Loading
Loading
Reference library
Each ATT&CK technique in this library, and the D3FEND countermeasures mapped to it. Coverage is a count of those mappings. ATLAS is a separate knowledge base for attacks on AI and ML systems, and it is not mixed into this table.
| ATT&CK | Technique | Tactic | D3FEND | Score |
|---|---|---|---|---|
| T1566 | Phishing | Initial | 25 | |
| T1190 | Exploit Public-Facing Application | Initial | 100 | |
| T1133 | External Remote Services | Initial | 50 | |
| T1059 | Command and Scripting Interpreter | Execution | 100 | |
| T1204 | User Execution | Execution | 75 | |
| T1547 | Boot or Logon Autostart Execution | Persist | 100 | |
| T1053 | Scheduled Task/Job | Persist | 25 | |
| T1068 | Exploitation for Privilege Escalation | Priv Esc | 75 | |
| T1548 | Abuse Elevation Control Mechanism | Priv Esc | 25 | |
| T1070 | Indicator Removal | Evasion | 25 | |
| T1027 | Obfuscated Files or Information | Evasion | 25 | |
| T1003 | OS Credential Dumping | Cred Access | 75 | |
| T1110 | Brute Force | Cred Access | 50 | |
| T1021 | Remote Services | Lateral | 75 | |
| T1550 | Use Alternate Authentication Material | Lateral | 25 | |
| T1071 | Application Layer Protocol | C2 | 100 | |
| T1105 | Ingress Tool Transfer | C2 | 25 | |
| T1486 | Data Encrypted for Impact | Impact | 50 | |
| T1489 | Service Stop | Impact | 25 |
Public MITRE knowledge bases. ATT&CK for adversary behavior, D3FEND for defensive countermeasures, ATLAS for attacks on AI and ML systems.