_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-03-001/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2013-03-001: Reg.exe called from Command Shell"

Reference - CAR-2013-04-002: Quick execution of a series of suspicious commands - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-QuickExecutionOfASeriesOfSuspiciousCommands_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-04-002/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2013-04-002: Quick execution of a series of suspicious commands"

Reference - CAR-2013-05-002: Suspicious Run Locations - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SuspiciousRunLocations_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-05-002/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2013-05-002: Suspicious Run Locations"

Reference - CAR-2013-05-003: SMB Write Request - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SMBWriteRequest_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-05-003/"^^any u r i
kb-reference-ofop IPC Traffic Analysis
kb-reference-titledp "CAR-2013-05-003: SMB Write Request"

Reference - CAR-2013-05-004: Execution with AT - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ExecutionWithAT_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-05-004/"^^any u r i
kb-reference-ofop Scheduled Job Analysis
kb-reference-titledp "CAR-2013-05-004: Execution with AT"

Reference - CAR-2013-05-005: SMB Copy and Execution - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SMBCopyAndExecution_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-05-005/"^^any u r i
kb-reference-ofop IPC Traffic Analysis
kb-reference-titledp "CAR-2013-05-005: SMB Copy and Execution"

Reference - CAR-2013-07-001: Suspicious Arguments - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SuspiciousArguments_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-07-001/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2013-07-001: Suspicious Arguments"

Reference - CAR-2013-07-002: RDP Connection Detection - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RDPConnectionDetection_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-07-002"^^any u r i
kb-reference-ofop Remote Terminal Session Detection
kb-reference-titledp "CAR-2013-07-002: RDP Connection Detection"

Reference - CAR-2013-07-005: Command Line Usage of Archiving Software - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CommandLineUsageOfArchivingSoftware_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-07-005/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2013-07-005: Command Line Usage of Archiving Software"

Reference - CAR-2013-08-001: Execution with schtasks - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ExecutionWithSchtasks_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-08-001/"^^any u r i
kb-reference-ofop Scheduled Job Analysis
kb-reference-titledp "CAR-2013-08-001: Execution with schtasks"

Reference - CAR-2013-09-003: SMB Session Setups - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SMBSessionSetups_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-09-003/"^^any u r i
kb-reference-ofop Authorization Event Thresholding
kb-reference-ofop IPC Traffic Analysis
kb-reference-titledp "CAR-2013-09-003: SMB Session Setups"

Reference - CAR-2013-09-005: Service Outlier Executables - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ServiceOutlierExecutables_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-09-005/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2013-09-005: Service Outlier Executables"

Reference - CAR-2013-10-001: User Login Activity Monitoring - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UserLoginActivityMonitoring_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-10-001/"^^any u r i
kb-reference-ofop Authentication Event Thresholding
kb-reference-titledp "CAR-2013-10-001: User Login Activity Monitoring"

Reference - CAR-2013-10-002: DLL Injection via Load Library - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DLLInjectionViaLoadLibrary_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2013-10-002/"^^any u r i
kb-reference-ofop System Call Analysis
kb-reference-titledp "CAR-2013-10-002: DLL Injection via Load Library"

Reference - CAR-2014-02-001: Service Binary Modifications - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ServiceBinaryModifications_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-02-001/"^^any u r i
kb-reference-ofop Service Binary Verification
kb-reference-titledp "CAR-2014-02-001: Service Binary Modifications"

Reference - CAR-2014-03-001: SMB Write Request - NamedPipes - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SMBWriteRequest-NamedPipes_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-03-001/"^^any u r i
kb-reference-ofop IPC Traffic Analysis
kb-reference-ofop RPC Traffic Analysis
kb-reference-titledp "CAR-2014-03-001: SMB Write Request - NamedPipes"

Reference - CAR-2014-03-005: Remotely Launched Executables via Services - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RemotelyLaunchedExecutablesViaServices_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-03-005/"^^any u r i
kb-reference-ofop RPC Traffic Analysis
kb-reference-titledp "CAR-2014-03-005: Remotely Launched Executables via Services"

Reference - CAR-2014-03-006: RunDLL32.exe monitoring - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RunDLL32.exeMonitoring_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-03-006/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2014-03-006: RunDLL32.exe monitoring"

Reference - CAR-2014-04-003: Powershell Execution - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PowershellExecution_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-04-003/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2014-04-003: Powershell Execution"

Reference - CAR-2014-05-001: RPC Activity - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2014-05-001%3ARPCActivity_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-05-001/"^^any u r i
kb-reference-ofop RPC Traffic Analysis
kb-reference-titledp "CAR-2014-05-001: RPC Activity"

Reference - CAR-2014-05-002: Services launching Cmd - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ServicesLaunchingCmd_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp ""^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2014-05-002: Services launching Cmd"

Reference - CAR-2014-07-001: Service Search Path Interception - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ServiceSearchPathInterception_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-07-001/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2014-07-001: Service Search Path Interception"

Reference - CAR-2014-11-002: Outlier Parents of Cmd - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-OutlierParentsOfCmd_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-11-002/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2014-11-002: Outlier Parents of Cmd"

Reference - CAR-2014-11-003: Debuggers for Accessibility Applications - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DebuggersForAccessibilityApplications_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-11-006/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2014-11-003: Debuggers for Accessibility Applications"

Reference - CAR-2014-11-005: Remote Registry - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RemoteRegistry_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-11-005/"^^any u r i
kb-reference-ofop Administrative Network Activity Analysis
kb-reference-titledp "CAR-2014-11-005: Remote Registry"

Reference - CAR-2014-11-006: Windows Remote Management (WinRM) - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-WindowsRemoteManagement_WinRM_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp ""^^any u r i
kb-reference-ofop Administrative Network Activity Analysis
kb-reference-titledp "CAR-2014-11-006: Windows Remote Management (WinRM)"

Reference - CAR-2014-11-007: Remote Windows Management Instrumentation (WMI) over RPC - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2014-11-007-RemoteWindowsManagementInstrumentation_WMI_OverRPC_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp ""^^any u r i
kb-reference-ofop RPC Traffic Analysis
kb-reference-titledp "CAR-2014-11-007: Remote Windows Management Instrumentation (WMI) over RPC"

Reference - CAR-2014-11-008: Command Launched from WinLogon - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CommandLaunchedFromWinLogon_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-11-008/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2014-11-008: Command Launched from WinLogon"

Reference - CAR-2014-12-001: Remotely Launched Executables via WMI - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RemotelyLaunchedExecutablesViaWMI_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2014-12-001/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-ofop RPC Traffic Analysis
kb-reference-titledp "CAR-2014-12-001: Remotely Launched Executables via WMI"

Reference - CAR-2015-04-001: Remotely Scheduled Tasks via AT - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2015-04-001%3ARemotelyScheduledTasksViaAT_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2015-04-001/"^^any u r i
kb-reference-ofop IPC Traffic Analysis
kb-reference-titledp "CAR-2015-04-001: Remotely Scheduled Tasks via AT"

Reference - CAR-2015-04-002: Remotely Scheduled Tasks via Schtasks - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RemotelyScheduledTasksViaSchtasks_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2015-04-002/"^^any u r i
kb-reference-ofop RPC Traffic Analysis
kb-reference-titledp "CAR-2015-04-002: Remotely Scheduled Tasks via Schtasks"

Reference - CAR-2015-07-001: All Logins Since Last Boot - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AllLoginsSinceLastBoot_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2015-07-001/"^^any u r i
kb-reference-ofop Credential Compromise Scope Analysis
kb-reference-titledp "CAR-2015-07-001: All Logins Since Last Boot"

Reference - CAR-2016-03-001: Host Discovery Commands - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-HostDiscoveryCommands_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2016-03-001/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2016-03-001: Host Discovery Commands"

Reference - CAR-2016-03-002: Create Remote Process via WMIC - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CreateRemoteProcessViaWMIC_MITRE_Other

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2016-03-002/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-ofop RPC Traffic Analysis
kb-reference-titledp "CAR-2016-03-002: Create Remote Process via WMIC"

Reference - CAR-2016-04-002: User Activity from Clearing Event Logs - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UserActivityFromClearingEventLogs_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2016-04-002/"^^any u r i
kb-reference-ofop System File Analysis
kb-reference-titledp "CAR-2016-04-002: User Activity from Clearing Event Logs"

Reference - CAR-2016-04-003: User Activity from Stopping Windows Defensive Services - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UserActivityFromStoppingWindowsDefensiveServices_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2016-04-003/"^^any u r i
kb-reference-ofop System Daemon Monitoring
kb-reference-titledp "CAR-2016-04-003: User Activity from Stopping Windows Defensive Services"

Reference - CAR-2016-04-004: Successful Local Account Loginni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2016-04-004_SuccessfulLocalAccountLogin

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2016-04-004/"^^any u r i
kb-reference-ofop Local Account Monitoring
kb-reference-titledp "Reference - CAR-2016-04-004: Successful Local Account Login"

Reference - CAR-2016-04-005: Remote Desktop Logon - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RemoteDesktopLogon_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2016-04-005/"^^any u r i
kb-reference-ofop Remote Terminal Session Detection
kb-reference-titledp "CAR-2016-04-005: Remote Desktop Logon"

Reference - CAR-2019-04-001: UAC Bypass - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UACBypass_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2019-04-001/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2019-04-001: UAC Bypass"

Reference - CAR-2019-04-002: Generic Regsvr32 - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-GenericRegsvr32_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2019-04-002/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2019-04-002: Generic Regsvr32"

Reference - CAR-2019-04-003: Squiblydoo - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Squiblydoo_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2019-04-003/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2019-04-003: Squiblydoo"

Reference - CAR-2019-04-004: Credential Dumping via Mimikatz - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CredentialDumpingViaMimikatz_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2019-04-004/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2019-04-004: Credential Dumping via Mimikatz"

Reference - CAR-2019-07-001: Access Permission Modification - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-AccessPermissionModification_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2019-07-001/"^^any u r i
kb-reference-ofop System File Analysis
kb-reference-titledp "CAR-2019-07-001: Access Permission Modification"

Reference - CAR-2019-07-002: Lsass Process Dump via Procdump - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-LsassProcessDumpViaProcdump_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2019-07-002/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2019-07-002: Lsass Process Dump via Procdump"

Reference - CAR-2019-08-001: Credential Dumping via Windows Task Manager - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CredentialDumpingViaWindowsTaskManager_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2019-08-001/"^^any u r i
kb-reference-ofop System Call Analysis
kb-reference-titledp "CAR-2019-08-001: Credential Dumping via Windows Task Manager"

Reference - CAR-2019-08-002: Active Directory Dumping via NTDSUtil - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ActiveDirectoryDumpingViaNTDSUtil_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2019-08-002/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2019-08-002: Active Directory Dumping via NTDSUtil"

Reference - CAR-2020-04-001: Shadow Copy Deletion - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-04-001%3AShadowCopyDeletion_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-04-001/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-04-001: Shadow Copy Deletion"

Reference - CAR-2020-05-001: MiniDump of LSASS - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-05-001%3AMiniDumpOfLSASS_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-05-001/"^^any u r i
kb-reference-ofop System Call Analysis
kb-reference-titledp "CAR-2020-05-001: MiniDump of LSASS"

Reference - CAR-2020-05-003: Rare LolBAS Command Lines - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-05-003%3ARareLolBASCommandLines_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-05-003/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-05-003: Rare LolBAS Command Lines"

Reference - CAR-2020-08-001: NTFS Alternate Data Stream Execution - System Utilities - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-08-001%3ANTFSAlternateDataStreamExecution-SystemUtilities_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-08-001/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-08-001: NTFS Alternate Data Stream Execution - System Utilities"

Reference - CAR-2020-09-001: Scheduled Task - FileAccess - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-09-001%3AScheduledTask-FileAccess_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-09-001/"^^any u r i
kb-reference-ofop File Creation Analysis
kb-reference-titledp "CAR-2020-09-001: Scheduled Task - FileAccess"

Reference - CAR-2020-09-002: Component Object Model Hijacking - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-09-002%3AComponentObjectModelHijacking_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-09-002/"^^any u r i
kb-reference-ofop User Session Init Config Analysis
kb-reference-titledp "CAR-2020-09-002: Component Object Model Hijacking"

Reference - CAR-2020-09-003: Indicator Blocking - Driver Unloaded - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-09-003%3AIndicatorBlocking-DriverUnloaded_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-09-003/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-09-003: Indicator Blocking - Driver Unloaded"

Reference - CAR-2020-09-004: Credentials in Files & Registry - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-09-004%3ACredentialsInFiles%26Registry_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-09-004/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-09-004: Credentials in Files & Registry"

Reference - CAR-2020-09-005: AppInit DLLs - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-09-005%3AAppInitDLLs_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-09-005/"^^any u r i
kb-reference-ofop System Init Config Analysis
kb-reference-titledp "CAR-2020-09-005: AppInit DLLs"

Reference - CAR-2020-11-001: Boot or Logon Initialization Scripts - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-001%3ABootOrLogonInitializationScripts_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-001/"^^any u r i
kb-reference-ofop System Init Config Analysis
kb-reference-titledp "CAR-2020-11-001: Boot or Logon Initialization Scripts"

Reference - CAR-2020-11-002: Local Network Sniffing - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-002%3ALocalNetworkSniffing_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-002/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2020-11-002: Local Network Sniffing"

Reference - CAR-2020-11-003: DLL Injection with Mavinject - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-003%3ADLLInjectionWithMavinject_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-003/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-11-003: DLL Injection with Mavinject"

Reference - CAR-2020-11-004: Processes Started From Irregular Parent - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-004%3AProcessesStartedFromIrregularParent_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-004/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2020-11-004: Processes Started From Irregular Parent"

Reference - CAR-2020-11-005: Clear Powershell Console Command History - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-005%3AClearPowershellConsoleCommandHistory_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-005/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-11-005: Clear Powershell Console Command History"

Reference - CAR-2020-11-006: Local Permission Group Discovery - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-006%3ALocalPermissionGroupDiscovery_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-006/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-11-006: Local Permission Group Discovery"

Reference - CAR-2020-11-007: Network Share Connection Removal - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-007%3ANetworkShareConnectionRemoval_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-007/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-11-007: Network Share Connection Removal"

Reference - CAR-2020-11-008: MSBuild and msxsl - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-008%3AMSBuildAndMsxsl_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-008/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-11-008: MSBuild and msxsl"

Reference - CAR-2020-11-009: Compiled HTML Access - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-009%3ACompiledHTMLAccess_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-009/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-11-009: Compiled HTML Access"

Reference - CAR-2020-11-010: CMSTP - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-010%3ACMSTP_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-010/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2020-11-010: CMSTP"

Reference - CAR-2020-11-011: Registry Edit from Screensaverni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2020-11-011%3ARegistryEditFromScreensaver

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2020-11-011/"^^any u r i
kb-reference-ofop User Session Init Config Analysis
kb-reference-titledp "CAR-2020-11-011: Registry Edit from Screensaver"

Reference - CAR-2021-01-002: Unusually Long Command Line Strings - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-01-002%3AUnusuallyLongCommandLineStrings_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-01-002/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-01-002: Unusually Long Command Line Strings"

Reference - CAR-2021-01-003: Clearing Windows Logs with Wevtutil - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-01-003%3AClearingWindowsLogsWithWevtutil_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-01-003/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-01-003: Clearing Windows Logs with Wevtutil"

Reference - CAR-2021-01-004: Unusual Child Process for Spoolsv.Exe or Connhost.Exe - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-01-004%3AUnusualChildProcessForSpoolsv.ExeOrConnhost.Exe_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-01-004/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-01-004: Unusual Child Process for Spoolsv.Exe or Connhost.Exe"

Reference - CAR-2021-01-006: Unusual Child Process spawned using DDE exploit - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-01-006%3AUnusualChildProcessSpawnedUsingDDEExploit_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-01-006/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-01-006: Unusual Child Process spawned using DDE exploit"

Reference - CAR-2021-01-007: Detecting Tampering of Windows Defender Command Prompt - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-01-007%3ADetectingTamperingOfWindowsDefenderCommandPrompt_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-01-007/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-01-007: Detecting Tampering of Windows Defender Command Prompt"

Reference - CAR-2021-01-008: Disable UAC - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-01-008%3ADisableUAC_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-01-008/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-01-008: Disable UAC"

Reference - CAR-2021-01-009: Detecting Shadow Copy Deletion via Vssadmin.exe - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-01-009%3ADetectingShadowCopyDeletionViaVssadmin.exe_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-01-009/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-01-009: Detecting Shadow Copy Deletion via Vssadmin.exe"

Reference - CAR-2021-02-001: Webshell-Indicative Process Tree - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-02-001%3AWebshell-IndicativeProcessTree_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-02-001/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-02-001: Webshell-Indicative Process Tree"

Reference - CAR-2021-02-002: Get System Elevation - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-02-002%3AGetSystemElevation_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-02-002/"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "CAR-2021-02-002: Get System Elevation"

Reference - CAR-2021-04-001: Common Windows Process Masquerading - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-04-001%3ACommonWindowsProcessMasquerading_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-04-001/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-04-001: Common Windows Process Masquerading"

Reference - CAR-2021-05-001: Attempt To Add Certificate To Untrusted Store - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-001%3AAttemptToAddCertificateToUntrustedStore_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-001/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-001: Attempt To Add Certificate To Untrusted Store"

Reference - CAR-2021-05-002: Batch File Write to System32 - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-002%3ABatchFileWriteToSystem32_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-002/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-002: Batch File Write to System32"

