D8 · CySA+

What is MITRE D3FEND?

MITRE D3FEND is a complementary framework to ATT&CK mapping defensive techniques to the ATT&CK offensive techniques — helping defenders understand what controls address which attacks.
If ATT&CK describes "T1059.001 PowerShell" then D3FEND shows defensive techniques (Script Execution Analysis, Process Spawn Analysis). Helps defenders achieve ATT&CK coverage through specific control investments.
← Back to Glossary Practice Questions →