D3-HBPI

Host-Based Process Isolation

Restrict process permissions and capabilities to limit the impact of compromised applications.

D3FEND / Isolate

Implementation

  • Implement application control policies
  • Use mandatory access controls
  • Deploy endpoint detection and response
  • Enable process sandboxing
  • Monitor for privilege escalation

Tools

  • Windows Defender Application Control
  • AppLocker
  • SELinux/AppArmor
  • CrowdStrike
  • Carbon Black

MITRE D3FEND ↗