Reference - CAR-2021-05-003: BCDEdit Failure Recovery Modification - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-003%3ABCDEditFailureRecoveryModification_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-003/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-003: BCDEdit Failure Recovery Modification"

Reference - CAR-2021-05-004: BITS Job Persistence - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-004%3ABITSJobPersistence_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-004/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-004: BITS Job Persistence"

Reference - CAR-2021-05-005: BITSAdmin Download File - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-005%3ABITSAdminDownloadFile_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-005/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-005: BITSAdmin Download File"

Reference - CAR-2021-05-006: CertUtil Download With URLCache and Split Arguments - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-006%3ACertUtilDownloadWithURLCacheAndSplitArguments_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-006/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-006: CertUtil Download With URLCache and Split Arguments"

Reference - CAR-2021-05-007: CertUtil Download With VerifyCtl and Split Arguments - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-007%3ACertUtilDownloadWithVerifyCtlAndSplitArguments_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-007/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-007: CertUtil Download With VerifyCtl and Split Arguments"

Reference - CAR-2021-05-008: Certutil exe certificate extraction - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-008%3ACertutilExeCertificateExtraction_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-008/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-008: Certutil exe certificate extraction"

Reference - CAR-2021-05-009: CertUtil With Decode Argument - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-009%3ACertUtilWithDecodeArgument_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-009/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-009: CertUtil With Decode Argument"

Reference - CAR-2021-05-010: Create local admin accounts using net exe - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-010%3ACreateLocalAdminAccountsUsingNetExe_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-010/"^^any u r i
kb-reference-ofop Process Spawn Analysis
kb-reference-titledp "CAR-2021-05-010: Create local admin accounts using net exe"

Reference - CAR-2021-05-011: Create Remote Thread into LSASS - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CAR-2021-05-011%3ACreateRemoteThreadIntoLSASS_MITRE

belongs to
External Knowledge Basec
has facts
has-linkdp "https://car.mitre.org/analytics/CAR-2021-05-011/"^^any u r i
kb-reference-ofop System Call Analysis
kb-reference-titledp "CAR-2021-05-011: Create Remote Thread into LSASS"

Reference - Catia UAF Pluginni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CatiaUAFPlugin

belongs to
Internet Article Referencec
has facts
has-linkdp "https://www.3ds.com/products-services/catia/products/no-magic/addons/uaf-plugin/"^^any u r i
kb-reference-ofop Data Exchange Mapping
kb-reference-ofop Operational Activity Mapping
kb-reference-ofop Operational Dependency Mapping
kb-reference-ofop Organization Mapping
kb-reference-ofop Service Dependency Mapping
kb-reference-ofop System Dependency Mapping
kb-reference-titledp "Catia UAF Plugin"

Reference - Certificate and Public Key Pinningni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CertificateAndPublicKeyPinning

belongs to
Technique Referencec
has facts
has-linkdp "https://owasp.org/www-community/controls/Certificate_and_Public_Key_Pinning"^^any u r i
kb-reference-ofop Certificate Pinning
kb-reference-titledp "Certificate and Public Key Pinning"

Reference - Certificate Transparencyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CertificateTransparency

belongs to
Technique Referencec
has facts
has-linkdp "https://www.certificate-transparency.org/"^^any u r i
kb-reference-ofop Passive Certificate Analysis
kb-reference-titledp "Certificate Transparency"

Reference - Cisco ASR 9000 Series Aggregation Services Routers - Access List Commandsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CiscoASR9000AccessListCommands

belongs to
User Manual Referencec
has facts
has-linkdp "https://www.cisco.com/c/en/us/td/docs/routers/asr9000/software/asr9k_r4-0/addr_serv/command/reference/ir40asrbook_chapter1.html"^^any u r i
kb-reference-ofop Network Traffic Policy Mapping
kb-reference-titledp "Cisco ASR 9000 Series Aggregation Services Routers - Access List Commands"

Reference - Computational modeling and classification of data streams - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ComputationalModelingAndClassificationOfDataStreams_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20180197089A1/en?oq=US-2018197089-A1"^^any u r i
kb-reference-ofop File Content Rules
kb-reference-titledp "Computational modeling and classification of data streams"

Reference - Computer motherboard having peripheral security functionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ComputerMotherboardHavingPeripheralSecurityFunctions

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8869308B2/en"^^any u r i
kb-reference-ofop IO Port Restriction
kb-reference-titledp "Computer motherboard having peripheral security functions"

Reference - Computer Worm Defense System and Method - FireEye Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ComputerWormDefenseSystemAndMethod_FireEyeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20130036472A1"^^any u r i
kb-reference-ofop File Carving
kb-reference-titledp "Computer Worm Defense System and Method"

Reference - Computer-implemented methods and systems for identifying visually similar text character strings - Greathorn Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Computer-implementedMethodsAndSystemsForIdentifyingVisuallySimilarTextCharacterStrings_GreathornInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10320815B2/en?oq=US-10320815-B2"^^any u r i
kb-reference-ofop Homoglyph Detection
kb-reference-titledp "Computer-implemented methods and systems for identifying visually similar text character strings"

Reference - Computing apparatus with automatic integrity reference generation and maintenance - Tripwire, Inc.ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ComputingApparatusWithAutomaticIntegrityReferenceGenerationAndMaintenance_Tripwire,Inc.

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20040060046A1"^^any u r i
kb-reference-ofop Executable Allowlisting
kb-reference-titledp "Computing apparatus with automatic integrity reference generation and maintenance"

Reference - Configure User Access Control and Permissionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ConfigureUserAccessControlAndPermissions

belongs to
Internet Article Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/windows-server/manage/windows-admin-center/configure/user-access-control"^^any u r i
kb-reference-ofop User Account Permissions
kb-reference-titledp "Configure User Access Control and Permissions"

Reference - Content extractor and analysis system - Bit 9 Inc, Carbon Black Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ContentExtractorAndAnalysisSystem_Bit9Inc,CarbonBlackInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20070028110A1"^^any u r i
kb-reference-ofop Executable Denylisting
kb-reference-titledp "Content extractor and analysis system"

Reference - Continuous authentication by analysis of keyboard typing characteristics - Bradford Univ., UKni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ContinuousAuthenticationByAnalysisOfKeyboardTypingCharacteristics_BradfordUniv.,UK

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://ieeexplore.ieee.org/document/491588?reload=true&arnumber=491588"^^any u r i
kb-reference-ofop Input Device Analysis
kb-reference-titledp "Continuous authentication by analysis of keyboard typing characteristics"

Reference - Cyber Command System (CYCS)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-CyberCommandSystemCYCS

belongs to
Internet Article Referencec
has facts
has-linkdp "https://www.mitre.org/research/technology-transfer/technology-licensing/cyber-command-system-cycs"^^any u r i
kb-reference-ofop Operational Dependency Mapping
kb-reference-titledp "Cyber Command System (CYCS)"

Reference - Dagger Fact Sheetni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DaggerFactSheet

belongs to
Internet Article Referencec
has facts
has-linkdp "https://www.jhuapl.edu/dagger/documents/DaggerFactSheet.pdf"^^any u r i
kb-reference-ofop Operational Dependency Mapping
kb-reference-titledp "Dagger Fact Sheet"

Reference - Dagger: Modeling and visualization for mission impact situational awarenessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DaggerModelingAndVisualizationForMissionImpactSituationalAwareness

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://ieeexplore.ieee.org/document/7795296"^^any u r i
kb-reference-ofop Operational Dependency Mapping
kb-reference-titledp "Dagger: Modeling and visualization for mission impact situational awareness"

Reference - Data processing and scanning systems for generating and populating a data inventoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DataProcessingAndScanningSystemsForGeneratingAndPopulatingADataInventory

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US11240273B2/"^^any u r i
kb-reference-ofop Data Inventory
kb-reference-titledp "Data processing and scanning systems for generating and populating a data inventory"

Reference - Database for receiving, storing and compiling information about email messagesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Database_for_receiving_storing_and_compiling_information_about_email_messages

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20050091319A1/"^^any u r i
kb-reference-ofop Domain Name Reputation Analysis
kb-reference-ofop IP Reputation Analysis
kb-reference-titledp "Database for receiving, storing and compiling information about email messages"

Reference - Dead code eliminationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DeadCodeElimination

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://nebelwelt.net/files/15LangSec.pdf"^^any u r i
kb-reference-ofop Dead Code Elimination
kb-reference-titledp "The Correctness-Security Gap in Compiler Optimization"

Reference - Deception-Based Responses to Security Attacks - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Deception-BasedResponsesToSecurityAttacks_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20140250524A1/en?oq=US-2014250524-A1"^^any u r i
kb-reference-ofop Decoy Network Resource
kb-reference-titledp "Deception-Based Responses to Security Attacks"

Reference - Decoy and deceptive data object technology - Cymmetria Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DecoyAndDeceptiveDataObjectTechnology_CymmetriaInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170134423A1"^^any u r i
kb-reference-ofop Decoy Session Token
kb-reference-ofop Decoy User Credential
kb-reference-titledp "Decoy and deceptive data object technology"

Reference - Decoy and deceptive data object technology - Cymmetria, Inc.ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DecoyAndDeceptiveDataObjectTechnology_Cymmetria,Inc.

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170134423A1"^^any u r i
kb-reference-ofop Decoy Persona
kb-reference-titledp "Decoy and deceptive data object technology"

Reference - Decoy Network-Based Service for Deceiving Attackers - Amazon Technologiesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DecoyNetwork-BasedServiceForDeceivingAttackers-AmazonTechnologies

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10873601B1"^^any u r i
kb-reference-ofop Decoy User Credential
kb-reference-titledp "Decoy network-based service for deceiving attackers"

Reference - Decoy Personas for Safeguarding Online Identity Using Deception - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DecoyPersonasForSafeguardingOnlineIdentityUsingDeception_

belongs to
Internet Article Referencec
has facts
has-linkdp "https://web.archive.org/web/20180407204216/https://isc.sans.edu/diary/Decoy+Personas+for+Safeguarding+Online+Identity+Using+Deception/16159"^^any u r i
kb-reference-ofop Decoy Persona
kb-reference-titledp "Decoy Personas for Safeguarding Online Identity Using Deception"

Reference - Detecting DDoS Attack Using Snortni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DetectingDDoSAttackUsingSnort

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://www.researchgate.net/publication/338660054_DETECTING_DDoS_ATTACK_USING_Snort"^^any u r i
kb-reference-ofop Inbound Session Volume Analysis
kb-reference-titledp "DETECTING DDoS ATTACK USING Snort"

Reference - Detecting network reconnaissance by tracking intranet dark-net communications - VECTRA NETWORKS Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DetectingNetworkReconnaissanceByTrackingIntranetDark-netCommunications_VECTRANETWORKSInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20150264078A1"^^any u r i
kb-reference-ofop Connection Attempt Analysis
kb-reference-titledp "Detecting network reconnaissance by tracking intranet dark-net communications"

Reference - Detecting script-based malware - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DetectingScript-basedMalware_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190188384A1"^^any u r i
kb-reference-ofop File Content Rules
kb-reference-ofop Script Execution Analysis
kb-reference-titledp "Detecting script-based malware"

Reference - Detection of Malicious IDNHomoglyph Domainsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DetectionOfMaliciousIDNHomoglyphDomains

belongs to
Internet Article Referencec
has facts
has-linkdp "http://essay.utwente.nl/79263/1/Yazdani_MA_EEMCS.pdf"^^any u r i
kb-reference-ofop Homoglyph Denylisting
kb-reference-titledp "Detection of Malicious IDN Homoglyph Domains Using Active DNS Measurements"

Reference - Deterministic method for detecting and blocking of exploits on interpreted code - K2 Cyber Security Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DeterministicMethodForDetectingAndBlockingOfExploitsOnInterpretedCode_K2CyberSecurityInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190180036A1/en?oq=US-2019180036-A1"^^any u r i
kb-reference-ofop System Call Analysis
kb-reference-titledp "Deterministic method for detecting and blocking of exploits on interpreted code"

Reference - Digital Identity Guidelines 800-63-3ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DigitalIdentityGuidelines800-63-3

belongs to
Guideline Referencec
has facts
has-linkdp "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63-3.pdf"^^any u r i
kb-reference-ofop Strong Password Policy
kb-reference-titledp "Digital Identity Guidelines"

Reference - Distributed meta-information query in a network - Bit 9 Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DistributedMeta-informationQueryInANetwork_Bit9Inc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20070028302A1/en?oq=US-2007028302-A1"^^any u r i
kb-reference-ofop File Content Rules
kb-reference-titledp "Distributed meta-information query in a network"

Reference - DNS Whitelist (DNSWL) Email Authentication Method Extensionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DNSWhitelist-DNSWL-EmailAuthenticationMethodExtension

belongs to
Specification Referencec
has facts
has-linkdp "https://datatracker.ietf.org/doc/html/rfc8904"^^any u r i
kb-reference-ofop DNS Allowlisting
kb-reference-titledp "DNS Whitelist (DNSWL) Email Authentication Method Extension"

Reference - Domain age registration alert - Inc Rapid7 Inc RAPID7 Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DomainAgeRegistrationAlert_IncRapid7IncRAPID7Inc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170026400A1/"^^any u r i
kb-reference-ofop DNS Traffic Analysis
kb-reference-titledp "Domain age registration alert"

Reference - Dynamic selection and generation of a virtual clone for detonation of suspicious content within a honey network - Palo Alto Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DynamicSelectionAndGenerationOfAVirtualCloneForDetonationOfSuspiciousContentWithinAHoneyNetwork_PaloAltoNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9882929B1/en?oq=US-9882929-B1"^^any u r i
kb-reference-ofop Decoy Network Resource
kb-reference-ofop Standalone Honeynet
kb-reference-titledp "Dynamic selection and generation of a virtual clone for detonation of suspicious content within a honey network"

Reference - Embedding contexts for on-line threats into response policy zones - Verisign Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-EmbeddingContextsForOn-lineThreatsIntoResponsePolicyZones-VerisignInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10440059B1"^^any u r i
kb-reference-ofop Hierarchical Domain Denylisting
kb-reference-titledp "Embedding contexts for on-line threats into response policy zones"

Reference - End-to-end certificate pinningni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-End-to-endCertificatePinning

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9847992B2/en?q=certificate+pinning&oq=certificate+pinning"^^any u r i
kb-reference-ofop Certificate Pinning
kb-reference-titledp "End-to-end Certificate Pinning"

Reference - Enhancing Network Security By Preventing User-Initiated Malware Execution - MITREni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-EnhancingNetworkSecurityByPreventingUser-InitiatedMalwareExecution_

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://ieeexplore.ieee.org/document/1425209"^^any u r i
kb-reference-ofop Executable Allowlisting
kb-reference-titledp "Enhancing Network Security By Preventing User-Initiated Malware Execution"

Reference - File and Folder Permissionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FileAndFolderPermissions

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-2000-server/bb727008(v=technet.10)?redirectedfrom=MSDN"^^any u r i
kb-reference-ofop Local File Permissions
kb-reference-titledp "File and Folder Permissions"

Reference - File-modifying malware detection - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-File-modifyingMalwareDetection_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20180121650A1/en?oq=US-2018121650-A1"^^any u r i
kb-reference-ofop File Access Pattern Analysis
kb-reference-titledp "File-modifying malware detection"

Reference - Finding phishing sitesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Finding_phishing_sites

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8839418B2/"^^any u r i
kb-reference-ofop Domain Name Reputation Analysis
kb-reference-ofop IP Reputation Analysis
kb-reference-ofop URL Reputation Analysis
kb-reference-titledp "Finding phishing sites"

Reference - Firewall for interent access - Secure Computing LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirewallForInterentAccess_SecureComputingLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/GB2317539A"^^any u r i
kb-reference-ofop Inbound Traffic Filtering
kb-reference-titledp "Firewall for interent access"

Reference - Firewall for processing a connectionless network packet - National Security Agencyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirewallForProcessingAConnectionlessNetworkPacket_NationalSecurityAgency

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US7073196B1"^^any u r i
kb-reference-ofop Inbound Traffic Filtering
kb-reference-titledp "Firewall for processing a connectionless network packet"

Reference - Firewall for processing connection-oriented and connectionless datagrams over a connection-oriented network - National Security Agencyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirewallForProcessingConnection-orientedAndConnectionlessDatagramsOverAConnection-orientedNetwork_NationalSecurityAgency

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US6615358B1"^^any u r i
kb-reference-ofop Inbound Traffic Filtering
kb-reference-titledp "Firewall for processing connection-oriented and connectionless datagrams over a connection-oriented network"

Reference - Firewalls that filter based upon protocol commands - Intel Corpni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirewallsThatFilterBasedUponProtocolCommands_IntelCorp

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US6832256B1"^^any u r i
kb-reference-ofop Inbound Traffic Filtering
kb-reference-titledp "Firewalls that filter based upon protocol commands"

Reference - Firmware Behavior Analysis ConFirmni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirmwareBehaviorAnalysisConFirm

belongs to
Academic Paper Referencec
has facts
has-linkdp "http://sites.nyuad.nyu.edu/moma/pdfs/pubs/C22.pdf"^^any u r i
kb-reference-ofop Firmware Behavior Analysis
kb-reference-titledp "ConFirm: Detecting Firmware Modifications in Embedded Systems using Hardware Performance Counters"

Reference - Firmware Behavior Analysis VIPERni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirmwareBehaviorAnalysisVIPER

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://dl.acm.org/doi/pdf/10.1145/2046707.2046711"^^any u r i
kb-reference-ofop Firmware Behavior Analysis
kb-reference-titledp "VIPER: Verifying the Integrity of PERipherals' Firmware"

