D3-EFA
Emulated File Analysis
Description
Emulating instructions in a file looking for specific patterns.
Mapped SPARTA techniques
No techniques mapped to this control.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 38 in MITRE ATT&CK Enterprise
- T1016System Network Configuration Discovery
- T1027.001Binary Padding
- T1027.002Software Packing
- T1027.004Compile After Delivery
- T1036.001Invalid Code Signature
- T1036.003Rename Legitimate Utilities
- T1037.001Logon Script (Windows)
- T1037.002Login Hook
- T1037.003Network Logon Script
- T1037.004RC Scripts
- T1055.003Thread Execution Hijacking
- T1059Command and Scripting Interpreter
- T1114.001Local Email Collection
- T1137.001Office Template Macros
- T1137.003Outlook Forms
- T1140Deobfuscate/Decode Files or Information
- T1204.002Malicious File
- T1218.005Mshta
- T1220XSL Script Processing
- T1505.003Web Shell
- T1534Internal Spearphishing
- T1546.002Screensaver
- T1546.005Trap
- T1546.006LC_LOAD_DYLIB Addition
- T1546.008Accessibility Features
- T1546.013PowerShell Profile
- T1546.015Component Object Model Hijacking
- T1547.001Registry Run Keys / Startup Folder
- T1547.009Shortcut Modification
- T1548.002Bypass User Account Control
- T1562.003Impair Command History Logging
- T1564.007VBA Stomping
- T1565.003Runtime Data Manipulation
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1574.007Path Interception by PATH Environment Variable
- T1574.008Path Interception by Search Order Hijacking
- T1574.009Path Interception by Unquoted Path
Cite as SafeMode Space, d3fend D3-EFA.