Skip to content

Evidence request lists

MITRE D3FEND

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Deceive Tactic - MITRE D3FEND

MITRE-D3FEND-Deceive-Tactic-Decoy-Environment-Decoy-Object-Honeypots-Honey-Tokens-Decoy-Network
MITRE D3FEND Deceive Tactic + Decoy Environment + Decoy Object + Honeypots + Honey Tokens + Decoy Network

Apply D3FEND DECEIVE tactic to present false data and impressions to adversaries to misdirect their efforts. D3-DE Decoy Environment (D3-DST Decoy Session Token + D3-DPB Decoy Public Release + D3-CDE Connected Honeynet + D3-DUC Decoy User Credential + D3-IDA Integrated Honeynet + D3-SHN Standalone Honeynet). D3-DO Decoy Object (D3-DF Decoy File + D3-DPR Decoy Persona + D3-DR Decoy Resource Development + D3-DK Decoy Knowledge + D3-DTAA Decoy User Account + D3-DT Decoy Token). Deception activities include honeypot deployment (Cowrie + Dionaea + Honeyd + T-Pot + Modern Honey Network) + honeytoken services (Canary Tokens + Thinkst Canary + Tracebit) + deception platforms (Acalvio + Attivo Networks + Illusive Networks + CounterCraft + TrapX) + decoy file generation + fake identity provisioning + deceptive credentials (LDAP traps + AD honeypot accounts) + breadcrumbs + tripwires + early warnin

Artefacts an auditor will ask for
  • Decoy environment (D3-DE including DST + DPB + CDE + DUC + IDA + SHN)
  • Decoy object (D3-DO including DF + DPR + DR + DK + DTAA + DT)
  • Honeypot deployment evidence (Cowrie + Dionaea + Honeyd + T-Pot + Modern Honey Network)
  • Honeytoken services (Canary Tokens + Thinkst Canary + Tracebit)
  • Deception platform (Acalvio + Attivo + Illusive + CounterCraft + TrapX) integration
  • Decoy AD accounts + decoy file documents + breadcrumbs evidence
  • NSA Active Cyber Defense + ENISA active defense alignment
Where this commonly fails
  • No deception programme despite high-value targets
  • Honeytokens not distributed across critical data stores
  • Decoy AD accounts not in scope for monitoring
  • Deception alerts not integrated with SIEM/SOAR

Detect Tactic - MITRE D3FEND

MITRE-D3FEND-Detect-Tactic-File-Process-Network-Identifier-Message-Platform-Analysis-SIEM-EDR
MITRE D3FEND Detect Tactic + File + Process + Network + Identifier + Message + Platform Analysis + SIEM + EDR

Apply D3FEND DETECT tactic to identify malicious activity occurring within an environment through observation of digital artifacts. D3-FA File Analysis (D3-FC File Carving + D3-FCR File Content Rules + D3-FH File Hashing + D3-DA Dynamic Analysis + D3-SAA Static Application Analysis). D3-PA Process Analysis (D3-PSA Process Spawn Analysis + D3-PCSV Process Code Segment Verification + D3-PSF Process Self-Modification Detection + D3-DLIC Dynamic Library Injection Detection + D3-PSM Process Self-Modification). D3-NTA Network Traffic Analysis (D3-DNSTA DNS Traffic Analysis + D3-IPRA Inbound Protocol Reputation Analysis + D3-IDTI Inbound Discovery Traffic Identification + D3-NWPA Network Whitelisting Analysis + D3-PHDURA Per-Host Download-Upload Ratio Analysis). D3-IA Identifier Analysis (D3-URLA URL Analysis + D3-FHRA File Hash Reputation Analysis + D3-DNSRA DNS Reputation Analysis + D3-IPRA I

Artefacts an auditor will ask for
  • File analysis (D3-FA including FC + FCR + FH + DA + SAA) via EDR + sandbox
  • Process analysis (D3-PA including PSA + PCSV + PSF + DLIC) via EDR
  • Network traffic analysis (D3-NTA including DNSTA + IPRA + NWPA + PHDURA) via NDR + SIEM
  • Identifier analysis (D3-IA including URLA + FHRA + DNSRA) via threat intel
  • Message analysis (D3-MA including SRA + SHA) via email gateway
  • Platform monitoring (D3-PM including SBV + SU + SI + MFRA + FAPP) via EDR + telemetry
  • SIEM + EDR + NDR + SOAR integration documentation
Where this commonly fails
  • File hashing without dynamic analysis sandbox
  • Process spawn analysis only on EDR endpoints (servers gap)
  • DNS traffic analysis limited (no encrypted DNS visibility)
  • Platform boot verification not enabled