Reference - Firmware Embedded Monitoring Code Red Balloonni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirmwareEmbeddedMonitoringCodeRedBalloon

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10657262B1/en"^^any u r i
kb-reference-ofop Firmware Embedded Monitoring Code
kb-reference-titledp "Method and apparatus for securing embedded device firmware"

Reference - Firmware Embedded Monitoring Code Symbiotesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirmwareEmbeddedMonitoringCodeSymbiotes

belongs to
Academic Paper Referencec
has facts
has-linkdp "http://nsl.cs.columbia.edu/projects/minestrone/papers/Symbiotes.pdf"^^any u r i
kb-reference-ofop Firmware Embedded Monitoring Code
kb-reference-titledp "Defending Embedded Systems with Software Symbiotes"

Reference - Firmware Verification Eclypsiumni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirmwareVerificationEclypsium

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20200074086A1/en"^^any u r i
kb-reference-ofop Firmware Verification
kb-reference-titledp "Methods and systems for hardware and firmware security monitoring"

Reference - Firmware Verification Trapezoidni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FirmwareVerificationTrapezoid

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9674183B2/en"^^any u r i
kb-reference-ofop Firmware Verification
kb-reference-titledp "System and method for hardware-based trust control management"

Reference - Framework for notifying a directory service of authentication events processed outside the directory service - Oracle International Corpni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FrameworkForNotifyingADirectoryServiceOfAuthenticationEventsProcessedOutsideTheDirectoryService_OracleInternationalCorp

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20090077645A1"^^any u r i
kb-reference-ofop Account Locking
kb-reference-titledp "Framework for notifying a directory service of authentication events processed outside the directory service"

Reference - FWTK - Firewall Toolkitni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FWTK-FirewallToolkit_

belongs to
Internet Article Referencec
has facts
has-linkdp "https://blogs.gartner.com/john_pescatore/2008/10/02/this-week-in-network-security-history-the-firewall-toolkit/"^^any u r i
kb-reference-titledp "FWTK - Firewall Toolkit"

Reference - FWTK Documentation - fwtk.orgni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-FWTKDocumentation-Fwtk.org

belongs to
Technique Referencec
has facts
has-linkdp "https://web.archive.org/web/20070510153306/http://www.fwtk.org/fwtk/docs/documentation.html#1.1"^^any u r i
kb-reference-ofop Inbound Traffic Filtering
kb-reference-titledp "FWTK Documentation"

Reference - Guards for application in software tamperproofing - Purdue Research Foundationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-GuardsForApplicationInSoftwareTamperproofing_PurdueResearchFoundation

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US7287166B1/en?oq=US-7287166-B1"^^any u r i
kb-reference-ofop Process Code Segment Verification
kb-reference-titledp "Guards for application in software tamperproofing"

Reference - Hardware-assisted system and method for detecting and analyzing system calls made to an operting system kernel - Endgame Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Hardware-assistedSystemAndMethodForDetectingAndAnalyzingSystemCallsMadeToAnOpertingSystemKernel_EndgameInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20180032728A1/en?oq=US20180032728-A1"^^any u r i
kb-reference-ofop System Call Analysis
kb-reference-titledp "Hardware-assisted system and method for detecting and analyzing system calls made to an operting system kernel"

Reference - Heuristic botnet detection - Palo Alto Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-HeuristicBotnetDetection_PaloAltoNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160156644A1"^^any u r i
kb-reference-ofop DNS Traffic Analysis
kb-reference-titledp "Heuristic botnet detection"

Reference - Host intrusion prevention system using software and user behavior analysis - Sophos Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-HostIntrusionPreventionSystemUsingSoftwareAndUserBehaviorAnalysis_SophosLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20110023115A1"^^any u r i
kb-reference-ofop Resource Access Pattern Analysis
kb-reference-ofop System Daemon Monitoring
kb-reference-ofop Web Session Activity Analysis
kb-reference-titledp "Host intrusion prevention system using software and user behavior analysis"

Reference - How ASLR protects Linux systems from buffer overflow attacks - Network Worldni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-HowASLRProtectsLinuxSystemsFromBufferOverflowAttacks_NetworkWorld

belongs to
Internet Article Referencec
has facts
has-linkdp "https://www.networkworld.com/article/3331199/what-does-aslr-do-for-linux.html"^^any u r i
kb-reference-ofop Segment Address Offset Randomization
kb-reference-titledp "How ASLR protects Linux systems from buffer overflow attacks"

Reference - How Does Antivirus Quarantine Work? - Safety Detectivesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-HowDoesAntivirusQuarantineWork-SafetyDetectives

belongs to
Internet Article Referencec
has facts
has-linkdp "https://www.safetydetectives.com/blog/how-does-antivirus-quarantine-work/"^^any u r i
kb-reference-ofop File Removal
kb-reference-titledp "How Does Antivirus Quarantine Work?"

Reference - How to change registry values or permissions from a command line or a scriptni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-HowToChangeRegistryValuesOrPermissionsFromACommandLineOrAScript

belongs to
Internet Article Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/troubleshoot/windows-client/application-management/change-registry-values-permissions"^^any u r i
kb-reference-titledp "How to change registry values or permissions from a command line or a script"

Reference - How trust relationships work for resource forests in Azure Active Directory Domain Servicesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-HowTrustRelationshipsWorkForResourceForestsInAzureActiveDirectoryDomainServices

belongs to
Internet Article Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/azure/active-directory-domain-services/concepts-forest-trust"^^any u r i
kb-reference-ofop Domain Trust Policy
kb-reference-titledp "How trust relationships work for resource forests in Azure Active Directory Domain Services"

Reference - http://www.biometric-solutions.com/keystroke-dynamics.html - biometric-solutions.comni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-www.biometric-solutions.com_keystroke-dynamics

belongs to
Internet Article Referencec
has facts
has-linkdp "http://www.biometric-solutions.com/keystroke-dynamics.html"^^any u r i
kb-reference-ofop Input Device Analysis
kb-reference-titledp "Keystroke Dynamics"

Reference - Identification and extraction of key forensics indicators of compromise using subject-specific filesystem viewsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-IdentificationAndExtractionOfKeyForensicsIndicatorsOfCompromiseUsingSubject-specificFilesystemViews

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20200004962A1/en"^^any u r i
kb-reference-titledp "Identification and extraction of key forensics indicators of compromise using subject-specific filesystem views"

Reference - Identification of traceroute nodes and associated devicesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-IdentificationOfTracerouteNodesAndAssociatedDevices

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10079749B2/en"^^any u r i
kb-reference-titledp "Identification of traceroute nodes and associated devices"

Reference - Identification of visual international domain name collisions - Verisign Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-IdentificationOfVisualInternationalDomainNameCollisions-VerisignInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10599836B2/en"^^any u r i
kb-reference-ofop Homoglyph Detection
kb-reference-titledp "Identification of visual international domain name collisions"

Reference - Identifying a denial-of-service attack in a cloud-based proxy service - Cloudfare Inc.ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-IdentifyingADenial-of-serviceAttackInACloud-basedProxyService-CloudfareInc.

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8613089B1"^^any u r i
kb-reference-ofop Inbound Session Volume Analysis
kb-reference-titledp "Identifying a denial-of-service attack in a cloud-based proxy service"

Reference - IEEE Standard for Local and Metropolitan Area Networks - Station and Media Access Control Connectivity Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-IEEE-802_1AB-2016

belongs to
Specification Referencec
has facts
has-linkdp "https://standards.ieee.org/ieee/802.1AB/6047/"^^any u r i
kb-reference-ofop Hardware Component Inventory
kb-reference-titledp "IEEE Standard for Local and Metropolitan Area Networks - Station and Media Access Control Connectivity Discovery"

Reference - Indirect Branching Callsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-IndirectBranchingCalls

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.1048.1241&rep=rep1&type=pdf"^^any u r i
kb-reference-ofop Indirect Branch Call Analysis
kb-reference-titledp "Transparent ROP Exploit Mitigation using Indirect Branch Tracing"

Reference - Inferential exploit attempt detection - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-InferentialExploitAttemptDetection_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10216934B2/en?oq=US-10216934-B2"^^any u r i
kb-reference-ofop Memory Boundary Tracking
kb-reference-titledp "Inferential exploit attempt detection"

Reference - Instant process termination tool to recover control of an information handling system - Dell Products LPni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-InstantProcessTerminationToolToRecoverControlOfAnInformationHandlingSystem_DellProductsLP

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20060236108A1/en"^^any u r i
kb-reference-ofop Process Termination
kb-reference-titledp "Instant process termination tool to recover control of an information handling system"

Reference - Integrity assurance through early loading in the boot phase - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-IntegrityAssuranceThroughEarlyLoadingInTheBootPhase_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170061127A1"^^any u r i
kb-reference-ofop Driver Load Integrity Checking
kb-reference-titledp "Integrity assurance through early loading in the boot phase"

Reference - Intrusion detection using a heartbeat - Sophos Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-IntrusionDetectionUsingAHeartbeat_SophosLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20180191752A1"^^any u r i
kb-reference-ofop Endpoint Health Beacon
kb-reference-titledp "Intrusion detection using a heartbeat"

Reference - Isolation of applications within a virtual machine - Bromium, Inc.ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-IsolationOfApplicationsWithinAVirtualMachine_Bromium,Inc.

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9921860B1"^^any u r i
kb-reference-ofop Hardware-based Process Isolation
kb-reference-titledp "Isolation of applications within a virtual machine"

Reference - Libre NMS - Network Map Extensionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-LibreNMSDocsNetworkMapExtension

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.librenms.org/Extensions/Network-Map/"^^any u r i
kb-reference-ofop Network Mapping
kb-reference-titledp "Libre NMS - Network Map Extension"

Reference - Libre NMS - Oxidized Extensionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-LibreNMSDocsOxidizedExtension

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.librenms.org/Extensions/Oxidized/"^^any u r i
kb-reference-ofop Disk Encryption
kb-reference-titledp "LibreNMSDocs - Oxidized Extension"

Reference - LUKS1 On-Disk Format SpecificationVersion 1.2.3ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-LUKS1On-DiskFormatSpecificationVersion1.2.3

belongs to
Specification Referencec
has facts
has-linkdp "https://mirrors.edge.kernel.org/pub/linux/utils/cryptsetup/LUKS_docs/on-disk-format.pdf"^^any u r i
kb-reference-ofop Disk Encryption
kb-reference-titledp "LUKS1 On-Disk Format SpecificationVersion 1.2.3"

Reference - Malicious relay detection on networks - VECTRA NETWORKS Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MaliciousRelayDetectionOnNetworks_VECTRANETWORKSInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20150264083A1"^^any u r i
kb-reference-ofop Relay Pattern Analysis
kb-reference-titledp "Malicious relay detection on networks"

Reference - Malware analysis system - Palo Alto Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MalwareAnalysisSystem_PaloAltoNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20150319136A1"^^any u r i
kb-reference-ofop Dynamic Analysis
kb-reference-titledp "Malware analysis system"

Reference - Malware detection in event loops - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MalwareDetectionInEventLoops_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190205530A1"^^any u r i
kb-reference-ofop System Call Analysis
kb-reference-titledp "Malware detection in event loops"

Reference - Malware detection using local computational models - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MalwareDetectionUsingLocalComputationalModels_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190026466A1"^^any u r i
kb-reference-ofop Process Termination
kb-reference-titledp "Malware detection using local computational models"

Reference - Method and Apparatus for Detecting Malicious Websites - Endgame Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndApparatusForDetectingMaliciousWebsites_EndgameInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20140331319A1"^^any u r i
kb-reference-ofop URL Analysis
kb-reference-titledp "Method and Apparatus for Detecting Malicious Websites"

Reference - Method and apparatus for increasing the speed at which computer viruses are detected - McAfee LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndApparatusForIncreasingTheSpeedAtWhichComputerVirusesAreDetected_McAfeeLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US5502815A"^^any u r i
kb-reference-ofop Executable Denylisting
kb-reference-titledp "Method and apparatus for increasing the speed at which computer viruses are detected"

Reference - Method and Apparatus for Network Fraud Detection and Remediation Through Analytics - Idaptive LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndApparatusForNetworkFraudDetectionAndRemediationThroughAnalytics_IdaptiveLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190081968A1/en"^^any u r i
kb-reference-ofop Authentication Event Thresholding
kb-reference-ofop Authorization Event Thresholding
kb-reference-ofop Resource Access Pattern Analysis
kb-reference-ofop Session Duration Analysis
kb-reference-ofop User Geolocation Logon Pattern Analysis
kb-reference-titledp "Method and Apparatus for Network Fraud Detection and Remediation Through Analytics"

Reference - Method and apparatus for utilizing a token for resource access - Rsa Security Inc.ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndApparatusForUtilizingATokenForResourceAccess_RsaSecurityInc.

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US5657388A/en"^^any u r i
kb-reference-ofop Multi-factor Authentication
kb-reference-titledp "Method and apparatus for utilizing a token for resource access"

Reference - Method and system for controlling communication portsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForControllingCommunicationPorts

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8566924"^^any u r i
kb-reference-ofop IO Port Restriction
kb-reference-titledp "Method and system for controlling communication ports"

Reference - Method and system for detecting algorithm-generated domains - VECTRA NETWORKS Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForDetectingAlgorithm-generatedDomains_VECTRANETWORKSInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20150264070A1"^^any u r i
kb-reference-ofop DNS Traffic Analysis
kb-reference-titledp "Method and system for detecting algorithm-generated domains"

Reference - Method and system for detecting external control of compromised hosts - VECTRA NETWORKS Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForDetectingExternalControlOfCompromisedHosts_VECTRANETWORKSInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9407647B2/en?oq=US-9407647-B2"^^any u r i
kb-reference-ofop Remote Terminal Session Detection
kb-reference-titledp "Method and system for detecting external control of compromised hosts"

Reference - Method and system for detecting malicious payloads - Vectra Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForDetectingMaliciousPayloads_VectraNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/EP3293937A1/en?oq=EP-3293937-A1"^^any u r i
kb-reference-ofop Client-server Payload Profiling
kb-reference-titledp "Method and system for detecting malicious payloads"

Reference - Method and system for detecting restricted content associated with retrieved content - Sophos Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForDetectingRestrictedContentAssociatedWithRetrievedContent_SophosLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160359883A1"^^any u r i
kb-reference-ofop URL Analysis
kb-reference-titledp "Method and system for detecting restricted content associated with retrieved content"

Reference - Method and system for detecting suspicious administrative activity - Vectra Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForDetectingSuspiciousAdministrativeActivity_VectraNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20180077186A1"^^any u r i
kb-reference-ofop Administrative Network Activity Analysis
kb-reference-titledp "Method and system for detecting suspicious administrative activity"

Reference - Method and system for detecting threats using metadata vectors - VECTRA NETWORKS Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForDetectingThreatsUsingMetadataVectors_VECTRANETWORKSInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160191551A1"^^any u r i
kb-reference-ofop Protocol Metadata Anomaly Detection
kb-reference-titledp "Method and system for detecting threats using metadata vectors"

Reference - Method and system for detecting threats using passive cluster mapping - Vectra Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForDetectingThreatsUsingPassiveClusterMapping_VectraNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160149936A1"^^any u r i
kb-reference-ofop Protocol Metadata Anomaly Detection
kb-reference-titledp "Method and system for detecting threats using passive cluster mapping"

Reference - Method and system for providing software updates to local machinesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForProvidingSoftwareUpdatesToLocalMachines

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10474448B2/en"^^any u r i
kb-reference-titledp "Method and system for providing software updates to local machines"

Reference - Method and system for UDP flood attack detection - Riorey LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodAndSystemForUDPFloodAttackDetection-RioreyLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8307430B1"^^any u r i
kb-reference-ofop Inbound Session Volume Analysis
kb-reference-titledp "Method and system for UDP flood attack detection"

Reference - Method for controlling computer network security - Checkpoint Software Technologies Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodForControllingComputerNetworkSecurity_CheckpointSoftwareTechnologiesLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/EP0658837B1/"^^any u r i
kb-reference-ofop Inbound Traffic Filtering
kb-reference-titledp "Method for controlling computer network security"

Reference - Method for file encryptionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodForFileEncryption

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9521123B2/en"^^any u r i
kb-reference-ofop File Encryption
kb-reference-titledp "Method for file encryption"

Reference - Method using kernel mode assistance for the detection and removal of threats which are actively preventing detection and removal from a running system - Symantec Corporationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MethodUsingKernelModeAssistanceForTheDetectionAndRemovalOfThreatsWhichAreActivelyPreventingDetectionAndRemovalFromARunningSystem_SymantecCorporation

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8239947B1"^^any u r i
kb-reference-ofop System Daemon Monitoring
kb-reference-titledp "Method using kernel mode assistance for the detection and removal of threats which are actively preventing detection and removal from a running system"

Reference - MGT516: Managing Security Vulnerabilities: Enterprise and Cloudni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MGT516ManagingSecurityVulnerabilitiesEnterpriseAndCloud

belongs to
Internet Article Referencec
has facts
has-linkdp "https://www.sans.org/cyber-security-courses/managing-enterprise-cloud-security-vulnerabilities/"^^any u r i
kb-reference-ofop Operational Risk Assessment
kb-reference-titledp "MGT516: Managing Security Vulnerabilities: Enterprise and Cloud"

Reference - Mission Dependency Modeling for Cyber Situational Awarenessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MissionDependencyModelingForCyberSituationalAwareness

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://csis.gmu.edu/noel/pubs/2016_NATO_IST_148.pdf"^^any u r i
kb-reference-ofop Operational Dependency Mapping
kb-reference-titledp "Mission Dependency Modeling for Cyber Situational Awareness"

