What MITRE D3FEND D3-ANAA: Administrative Network Activity Analysis (Defensive Tactic - Detect -> Administrative Network Activity Analysis) requires
MITRE D3FEND D3-ANAA (Administrative Network Activity Analysis) is a Detect defensive technique. Detection of unauthorized use of administrative network protocols by analyzing network activity against a baseline. Network protocols such as RDP, IPMI, SSH, SNMP, VNC, MOSH, NX, TeamViewer, SPICE, PCoIP, and others are used by system administrators to remotely manage servers. Defenders monitor administrative network activity to determine if the use of remote protocols is malicious. Attackers can abuse administrative protocols and leverage them for initial access to various endpoints. In the D3FEND model it analyzes the intranet administrative network traffic. It counters ATT&CK techniques T1003.006, T1047, T1098.001, T1110.003, T1110.004, T1207, T1546.003, T1546.008. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-16, AC-17.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:AdministrativeNetworkActivityAnalysis/
SHA-256 integrity: 3feb9e7e4f7d1c3d99ba46312f1eee9518f5dc15f4c0a0790b36d8380e96c742
Primary Citations — 7 traced to source
- MITRE D3FEND Defensive Technique D3-ANAA: Administrative Network Activity Analysis (https://d3fend.mitre.org/technique/d3f:AdministrativeNetworkActivityAnalysis/)
- MITRE D3FEND Detect Tactic (https://d3fend.mitre.org/tactic/d3f:Detect/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access