{
  "node_id": "mitre-d3fend-d3-cr-credential-revocation",
  "title": "MITRE D3FEND D3-CR: Credential Revocation (Defensive Tactic - Evict -> Credential Revocation)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE D3FEND D3-CR (Credential Revocation) is a Evict defensive technique. Deleting a set of credentials permanently to prevent them from being used to authenticate. Management servers with enterprise policies for account management provide the ability remove permissions, accounts, or credentials. Compromised credentials should be revoked to prevent further malicious activity. In the D3FEND model it deletes the credential. It counters ATT&CK techniques T1003.003, T1003.005, T1003.008, T1098.001, T1110.001, T1110.002, T1110.003, T1134.001, T1134.002, T1134.003, and 10 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-10, AC-16.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "mitre-attack-t1003-003-ntds",
    "mitre-attack-t1003-005-cached-domain-credentials",
    "mitre-attack-t1003-008-etc-passwd-and-etc-shadow",
    "nist-cybersecurity-framework-2-0",
    "nist-sp-800-53-r5",
    "iso-27001-2022"
  ],
  "primary_citations_count": 7
}