Reference - Mitigate threats by using Windows 10 security features: Data Execution Prevention - Microsoftni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DataExecutionPrevention_Microsoft

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/windows/security/threat-protection/overview-of-threat-mitigations-in-windows-10#data-execution-prevention"^^any u r i
kb-reference-ofop Process Segment Execution Prevention
kb-reference-titledp "Mitigate threats by using Windows 10 security features: Data Execution Prevention"

Reference - Mock attack cybersecurity training system and methods - WOMBAT SECURITY TECHNOLOGIES Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-MockAttackCybersecurityTrainingSystemAndMethods_WOMBATSECURITYTECHNOLOGIESInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9558677B2/"^^any u r i
kb-reference-ofop Decoy Public Release
kb-reference-titledp "Mock attack cybersecurity training system and methods"

Reference - Modeling user access to computer resources - Daedalus Group LLC (formerly IBM)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ModelingUserAccessToComputerResources_DaedalusGroupLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8214364B2"^^any u r i
kb-reference-ofop Resource Access Pattern Analysis
kb-reference-titledp "Modeling user access to computer resources"

Reference - Modification of a Server to Mimic a Deception Mechanism - Acalvio Technologies Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ModificationOfAServerToMimicADeceptionMechanism_AcalvioTechnologiesInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170149825A1"^^any u r i
kb-reference-ofop Connected Honeynet
kb-reference-titledp "Modification of a Server to Mimic a Deception Mechanism"

Reference - Muninni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Munin

belongs to
Source Code Referencec
has facts
has-linkdp "https://github.com/Neo23x0/munin"^^any u r i
kb-reference-titledp "Online Hash Checker for Virustotal and Other Services"

Reference - Network firewall with proxy - Secure Computing LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-NetworkFirewallWithProxy_SecureComputingLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/GB2318031A"^^any u r i
kb-reference-ofop Inbound Traffic Filtering
kb-reference-titledp "Network firewall with proxy"

Reference - Network-Based Buffer Overflow Detection by Exploit Code Analysis - Information Security Research Centreni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Network-BasedBufferOverflowDetectionByExploitCodeAnalysis_InformationSecurityResearchCentre

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://eprints.qut.edu.au/21172/1/21172.pdf"^^any u r i
kb-reference-ofop Byte Sequence Emulation
kb-reference-titledp "Network-Based Buffer Overflow Detection by Exploit Code Analysis"

Reference - Network-level polymorphic shellcode detection using emulationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Network-levelPolymorphicShellcodeDetectionUsingEmulation

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://www.cs.unc.edu/~fabian/course_papers/polymorphic-detect.pdf"^^any u r i
kb-reference-ofop Byte Sequence Emulation
kb-reference-titledp "Network-level polymorphic shellcode detection using emulation"

Reference - NIST RMF Quick Start Guide - Assess Step - Frequently Asked Questions (FAQ)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-NIST-RMF-Quick-Start-Guide-Assess-Step-FAQ

belongs to
Internet Article Referencec
has facts
has-linkdp "https://csrc.nist.gov/CSRC/media/Projects/risk-management/documents/05-Assess%20Step/NIST%20RMF%20Assess%20Step-FAQs.pdf"^^any u r i
kb-reference-ofop Operational Risk Assessment
kb-reference-titledp "NIST RMF Quick Start Guide - Assess Step - Frequently Asked Questions (FAQ)"

Reference - NIST Special Publication 800-160 Volume 1 - System Security Engineeringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-NIST-Special-Publication-800-160-Volume-1

belongs to
Guideline Referencec
has facts
has-linkdp "https://doi.org/10.6028/NIST.SP.800-160v1"^^any u r i
kb-reference-ofop Operational Risk Assessment
kb-reference-titledp "NIST Special Publication 800-160 Volume 1 - Systems Security Engineering"

Reference - NIST Special Publication 800-37 Revision 2 - Risk Management Framework for Information Systems and Organizationsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-NIST-Special-Publication-800-37-Revision-2

belongs to
Guideline Referencec
has facts
has-linkdp "https://doi.org/10.6028/NIST.SP.800-37r2"^^any u r i
kb-reference-ofop Operational Risk Assessment
kb-reference-titledp "NIST Special Publication 800-37 Revision 2 - Risk Management Framework for Information Systems and Organizations"

Reference - NIST Special Publication 800-53A Revision 5 - Assessing Security and Privacy Controls in Information Systems and Organizationsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-NIST-Special-Publication-800-53A-Revision-5

belongs to
Guideline Referencec
has facts
has-linkdp "https://doi.org/10.6028/NIST.SP.800-53Ar5"^^any u r i
kb-reference-ofop Operational Risk Assessment
kb-reference-titledp "NIST Special Publication 800-53A Revision 5 - Assessing Security and Privacy Controls in Information Systems and Organizations"

Reference - NISTIR 8011 Volume 1 - Automation Support for Security Control Assessmentsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-NISTIR-8011-Volume-1

belongs to
Guideline Referencec
has facts
has-linkdp "https://doi.org/10.6028/NIST.IR.8011-1"^^any u r i
kb-reference-ofop Operational Risk Assessment
kb-reference-titledp "NIST Interagency Report 8011 Volume 1 - Automation Support for Security Control Assessments"

Reference - Open source intelligence deceptions - Illusive Networks Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-OpenSourceIntelligenceDeceptions_IllusiveNetworksLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10333976B1/en?assignee=Illusive+Networks+Ltd&oq=Illusive+Networks+Ltd+"^^any u r i
kb-reference-ofop Decoy File
kb-reference-titledp "Open source intelligence deceptions"

Reference - Organizational Management in SAP ERP HCMni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-OrganizationalManagementInSAPERPHCM

belongs to
Book Referencec
has facts
has-linkdp "https://www.sap-press.com/organizational-management-in-sap-erp-hcm_3996/"^^any u r i
kb-reference-ofop Organization Mapping
kb-reference-titledp "Organization Mapping in SAP ERP HCM"

Reference - OS Query Windows User Collection Codeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-OSQueryWindowsUserCollectionCode

belongs to
Source Code Referencec
has facts
has-linkdp "https://github.com/osquery/osquery/blob/d2be385d71f401c85872f00d479df8f499164c5a/osquery/tables/system/windows/users.cpp"^^any u r i
kb-reference-titledp "OS Query Windows User Collection Code"

Reference - Overview of the seccomp sandboxni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-OverviewOfTheSeccompSandbox

belongs to
Internet Article Referencec
has facts
has-linkdp "https://code.google.com/archive/p/seccompsandbox/wikis/overview.wiki"^^any u r i
kb-reference-ofop System Call Filtering
kb-reference-titledp "Overview of the seccomp sandbox"

Reference - Platform Firmware Resiliency Guidelines - NISTni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PlatformFirmwareResiliencyGuidelines_NIST

belongs to
Guideline Referencec
has facts
has-linkdp "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-193.pdf"^^any u r i
kb-reference-ofop Firmware Verification
kb-reference-titledp "Platform Firmware Resiliency Guidelines"

Reference - Pointer Authentication on ARMv8.3ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PointerAuthenticationOnARMv8.3

belongs to
Specification Referencec
has facts
has-linkdp "https://www.qualcomm.com/media/documents/files/whitepaper-pointer-authentication-on-armv8-3.pdf"^^any u r i
kb-reference-ofop Pointer Authentication
kb-reference-titledp "Pointer Authentication on ARMv8.3"

Reference - Pointer Authentication Project Zeroni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PointerAuthenticationProjectZero

belongs to
Internet Article Referencec
has facts
has-linkdp "https://googleprojectzero.blogspot.com/2019/02/examining-pointer-authentication-on.html"^^any u r i
kb-reference-ofop Pointer Authentication
kb-reference-titledp "Examining Pointer Authentication on the iPhone XS"

Reference - Post sandbox methods and systems for detecting and blocking zero-day exploits via api call validation - K2 Cyber Security Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PostSandboxMethodsAndSystemsForDetectingAndBlockingZero-dayExploitsViaApiCallValidation_K2CyberSecurityInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190138715A1/"^^any u r i
kb-reference-ofop System Call Analysis
kb-reference-titledp "Post sandbox methods and systems for detecting and blocking zero-day exploits via api call validation"

Reference - Predicting Domain Generation Algorithms with Long Short-Term Memory Networksni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PredictingDomainGenerationAlgorithmsWithLongShort-TermMemoryNetworks_

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://arxiv.org/abs/1611.007911"^^any u r i
kb-reference-ofop DNS Traffic Analysis
kb-reference-titledp "Predicting Domain Generation Algorithms with Long Short-Term Memory Networks"

Reference - Preventing execution of task scheduled malware - McAfee LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PreventingExecutionOfTaskScheduledMalware_McAfeeLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160105450A1"^^any u r i
kb-reference-ofop Scheduled Job Analysis
kb-reference-titledp "Preventing execution of task scheduled malware"

Reference - Privacy and security systems and methods of useni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PrivacyAndSecuritySystemsAndMethodsOfUse

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10128890B2/en"^^any u r i
kb-reference-titledp "Privacy and security systems and methods of use"

Reference - Private virtual local area network isolation - Cisco Technology Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PrivateVirtualLocalAreaNetworkIsolation_CiscoTechnologyInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20120331142A1"^^any u r i
kb-reference-ofop Broadcast Domain Isolation
kb-reference-titledp "Private virtual local area network isolation"

Reference - Protected computing environment - Microsoft Technology Licensing LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ProtectedComputingEnvironment_MicrosoftTechnologyLicensingLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20060242406A1"^^any u r i
kb-reference-ofop Driver Load Integrity Checking
kb-reference-titledp "Protected computing environment"

Reference - Protecting against distributed denial of service attacks - Cisco Technology Inc.ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ProtectingAgainstDistributedDenialOfServiceAttacks-CiscoTechnologyInc.

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US7171683B2"^^any u r i
kb-reference-ofop Inbound Session Volume Analysis
kb-reference-titledp "Protecting against distributed denial of service attacks"

Reference - Protecting against distributed network flood attacks - Juniper Networks Inc.ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ProtectingAgainstDistributedNetworkFloodAttacks-JuniperNetworksInc.

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8789173B2"^^any u r i
kb-reference-ofop Inbound Session Volume Analysis
kb-reference-titledp "Protecting against distributed network flood attacks"

Reference - PsSuspend - Microsoftni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-PsSuspend

belongs to
Specification Referencec
has facts
has-linkdp "https://learn.microsoft.com/en-us/sysinternals/downloads/pssuspend"^^any u r i
kb-reference-ofop Process Suspension
kb-reference-titledp "PsSuspend"

Reference - Qualys Network Passive Sensor Getting Started Guideni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-QualysNetworkPassiveSensorGettingStartedGuide

belongs to
User Manual Referencec
has facts
has-linkdp "https://www.qualys.com/passive-scanning-sensor/"^^any u r i
kb-reference-ofop Hardware Component Inventory
kb-reference-ofop Network Node Inventory
kb-reference-titledp "Qualys Network Passive Sensor Getting Started Guide"

Reference - Red Hat Enterprise Linux 8 Security Technical Implementation Guideni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RedHatEnterpriseLinux8SecurityTechnicalImplementationGuide

belongs to
Guideline Referencec
has facts
has-linkdp "https://www.stigviewer.com/stig/red_hat_enterprise_linux_8/"^^any u r i
kb-reference-ofop Application Configuration Hardening
kb-reference-titledp "Red Hat Enterprise Linux 8 Security Technical Implementation Guide"

Reference - Registry Key Security and Access Rightsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RegistryKeySecurityAndAccessRights

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/windows/win32/sysinfo/registry-key-security-and-access-rights"^^any u r i
kb-reference-ofop User Session Init Config Analysis
kb-reference-titledp "Registry Key Security and Access Rights"

Reference - Reputation of an entity associated with a content itemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Reputation_of_an_entity_associated_with_a_content_item

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20060253584A1"^^any u r i
kb-reference-ofop File Hash Reputation Analysis
kb-reference-titledp "Reputation of an entity associated with a content item"

Reference - Reverse DNS Blocking - Barracuda Networksni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ReverseDNSBlocking_BarracudaNetworks

belongs to
User Manual Referencec
has facts
has-linkdp "https://campus.barracuda.com/product/emailsecuritygateway/doc/39819732/reverse-dns-blocking/"^^any u r i
kb-reference-ofop Reverse Resolution Domain Denylisting
kb-reference-titledp "Reverse DNS Blocking"

Reference - Revoke a previously issued verifiable credential - Microsoftni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RevokingaPreviouslyIssuedVerifiableCredential-Microsoft

belongs to
Specification Referencec
has facts
has-linkdp "https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/how-to-issuer-revoke"^^any u r i
kb-reference-ofop Credential Revoking
kb-reference-titledp "Revoke a previously issued verifiable credential"

Reference - RFC 2289 - A One-Time Password Systemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RFC2289-AOne-TimePasswordSystem

belongs to
Specification Referencec
has facts
has-linkdp "https://tools.ietf.org/html/rfc2289"^^any u r i
kb-reference-ofop One-time Password
kb-reference-titledp "A One-Time Password System"

Reference - RFC 6376: DomainKeys Identified Mail (DKIM) Signatures - IETFni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-DomainKeysIdentifiedMail-Signatures-IETF

belongs to
Specification Referencec
has facts
has-linkdp "https://tools.ietf.org/html/rfc6376"^^any u r i
kb-reference-ofop Transfer Agent Authentication
kb-reference-titledp "RFC 6376: DomainKeys Identified Mail (DKIM) Signatures"

Reference - RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email - IETFni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RFC7208-SenderPolicyFramework-SPF-ForAuthorizingUseOfDomainsInEmail-IETF

belongs to
Specification Referencec
has facts
has-linkdp "https://tools.ietf.org/html/rfc7208"^^any u r i
kb-reference-ofop Transfer Agent Authentication
kb-reference-titledp "RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email"

Reference - RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) - IETFni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RFC7489-Domain-basedMessageAuthentication-Reporting-AndConformance-DMARC

belongs to
Specification Referencec
has facts
has-linkdp "https://tools.ietf.org/html/rfc7489"^^any u r i
kb-reference-ofop Transfer Agent Authentication
kb-reference-titledp "RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)"

Reference - RFC 7642: System for Cross-domain Identity Management: Definitions, Overview, Concepts, and Requirementsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RFC7642SystemForCrossDomainIdentityManagementDefinitionsOverviewConceptsAndRequirements

belongs to
Specification Referencec
has facts
has-linkdp "https://datatracker.ietf.org/doc/html/rfc7642"^^any u r i
kb-reference-ofop Access Modeling
kb-reference-titledp "RFC7642: System for Cross-domain Identity Management: Definitions, Overview, Concepts, and Requirements"

Reference - RPC call interception - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-RPCCallInterception_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20150163109"^^any u r i
kb-reference-ofop RPC Traffic Analysis
kb-reference-titledp "RPC call interception"

Reference - Secure caching of server credentials - Dell Products LPni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SecureCachingOfServerCredentials_DellProductsLP

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20100107241A1"^^any u r i
kb-reference-ofop Authentication Cache Invalidation
kb-reference-titledp "Secure caching of server credentials"

Reference - Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.1ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SecureMultipurposeInternetMailExtensionsMIME-Version3.1

belongs to
Specification Referencec
has facts
has-linkdp "https://tools.ietf.org/html/rfc3851"^^any u r i
kb-reference-titledp "Secure/Multipurpose Internet Mail Extensions (S/MIME) Version 3.1 Message Specification"

Reference - Securing Web Transactionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SecuringWebTransactions

belongs to
Guideline Referencec
has facts
has-linkdp "https://www.nccoe.nist.gov/sites/default/files/library/sp1800/tls-serv-cert-mgt-nist-sp1800-16b-final.pdf"^^any u r i
kb-reference-ofop Active Certificate Analysis
kb-reference-titledp "Securing Web Transactions"

Reference - Securing Web Transactions TLS Server Certificate Management - Appendix A Passive Inspectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Securing_Web_Transactions__TLS_Server_Certificate_Management_Appendix_A_Passive_Inspection

belongs to
Guideline Referencec
has facts
has-linkdp "https://www.nccoe.nist.gov/publication/1800-16/VolD/vol-d-appendix.html"^^any u r i
kb-reference-ofop Passive Certificate Analysis
kb-reference-titledp "Securing Web Transactions TLS Server Certificate Management - Appendix A Passive Inspection"

Reference - Security Architecture for the Internet Protocolni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SecurityArchitectureForTheInternetProtocol

belongs to
Specification Referencec
has facts
has-linkdp "https://datatracker.ietf.org/doc/html/rfc1825"^^any u r i
kb-reference-ofop Encrypted Tunnels
kb-reference-titledp "Security Architecture for the Internet Protocol"

Reference - Security System with Methodology for Interprocess Communication Control - Check Point Software Tech Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SecuritySystemWithMethodologyForInterprocessCommunicationControl_CheckPointSoftwareTechInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20040199763"^^any u r i
kb-reference-ofop IPC Traffic Analysis
kb-reference-titledp "Security System with Methodology for Interprocess Communication Control"

Reference - Security Technologies: Stack Smashing Protection (StackGuard) - Red Hatni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-StackSmashingProtection_StackGuard_RedHat

belongs to
Internet Article Referencec
has facts
has-linkdp "https://access.redhat.com/blogs/766093/posts/3548631"^^any u r i
kb-reference-ofop Stack Frame Canary Validation
kb-reference-titledp "Security Technologies: Stack Smashing Protection (StackGuard)"

Reference - Security vulnerability information aggregationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SecurityVulnerabilityInformationAggregation

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8544098B2"^^any u r i
kb-reference-ofop Asset Vulnerability Enumeration
kb-reference-titledp "Security vulnerability information aggregation"

Reference - Sinkholing bad network domains by registering the bad network domains on the internet - Palo Alto Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SinkholingBadNetworkDomainsByRegisteringTheBadNetworkDomainsOnTheInternet_PaloAltoNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160381065A1"^^any u r i
kb-reference-ofop DNS Traffic Analysis
kb-reference-titledp "Sinkholing bad network domains by registering the bad network domains on the internet"

Reference - SNMP - Network Auto-Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SNMPNetworkAutoDiscovery

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.device42.com/auto-discovery/network-auto-discovery/"^^any u r i
kb-reference-ofop Active Logical Link Mapping
kb-reference-titledp "SNMP - Network Auto Discovery"

Reference - Software vulnerability graph databaseni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SoftwareVulnerabilityGraphDatabase

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/WO2020028535A1"^^any u r i
kb-reference-ofop Asset Vulnerability Enumeration
kb-reference-ofop System Dependency Mapping
kb-reference-ofop System Vulnerability Assessment
kb-reference-titledp "Software vulnerability graph database"

Reference - StreamingPhishni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-StreamingPhish

belongs to
Technique Referencec
has facts
has-linkdp "https://github.com/wesleyraptor/streamingphish"^^any u r i
kb-reference-ofop Passive Certificate Analysis
kb-reference-titledp "StreamingPhish"

Reference - Supply chain cyber-deception - Cymmetria, Inc.ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SupplyChainCyber-deception_Cymmetria,Inc.

