Process Segment Execution Prevention
Description
Preventing execution of any address in a memory region other than the code segment.
Mapped SPARTA techniques
4 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Process Segment Execution Prevention counters T1190 Exploit Public-Facing Application; SafeMode's curated mapping records EX-0009 as addressing that same adversary behaviour in the space domain. Marking non-code memory non-executable is a processor feature available on flight hardware, so the control applies on-board. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Process Segment Execution Prevention counters T1203 Exploitation for Client Execution; SafeMode's curated mapping records EX-0009.01 as addressing that same adversary behaviour in the space domain. Marking non-code memory non-executable is a processor feature available on flight hardware, so the control applies on-board. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Process Segment Execution Prevention counters T1203 Exploitation for Client Execution; SafeMode's curated mapping records EX-0009.02 as addressing that same adversary behaviour in the space domain. Marking non-code memory non-executable is a processor feature available on flight hardware, so the control applies on-board. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Process Segment Execution Prevention counters T1190 Exploit Public-Facing Application; SafeMode's curated mapping records EX-0009.03 as addressing that same adversary behaviour in the space domain. Marking non-code memory non-executable is a processor feature available on flight hardware, so the control applies on-board. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 12 in MITRE ATT&CK Enterprise
- T1033System Owner/User Discovery
- T1055.012Process Hollowing
- T1056.004Credential API Hooking
- T1068Exploitation for Privilege Escalation
- T1189Drive-by Compromise
- T1190Exploit Public-Facing Application
- T1203Exploitation for Client Execution
- T1210Exploitation of Remote Services
- T1211Exploitation for Defense Evasion
- T1212Exploitation for Credential Access
- T1218.013Mavinject
- T1620Reflective Code Loading
Cite as SafeMode Space, d3fend D3-PSEP.