MITRE D3FEND
Detect Tactic - MITRE D3FEND

MITRE D3FEND MITRE-D3FEND-Detect-Tactic-File-Process-Network-Identifier-Message-Platform-Analysis-SIEM-EDR: MITRE D3FEND Detect Tactic + File + Process + Network + Identifier + Message + Platform Analysis + SIEM + EDR

Apply D3FEND DETECT tactic to identify malicious activity occurring within an environment through observation of digital artifacts. D3-FA File Analysis (D3-FC File Carving + D3-FCR File Content Rules + D3-FH File Hashing + D3-DA Dynamic Analysis + D3-SAA Static Application Analysis). D3-PA Process Analysis (D3-PSA Process Spawn Analysis + D3-PCSV Process Code Segment Verification + D3-PSF Process Self-Modification Detection + D3-DLIC Dynamic Library Injection Detection + D3-PSM Process Self-Modification). D3-NTA Network Traffic Analysis (D3-DNSTA DNS Traffic Analysis + D3-IPRA Inbound Protocol Reputation Analysis + D3-IDTI Inbound Discovery Traffic Identification + D3-NWPA Network Whitelisting Analysis + D3-PHDURA Per-Host Download-Upload Ratio Analysis). D3-IA Identifier Analysis (D3-URLA URL Analysis + D3-FHRA File Hash Reputation Analysis + D3-DNSRA DNS Reputation Analysis + D3-IPRA IP Reputation Analysis + D3-URLRA URL Reputation Analysis). D3-MA Message Analysis (D3-SRA Sender Reputation Analysis + D3-SHA Sender MTA Reputation Analysis + D3-SBN Spam Botnet Network Identification). D3-PM Platform Monitoring (D3-SBV System Boot Verification + D3-SU System File Permissions + D3-SI System Init Configuration + D3-MFRA Memory Function Read + D3-FAPP File Access Pattern Analysis). Detect integrates SIEM + EDR + NDR + UEBA + threat hunting + SOAR.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 35 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention
  • IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM
  • IACS-UR-E27-Logging-Forensics-EventCapture IACS UR E27 - Equipment Logging + Forensic Readiness + Event Capture + Tamper Detection

MARS-E · 2 controls

FDA 21 CFR Part 11 · 1 control

  • Part11.AuditTrail Audit trail requirements - secure computer-generated time-stamped (21 CFR §11.10(e))
  • CAT-D3-2 Detective controls

FISMA · 1 control

  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

FedRAMP Rev 5 · 1 control

  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests

GHG Protocol · 1 control

  • GHG-Suite-Corporate-Principles GHG Protocol Suite, Corporate Standard and 5 Reporting Principles
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics

HITECH Act · 1 control

  • HITECH-Coord-HIPAA-Privacy-Security-Cures-ONC HITECH Coordination with HIPAA Privacy Rule + HIPAA Security Rule (Verified Separately) + 21st Century Cures Act + ONC
  • 62351-14 Cyber security event logging

ISMAP (Japan) · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.4 Logging and monitoring
  • MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring

MITRE ATT&CK · 1 control

OWASP ASVS · 1 control

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 35 it maps to, and the evidence behind each claim, over MCP and REST.