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/WO2017187379A1"^^any u r i
kb-reference-ofop Decoy File
kb-reference-titledp "Supply chain cyber-deception"

Reference - Synchronizing a honey network configuration to reflect a target network environment - Palo Alto Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SynchronizingAHoneyNetworkConfigurationToReflectATargetNetworkEnvironment_PaloAltoNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170019425A1"^^any u r i
kb-reference-ofop Integrated Honeynet
kb-reference-titledp "Synchronizing a honey network configuration to reflect a target network environment"

Reference - System and a method for identifying the presence of malware and ransomware using mini-traps set at network endpoints - Fidelis Cybersecurity Solutions Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndAMethodForIdentifyingThePresenceOfMalwareAndRansomwareUsingMini-trapsSetAtNetworkEndpoints_FidelisCybersecuritySolutionsInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9807115B2/en?oq=US-9807115-B2"^^any u r i
kb-reference-ofop Decoy File
kb-reference-titledp "System and a method for identifying the presence of malware and ransomware using mini-traps set at network endpoints"

Reference - System and method for detecting homoglyph attacks with a siamese convolutional neural network - Endgame Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForDetectingHomoglyphAttacksWithASiameseConvolutionalNeuralNetwork_EndgameInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190019058A1/"^^any u r i
kb-reference-ofop Homoglyph Detection
kb-reference-titledp "System and method for detecting homoglyph attacks with a siamese convolutional neural network"

Reference - System and method for detecting malware injected into memory of a computing device - Endgame Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForDetectingMalwareInjectedIntoMemoryOfAComputingDevice_EndgameInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190018958A1/en?oq=US20190018958-A1"^^any u r i
kb-reference-ofop Process Code Segment Verification
kb-reference-titledp "System and method for detecting malware injected into memory of a computing device"

Reference - System and Method for Detection of a Change in Behavior in the Use of a Website Through Vector Velocity Analysis - Silver Tail Systemsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForDetectionOfAChangeInBehaviorInTheUseOfAWebsiteThroughVectorVelocityAnalysis_SilverTailSystems

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20100235909A1/en?oq=US+20100235909+A1"^^any u r i
kb-reference-ofop Web Session Activity Analysis
kb-reference-titledp "System and Method for Detection of a Change in Behavior in the Use of a Website Through Vector Velocity Analysis"

Reference - System and method for identifying the presence of malware using mini-traps set at network endpoints - Fidelis Cybersecurity Solutions Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForIdentifyingThePresenceOfMalwareUsingMini-trapsSetAtNetworkEndpoints_FidelisCybersecuritySolutionsInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9807114B2/en?oq=US-9807114-B2"^^any u r i
kb-reference-ofop Decoy Network Resource
kb-reference-ofop Decoy User Credential
kb-reference-titledp "System and method for identifying the presence of malware using mini-traps set at network endpoints"

Reference - System and method for internet security - Cylance Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForInternetSecurity_CylanceInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20120117644A1"^^any u r i
kb-reference-ofop Database Query String Analysis
kb-reference-titledp "System and method for internet security"

Reference - System and method for managed security assessment and mitigationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForManagedSecurityAssessmentAndMitigation

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9544324B2"^^any u r i
kb-reference-ofop Network Vulnerability Assessment
kb-reference-titledp "System and method for managed security assessment and mitigation"

Reference - System and Method for Network Security Including Detection of Attacks Through Partner Websites - EMC IP Holding Co LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForNetworkSecurityIncludingDetectionOfAttacksThroughPartnerWebsites_EMCIPHoldingCoLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20110302653A1/en?oq=US+20110302653+A1"^^any u r i
kb-reference-ofop Web Session Activity Analysis
kb-reference-titledp "System and Method for Network Security Including Detection of Attacks Through Partner Websites"

Reference - System and Method for Process Hollowing Detection - Carbon Black Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForProcessHollowingDetection_CarbonBlackInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170272462A1"^^any u r i
kb-reference-ofop Process Self-Modification Detection
kb-reference-titledp "System and Method for Process Hollowing Detection"

Reference - System and method for providing an actively invalidated client-side network resource cache - IMVUni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForProvidingAnActivelyInvalidatedClient-sideNetworkResourceCache_IMVU

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9578081B2/en"^^any u r i
kb-reference-ofop Authentication Cache Invalidation
kb-reference-titledp "System and method for providing an actively invalidated client-side network resource cache"

Reference - System and method for scanning remote services to locate stored objects with malwareni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForScanningRemoteServicesToLocateStoredObjectsWithMalware

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US11368475B1/"^^any u r i
kb-reference-ofop Email Removal
kb-reference-titledp "System and method for scanning remote services to locate stored objects with malware"

Reference - System and method for validating in-memory integrity of executable files to identify malicious activity - Endgame Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForValidatingIn-memoryIntegrityOfExecutableFilesToIdentifyMaliciousActivity_EndgameInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190018962A1/en?oq=15648887"^^any u r i
kb-reference-ofop Process Code Segment Verification
kb-reference-titledp "System and method for validating in-memory integrity of executable files to identify malicious activity"

Reference - System and method for vulnerability risk analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodForVulnerabilityRiskAssessment

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9317692B2"^^any u r i
kb-reference-ofop Asset Vulnerability Enumeration
kb-reference-titledp "System and method for vulnerability risk analysis"

Reference - System and method thereof for identifying and responding to security incidents based on preemptive forensics - Palo Alto Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodThereofForIdentifyingAndRespondingToSecurityIncidentsBasedOnPreemptiveForensics_PaloAltoNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160142424A1"^^any u r i
kb-reference-ofop Resource Access Pattern Analysis
kb-reference-ofop User Data Transfer Analysis
kb-reference-ofop Web Session Activity Analysis
kb-reference-titledp "System and method thereof for identifying and responding to security incidents based on preemptive forensics"

Reference - System and methods thereof for causality identification and attributions determination of processes in a network - Palo Alto Networks IncCyber Secdo Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodsThereofForCausalityIdentificationAndAttributionsDeterminationOfProcessesInANetwork_PaloAltoNetworksIncCyberSecdoLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170195350A1/en?oq=US-2017195350-A1"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "System and methods thereof for causality identification and attributions determination of processes in a network"

Reference - System and methods thereof for detection of persistent threats in a computerized environment background - Palo Alto Networks IncCyber Secdo Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodsThereofForDetectionOfPersistentThreatsInAComputerizedEnvironmentBackground_PaloAltoNetworksIncCyberSecdoLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170206358A1/en?oq=US-2017206358-A1"^^any u r i
kb-reference-titledp "System and methods thereof for detection of persistent threats in a computerized environment background"

Reference - System and methods thereof for identification of suspicious system processes - Palo Alto Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodsThereofForIdentificationOfSuspiciousSystemProcesses_PaloAltoNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170286683A1/en?oq=US-2017286683-A1"^^any u r i
kb-reference-ofop Process Lineage Analysis
kb-reference-titledp "System and methods thereof for identification of suspicious system processes"

Reference - System and methods thereof for logical identification of malicious threats across a plurality of end-point devices (epd) communicatively connected by a network - Palo Alto Networks IncCyber Secdo Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodsThereofForLogicalIdentificationOfMaliciousThreatsAcrossAPluralityOfEnd-pointDevicesCommunicativelyConnectedByANetwork_PaloAltoNetworksIncCyberSecdoLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20180373870A1/en?oq=US-2018373870-A1"^^any u r i
kb-reference-ofop File Content Rules
kb-reference-titledp "System and methods thereof for logical identification of malicious threats across a plurality of end-point devices (epd) communicatively connected by a network"

Reference - System and methods thereof for preventing ransomware from encrypting data elements stored in a memory of a computer-based system - Palo Alto Networks Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemAndMethodsThereofForPreventingRansomwareFromEncryptingDataElementsStoredInAMemoryOfAComputer-basedSystem_PaloAltoNetworksInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170308711A1/en?oq=US-2017308711-A1"^^any u r i
kb-reference-ofop Decoy File
kb-reference-titledp "System and methods thereof for preventing ransomware from encrypting data elements stored in a memory of a computer-based system"

Reference - System for detecting threats using scenario-based tracking of internal and external network traffic - VECTRA NETWORKS Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemForDetectingThreatsUsingScenario-basedTrackingOfInternalAndExternalNetworkTraffic_VECTRANETWORKSInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160191563A1"^^any u r i
kb-reference-ofop Per Host Download-Upload Ratio Analysis
kb-reference-titledp "System for detecting threats using scenario-based tracking of internal and external network traffic"

Reference - System for implementing threat detection using daily network traffic community outliers - VECTRA NETWORKS Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemForImplementingThreatDetectionUsingDailyNetworkTrafficCommunityOutliers_VECTRANETWORKSInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160191560A1"^^any u r i
kb-reference-ofop Network Traffic Community Deviation
kb-reference-ofop Protocol Metadata Anomaly Detection
kb-reference-titledp "System for implementing threat detection using daily network traffic community outliers"

Reference - System for implementing threat detection using threat and risk assessment of asset-actor interactions - VECTRA NETWORKS Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemForImplementingThreatDetectionUsingThreatAndRiskAssessmentOfAsset-actorInteractions_VECTRANETWORKSInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20160191559A1"^^any u r i
kb-reference-ofop User Data Transfer Analysis
kb-reference-titledp "System for implementing threat detection using threat and risk assessment of asset-actor interactions"

Reference - System, method, and computer program product for detecting and assessing security risks in a network - Exabeam Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-System,Method,AndComputerProgramProductForDetectingAndAssessingSecurityRisksInANetwork_ExabeamInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20190034641A1"^^any u r i
kb-reference-ofop Authentication Event Thresholding
kb-reference-ofop Authorization Event Thresholding
kb-reference-ofop Resource Access Pattern Analysis
kb-reference-ofop Session Duration Analysis
kb-reference-ofop User Geolocation Logon Pattern Analysis
kb-reference-titledp "System, method, and computer program product for detecting and assessing security risks in a network"

Reference - Systems and methods for detecting and/or handling targeted attacks in the email channel - Graphus Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemsAndMethodsForDetectingAnd_orHandlingTargetedAttacksInTheEmailChannel_GraphusInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20170324767A1"^^any u r i
kb-reference-ofop Sender MTA Reputation Analysis
kb-reference-ofop Sender Reputation Analysis
kb-reference-titledp "Systems and methods for detecting and/or handling targeted attacks in the email channel"

Reference - Systems and methods for detecting credential theft - Symantec Corpni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-SystemsAndMethodsForDetectingCredentialTheft_SymantecCorp

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10162962B1"^^any u r i
kb-reference-ofop Credential Compromise Scope Analysis
kb-reference-titledp "Systems and methods for detecting credential theft"

Reference - Tamper proof mutating software - ARXAN TECHNOLOGIES Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-TamperProofMutatingSoftware_ARXANTECHNOLOGIESInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9262600B2/en?oq=US9262600B2"^^any u r i
kb-reference-ofop Process Code Segment Verification
kb-reference-titledp "Tamper proof mutating software"

Reference - TCG Trusted Attestation Protocol Use Cases for TPM Families 1.2 and 2.0 and DICEni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-TCGTrustedAttestationProtocolUseCasesForTPMFamilies1.2And2.0AndDICE

belongs to
Specification Referencec
has facts
has-linkdp "https://trustedcomputinggroup.org/wp-content/uploads/TCG_TNC_TAP_Use_Cases_v1r0p35_published.pdf"^^any u r i
kb-reference-titledp "TCG Trusted Attestation Protocol Use Cases for TPM Families 1.2 and 2.0 and DICE"

Reference - Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilitiesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Technical_Specifications_for_Construction_and_Management_of_Sensitive_Compartmented_Information_Facilities

belongs to
Specification Referencec
has facts
has-linkdp "https://www.dni.gov/files/Governance/IC-Tech-Specs-for-Const-and-Mgmt-of-SCIFs-v15.pdf"^^any u r i
kb-reference-ofop RF Shielding
kb-reference-titledp "Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities"

Reference - Techniques for impeding and detecting network threats - Verisign Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-TechniquesForImpedingAndDetectingNetworkThreats_VerisignInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US10904273B1/"^^any u r i
kb-reference-ofop Decoy Network Resource
kb-reference-titledp "Techniques for impeding and detecting network threats"

Reference - Tenable Passive Network Monitoringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-TenablePassiveNetworkMonitoring

belongs to
Internet Article Referencec
has facts
has-linkdp "https://www.tenable.com/sites/default/files/solution-briefs/SB-Passive-Network-Monitoring.pdf"^^any u r i
kb-reference-ofop Passive Logical Link Mapping
kb-reference-ofop Passive Physical Link Mapping
kb-reference-titledp "Tenable Passive Network Monitoring"

Reference - Testing Metrics for Password Creation Policies by Attacking Large Sets of Revealed Passwordsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Testing_Metrics_for_Password_Creation_Policies_by_Attacking_Large_Sets_of_Revealed_Passwords

belongs to
Academic Paper Referencec
has facts
has-linkdp "https://www.cs.umd.edu/~jkatz/security/downloads/passwords_revealed-weir.pdf"^^any u r i
kb-reference-ofop Strong Password Policy
kb-reference-titledp "Testing Metrics for Password Creation Policies by Attacking Large Sets of Revealed Passwords"

Reference - The Pyramid of Pain - David Bianconi back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ThePyramidOfPain-DavidBianco

belongs to
Internet Article Referencec
has facts
has-linkdp "http://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html"^^any u r i
kb-reference-ofop Identifier Activity Analysis
kb-reference-titledp "The Pyramid of Pain"

Reference - Threat detection for return oriented programming - Crowdstrike Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ThreatDetectionForReturnOrientedProgramming_CrowdstrikeInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20140075556A1"^^any u r i
kb-reference-ofop Shadow Stack Comparisons
kb-reference-titledp "Threat detection for return oriented programming"

Reference - Threat detection through the accumulated detection of threat characteristics - Sophos Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-ThreatDetectionThroughTheAccumulatedDetectionOfThreatCharacteristics_SophosLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9104864B2/en?oq=US-9104864-B2"^^any u r i
kb-reference-ofop Process Code Segment Verification
kb-reference-titledp "Threat detection through the accumulated detection of threat characteristics"

Reference - Tivoli Application Dependency Discovery Manager 7.3.0 - Dependencies between resourcesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-TivoliApplicationDependencyDiscoverManager7_3_0DependenciesBetweenResources

belongs to
User Manual Referencec
has facts
has-linkdp "https://www.ibm.com/docs/en/taddm/7.3.0?topic=model-dependencies-between-resources"^^any u r i
kb-reference-ofop Data Exchange Mapping
kb-reference-ofop Service Dependency Mapping
kb-reference-ofop System Dependency Mapping
kb-reference-titledp "Tivoli Application Dependency Discovery Manager 7.3.0 - Dependencies between resources"

Reference - Tokenless biometric transaction authorization method and systemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-TokenlessBiometricTransactionAuthorizationMethodAndSystem

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US5870723A/"^^any u r i
kb-reference-ofop Biometric Authentication
kb-reference-titledp "Tokenless biometric transaction authorization method and system"

Reference - TPM 2.0 Library Specification - Trusted Computing Group, Incorporatedni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-TPM2.0LibrarySpecification_TrustedComputingGroup,Incorporated

belongs to
Specification Referencec
has facts
has-linkdp "https://trustedcomputinggroup.org/resource/tpm-library-specification/"^^any u r i
kb-reference-ofop TPM Boot Integrity
kb-reference-titledp "TPM 2.0 Library Specification"

Reference - Trusted Attestation Protocol Use Casesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-TrustedAttestationProtocolUseCases

belongs to
Specification Referencec
has facts
has-linkdp "https://trustedcomputinggroup.org/wp-content/uploads/TCG_TNC_TAP_Use_Cases_v1r0p35_published.pdf"^^any u r i
kb-reference-titledp "Trusted Attestation Protocol Use Cases"

Reference - Trusted Communications With Child Processes - Microsoft Technology Licensing LLCni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-TrustedCommunicationsWithChildProcesses_MicrosoftTechnologyLicensingLLC

