What MITRE D3FEND D3-FH: File Hashing (Defensive Tactic - Detect) requires
MITRE D3FEND D3-FH (File Hashing) is a defensive technique that uses file hash comparisons to detect known malware. Requires a database of malicious hashes to compare against environment files. Counters ATT&CK T1204 (User Execution), T1055 (Process Injection), T1547 (Boot or Logon Autostart), T1027 (Obfuscated Files). Required under NIST SP 800-53 SI-3 + SI-7, ISO 27001 A.8.7, PCI DSS Req 5.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://d3fend.mitre.org/technique/d3f:FileHashing/
SHA-256 integrity: ab38c3f12a3375343bc890c117db6f7150bfc6768ca414fb19845fa38b8a0f24
Primary Citations — 8 traced to source
- MITRE D3FEND D3-FH: File Hashing (https://d3fend.mitre.org/technique/d3f:FileHashing/)
- NIST SP 800-53 Rev 5: SI-3 Malicious Code Protection, SI-7 Software Firmware Information Integrity
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-d3fend-d3-fh-file-hashing.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-d3fend-d3-fh-file-hashing.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-d3fend-d3-fh-file-hashing
- Back to registry: Browse all 10,085 compliance nodes