D3-DI
Data Inventory
Description
Data inventorying identifies and records the schemas, formats, volumes, and locations of data stored and used on the organization's architecture.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 29 in MITRE ATT&CK Enterprise
- T1003.002Security Account Manager
- T1003.004LSA Secrets
- T1003.008/etc/passwd and /etc/shadow
- T1012Query Registry
- T1033System Owner/User Discovery
- T1112Modify Registry
- T1114.001Local Email Collection
- T1137.003Outlook Forms
- T1137.006Add-ins
- T1207Rogue Domain Controller
- T1213.003Code Repositories
- T1218.005Mshta
- T1218.014MMC
- T1534Internal Spearphishing
- T1543.003Windows Service
- T1546.012Image File Execution Options Injection
- T1546.015Component Object Model Hijacking
- T1548.004Elevated Execution with Prompt
- T1552.002Credentials in Registry
- T1555Credentials from Password Stores
- T1555.001Keychain
- T1555.002Securityd Memory
- T1555.003Credentials from Web Browsers
- T1564.003Hidden Window
- T1564.005Hidden File System
- T1564.007VBA Stomping
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1614.001System Language Discovery
Cite as SafeMode Space, d3fend D3-DI.