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20120174210A1"^^any u r i
kb-reference-titledp "Trusted Communications With Child Processes"

Reference - UEFI Platform Initialization (PI) Specificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UEFIPlatformInitialization-Specification

belongs to
Specification Referencec
has facts
has-linkdp "https://uefi.org/sites/default/files/resources/PI_Spec_1_7_A_final_May1.pdf"^^any u r i
kb-reference-ofop Bootloader Authentication
kb-reference-titledp "UEFI Platform Initialization (PI) Specification"

Reference - Unified Architecture Framework (UAF)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UnifiedArchitectureFrameworkUAF

belongs to
Specification Referencec
has facts
has-linkdp "https://www.omg.org/spec/UAF/"^^any u r i
kb-reference-ofop Data Exchange Mapping
kb-reference-ofop Operational Activity Mapping
kb-reference-ofop Operational Dependency Mapping
kb-reference-ofop Organization Mapping
kb-reference-ofop Service Dependency Mapping
kb-reference-ofop System Dependency Mapping
kb-reference-titledp "Unified Architecture Framework (UAF)"

Reference - USB filter for hub malicious code prevention systemni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-USBFilterForHubMaliciousCodePreventionSystem

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US9990325B2/en"^^any u r i
kb-reference-ofop IO Port Restriction
kb-reference-titledp "Universal serial bus (USB) filter hub malicious code prevention system"

Reference - Use DNS Policy for Applying Filters on DNS Queriesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UseDNSPolicyForApplyingFiltersOnDNSQueries

belongs to
User Manual Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/windows-server/networking/dns/deploy/apply-filters-on-dns-queries"^^any u r i
kb-reference-titledp "Use DNS Policy for Applying Filters on DNS Queries"

Reference - Use of an application controller to monitor and control software file and application environments - Sophos Ltdni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UseOfAnApplicationControllerToMonitorAndControlSoftwareFileAndApplicationEnvironments_SophosLtd

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20180032727A1"^^any u r i
kb-reference-ofop Dynamic Analysis
kb-reference-titledp "Use of an application controller to monitor and control software file and application environments"

Reference - Use Rkill to Stop Malware Processes - ghacks.netni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UseRkillToStopMalwareProcesses-Ghacks.net

belongs to
Technique Referencec
has facts
has-linkdp "https://www.ghacks.net/2011/07/29/use-rkill-to-stop-malware-processes/"^^any u r i
kb-reference-ofop Process Termination
kb-reference-titledp "Use Rkill to Stop Malware Processes"

Reference - Using spanning tree protocol (STP) to enhance layer-2 topology mapsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-UsingSpanningTreeProtocolSTPToEnhanceLayer2NetworkTopologyMaps

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US8045488B2"^^any u r i
kb-reference-ofop Active Physical Link Mapping
kb-reference-titledp "Using spanning tree protocol (STP) to enhance layer-2 topology maps"

Reference - Virtualized process isolation - Advanced Micro Devices Incni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-VirtualizedProcessIsolation_AdvancedMicroDevicesInc

belongs to
Patent Referencec
has facts
has-linkdp "https://patents.google.com/patent/US20180081829A1"^^any u r i
kb-reference-ofop Hardware-based Process Isolation
kb-reference-titledp "Virtualized process isolation"

Reference - Web Authentication: An API for accessing Public Key Credentials Level 2ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-WebAuthentication_AnAPIForAccessingPublicKeyCredentials%0ALevel2

belongs to
Specification Referencec
has facts
has-linkdp "https://www.w3.org/TR/webauthn-2/"^^any u r i
kb-reference-ofop Credential Transmission Scoping
kb-reference-titledp "Web Authentication: An API for accessing Public Key Credentials Level 2"

Reference - Web-Based Enterprise Managementni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Web-BasedEnterpriseManagement

belongs to
Specification Referencec
has facts
has-linkdp "https://www.dmtf.org/standards/wbem"^^any u r i
kb-reference-ofop Configuration Inventory
kb-reference-ofop Hardware Component Inventory
kb-reference-ofop Network Node Inventory
kb-reference-ofop Software Inventory
kb-reference-titledp "Web-Based Enterprise Management"

Reference - What is NX/XD feature?ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-WhatIsNX_XDFeature_RedHat

belongs to
Internet Article Referencec
has facts
has-linkdp "https://access.redhat.com/solutions/2936741"^^any u r i
kb-reference-ofop Process Segment Execution Prevention
kb-reference-titledp "What is NX/XD feature?"

Reference - Windows 10 STIGni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Windows10STIG

belongs to
Guideline Referencec
has facts
has-linkdp "https://www.stigviewer.com/stig/windows_10/"^^any u r i
kb-reference-ofop Application Configuration Hardening
kb-reference-titledp "Windows 10 Security Technical Implementation Guide"

Reference - Windows Management Infrastructure (MI)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Windows-Management-Infrastructure

belongs to
Specification Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/previous-versions/windows/desktop/wmi_v2/windows-management-infrastructure"^^any u r i
kb-reference-ofop Configuration Inventory
kb-reference-ofop Hardware Component Inventory
kb-reference-ofop Network Node Inventory
kb-reference-ofop Software Inventory
kb-reference-titledp "Windows Management Infrastructure"

Reference - Windows Management Instrumentation (WMI)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Reference-Windows-Management-Instrumentation

belongs to
Specification Referencec
has facts
has-linkdp "https://docs.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page"^^any u r i
kb-reference-ofop Configuration Inventory
kb-reference-ofop Hardware Component Inventory
kb-reference-ofop Network Node Inventory
kb-reference-ofop Software Inventory
kb-reference-titledp "Windows Management Instrumentation"

Reflection Amplificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1498.002

has facts
producesop Inbound Internet Network Traffic
is also defined as
class

Reflective Code Loadingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1620

has facts
modifiesop Process Segment
is also defined as
class

reg open key ani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegOpenKeyA

belongs to
Get System Config Valuec

reg open key ex ani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegOpenKeyExA

belongs to
Get System Config Valuec

reg open key ex wni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegOpenKeyExW

belongs to
Get System Config Valuec

reg open key transacted ani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegOpenKeyTransactedA

belongs to
Get System Config Valuec

reg open key transacted wni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegOpenKeyTransactedW

belongs to
Get System Config Valuec

reg open key wni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegOpenKeyW

belongs to
Get System Config Valuec

reg set key value ani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegSetKeyValueA

belongs to
Set System Config Valuec

reg set key value wni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegSetKeyValueW

belongs to
Set System Config Valuec

reg set value ani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegSetValueA

belongs to
Set System Config Valuec

reg set value ex ani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegSetValueExA

belongs to
Set System Config Valuec

reg set value ex wni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegSetValueExW

belongs to
Set System Config Valuec

reg set value wni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RegSetValueW

belongs to
Set System Config Valuec

Registry Run Keys / Startup Folderni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.001

has facts
may-modifyop System Configuration Init Database Record
may-modifyop User Startup Script File
is also defined as
class

Relay Pattern Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RelayPatternAnalysis

belongs to
Network Traffic Analysisc
has facts
analyzesop Outbound Internet Network Traffic
d3fend-iddp "D3-RPA"
kb-referenceop Reference - Malicious relay detection on networks - VECTRA NETWORKS Inc
is also defined as
class

Remote Access Softwareni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1219

has facts
producesop Outbound Internet Network Traffic
is also defined as
class

Remote Data Stagingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1074.002

has facts
modifiesop Network Resource
is also defined as
class

Remote Data Storageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1029

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "IT disaster recovery plans are outside the current scope of D3FEND."

Remote Desktop Protocolni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021.001

has facts
createsop RDP Session
producesop Administrative Network Traffic
is also defined as
class

Remote Email Collectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1114.002

has facts
accessesop Mail Server
is also defined as
class

Remote Service Session Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1563

has facts
accessesop Remote Session
producesop Administrative Network Traffic
is also defined as
class

Remote Servicesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021

has facts
producesop Intranet Network Traffic
is also defined as
class

Remote System Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1018

has facts
may-accessop Operating System Configuration File
may-invokeop Create Process
may-invokeop Create Socket
producesop Network Traffic
is also defined as
class

Remote Terminal Session Detectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RemoteTerminalSessionDetection

belongs to
Network Traffic Analysisc
has facts
analyzesop Network Traffic
d3fend-iddp "D3-RTSD"
kb-referenceop Reference - Method and system for detecting external control of compromised hosts - VECTRA NETWORKS Inc
kb-referenceop Reference - CAR-2013-07-002: RDP Connection Detection - MITRE
kb-referenceop Reference - CAR-2016-04-005: Remote Desktop Logon - MITRE
is also defined as
class

Rename System Utilitiesni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.003

has facts
may-createop Executable File
may-modifyop Operating System Executable File
is also defined as
class

Replication Through Removable Mediani back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1091

has facts
executesop Removable Media Device
is also defined as
class

Resource Access Pattern Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ResourceAccessPatternAnalysis

belongs to
User Behavior Analysisc
has facts
analyzesop Authentication
analyzesop Authorization
d3fend-iddp "D3-RAPA"
kb-referenceop Reference - Host intrusion prevention system using software and user behavior analysis - Sophos Ltd
kb-referenceop Reference - Method and Apparatus for Network Fraud Detection and Remediation Through Analytics - Idaptive LLC
kb-referenceop Reference - Modeling user access to computer resources - Daedalus Group LLC (formerly IBM)
kb-referenceop Reference - System and method thereof for identifying and responding to security incidents based on preemptive forensics - Palo Alto Networks Inc
kb-referenceop Reference - System, method, and computer program product for detecting and assessing security risks in a network - Exabeam Inc
is also defined as
class

Resource Development Techniqueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ResourceDevelopmentTechnique

has facts
enablesop reconnaissance
is also defined as
class

Resource Forkingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.009

has facts
may-createop Resource Fork
may-modifyop Resource Fork
is also defined as
class

Restrict File and Directory Permissionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1022

belongs to
ATTACK Mitigationc
has facts
relatedop Local File Permissions

Restrict Library Loadingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1044

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "D3-SCF is one possible way to filter library loading."
relatedop System Call Filtering

Restrict Registry Permissionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1024

belongs to
ATTACK Mitigationc
has facts
relatedop System Configuration Permissions

Restrict Web-Based Contentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1021

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "M1021 scope is broad, touches on an wide variety of techniques in d3fend."
relatedop DNS Allowlisting
relatedop DNS Denylisting
relatedop File Analysis
relatedop Inbound Traffic Filtering
relatedop Network Traffic Analysis
relatedop Outbound Traffic Filtering
relatedop URL Analysis

Reverse Resolution Domain Denylistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReverseResolutionDomainDenylisting

belongs to
DNS Denylistingc
has facts
blocksop Inbound Internet DNS Response Traffic
d3fend-iddp "D3-RRDD"
is also defined as
class

Reverse Resolution IP Denylistingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ReverseResolutionIPDenylisting

belongs to
DNS Denylistingc
has facts
blocksop Outbound Internet DNS Lookup Traffic
d3fend-iddp "D3-RRID"
kb-referenceop Reference - Use DNS Policy for Applying Filters on DNS Queries
is also defined as
class

RF Shieldingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RFShielding

belongs to
Platform Hardeningc
has facts
d3fend-iddp "D3-RFS"
kb-referenceop Reference - Privacy and security systems and methods of use
kb-referenceop Reference - Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities
is also defined as
class

Right-to-Left Overrideni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.002

has facts
modifiesop File System Metadata
is also defined as
class

Rogue Domain Controllerni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1207

has facts
modifiesop System Configuration Database
producesop Intranet Administrative Network Traffic
is also defined as
class

Rootkitni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1014

has facts
may-modifyop Boot Sector
may-modifyop Firmware
may-modifyop Kernel
may-modifyop Kernel Module
may-modifyop Shared Library File
is also defined as
class

RPC Traffic Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RPCTrafficAnalysis

belongs to
Network Traffic Analysisc
has facts
analyzesop RPC Network Traffic
d3fend-iddp "D3-RTA"
kb-referenceop Reference - CAR-2014-11-007: Remote Windows Management Instrumentation (WMI) over RPC - MITRE
kb-referenceop Reference - CAR-2016-03-002: Create Remote Process via WMIC - MITRE
kb-referenceop Reference - RPC call interception - Crowdstrike Inc
kb-referenceop Reference - CAR-2014-03-005: Remotely Launched Executables via Services - MITRE
kb-referenceop Reference - CAR-2014-12-001: Remotely Launched Executables via WMI - MITRE
kb-referenceop Reference - CAR-2015-04-002: Remotely Scheduled Tasks via Schtasks - MITRE
kb-referenceop Reference - CAR-2014-03-001: SMB Write Request - NamedPipes - MITRE
kb-referenceop Reference - CAR-2014-05-001: RPC Activity - MITRE
is also defined as
class

Ruby Script Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#RubyScriptFile

belongs to
Executable Scriptc

Run Virtual Instanceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.006

has facts
createsop File
executesop Virtualization Software
may-addop Virtualization Software
may-createop Directory
is also defined as
class

Rundll32 Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1218.011

has facts
invokesop Create Process
loadsop Shared Library File
is also defined as
class

Runtime Data Manipulationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1565.003

has facts
may-modifyop Executable File
is also defined as
class

SA-10(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SA-10_1

belongs to
NIST Controlc
has facts
control-namedp "Developer Configuration Management | Software and Firmware Integrity Verification"
member-ofop NIST SP 800-53 R5
relatedop Firmware Verification
relatedop Platform Hardening

SA-10(3)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SA-10_3

belongs to
NIST Controlc
has facts
control-namedp "Developer Configuration Management | Hardware Integrity Verification"
member-ofop NIST SP 800-53 R5
relatedop Firmware Verification

SA-10(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SA-10_4

belongs to
NIST Controlc
has facts
control-namedp "Developer Configuration Management | Trusted Generation"
member-ofop NIST SP 800-53 R5
relatedop Firmware Verification

SA-10(5)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SA-10_5

belongs to
NIST Controlc
has facts
control-namedp "Developer Configuration Management | Mapping Integrity for Version Control"
member-ofop NIST SP 800-53 R5
relatedop Firmware Verification
relatedop Platform Hardening

SA-10(6)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SA-10_6

belongs to
NIST Controlc
has facts
control-namedp "Developer Configuration Management | Trusted Distribution"
member-ofop NIST SP 800-53 R5
relatedop Firmware Verification
relatedop Platform Hardening

SA-11(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SA-11_1

belongs to
NIST Controlc
has facts
control-namedp "Developer Testing and Evaluation | Static Code Analysis"
member-ofop NIST SP 800-53 R5
relatedop Application Hardening

SA-11(8)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SA-11_8

belongs to
NIST Controlc
has facts
control-namedp "Developer Testing and Evaluation | Dynamic Code Analysis"
member-ofop NIST SP 800-53 R5
relatedop Application Hardening

SA-8(18)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SA-8_18

belongs to
NIST Controlc
has facts
control-namedp "Security and Privacy Engineering Principles | Trusted Communications Channels"
member-ofop NIST SP 800-53 R5
relatedop Encrypted Tunnels

SA-8(22)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SA-8_22

belongs to
NIST Controlc
has facts
control-namedp "Security and Privacy Engineering Principles | Accountability and Traceability"
member-ofop NIST SP 800-53 R5
relatedop Domain Account Monitoring

Safe Mode Bootni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1562.009

has facts
disablesop Endpoint Sensor
disablesop System Configuration Init Database Record
may-modifyop Endpoint Health Beacon
is also defined as
class

SC-2ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SC-2

belongs to
NIST Controlc
has facts
broaderop Local File Permissions
broaderop Mandatory Access Control
broaderop System Configuration Permissions
control-namedp "Separation of System and User Functionality"
member-ofop NIST SP 800-53 R5

SC-2(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SC-2_1

belongs to
NIST Controlc
has facts
control-namedp "Separation of System and User Functionality | Interfaces for Non-privileged Users"
member-ofop NIST SP 800-53 R5
narrowerop Local File Permissions
narrowerop Mandatory Access Control
narrowerop System Configuration Permissions

SC-3ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SC-3

belongs to
NIST Controlc
has facts
broaderop Execution Isolation
broaderop Network Isolation
control-namedp "Security Function Isolation"
member-ofop NIST SP 800-53 R5

SC-3(1)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SC-3_1

belongs to
NIST Controlc
has facts
control-namedp "Security Function Isolation | Hardware Separation"
member-ofop NIST SP 800-53 R5
narrowerop Execution Isolation

Scheduled Job Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ScheduledJobAnalysis

belongs to
Operating System Monitoringc
has facts
analyzesop Task Schedule
d3fend-iddp "D3-SJA"
kb-referenceop Reference - CAR-2013-05-004: Execution with AT - MITRE
kb-referenceop Reference - CAR-2013-08-001: Execution with schtasks - MITRE
kb-referenceop Reference - Preventing execution of task scheduled malware - McAfee LLC
is also defined as
class

Scheduled Task/Job Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1053

has facts
invokesop Create Process
modifiesop Task Schedule
is also defined as
class

Scheduled Transferni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1029

has facts
producesop Internet Network Traffic
is also defined as
class

Screen Captureni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1113

has facts
may-accessop Display Server
may-invokeop Get Screen Capture
is also defined as
class

Screensaverni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.002

has facts
createsop Executable File
modifiesop System Configuration Database Record
is also defined as
class

Script Application Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ScriptApplicationProcess

has facts
interpretsop Executable Script
is also defined as
class

Script Execution Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ScriptExecutionAnalysis

belongs to
Process Analysisc
has facts
analyzesop Script Application Process
d3fend-iddp "D3-SEA"
kb-referenceop Reference - Detecting script-based malware - Crowdstrike Inc
is also defined as
class

