MITRE D3FEND (Defensive Techniques)
D3-DF

Decoy File

Description

A file created for the purposes of deceiving an adversary.

Mapped SPARTA techniques

2 techniques

  • EXF-0007Compromised Ground SystemST0008
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Decoy File counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records EXF-0007 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • IMP-0006TheftST0009
    addresses
    low

    Derived by composition, not from a source that names this pair. D3FEND publishes that Decoy File counters T1041 Exfiltration Over C2 Channel; SafeMode's curated mapping records IMP-0006 as addressing that same adversary behaviour in the space domain. The control assumes an enterprise host or network -- interactive user accounts, IP session structure, or an organisational perimeter -- so it reaches the mission ground segment and not the spacecraft. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly, and because IMP-0006 spans both a ground and a space face while the control reaches only one of them.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Counters 96 in MITRE ATT&CK Enterprise

Cite as SafeMode Space, d3fend D3-DF.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.