Evict Tactic - MITRE D3FEND

MITRE-D3FEND-Evict-Tactic-Credential-Process-Eviction-Containment-Incident-Response-Recovery
MITRE D3FEND Evict Tactic + Credential + Process Eviction + Containment + Incident Response + Recovery

Apply D3FEND EVICT tactic to remove adversary access from a system after detected compromise. D3-CE Credential Eviction (D3-ANR Authentication Cache Invalidation + D3-CR Credential Revoking + D3-CRO Credential Rotation + D3-OACA Outbound Authentication Channel Authentication + D3-PEC Password Eviction + D3-CBT Certificate Blocklist + D3-TCBA Token Certificate Blocklist Action). D3-PE Process Eviction (D3-PT Process Termination + D3-PS Process Suspension + D3-RTM Remote Termination + D3-PNS Privilege Negotiation Suspension). Eviction activities include incident response procedures aligned with NIST 800-61 + ISO 27035 + ENISA Good Practice + SANS PICERL framework (Preparation + Identification + Containment + Eradication + Recovery + Lessons Learned). Credential eviction via Active Directory + Azure AD/Entra ID + Okta + Ping Identity bulk password reset + session token revocation (D3-ANR ca

Artefacts an auditor will ask for
  • Credential eviction (D3-CE including ANR + CR + CRO + OACA + PEC + CBT + TCBA) procedures
  • Process eviction (D3-PE including PT + PS + RTM + PNS) capability via EDR + SOAR
  • Incident response plan aligned with NIST 800-61 + ISO 27035 + SANS PICERL
  • Active Directory + Azure AD bulk credential reset capability
  • Kerberos ticket reset (KRBTGT) procedure + golden ticket prevention
  • Backup restoration (testing + air-gapped + immutable + offsite) evidence
  • Tabletop exercise records + lessons learned + control updates
  • CISA + FBI + NSA joint advisory tracking
Where this commonly fails
  • No bulk Active Directory credential reset capability
  • EDR-driven process termination not automated via SOAR
  • Backup restoration not tested quarterly
  • Air-gapped backup absent leaving ransomware vulnerability

Harden Tactic - MITRE D3FEND

MITRE-D3FEND-Harden-Tactic-Application-Credential-Message-Platform-Hardening-MFA-Encryption-Secure-Boot
MITRE D3FEND Harden Tactic + Application + Credential + Message + Platform + MFA + Encryption + Secure Boot

Apply D3FEND HARDEN tactic to make compromise more difficult prior to attack. D3-AH Application Hardening (D3-DCE Dead Code Elimination + D3-EAL Exception Handler Pointer Validation + D3-PSL Pointer Authentication + D3-SU Software Update + D3-DLIC Driver Load Integrity Checking). D3-CH Credential Hardening (D3-MFA Multi-factor Authentication + D3-SPP Strong Password Policy + D3-CBM Certificate-based Authentication + D3-CRO Credential Rotation + D3-OTPC One-time Password + D3-BAN Biometric Authentication). D3-MH Message Hardening (D3-DKIM DomainKeys Identified Mail + D3-DMARC DMARC + D3-MENCR Message Encryption + D3-TBA Transfer Agent Authentication + D3-SPF Sender Policy Framework). D3-PH Platform Hardening (D3-DENCR Disk Encryption + D3-BCH Bootloader Authentication + D3-RFS RF Shielding + D3-SBP Secure Boot Protocol + D3-LH Local System Hardening + D3-TPM Trusted Platform Module + D3-M

