D3-HBPI
Host-Based Process Isolation
Restrict process permissions and capabilities to limit the impact of compromised applications.
D3FEND / Isolate
Implementation
- Implement application control policies
- Use mandatory access controls
- Deploy endpoint detection and response
- Enable process sandboxing
- Monitor for privilege escalation
Tools
- Windows Defender Application Control
- AppLocker
- SELinux/AppArmor
- CrowdStrike
- Carbon Black
ATT&CK mappings
3