What MITRE D3FEND D3-CS: Credential Scrubbing (Defensive Tactic - Harden -> Credential Scrubbing) requires
MITRE D3FEND D3-CS (Credential Scrubbing) is a Harden defensive technique. The systematic removal of hard-coded credentials from source code to prevent accidental exposure and unauthorized access. Credential Scrubbing involves identifying and eliminating hard-coded credentials such as usernames, passwords, API keys, and tokens from source code repositories. These credentials should be managed securely using environment variables, secret management tools, or secure vaults where they can be safely accessed when needed. In the D3FEND model it hardens the subroutine. It counters ATT&CK technique T1505.001. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-16, CM-02, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:CredentialScrubbing/
SHA-256 integrity: a275f9de63e14f9bc9b8c8038aacf8053f0af9d4c4bd7865997233f09ba4e722
Primary Citations — 7 traced to source
- MITRE D3FEND Defensive Technique D3-CS: Credential Scrubbing (https://d3fend.mitre.org/technique/d3f:CredentialScrubbing/)
- MITRE D3FEND Harden Tactic (https://d3fend.mitre.org/tactic/d3f:Harden/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access