D3-EDL
Executable Denylisting
Description
Blocking the execution of files on a host in accordance with defined application policy rules.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 51 in MITRE ATT&CK Enterprise
- T1007System Service Discovery
- T1010Application Window Discovery
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1027.001Binary Padding
- T1027.002Software Packing
- T1027.004Compile After Delivery
- T1033System Owner/User Discovery
- T1036.001Invalid Code Signature
- T1036.003Rename Legitimate Utilities
- T1037.001Logon Script (Windows)
- T1037.002Login Hook
- T1037.003Network Logon Script
- T1037.004RC Scripts
- T1047Windows Management Instrumentation
- T1053Scheduled Task/Job
- T1055.003Thread Execution Hijacking
- T1055.004Asynchronous Procedure Call
- T1055.013Process Doppelgänging
- T1057Process Discovery
- T1059Command and Scripting Interpreter
- T1082System Information Discovery
- T1124System Time Discovery
- T1134.004Parent PID Spoofing
- T1137.001Office Template Macros
- T1140Deobfuscate/Decode Files or Information
- T1204.002Malicious File
- T1218.001Compiled HTML File
- T1218.002Control Panel
- T1218.003CMSTP
- T1218.005Mshta
- T1218.011Rundll32
- T1220XSL Script Processing
- T1505.001SQL Stored Procedures
- T1505.003Web Shell
- T1546.002Screensaver
- T1546.005Trap
- T1546.006LC_LOAD_DYLIB Addition
- T1546.008Accessibility Features
- T1546.009AppCert DLLs
- T1546.010AppInit DLLs
- T1546.013PowerShell Profile
- T1546.015Component Object Model Hijacking
- T1547.001Registry Run Keys / Startup Folder
- T1547.009Shortcut Modification
- T1548.002Bypass User Account Control
- T1562.003Impair Command History Logging
- T1565.003Runtime Data Manipulation
- T1574.007Path Interception by PATH Environment Variable
- T1574.008Path Interception by Search Order Hijacking
- T1574.009Path Interception by Unquoted Path
Cite as SafeMode Space, d3fend D3-EDL.