D3-NTF
Network Traffic Filtering
Block malicious network communications to sever adversary command and control channels.
D3FEND / Evict
Implementation
- Block known C2 infrastructure
- Implement geo-blocking where appropriate
- Use threat intelligence for blocking
- Monitor for new C2 channels
- Coordinate blocks with investigation
Tools
- Palo Alto Networks
- Cisco Firepower
- Zscaler
- Cloudflare
- AWS WAF
ATT&CK mappings
3