Executable Allowlisting
Description
Using a digital signature to authenticate a file before opening.
Mapped SPARTA techniques
4 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Executable Allowlisting counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. Authenticating a file by digital signature before it is opened is the same mechanism as verifying a signed software or table upload before the spacecraft loads it. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Executable Allowlisting counters T1565.003 Runtime Data Manipulation; SafeMode's curated mapping records EX-0012.01 as addressing that same adversary behaviour in the space domain. Authenticating a file by digital signature before it is opened is the same mechanism as verifying a signed software or table upload before the spacecraft loads it. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Executable Allowlisting counters T1565.003 Runtime Data Manipulation; SafeMode's curated mapping records EX-0012.03 as addressing that same adversary behaviour in the space domain. Authenticating a file by digital signature before it is opened is the same mechanism as verifying a signed software or table upload before the spacecraft loads it. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Executable Allowlisting counters T1565.003 Runtime Data Manipulation; SafeMode's curated mapping records EX-0012.12 as addressing that same adversary behaviour in the space domain. Authenticating a file by digital signature before it is opened is the same mechanism as verifying a signed software or table upload before the spacecraft loads it. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 51 in MITRE ATT&CK Enterprise
- T1007System Service Discovery
- T1010Application Window Discovery
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1027.001Binary Padding
- T1027.002Software Packing
- T1027.004Compile After Delivery
- T1033System Owner/User Discovery
- T1036.001Invalid Code Signature
- T1036.003Rename Legitimate Utilities
- T1037.001Logon Script (Windows)
- T1037.002Login Hook
- T1037.003Network Logon Script
- T1037.004RC Scripts
- T1047Windows Management Instrumentation
- T1053Scheduled Task/Job
- T1055.003Thread Execution Hijacking
- T1055.004Asynchronous Procedure Call
- T1055.013Process Doppelgänging
- T1057Process Discovery
- T1059Command and Scripting Interpreter
- T1082System Information Discovery
- T1124System Time Discovery
- T1134.004Parent PID Spoofing
- T1137.001Office Template Macros
- T1140Deobfuscate/Decode Files or Information
- T1204.002Malicious File
- T1218.001Compiled HTML File
- T1218.002Control Panel
- T1218.003CMSTP
- T1218.005Mshta
- T1218.011Rundll32
- T1220XSL Script Processing
- T1505.001SQL Stored Procedures
- T1505.003Web Shell
- T1546.002Screensaver
- T1546.005Trap
- T1546.006LC_LOAD_DYLIB Addition
- T1546.008Accessibility Features
- T1546.009AppCert DLLs
- T1546.010AppInit DLLs
- T1546.013PowerShell Profile
- T1546.015Component Object Model Hijacking
- T1547.001Registry Run Keys / Startup Folder
- T1547.009Shortcut Modification
- T1548.002Bypass User Account Control
- T1562.003Impair Command History Logging
- T1565.003Runtime Data Manipulation
- T1574.007Path Interception by PATH Environment Variable
- T1574.008Path Interception by Search Order Hijacking
- T1574.009Path Interception by Unquoted Path
Cite as SafeMode Space, d3fend D3-EAL.