Apply D3FEND DETECT tactic to identify malicious activity occurring within an environment through observation of digital artifacts. D3-FA File Analysis (D3-FC File Carving + D3-FCR File Content Rules + D3-FH File Hashing + D3-DA Dynamic Analysis + D3-SAA Static Application Analysis). D3-PA Process Analysis (D3-PSA Process Spawn Analysis + D3-PCSV Process Code Segment Verification + D3-PSF Process Self-Modification Detection + D3-DLIC Dynamic Library Injection Detection + D3-PSM Process Self-Modification). D3-NTA Network Traffic Analysis (D3-DNSTA DNS Traffic Analysis + D3-IPRA Inbound Protocol Reputation Analysis + D3-IDTI Inbound Discovery Traffic Identification + D3-NWPA Network Whitelisting Analysis + D3-PHDURA Per-Host Download-Upload Ratio Analysis). D3-IA Identifier Analysis (D3-URLA URL Analysis + D3-FHRA File Hash Reputation Analysis + D3-DNSRA DNS Reputation Analysis + D3-IPRA IP Reputation Analysis + D3-URLRA URL Reputation Analysis). D3-MA Message Analysis (D3-SRA Sender Reputation Analysis + D3-SHA Sender MTA Reputation Analysis + D3-SBN Spam Botnet Network Identification). D3-PM Platform Monitoring (D3-SBV System Boot Verification + D3-SU System File Permissions + D3-SI System Init Configuration + D3-MFRA Memory Function Read + D3-FAPP File Access Pattern Analysis). Detect integrates SIEM (Splunk + Sentinel + QRadar + Chronicle + Elastic) + EDR (CrowdStrike + Microsoft Defender + SentinelOne + Cybereason + Carbon Black + Sophos) + NDR (Vectra + Darktrace + ExtraHop + Corelight + Cisco Stealthwatch) + UEBA + threat hunting + SOAR (Splunk Phantom + Microsoft Sentinel + Cortex XSOAR + Tines).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.