Security Account Managerni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1003.002

has facts
may-accessop Authentication Service
may-accessop Process
may-accessop System Password Database
is also defined as
class

Security Software Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1518.001

has facts
may-accessop File System Metadata
may-accessop Kernel Process Table
may-accessop System Configuration Database Record
may-accessop System Firewall Configuration
may-invokeop Get Running Processes
is also defined as
class

Security Support Providerni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.005

has facts
modifiesop System Configuration Database Record
is also defined as
class

Security Tokenni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SecurityToken

has facts
containsop Access Token
is also defined as
class

Securityd Memoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1555.002

has facts
accessesop In-memory Password Store
is also defined as
class

Segment Address Offset Randomizationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SegmentAddressOffsetRandomization

belongs to
Application Hardeningc
has facts
d3fend-iddp "D3-SAOR"
kb-referenceop Reference - /DYNAMICBASE (Use address space layout randomization) - Microsoft Docs
kb-referenceop Reference - How ASLR protects Linux systems from buffer overflow attacks - Network World
obfuscatesop Process Segment
is also defined as
class

Sender MTA Reputation Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SenderMTAReputationAnalysis

belongs to
Message Analysisc
has facts
analyzesop Email
d3fend-iddp "D3-SMRA"
kb-referenceop Reference - Systems and methods for detecting and/or handling targeted attacks in the email channel - Graphus Inc
is also defined as
class

Sender Reputation Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SenderReputationAnalysis

belongs to
Message Analysisc
has facts
analyzesop Email
d3fend-iddp "D3-SRA"
kb-referenceop Reference - Systems and methods for detecting and/or handling targeted attacks in the email channel - Graphus Inc
is also defined as
class

Serverni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Server

has facts
managesop Service Application Process
runsop Service Application
is also defined as
class

Server-Side Request Forgery (SSRF)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-918

has facts
weakness ofop User Input Function
is also defined as
class

Service Binary Verificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ServiceBinaryVerification

belongs to
System File Analysisc
has facts
d3fend-iddp "D3-SBV"
kb-referenceop Reference - CAR-2014-02-001: Service Binary Modifications - MITRE
verifiesop Service Application
is also defined as
class

Service Dependency Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ServiceDependencyMapping

belongs to
System Mappingc
has facts
d3fend-iddp "D3-SVCDM"
kb-referenceop Reference - Catia UAF Plugin
kb-referenceop Reference - Tivoli Application Dependency Discovery Manager 7.3.0 - Dependencies between resources
kb-referenceop Reference - Unified Architecture Framework (UAF)
mapsop Service Dependency
is also defined as
class

Service Exhaustion Floodni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1499.002

has facts
producesop Inbound Internet Network Traffic
is also defined as
class

Services File Permissions Weaknessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.010

has facts
modifiesop Service Application
is also defined as
class

Services Registry Permissions Weaknessni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1574.011

has facts
modifiesop System Configuration Init Database Record
is also defined as
class

Session Duration Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SessionDurationAnalysis

belongs to
User Behavior Analysisc
has facts
analyzesop Authentication
analyzesop Authorization
d3fend-iddp "D3-SDA"
kb-referenceop Reference - Method and Apparatus for Network Fraud Detection and Remediation Through Analytics - Idaptive LLC
kb-referenceop Reference - System, method, and computer program product for detecting and assessing security risks in a network - Exabeam Inc
is also defined as
class

Set System Config Valueni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SetSystemConfigValue

has facts
modifiesop System Configuration Database Record
is also defined as
class

Setuid and Setgidni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1548.001

has facts
modifiesop Access Control Configuration
is also defined as
class

Shadow Stackni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ShadowStack

has facts
copy-ofop Call Stack
is also defined as
class

Shadow Stack Comparisonsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ShadowStackComparisons

belongs to
Process Analysisc
has facts
analyzesop Stack Frame
d3fend-iddp "D3-SSC"
kb-referenceop Reference - Threat detection for return oriented programming - Crowdstrike Inc
is also defined as
class

Shared Resource Access Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SharedResourceAccessFunction

has facts
accessesop Resource
is also defined as
class

Sharepointni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1213.002

has facts
accessesop Web File Resource
is also defined as
class

Shortcut Modificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.009

has facts
may-modifyop Symbolic Link
may-modifyop User Startup Script File
is also defined as
class

SI-2(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-2_4

belongs to
NIST Controlc
has facts
control-namedp "Flaw Remediation | Automated Patch Management Tools"
member-ofop NIST SP 800-53 R5
narrowerop Software Update

SI-2(5)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-2_5

belongs to
NIST Controlc
has facts
control-namedp "Flaw Remediation | Automatic Software and Firmware Updates"
exactlyop Firmware Verification
exactlyop Peripheral Firmware Verification
exactlyop Software Update
exactlyop System Firmware Verification
member-ofop NIST SP 800-53 R5

SI-2(6)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-2_6

belongs to
NIST Controlc
has facts
control-namedp "Flaw Remediation | Removal of Previous Versions of Software and Firmware"
member-ofop NIST SP 800-53 R5
narrowerop Firmware Verification
narrowerop Peripheral Firmware Verification
narrowerop Software Update
narrowerop System Firmware Verification

SI-3ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-3

belongs to
NIST Controlc
has facts
broaderop File Analysis
broaderop Network Traffic Analysis
broaderop Platform Monitoring
broaderop Process Analysis
control-namedp "Malicious Code Protection"
member-ofop NIST SP 800-53 R5

SI-3(10)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-3_10

belongs to
NIST Controlc
has facts
control-namedp "Malicious Code Protection | Malicious Code Analysis"
exactlyop Dynamic Analysis
member-ofop NIST SP 800-53 R5

SI-3(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-3_4

belongs to
NIST Controlc
has facts
control-namedp "Malicious Code Protection | Updates Only by Privileged Users"
member-ofop NIST SP 800-53 R5
narrowerop Local File Permissions
narrowerop Mandatory Access Control
narrowerop System Configuration Permissions

SI-3(8)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-3_8

belongs to
NIST Controlc
has facts
control-namedp "Malicious Code Protection | Detect Unauthorized Commands"
member-ofop NIST SP 800-53 R5
narrowerop User Behavior Analysis

SI-4ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-4

belongs to
NIST Controlc
has facts
broaderop Operating System Monitoring
control-namedp "System Monitoring"
member-ofop NIST SP 800-53 R5

SI-4(2)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-4_2

belongs to
NIST Controlc
has facts
control-namedp "System Monitoring | Automated Tools and Mechanisms for Real-time Analysis"
member-ofop NIST SP 800-53 R5
narrowerop Network Traffic Analysis

SI-4(4)ni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#NIST_SP_800-53_R5_SI-4_4

belongs to
NIST Controlc
has facts
control-namedp "System Monitoring | Inbound and Outbound Communications Traffic"
member-ofop NIST SP 800-53 R5
narrowerop Network Traffic Analysis

SID-History Injectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.005

has facts
modifiesop Access Control Configuration
is also defined as
class

SIP and Trust Provider Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1553.003

has facts
modifiesop System Configuration Database Record
is also defined as
class

Softwareni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Software

has facts
containsop Executable File
instructsop Process
is also defined as
class

Software Configurationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1054

belongs to
ATTACK Mitigationc
has facts
relatedop Application Configuration Hardening
relatedop Certificate Pinning

Software Deployment Tools Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1072

has facts
addsop File
executesop Software Deployment Tool
installsop Software
is also defined as
class

Software Inventoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareInventory

belongs to
Asset Inventoryc
has facts
d3fend-iddp "D3-SWI"
inventoriesop Software
kb-referenceop Reference - Web-Based Enterprise Management
kb-referenceop Reference - Windows Management Infrastructure (MI)
kb-referenceop Reference - Windows Management Instrumentation (WMI)
is also defined as
class

Software Libraryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareLibrary

has facts
containsop Software Library File
is also defined as
class

Software Library Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareLibraryFile

has facts
containsop Subroutine
may-containop Executable Binary
may-containop Executable Script
is also defined as
class

Software Packingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1027.002

has facts
obfuscatesop Executable File
is also defined as
class

Software Updateni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SoftwareUpdate

belongs to
Platform Hardeningc
has facts
d3fend-iddp "D3-SU"
kb-referenceop Reference - Method and system for providing software updates to local machines
updatesop Software
is also defined as
class

Source Codeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SourceCode

belongs to
Reference Typec
is also defined as
class

Space after Filenameni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1036.006

has facts
createsop File
is also defined as
class

Spearphishing Attachmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1566.001

has facts
producesop Email
producesop Inbound Internet Mail Traffic
is also defined as
class

Spearphishing Linkni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1566.002

has facts
producesop Email
producesop Inbound Internet Mail Traffic
producesop URL
is also defined as
class

Spearphishing Via Serviceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1566.003

has facts
producesop File
producesop URL
is also defined as
class

SQL Stored Proceduresni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.001

has facts
createsop Stored Procedure
invokesop Create Process
is also defined as
class

SSHni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1021.004

has facts
createsop SSH Session
producesop Administrative Network Traffic
is also defined as
class

SSH Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1563.001

has facts
accessesop SSH Session
is also defined as
class

SSL/TLS Inspectionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1020

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "D3FEND models this as an infrastructure dependency to support D3-NTA."
relatedop Network Traffic Analysis

Stack Frameni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StackFrame

has facts
may-containop Pointer
may-containop Stack Frame Canary
is also defined as
class

Stack Frame Canary Validationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StackFrameCanaryValidation

belongs to
Application Hardeningc
has facts
d3fend-iddp "D3-SFCV"
kb-referenceop Reference - /GS (Buffer Security Check) - Microsoft Docs
kb-referenceop Reference - Security Technologies: Stack Smashing Protection (StackGuard) - Red Hat
validatesop Stack Frame
is also defined as
class

Stack Segmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StackSegment

has facts
containsop Stack Frame
is also defined as
class

Standalone Honeynetni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StandaloneHoneynet

belongs to
Decoy Environmentc
has facts
d3fend-iddp "D3-SHN"
kb-referenceop Reference - Dynamic selection and generation of a virtual clone for detonation of suspicious content within a honey network - Palo Alto Networks Inc
spoofsop Intranet Network
is also defined as
class

Startup Itemsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1037.005

has facts
modifiesop System Startup Directory
is also defined as
class

Steal Application Access Tokenni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1528

has facts
accessesop Access Token
is also defined as
class

Steal or Forge Kerberos Ticketsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1558

has facts
may-accessop Kerberos Ticket
may-createop Kerberos Ticket
is also defined as
class

Steal Web Session Cookieni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1539

has facts
accessesop Session Cookie
is also defined as
class

Step 1 - Copy Tokenni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#step-1

belongs to
stepc
has facts
invokesop Copy Token
nextop Step 2 - Impersonate User

Step 2 - Impersonate Userni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#step-2

belongs to
stepc
has facts
createsop Authentication
invokesop Impersonate User

Storageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#Storage

has facts
may-containop File System
is also defined as
class

Stored Data Manipulationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1565.001

has facts
modifiesop File
is also defined as
class

Strong Password Policyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#StrongPasswordPolicy

belongs to
Credential Hardeningc
has facts
d3fend-iddp "D3-SPP"
kb-referenceop Reference - Digital Identity Guidelines 800-63-3
kb-referenceop Reference - Testing Metrics for Password Creation Policies by Attacking Large Sets of Revealed Passwords
strengthensop Password
strengthensop User Account
is also defined as
class

Sudo and Sudo Cachingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1548.003

has facts
may-modifyop Event Log
modifiesop Operating System Configuration File
is also defined as
class

Supply Chain Compromiseni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1195

has facts
modifiesop Digital Artifact
is also defined as
class

Suspend Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SuspendProcess

has facts
evictsop Process
is also defined as
class

Symbolic Linkni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SymbolicLink

has facts
addressesop File
is also defined as
class

Symmetric Cryptographyni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1573.001

has facts
createsop Outbound Internet Encrypted Traffic
is also defined as
class

System Callni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemCall

has facts
executesop Subroutine
is also defined as
class

System Call Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemCallAnalysis

belongs to
Process Analysisc
has facts
analyzesop System Call
d3fend-iddp "D3-SCA"
kb-referenceop Reference - CAR-2019-08-001: Credential Dumping via Windows Task Manager - MITRE
kb-referenceop Reference - CAR-2013-10-002: DLL Injection via Load Library - MITRE
kb-referenceop Reference - Deterministic method for detecting and blocking of exploits on interpreted code - K2 Cyber Security Inc
kb-referenceop Reference - Hardware-assisted system and method for detecting and analyzing system calls made to an operting system kernel - Endgame Inc
kb-referenceop Reference - Malware detection in event loops - Crowdstrike Inc
kb-referenceop Reference - Post sandbox methods and systems for detecting and blocking zero-day exploits via api call validation - K2 Cyber Security Inc
kb-referenceop Reference - CAR-2020-05-001: MiniDump of LSASS - MITRE
kb-referenceop Reference - CAR-2021-05-011: Create Remote Thread into LSASS - MITRE
is also defined as
class

System Call Filteringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemCallFiltering

belongs to
Kernel-based Process Isolationc
has facts
d3fend-iddp "D3-SCF"
filtersop System Call
kb-referenceop Reference - Overview of the seccomp sandbox
is also defined as
class

System Configuration Databaseni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemConfigurationDatabase

has facts
containsop System Configuration Database Record
is also defined as
class

System Configuration Permissionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemConfigurationPermissions

belongs to
Platform Hardeningc
has facts
d3fend-iddp "D3-SCP"
kb-referenceop Reference - How to change registry values or permissions from a command line or a script
restrictsop System Configuration Database
is also defined as
class

System Daemon Monitoringni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemDaemonMonitoring

belongs to
Operating System Monitoringc
has facts
d3fend-iddp "D3-SDM"
kb-referenceop Reference - Host intrusion prevention system using software and user behavior analysis - Sophos Ltd
kb-referenceop Reference - Method using kernel mode assistance for the detection and removal of threats which are actively preventing detection and removal from a running system - Symantec Corporation
kb-referenceop Reference - CAR-2016-04-003: User Activity from Stopping Windows Defensive Services - MITRE
monitorsop Operating System Process
is also defined as
class

System Dependency Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemDependencyMapping

belongs to
System Mappingc
has facts
d3fend-iddp "D3-SYSDM"
kb-referenceop Reference - Catia UAF Plugin
kb-referenceop Reference - Software vulnerability graph database
kb-referenceop Reference - Tivoli Application Dependency Discovery Manager 7.3.0 - Dependencies between resources
kb-referenceop Reference - Unified Architecture Framework (UAF)
mapsop System Dependency
is also defined as
class

System File Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemFileAnalysis

belongs to
Operating System Monitoringc
has facts
analyzesop Operating System File
d3fend-iddp "D3-SFA"
kb-referenceop Reference - CAR-2019-07-001: Access Permission Modification - MITRE
kb-referenceop Reference - CAR-2013-01-002: Autorun Differences - MITRE
kb-referenceop Reference - CAR-2016-04-002: User Activity from Clearing Event Logs - MITRE
is also defined as
class

System Firewall Configurationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemFirewallConfiguration

has facts
configuresop Host-based Firewall
is also defined as
class

System Firmwareni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1542.001

has facts
modifiesop System Firmware
is also defined as
class

System Firmware Verificationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemFirmwareVerification

belongs to
Firmware Verificationc
has facts
d3fend-iddp "D3-SFV"
kb-referenceop Reference - Firmware Verification Eclypsium
kb-referenceop Reference - Platform Firmware Resiliency Guidelines - NIST
verifiesop System Firmware
is also defined as
class

System Information Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1082

has facts
may-accessop Decoy Artifact
may-invokeop Create Process
is also defined as
class

System Init Config Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemInitConfigAnalysis

belongs to
Operating System Monitoringc
has facts
analyzesop System Init Configuration
d3fend-iddp "D3-SICA"
kb-referenceop Reference - CAR-2013-01-002: Autorun Differences - MITRE
kb-referenceop Reference - CAR-2020-09-005: AppInit DLLs - MITRE
kb-referenceop Reference - CAR-2020-11-001: Boot or Logon Initialization Scripts - MITRE
is also defined as
class

System Language Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1614.001

has facts
queriesop System Configuration Database
is also defined as
class

System Location Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1614

has facts
accessesop Configuration Resource
is also defined as
class

System Mappingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemMapping

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-SYSM"
enablesop Model
is also defined as
class

System Network Configuration Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1016

has facts
may-executeop Executable Script
may-invokeop Create Process
may-invokeop Get System Network Config Value
is also defined as
class

System Network Connections Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1049

has facts
may-invokeop Get Open Sockets
is also defined as
class

System Owner/User Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1033

has facts
may-accessop Directory Service
may-accessop Get System Config Value
may-accessop Password File
may-accessop Process Segment
may-invokeop Copy Token
may-invokeop Create Process
is also defined as
class

System Service Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1007

has facts
may-invokeop Create Process
may-invokeop Get Running Processes
is also defined as
class

System Service Softwareni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemServiceSoftware

has facts
containsop Operating System File
is also defined as
class

System Time Discoveryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1124

has facts
may-invokeop Create Process
may-invokeop Get System Time
is also defined as
class

System Vulnerability Assessmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#SystemVulnerabilityAssessment

belongs to
System Mappingc
has facts
d3fend-iddp "D3-SYSVA"
evaluatesop Digital System
identifiesop vulnerability
kb-referenceop Reference - Software vulnerability graph database
is also defined as
class

Systemd Serviceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1543.002

has facts
may-createop Operating System Configuration File
may-modifyop Operating System Configuration File
is also defined as
class

Taint Shared Contentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1080

has facts
modifiesop Network Resource
is also defined as
class

Terminate Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TerminateProcess

has facts
terminatesop Process
is also defined as
class

Thread Execution Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.003

has facts
invokesop System Call
may-addop Executable Binary
is also defined as
class

Thread Local Storageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.005

has facts
invokesop System Call
is also defined as
class

Thread Start Functionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#ThreadStartFunction

has facts
executesop Thread
is also defined as
class

Threat Intelligence Programni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1019

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "Establishing and running a Threat Intelligence Program is outside the scope of D3FEND."

