What MITRE D3FEND D3-APCA: Application Protocol Command Analysis (Defensive Tactic - Detect -> Application Protocol Command Analysis) requires
MITRE D3FEND D3-APCA (Application Protocol Command Analysis) is a Detect defensive technique. Analyzing application protocol level remote commands to detect unauthorized activity. This technique requires the ability to parse application layer protocols to understand the commands being sent to a remote service. Signature-based or statistical analysis may be employed to identify unauthorized commands being sent. These commands can be observed by monitoring network traffic or application logs. In the D3FEND model it monitors the network traffic. It counters ATT&CK techniques T1001, T1003.006, T1008, T1011, T1018, T1020, T1021, T1021.001, T1021.004, T1029, and 62 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-08, AC-10.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:ApplicationProtocolCommandAnalysis/
SHA-256 integrity: f12cc82f89f94d7afab0141c0fd51b9370fca0f2cd5b8c8ccdf01f3a35a979ce
Primary Citations — 7 traced to source
- MITRE D3FEND Defensive Technique D3-APCA: Application Protocol Command Analysis (https://d3fend.mitre.org/technique/d3f:ApplicationProtocolCommandAnalysis/)
- MITRE D3FEND Detect Tactic (https://d3fend.mitre.org/tactic/d3f:Detect/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access