Compliance Node Overview
MITRE D3FEND D3-FC (File Carving) is a Detect defensive technique. Identifying and extracting files from network application protocols through the use of network stream reassembly software. Protocol stream reassembly software recreates a directional byte stream by analyzing captured network packets. Once the stream is reassembled pattern matching is applied to determine if it contains a file of interest. Files of interest range from executable, archive, or document file formats. Once the file is captured, it is then processed with standard File Analysis Techniques. In the D3FEND model it analyzes the file transfer network traffic. It counters ATT&CK techniques T1071.002, T1570. Via the Center for Threat-Informed Defense mapping of the countered techniques, it supports NIST SP 800-53 Rev 5 controls AC-03, AC-04, CA-07, CM-02, CM-06, CM-07, SC-07, SC-10.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:FileCarving/
SHA-256 integrity: 43b95269a229707f1b28c27d377b14cc15f5652de8ad7d95f402eb8bdfed4d68
Primary Citations — 7 traced to source
- MITRE D3FEND Defensive Technique D3-FC: File Carving (https://d3fend.mitre.org/technique/d3f:FileCarving/)
- MITRE D3FEND Detect Tactic (https://d3fend.mitre.org/tactic/d3f:Detect/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access