Time Based Evasionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1497.003

has facts
may-invokeop Get System Time
may-runop System Time Application
is also defined as
class

Time Providersni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.003

has facts
modifiesop System Configuration Database Record
is also defined as
class

Timestompni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1070.006

has facts
forgesop File System Metadata
is also defined as
class

Token Impersonation/Theftni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1134.001

belongs to
Access Tokenc
has facts
copiesop Access Token
is also defined as
class

TPM Boot Integrityni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TPMBootIntegrity

belongs to
Platform Hardeningc
has facts
d3fend-iddp "D3-TBI"
kb-referenceop Reference - TCG Trusted Attestation Protocol Use Cases for TPM Families 1.2 and 2.0 and DICE
kb-referenceop Reference - Trusted Attestation Protocol Use Cases
kb-referenceop Reference - TPM 2.0 Library Specification - Trusted Computing Group, Incorporated
is also defined as
class

Trace Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TraceProcess

has facts
monitorsop Process
is also defined as
class

Traffic Signalingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1205

has facts
producesop Network Traffic
is also defined as
class

Transfer Agent Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#TransferAgentAuthentication

belongs to
Message Hardeningc
has facts
d3fend-iddp "D3-TAAN"
kb-referenceop Reference - RFC 6376: DomainKeys Identified Mail (DKIM) Signatures - IETF
kb-referenceop Reference - RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email - IETF
kb-referenceop Reference - RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) - IETF
is also defined as
class

Transmitted Data Manipulationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1565.002

has facts
may-modifyop Network Traffic
is also defined as
class

Transport Agentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.002

has facts
addsop Message Transfer Agent
modifiesop Mail Server
is also defined as
class

Trapni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.005

has facts
executesop Command
may-createop Executable Script
may-modifyop Executable Script
modifiesop Event Log
is also defined as
class

Trusted Relationshipni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1199

has facts
createsop Login Session
producesop Intranet Network Traffic
is also defined as
class

Two-Factor Authentication Interceptionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1111

has facts
may-accessop Security Token
is also defined as
class

Unrestricted Upload of File with Dangerous Typeni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-434

has facts
weakness ofop User Input Function
is also defined as
class

Unsecured Credentialsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1552

has facts
accessesop Credential
is also defined as
class

Update Softwareni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1051

belongs to
ATTACK Mitigationc
has facts
relatedop Software Update

URLni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#URL

has facts
addressesop Resource
is also defined as
class

URL Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#URLAnalysis

belongs to
Identifier Analysisc
has facts
analyzesop URL
d3fend-iddp "D3-UA"
kb-referenceop Reference - Method and Apparatus for Detecting Malicious Websites - Endgame Inc
kb-referenceop Reference - Method and system for detecting restricted content associated with retrieved content - Sophos Ltd
is also defined as
class

URL Reputation Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#URLReputationAnalysis

belongs to
Identifier Reputation Analysisc
has facts
analyzesop URL
d3fend-iddp "D3-URA"
kb-referenceop Reference - Finding phishing sites
is also defined as
class

Use Alternate Authentication Materialni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550

has facts
accessesop Authentication Service
is also defined as
class

Use of Hard-coded Credentialsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-798

has facts
weakness ofop Authentication Function
is also defined as
class

Userni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#User

has facts
has-accountop User Account
is also defined as
class

User Account Controlni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1052

belongs to
ATTACK Mitigationc
has facts
relatedop Mandatory Access Control

User Account Managementni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1018

belongs to
ATTACK Mitigationc
has facts
relatedop Local File Permissions
relatedop Mandatory Access Control
relatedop System Configuration Permissions

User Account Permissionsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserAccountPermissions

belongs to
Credential Hardeningc
has facts
d3fend-iddp "D3-UAP"
kb-referenceop Reference - Configure User Access Control and Permissions
restrictsop User Account
is also defined as
class

User Behaviorni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserBehavior

has facts
containsop User Action
is also defined as
class

User Behavior Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserBehaviorAnalysis

belongs to
Defensive Techniquec
has facts
d3fend-iddp "D3-UBA"
enablesop Detect
is also defined as
class

User Data Transfer Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserDataTransferAnalysis

belongs to
User Behavior Analysisc
has facts
analyzesop Resource Access
d3fend-iddp "D3-UDTA"
kb-referenceop Reference - System and method thereof for identifying and responding to security incidents based on preemptive forensics - Palo Alto Networks Inc
kb-referenceop Reference - System for implementing threat detection using threat and risk assessment of asset-actor interactions - VECTRA NETWORKS Inc
is also defined as
class

User Geolocation Logon Pattern Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserGeolocationLogonPatternAnalysis

belongs to
User Behavior Analysisc
has facts
analyzesop Network Traffic
d3fend-iddp "D3-UGLPA"
kb-referenceop Reference - Method and Apparatus for Network Fraud Detection and Remediation Through Analytics - Idaptive LLC
kb-referenceop Reference - System, method, and computer program product for detecting and assessing security risks in a network - Exabeam Inc
is also defined as
class

User Manualni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserManual

belongs to
Reference Typec
is also defined as
class

User Session Init Config Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserSessionInitConfigAnalysis

belongs to
Operating System Monitoringc
has facts
analyzesop User Init Configuration File
d3fend-iddp "D3-USICA"
kb-referenceop Reference - Identification and extraction of key forensics indicators of compromise using subject-specific filesystem views
kb-referenceop Reference - Registry Key Security and Access Rights
kb-referenceop Reference - CAR-2020-09-002: Component Object Model Hijacking - MITRE
kb-referenceop Reference - CAR-2020-11-011: Registry Edit from Screensaver
is also defined as
class

User Startup Directoryni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserStartupDirectory

has facts
containsop User Startup Script File
is also defined as
class

User to User Messageni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#UserToUserMessage

has facts
has-recipientop User Account
has-senderop User Account
is also defined as
class

User Trainingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1017

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "Modeling user training is outside the scope of D3FEND."

Valid Accountsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1078

has facts
producesop Authentication
producesop Authorization
usesop User Account
is also defined as
class

VBA Stompingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1564.007

has facts
modifiesop Office Application File
is also defined as
class

VDSO Hijackingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1055.014

has facts
accessesop Shared Library File
invokesop System Call
is also defined as
class

Video Captureni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1125

has facts
accessesop Video Input Device
is also defined as
class

Vulnerability Scanningni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#M1016

belongs to
ATTACK Mitigationc
has facts
d3fend-commentdp "Future D3FEND releases will model the scanning and inventory domains."

Web Authenticationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebAuthentication

has facts
may-createop Session Cookie
is also defined as
class

Web File Resourceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebFileResource

has facts
addressed-byop URL
is also defined as
class

Web Portal Captureni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1056.003

has facts
modifiesop Web Server Application
is also defined as
class

Web Protocolsni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1071.001

has facts
may-transferop Certificate File
producesop Outbound Internet Web Traffic
is also defined as
class

Web Serviceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1102

has facts
producesop Outbound Internet Web Traffic
is also defined as
class

Web Session Activity Analysisni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebSessionActivityAnalysis

belongs to
User Behavior Analysisc
has facts
analyzesop Web Resource Access
d3fend-iddp "D3-WSAA"
kb-referenceop Reference - Host intrusion prevention system using software and user behavior analysis - Sophos Ltd
kb-referenceop Reference - System and Method for Detection of a Change in Behavior in the Use of a Website Through Vector Velocity Analysis - Silver Tail Systems
kb-referenceop Reference - System and Method for Network Security Including Detection of Attacks Through Partner Websites - EMC IP Holding Co LLC
kb-referenceop Reference - System and method thereof for identifying and responding to security incidents based on preemptive forensics - Palo Alto Networks Inc
is also defined as
class

Web Session Cookieni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1550.004

has facts
addsop Session Cookie
producesop Web Network Traffic
is also defined as
class

Web Shellni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.003

has facts
addsop Web Script File
modifiesop Web Server
producesop Process
is also defined as
class

Web Socket URLni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WebSocketURL

belongs to
URLc

WHOIS Compatible Domain Registrationni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WHOISCompatibleDomainRegistration

belongs to
Domain Registrationc

Windows Batch Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WindowsBatchFile

belongs to
Executable Scriptc

Windows Management Instrumentation Event Subscriptionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1546.003

has facts
modifiesop Event Log
producesop Intranet Administrative Network Traffic
is also defined as
class

Windows Management Instrumentation Executionni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1047

has facts
may-createop Intranet Administrative Network Traffic
may-invokeop Create Process
is also defined as
class

Windows Processni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WindowsProcess

belongs to
Processc

Windows Serviceni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1543.003

has facts
modifiesop System Configuration Database
is also defined as
class

Winlogon Helper DLLni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1547.004

has facts
modifiesop System Configuration Database Record
is also defined as
class

Write Fileni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#WriteFile

has facts
modifiesop File
is also defined as
class

X86 Code Segmentni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#X86CodeSegment

belongs to
Image Code Segmentc
Process Code Segmentc

XSL Script Processingni back to ToC or Named Individual ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#T1220

has facts
addsop File
interpretsop Executable Script
invokesop Create Process
is also defined as
class

Annotation Properties

altLabelap back to ToC or Annotation Property ToC

IRI: http://www.w3.org/2004/02/skos/core#altLabel

is defined by
http://www.w3.org/2004/02/skos/core#

attack-idap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#attack-id

has super-properties
attack-kb-annotationap
has domain
Offensive Techniquec
has range
string

attack-kb-annotationap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#attack-kb-annotation

has super-properties
d3fend-annotationap
has sub-properties
attack-idap
has domain
Offensive Techniquec

commentap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#definition

is defined by
http://purl.obolibrary.org/obo/IAO_0000115
has super-properties
d3fend-annotationap

cwe idap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#cwe-id

has super-properties
cwe kb annotationap

cwe kb annotationap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#cwe-kb-annotation

has super-properties
d3fend-annotationap
has sub-properties
cwe idap

d3fend display annotationap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-display-annotation

has super-properties
d3fend-annotationap
has sub-properties
display baseurlap, display priorityap, display-orderap

d3fend-annotationap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-annotation

d3fend-catalog-annotation-propertyap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-catalog-annotation-property

has super-properties
d3fend-annotationap
has sub-properties
descriptionap

d3fend-kb-annotation-propertyap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-kb-annotation-property

d3fend-kb-reference-annotationap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#d3fend-kb-reference-annotation

has super-properties
d3fend-kb-annotation-propertyap
has sub-properties
kb-abstractap, kb-articleap, kb-authorap
has domain
Referencec
has range
string

descriptionap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#description

is defined by
https://d3fend.mitre.org/ontologies/d3fend.owl

descriptionap back to ToC or Annotation Property ToC

IRI: http://purl.org/dc/terms/description

display baseurlap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#display-baseurl

has super-properties
d3fend display annotationap

display priorityap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#display-priority

has super-properties
d3fend display annotationap

display-orderap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#display-order

has super-properties
d3fend display annotationap

isDefinedByap back to ToC or Annotation Property ToC

IRI: http://www.w3.org/2000/01/rdf-schema#isDefinedBy

kb-abstractap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#kb-abstract

has super-properties
d3fend-kb-reference-annotationap
has domain
Referencec
has range
string

kb-articleap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#kb-article

has super-properties
d3fend-kb-reference-annotationap
has domain
Techniquec
has range
string

kb-authorap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#kb-author

has super-properties
d3fend-kb-reference-annotationap
has domain
Referencec
has range
string

kb-mitre-analysisap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#kb-mitre-analysis

has super-properties
d3fend-kb-annotation-propertyap
has domain
Referencec
has range
string

kb-organizationap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#kb-organization

has super-properties
d3fend-kb-annotation-propertyap

labelap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#label

has super-properties
labelap

labelap back to ToC or Annotation Property ToC

IRI: http://www.w3.org/2000/01/rdf-schema#label

has sub-properties
labelap

licenseap back to ToC or Annotation Property ToC

IRI: http://purl.org/dc/terms/license

pref-labelap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#pref-label

has super-properties
d3fend-annotationap

release-dateap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#release-date

has super-properties
d3fend-annotationap
version info

see alsoap back to ToC or Annotation Property ToC

IRI: http://www.w3.org/2000/01/rdf-schema#seeAlso

synonymap back to ToC or Annotation Property ToC

IRI: http://d3fend.mitre.org/ontologies/d3fend.owl#synonym

has super-properties
d3fend-annotationap

titleap back to ToC or Annotation Property ToC

IRI: http://purl.org/dc/terms/title

General Axioms

All Disjoint Classes back to ToC

D3FEND Use Casec, Target Audiencec, Use Case Goalc, Use Case Prerequisitec, Use Case Procedurec, Use Case Stepc

Namespace Declarations back to ToC

default namespace
http://d3fend.mitre.org/ontologies/d3fend.owl#
0-12-0-beta-1
http://d3fend.mitre.org/ontologies/d3fend/0.12.0-BETA-1/
10-1007
https://doi.org/10.1007/
2
https://linux.die.net/man/2/
30750
https://www.techopedia.com/definition/30750/
9780122272400
https://www.sciencedirect.com/referencework/9780122272400/
about
https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.core/about/
access-control
http://dbpedia.org/resource/Access_control#
blog
https://www.cyberark.com/resources/blog/
call-stack
http://dbpedia.org/resource/Call_stack#
cloud+metadata+urls
https://isc.sans.edu/forums/diary/Cloud+Metadata+Urls/
commoncoreontologies
http://www.ontologyrepository.com/CommonCoreOntologies/
d3fend
http://d3fend.mitre.org/ontologies/d3fend.owl#
data-segment
http://dbpedia.org/resource/Data_segment#
device-file
http://dbpedia.org/resource/Device_file#
dictionaries-thesauruses-pictures-and-press-releases
https://www.encyclopedia.com/computing/dictionaries-thesauruses-pictures-and-press-releases/
docs
https://attack.mitre.org/docs/
edpresso
https://www.educative.io/edpresso/
encyclopedia2-thefreedictionary-com
https://encyclopedia2.thefreedictionary.com/
file-system
http://dbpedia.org/resource/File_system#
fileapi
https://docs.microsoft.com/en-us/windows/win32/api/fileapi/
fingerprint
http://dbpedia.org/resource/Fingerprint#
glossary
https://www.gartner.com/en/information-technology/glossary/
http-cookie
http://dbpedia.org/resource/HTTP_cookie#
id
http://wordnet-rdf.princeton.edu/id/
input-device
http://dbpedia.org/resource/Input_device#
intrusion-detection-system
http://dbpedia.org/resource/Intrusion_detection_system#
l4
http://people.scs.carleton.ca/~maheshwa/courses/300/l4/
library-(computing)
http://dbpedia.org/resource/Library_(computing)#
log-file
http://dbpedia.org/resource/Log_file#
man2
https://man7.org/linux/man-pages/man2/
memory-management
http://dbpedia.org/resource/Memory_management#
modem
http://dbpedia.org/resource/Modem#
ms-nspi
https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-nspi/
networkencyclopedia-com
https://networkencyclopedia.com/
new-pubs
https://web.archive.org/web/20081123014953/http://www.dtic.mil/doctrine/jel/new_pubs/
obo
http://purl.obolibrary.org/obo/
ontologies
http://d3fend.mitre.org/ontologies/
owl
http://www.w3.org/2002/07/owl#
page
https://dbpedia.org/page/
posts-specterops-io
https://posts.specterops.io/
ppt-dir
https://www.os-book.com/OS9/slide-dir/PPT-dir/
processthreadsapi
https://docs.microsoft.com/en-us/windows/win32/api/processthreadsapi/
procthread
https://docs.microsoft.com/en-us/windows/win32/procthread/
rdf
http://www.w3.org/1999/02/22-rdf-syntax-ns#
rdfs
http://www.w3.org/2000/01/rdf-schema#
resource
http://dbpedia.org/resource/
resources
https://www.docker.com/resources/
shim-(computing)
http://dbpedia.org/resource/Shim_(computing)#
shortcut-(computing)
http://dbpedia.org/resource/Shortcut_(computing)#
skos
http://www.w3.org/2004/02/skos/core#
stack-buffer-overflow
http://dbpedia.org/resource/Stack_buffer_overflow#
symbolic-link
http://dbpedia.org/resource/Symbolic_link#
system-image
http://dbpedia.org/resource/System_image#
term
https://csrc.nist.gov/glossary/term/
terms
http://purl.org/dc/terms/
thin-client
http://dbpedia.org/resource/Thin_client#
tig-stage
https://pages.nist.gov/TIG-Stage/
user
https://www.ssh.com/iam/user/
user-(computing)
http://dbpedia.org/resource/User_(computing)#
v1-chap03-html
https://pubs.opengroup.org/onlinepubs/9699919799/basedefs/V1_chap03.html#
wiki
https://dbpedia.org/wiki/
windows-registry
http://dbpedia.org/resource/Windows_Registry#
www-linfo-org
http://www.linfo.org/
xsd
http://www.w3.org/2001/XMLSchema#

This HTML document was obtained by processing the OWL ontology source code through LODE, Live OWL Documentation Environment, developed by Silvio Peroni .