Hardware-based Process Isolation
Description
Preventing one process from writing to the memory space of another process through hardware based address manager implementations.
Mapped SPARTA techniques
3 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Hardware-based Process Isolation counters T1556 Modify Authentication Process; SafeMode's curated mapping records EX-0003 as addressing that same adversary behaviour in the space domain. Hardware memory protection is standard on flight processors (MMU or MPU partitioning), so the control applies on-board. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Hardware-based Process Isolation counters T1550 Use Alternate Authentication Material; SafeMode's curated mapping records LM-0007 as addressing that same adversary behaviour in the space domain. Hardware memory protection is standard on flight processors (MMU or MPU partitioning), so the control applies on-board. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Hardware-based Process Isolation counters T1556 Modify Authentication Process; SafeMode's curated mapping records PER-0004 as addressing that same adversary behaviour in the space domain. Hardware memory protection is standard on flight processors (MMU or MPU partitioning), so the control applies on-board. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 36 in MITRE ATT&CK Enterprise
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.004LSA Secrets
- T1007System Service Discovery
- T1010Application Window Discovery
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1033System Owner/User Discovery
- T1047Windows Management Instrumentation
- T1053Scheduled Task/Job
- T1053.005Scheduled Task
- T1055.004Asynchronous Procedure Call
- T1055.013Process Doppelgänging
- T1057Process Discovery
- T1082System Information Discovery
- T1124System Time Discovery
- T1134.004Parent PID Spoofing
- T1140Deobfuscate/Decode Files or Information
- T1212Exploitation for Credential Access
- T1218.001Compiled HTML File
- T1218.002Control Panel
- T1218.003CMSTP
- T1218.005Mshta
- T1218.011Rundll32
- T1220XSL Script Processing
- T1505.001SQL Stored Procedures
- T1505.002Transport Agent
- T1505.003Web Shell
- T1546.007Netsh Helper DLL
- T1546.009AppCert DLLs
- T1546.010AppInit DLLs
- T1548.002Bypass User Account Control
- T1550Use Alternate Authentication Material
- T1556Modify Authentication Process
- T1562.001Disable or Modify Tools
- T1621Multi-Factor Authentication Request Generation
Cite as SafeMode Space, d3fend D3-HBPI.