{
  "node_id": "mitre-d3fend-d3-ef-email-filtering",
  "title": "MITRE D3FEND D3-EF: Email Filtering (Defensive Tactic - Isolate -> Email Filtering)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE D3FEND D3-EF (Email Filtering) is a Isolate defensive technique. Filtering incoming email traffic based on specific criteria. Mail filters can be implemented to scan inbound email messages at the initial SMTP connection stage to detect and reject email containing spam and malware. This technique is distinct from d3f:EmailDeletion because it prevents an email from reaching an user's inbox. This technique can also be used for outbound email traffic. In the D3FEND model it filters the email. It counters ATT&CK techniques T1114.001, T1534, T1566.001, T1566.002. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-03, AC-04, AC-16, AC-17, AC-19, AC-20, CA-07, CM-02.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "mitre-attack-t1114-001-local-email-collection",
    "mitre-attack-t1534-internal-spearphishing",
    "mitre-attack-t1566-001-spearphishing-attachment",
    "nist-cybersecurity-framework-2-0",
    "nist-sp-800-53-r5",
    "iso-27001-2022"
  ],
  "primary_citations_count": 7
}