Artefacts an auditor will ask for
  • Application hardening evidence (D3-AH including DCE + EAL + PSL + memory protection ASLR/DEP/CFG/CET)
  • Credential hardening (D3-CH including MFA + SPP + CRO + biometric)
  • Platform hardening (D3-PH including disk encryption + secure boot + TPM + measurement verification)
  • Message hardening (D3-MH including DKIM + DMARC + SPF + S/MIME)
  • CIS Benchmarks + DISA STIG + Microsoft Security Baselines adherence
  • Patch management programme records
Where this commonly fails
  • MFA not enforced for all administrative paths
  • Disk encryption not enforced for all endpoints
  • DMARC at p=reject not deployed
  • Secure boot disabled on some endpoints

Integration and Mapping - MITRE D3FEND

MITRE-D3FEND-Integration-Mapping-ATTACK-CWE-CVE-CAPEC-NIST-CSF-CIS-ISO-27001-STIX-OpenC2
MITRE D3FEND Integration + Mapping + ATT&CK + CWE + CVE + CAPEC + NIST CSF + CIS + ISO 27001 + STIX + OpenC2

Integrate D3FEND with broader cybersecurity ecosystem and frameworks. ATT&CK-D3FEND bidirectional mappings - each D3FEND defensive technique is mapped to ATT&CK offensive techniques it counters + each ATT&CK offensive technique maps to D3FEND defensive techniques that detect/prevent/respond to it. Machine-readable JSON/STIX exports. D3FEND Mapper tool for creating custom mappings. D3FEND-Decompose for breaking down techniques into atomic operations. Integration with MITRE ATT&CK + MITRE CWE (Common Weakness Enumeration) for vulnerability classification + MITRE CVE for vulnerability tracking + MITRE CAPEC (Common Attack Pattern Enumeration) for attack patterns + MITRE EMB3D for embedded device threat modelling. Cross-walks to NIST Cybersecurity Framework 2.0 (mapping techniques to Identify + Protect + Detect + Respond + Recover + Govern functions) + NIST 800-53 + NIST 800-160 + NIST 800-6

Artefacts an auditor will ask for
  • ATT&CK-D3FEND bidirectional mapping evidence per technique
  • D3FEND Mapper tool usage records
  • D3FEND-Decompose atomic operation analysis
  • NIST CSF 2.0 + 800-53 + 800-160 + 800-61 + ISO 27001 + 27034 + CIS v8 + CISA CPG + CISA Zero Trust cross-walks
  • STIX 2.x / TAXII 2.x integration with TIPs
  • OpenC2 + CACAO playbook integration
  • Tool integration documentation (EDR + SIEM + SOAR + GRC)
Where this commonly fails
  • ATT&CK mappings used without corresponding D3FEND defensive technique selection
  • Framework cross-walks not maintained for control rationalisation
  • OpenC2 + CACAO automated response not implemented
  • GRC tooling not consuming D3FEND mappings

Isolate Tactic - MITRE D3FEND

MITRE-D3FEND-Isolate-Tactic-Execution-Network-Isolation-Sandboxing-Microsegmentation-DNS-Filtering
MITRE D3FEND Isolate Tactic + Execution + Network Isolation + Sandboxing + Microsegmentation + DNS Filtering

Apply D3FEND ISOLATE tactic to create logical or physical barriers in a system to reduce attack opportunities and impact. D3-EI Execution Isolation (D3-HBPI Hardware-based Process Isolation + D3-SCF System Call Filtering + D3-IBCA IO Channel Authentication + D3-MAC Mandatory Access Control + D3-OSM Operating System Monitor). D3-NI Network Isolation (D3-OTF Outbound Traffic Filtering + D3-DNSDL DNS Denylisting + D3-DNSAL DNS Allowlisting + D3-EHB Email Header Blocking + D3-EI Encrypted Tunnels + D3-FBE Forward Resolution Domain Denylisting + D3-HDDL Hierarchical Domain Denylisting + D3-HDAL Hierarchical Domain Allowlisting + D3-ITF Inbound Traffic Filtering + D3-NTF Network Traffic Filtering + D3-RTA Reverse Resolution IP Denylisting + D3-RTAA Reverse Resolution IP Allowlisting + D3-RDR Routing Rule). Isolation activities include process sandboxing (Bromium + Sandboxie + Microsoft Applica

