Apply D3FEND MODEL tactic - establishing the digital domain that the defender intends to defend. D3-AM Asset Inventory + D3-NM Network Mapping + D3-ID Identity Discovery + D3-NM-AM Asset Mapping + D3-SI System Inventory + D3-UA User Account Inventory + D3-SWI Software Inventory + D3-DFR Data Flow Reconnaissance + D3-CSCM Cybersecurity Cartography. Model tactic provides the foundation for all subsequent defensive operations by establishing comprehensive visibility of what exists in the digital environment. Activities include: enumerating systems + cataloguing accounts + mapping network topology + identifying data flows + documenting identities + recording configurations + maintaining software bill of materials (SBOM) + understanding business processes + mapping privilege relationships. Integration with Configuration Management Database (CMDB) + IT Asset Management (ITAM) + Cybersecurity Asset Attack Surface Management (CAASM) tools (Axonius + JupiterOne + Sevco + Lansweeper + Tanium). Identity Discovery via Active Directory + Azure AD/Entra ID + LDAP + Identity Providers + SCIM. Network mapping via passive flow monitoring + active probing + topology discovery. Data flow reconnaissance via DLP discovery + database scanning + sensitivity classification.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.