Application-based Process Isolation
Description
Application code which prevents its own subroutines from accessing intra-process / internal memory space.
Mapped SPARTA techniques
3 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Application-based Process Isolation counters T1556 Modify Authentication Process; SafeMode's curated mapping records EX-0003 as addressing that same adversary behaviour in the space domain. Intra-process memory partitioning is implemented in flight software itself, so the control applies wherever that software runs. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application-based Process Isolation counters T1550 Use Alternate Authentication Material; SafeMode's curated mapping records LM-0007 as addressing that same adversary behaviour in the space domain. Intra-process memory partitioning is implemented in flight software itself, so the control applies wherever that software runs. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Application-based Process Isolation counters T1556 Modify Authentication Process; SafeMode's curated mapping records PER-0004 as addressing that same adversary behaviour in the space domain. Intra-process memory partitioning is implemented in flight software itself, so the control applies wherever that software runs. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 15 in MITRE ATT&CK Enterprise
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.004LSA Secrets
- T1033System Owner/User Discovery
- T1053Scheduled Task/Job
- T1053.005Scheduled Task
- T1212Exploitation for Credential Access
- T1505.001SQL Stored Procedures
- T1505.002Transport Agent
- T1505.003Web Shell
- T1546.007Netsh Helper DLL
- T1550Use Alternate Authentication Material
- T1556Modify Authentication Process
- T1562.001Disable or Modify Tools
- T1621Multi-Factor Authentication Request Generation
Cite as SafeMode Space, d3fend D3-ABPI.