Memory Boundary Tracking
Parent: D3-PM
Description
Analyzing a call stack for return addresses which point to unexpected memory locations.
Mapped SPARTA techniques
4 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Memory Boundary Tracking counters T1203 Exploitation for Client Execution; SafeMode's curated mapping records EX-0009 as addressing that same adversary behaviour in the space domain. Call-stack return-address checking is a compile-and-runtime property of the software, so it applies to flight software built with the same protections. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Memory Boundary Tracking counters T1203 Exploitation for Client Execution; SafeMode's curated mapping records EX-0009.01 as addressing that same adversary behaviour in the space domain. Call-stack return-address checking is a compile-and-runtime property of the software, so it applies to flight software built with the same protections. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Memory Boundary Tracking counters T1203 Exploitation for Client Execution; SafeMode's curated mapping records EX-0009.02 as addressing that same adversary behaviour in the space domain. Call-stack return-address checking is a compile-and-runtime property of the software, so it applies to flight software built with the same protections. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Memory Boundary Tracking counters T1203 Exploitation for Client Execution; SafeMode's curated mapping records EX-0009.03 as addressing that same adversary behaviour in the space domain. Call-stack return-address checking is a compile-and-runtime property of the software, so it applies to flight software built with the same protections. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Cite as SafeMode Space, d3fend D3-MBT.