Apply D3FEND DETECT tactic to identify malicious activity occurring within an environment through observation of digital artifacts. D3-FA File Analysis (D3-FC File Carving + D3-FCR File Content Rules + D3-FH File Hashing + D3-DA Dynamic Analysis + D3-SAA Static Application Analysis). D3-PA Process Analysis (D3-PSA Process Spawn Analysis + D3-PCSV Process Code Segment Verification + D3-PSF Process Self-Modification Detection + D3-DLIC Dynamic Library Injection Detection + D3-PSM Process Self-Modification). D3-NTA Network Traffic Analysis (D3-DNSTA DNS Traffic Analysis + D3-IPRA Inbound Protocol Reputation Analysis + D3-IDTI Inbound Discovery Traffic Identification + D3-NWPA Network Whitelisting Analysis + D3-PHDURA Per-Host Download-Upload Ratio Analysis). D3-IA Identifier Analysis (D3-URLA URL Analysis + D3-FHRA File Hash Reputation Analysis + D3-DNSRA DNS Reputation Analysis + D3-IPRA IP Reputation Analysis + D3-URLRA URL Reputation Analysis). D3-MA Message Analysis (D3-SRA Sender Reputation Analysis + D3-SHA Sender MTA Reputation Analysis + D3-SBN Spam Botnet Network Identification). D3-PM Platform Monitoring (D3-SBV System Boot Verification + D3-SU System File Permissions + D3-SI System Init Configuration + D3-MFRA Memory Function Read + D3-FAPP File Access Pattern Analysis). Detect integrates SIEM + EDR + NDR + UEBA + threat hunting + SOAR.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 35 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.