D3-NTF

Network Traffic Filtering

Block malicious network communications to sever adversary command and control channels.

D3FEND / Evict

Implementation

  • Block known C2 infrastructure
  • Implement geo-blocking where appropriate
  • Use threat intelligence for blocking
  • Monitor for new C2 channels
  • Coordinate blocks with investigation

Tools

  • Palo Alto Networks
  • Cisco Firepower
  • Zscaler
  • Cloudflare
  • AWS WAF

MITRE D3FEND ↗