MITRE D3FEND™
The MITRE D3FEND™ object describes the tactic, technique & sub-technique associated with a countermeasure as defined in DEFEND MatrixTM.
Attributes
Caption | Name | Type | Description |
---|---|---|---|
MITRE DEFEND™ Tactic | d3f_tactic |
MITRE D3FEND™ Tactic[] | The Tactic object describes the tactic ID and/or name that is associated with a countermeasure, as defined by D3FEND MatrixTM. |
MITRE DEFEND™ Technique | d3f_technique |
MITRE DEFEND™ Technique[] | The Defend Technique object describes the technique ID and/or name associated with a countermeasure, as defined by D3FEND MatrixTM. |
Raw Data | raw_data |
JSON | The event data as received from the event source. |
Record ID | record_id |
String | Unique identifier for the object |
Unmapped Data | unmapped |
Unmapped[] | The attributes that are not mapped to the event schema. The names and values of those attributes are specific to the event source. |
Version | version |
String | The D3FEND MatrixTM version. |
Relationships
Inbound Relationships
These objects and events reference MITRE D3FEND™ in their attributes:
- Remediation Activity
- Network Remediation Activity
- File Remediation Activity
- Process Remediation Activity
Outbound Relationships
MITRE D3FEND™ references the following objects and events in its attributes:
This page describes qdm-1.3.2+ocsf-1.3.0
Updated about 2 months ago