MITRE D3FEND
Evict Tactic - MITRE D3FEND

MITRE D3FEND MITRE-D3FEND-Evict-Tactic-Credential-Process-Eviction-Containment-Incident-Response-Recovery: MITRE D3FEND Evict Tactic + Credential + Process Eviction + Containment + Incident Response + Recovery

Apply D3FEND EVICT tactic to remove adversary access from a system after detected compromise. D3-CE Credential Eviction (D3-ANR Authentication Cache Invalidation + D3-CR Credential Revoking + D3-CRO Credential Rotation + D3-OACA Outbound Authentication Channel Authentication + D3-PEC Password Eviction + D3-CBT Certificate Blocklist + D3-TCBA Token Certificate Blocklist Action). D3-PE Process Eviction (D3-PT Process Termination + D3-PS Process Suspension + D3-RTM Remote Termination + D3-PNS Privilege Negotiation Suspension). Eviction activities include incident response procedures aligned with NIST 800-61 + ISO 27035 + ENISA Good Practice + SANS PICERL framework (Preparation + Identification + Containment + Eradication + Recovery + Lessons Learned). Credential eviction via Active Directory + cloud identity provider bulk password reset + session token revocation (D3-ANR cache invalidation) + certificate revocation lists (CRL) + OAuth refresh token invalidation + Kerberos ticket reset (KRBTGT) + golden ticket prevention. Process eviction via EDR-driven process termination + automated playbooks (SOAR) + containment quarantine + network isolation of compromised endpoints. Recovery includes backup restoration (testing + air-gapped + immutable + offsite) + alternate processing capability + business continuity plan execution + post-incident review + lessons learned + control updates. CISA + FBI + NSA joint advisories on incident response procedures.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 37 controls across 21 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

FedRAMP Rev 5 · 2 controls

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-IncidentReporting FedRAMP incident reporting to PMO and US-CERT
  • IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience
  • IMO-MSC-FAL-Respond-IncidentResponse-Communication-FlagState-PortAuthority-CIRT-USCGNVIC IMO MSC-FAL Respond Function - Incident Response Plan + Containment + Communication + Flag State + Port Authority + USCG NVIC + Class Society Notification + CIRT
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development
  • 4.4.8 Business Continuity and Recovery
  • FIRST-CSIRTF-SA2-ISIM Service Area 2 - Information Security Incident Management (Intake, Analysis, Containment, Recovery, Coordination, Crisis)
  • GAMP5-Supplier-Operations-Change-Periodic Supplier Assessment, Operational Phase, Change Control and Periodic Review

GLBA · 1 control

  • GLBA-Subordinate-Rules-Operationalisation GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines

HKMA SPM · 1 control

  • HKMA-SPM-OR-RR-SA-OperationalResilience HKMA SPM Operational Risk (OR-1), Operational Resilience (OR-2), Recovery Planning (RR-1), Outsourcing (SA-2)
  • IACS-UR-E26-Respond-Recover-IncidentResponse-Recovery-Backup-Lessons IACS UR E26 Respond + Recover Goals - Incident Response + Communication + Recovery + Backup + Lessons Learned

IEEE 1686 · 1 control

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills

ISMAP (Japan) · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-8.6 Data protection and backup
  • JP-FSA-CYB-Incident-Response-Playbooks-Containment-Eradication-Recovery-Post-Mortem-Tabletop-CSIRT Japan FSA Cybersecurity Incident Response + Playbooks + Containment + Eradication + Recovery + Post-Mortem + Tabletop Exercises + CSIRT + FSA Notification + Customer Communication + Forensics + Lessons Learned

MITRE ATT&CK · 1 control

OWASP ASVS · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.