What MITRE D3FEND D3-DA: Dynamic Analysis (Defensive Tactic - Detect -> Dynamic Analysis) requires
MITRE D3FEND D3-DA (Dynamic Analysis) is a Detect defensive technique. Executing or opening a file in a synthetic "sandbox" environment to determine if the file is a malicious program or if the file exploits another program such as a document reader. Analyzing the interaction of a piece of code with a system while the code is being executed in a controlled environment such as a sandbox, virtual machine, or simulator. This exposes the natural behavior of the piece of code without requiring the code to be disassembled. In the D3FEND model it analyzes the document file; analyzes the executable file. It counters ATT&CK techniques T1016, T1027.001, T1027.002, T1027.004, T1036.001, T1036.003, T1037.001, T1037.002, T1037.003, T1037.004, and 28 more. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-10, AC-16, AC-17.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:DynamicAnalysis/
SHA-256 integrity: c589d7919b72f0c6226d481f1132eb85dc236ab0c71a666d927f2b64a16c2cd3
Primary Citations — 7 traced to source
- MITRE D3FEND Defensive Technique D3-DA: Dynamic Analysis (https://d3fend.mitre.org/technique/d3f:DynamicAnalysis/)
- MITRE D3FEND Detect Tactic (https://d3fend.mitre.org/tactic/d3f:Detect/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access