MITRE D3FEND
Evict Tactic - MITRE D3FEND

MITRE D3FEND MITRE-D3FEND-Evict-Tactic-Credential-Process-Eviction-Containment-Incident-Response-Recovery: MITRE D3FEND Evict Tactic + Credential + Process Eviction + Containment + Incident Response + Recovery

Apply D3FEND EVICT tactic to remove adversary access from a system after detected compromise. D3-CE Credential Eviction (D3-ANR Authentication Cache Invalidation + D3-CR Credential Revoking + D3-CRO Credential Rotation + D3-OACA Outbound Authentication Channel Authentication + D3-PEC Password Eviction + D3-CBT Certificate Blocklist + D3-TCBA Token Certificate Blocklist Action). D3-PE Process Eviction (D3-PT Process Termination + D3-PS Process Suspension + D3-RTM Remote Termination + D3-PNS Privilege Negotiation Suspension). Eviction activities include incident response procedures aligned with NIST 800-61 + ISO 27035 + ENISA Good Practice + SANS PICERL framework (Preparation + Identification + Containment + Eradication + Recovery + Lessons Learned). Credential eviction via Active Directory + Azure AD/Entra ID + Okta + Ping Identity bulk password reset + session token revocation (D3-ANR cache invalidation) + certificate revocation lists (CRL) + OAuth refresh token invalidation + Kerberos ticket reset (KRBTGT) + golden ticket prevention. Process eviction via EDR-driven process termination + automated playbooks (SOAR) + containment quarantine + network isolation of compromised endpoints. Recovery includes backup restoration (testing + air-gapped + immutable + offsite) + alternate processing capability + business continuity plan execution + post-incident review + lessons learned + control updates. CISA + FBI + NSA joint advisories on incident response procedures.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.