Artefacts an auditor will ask for
  • Execution isolation (D3-EI including HBPI + SCF + MAC + OSM) via sandboxing + container security
  • Network isolation (D3-NI including OTF + DNSDL + DNSAL + ITF + NTF) via firewalls + DNS filtering + microsegmentation
  • Microsegmentation evidence (Illumio + Guardicore + Cisco ACI + VMware NSX)
  • Browser isolation deployment (Cloudflare + Menlo + Talon + Island.io)
  • ZTNA + SSE + SASE implementation evidence
  • DNS filtering (Cisco Umbrella + DNSFilter + Quad9)
  • Just-In-Time access + Privileged Access Workstation
Where this commonly fails
  • Microsegmentation deployed only at perimeter (no east-west)
  • DNS filtering bypassable via DoH/DoT
  • Browser isolation not enforced for high-risk users
  • ZTNA only for VPN replacement (missing app-by-app)

Model Tactic - MITRE D3FEND

MITRE-D3FEND-Model-Tactic-System-Inventory-Network-Mapping-Identity-Discovery-Asset-Identification
MITRE D3FEND Model Tactic + System Inventory + Network Mapping + Identity Discovery + Asset Identification

Apply D3FEND MODEL tactic - establishing the digital domain that the defender intends to defend. D3-AM Asset Inventory + D3-NM Network Mapping + D3-ID Identity Discovery + D3-NM-AM Asset Mapping + D3-SI System Inventory + D3-UA User Account Inventory + D3-SWI Software Inventory + D3-DFR Data Flow Reconnaissance + D3-CSCM Cybersecurity Cartography. Model tactic provides the foundation for all subsequent defensive operations by establishing comprehensive visibility of what exists in the digital environment. Activities include: enumerating systems + cataloguing accounts + mapping network topology + identifying data flows + documenting identities + recording configurations + maintaining software bill of materials (SBOM) + understanding business processes + mapping privilege relationships. Integration with Configuration Management Database (CMDB) + IT Asset Management (ITAM) + Cybersecurity A

Artefacts an auditor will ask for
  • Comprehensive asset inventory (D3-AM + D3-SI + D3-SWI) including SBOM
  • Network mapping (D3-NM) with topology + flows + segments
  • User account inventory (D3-UA) including service + privileged + dormant
  • Identity discovery (D3-ID) via AD + Azure AD + IdPs + SCIM
  • Data flow reconnaissance (D3-DFR) with sensitivity classification
  • CMDB + ITAM + CAASM integration (Axonius + JupiterOne + Sevco + Lansweeper)
Where this commonly fails
  • Asset inventory not refreshed monthly
  • Shadow IT not captured (CAASM gap)
  • SBOM not generated for in-house software
  • Identity discovery limited to AD (missing SaaS identities)

Scope and Foundation - MITRE D3FEND

MITRE-D3FEND-Scope-MITRE-NSA-2021-CC-BY-4-0-Countermeasure-Knowledge-Graph-Companion-ATTACK-Ontology
MITRE D3FEND Scope + MITRE + NSA 2021 + CC BY 4.0 + Countermeasure Knowledge Graph + Companion to ATT&CK + Ontology

Establish the scope of MITRE D3FEND (Detection, Denial and Disruption Framework Empowering Network Defense) - defensive cybersecurity countermeasure knowledge graph developed by MITRE Corporation under funding from National Security Agency (NSA) Information Assurance Directorate + initial public release June 2021 + ongoing version evolution + companion to MITRE ATT&CK providing defensive techniques counterpart + released as open standard under Creative Commons Attribution 4.0 (CC BY 4.0). D3FEND structures defensive techniques around DIGITAL ARTIFACTS they operate on (Network Node + Network Traffic + File + Process + User + Software + Hardware + Credential + Identifier + Behavior + Configuration + Account + many more) - providing the ontological substructure that distinguishes D3FEND from prior defensive control frameworks. ATT&CK-D3FEND bidirectional mapping enables defenders to identif

Artefacts an auditor will ask for
  • D3FEND version + ontology version documented
  • CC BY 4.0 attribution evidence
  • ATT&CK-D3FEND mapping coverage report
  • Cross-walk to NSA Information Assurance evidence
  • Tool integration with D3FEND ontology
Where this commonly fails
  • Using outdated D3FEND version without refresh
  • CC BY 4.0 attribution missing from derivative work
  • ATT&CK-D3FEND mappings not consulted during defensive design
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the MITRE D3FEND framework page.