Compliance Node Overview
MITRE D3FEND D3-CCSA (Credential Compromise Scope Analysis) is a Detect defensive technique. Determining which credentials may have been compromised by analyzing the user logon history of a particular system. Memory Credentials may be stored in memory for a variety of reasons; on Windows, they may be stored in lsass.exe. Once a credential dumper like mimikatz runs and dumps the memory of lsass.exe, the credentials of every account logged on since boot are potentially compromised. When such an event occurs, this analytic will give the forensic context to identify compromised users. Those users could potentially be used in later events for additional logons. In the D3FEND model it analyzes the credential. It counters ATT&CK techniques T1003.003, T1003.005, T1003.008, T1098.001, T1110.001, T1110.002, T1110.003, T1134.001, T1134.002, T1134.003, and 10 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-10, AC-16.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:CredentialCompromiseScopeAnalysis/
SHA-256 integrity: fb178d778ff2630db18a7702f960ad78b018d938b9a8a10923dced78682c0426
Primary Citations — 7 traced to source
- MITRE D3FEND Defensive Technique D3-CCSA: Credential Compromise Scope Analysis (https://d3fend.mitre.org/technique/d3f:CredentialCompromiseScopeAnalysis/)
- MITRE D3FEND Detect Tactic (https://d3fend.mitre.org/tactic/d3f:Detect/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access