CyberGlossary

Compliance & Frameworks

MITRE D3FEND

Also known as: D3FEND, MITRE D3FEND Framework

Definition

A MITRE knowledge graph of defensive cybersecurity countermeasures and the digital artifacts they observe or modify, complementing MITRE ATT&CK.

MITRE D3FEND is a knowledge graph of cybersecurity defensive countermeasures, developed by MITRE with U.S. National Security Agency (NSA) sponsorship. It catalogues defensive techniques organised into tactics such as Harden, Detect, Isolate, Deceive, and Evict, and links them to the digital artifacts they operate on (processes, files, network flows, etc.) using a formal ontology. D3FEND is designed as the defensive counterpart to MITRE ATT&CK: security teams can map adversary techniques (ATT&CK) to candidate countermeasures (D3FEND) to plan, evaluate, and communicate defensive coverage. It is widely used by architects, product managers, and government acquirers.

Examples

  • A security architect using D3FEND to identify candidate mitigations for an ATT&CK technique.
  • A vendor mapping its EDR capabilities to D3FEND techniques to communicate coverage.

Related terms