Establish the scope of MITRE D3FEND (Detection, Denial and Disruption Framework Empowering Network Defense) - defensive cybersecurity countermeasure knowledge graph developed by MITRE Corporation under funding from National Security Agency (NSA) Information Assurance Directorate + initial public release June 2021 + ongoing version evolution + companion to MITRE ATT&CK providing defensive techniques counterpart + released as open standard under Creative Commons Attribution 4.0 (CC BY 4.0). D3FEND structures defensive techniques around DIGITAL ARTIFACTS they operate on (Network Node + Network Traffic + File + Process + User + Software + Hardware + Credential + Identifier + Behavior + Configuration + Account + many more) - providing the ontological substructure that distinguishes D3FEND from prior defensive control frameworks. ATT&CK-D3FEND bidirectional mapping enables defenders to identify which D3FEND defensive techniques counter each specific ATT&CK offensive technique. D3FEND ontology available in OWL/RDF format + JSON bundle exports + machine-readable for tooling integration. Used by federal agencies (NSA + CISA + DOD + USCYBERCOM + FBI + DHS) + allied nations + private SOCs + threat intelligence vendors + cybersecurity researchers + academic institutions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.