MITRE D3FEND (Defensive Techniques)
D3-EAL

Executable Allowlisting

Description

Using a digital signature to authenticate a file before opening.

Mapped SPARTA techniques

4 techniques

  • DE-0003.08Received CommandsST0006
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Executable Allowlisting counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. Authenticating a file by digital signature before it is opened is the same mechanism as verifying a signed software or table upload before the spacecraft loads it. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EX-0012.01RegistersST0004
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Executable Allowlisting counters T1565.003 Runtime Data Manipulation; SafeMode's curated mapping records EX-0012.01 as addressing that same adversary behaviour in the space domain. Authenticating a file by digital signature before it is opened is the same mechanism as verifying a signed software or table upload before the spacecraft loads it. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EX-0012.03Memory Write/LoadsST0004
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Executable Allowlisting counters T1565.003 Runtime Data Manipulation; SafeMode's curated mapping records EX-0012.03 as addressing that same adversary behaviour in the space domain. Authenticating a file by digital signature before it is opened is the same mechanism as verifying a signed software or table upload before the spacecraft loads it. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EX-0012.12System ClockST0004
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that Executable Allowlisting counters T1565.003 Runtime Data Manipulation; SafeMode's curated mapping records EX-0012.12 as addressing that same adversary behaviour in the space domain. Authenticating a file by digital signature before it is opened is the same mechanism as verifying a signed software or table upload before the spacecraft loads it. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Counters 51 in MITRE ATT&CK Enterprise

Cite as SafeMode Space, d3fend D3-EAL.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.