Restore Configuration
Description
Restoring an software configuration.
Mapped SPARTA techniques
1 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Restore Configuration counters T1562.003 Impair Command History Logging; SafeMode's curated mapping records DE-0003.08 as addressing that same adversary behaviour in the space domain. Restoring a known-good configuration covers reloading flight tables and parameter sets from a golden copy. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 53 in MITRE ATT&CK Enterprise
- T1037.004RC Scripts
- T1037.005Startup Items
- T1114.003Email Forwarding Rule
- T1134.005SID-History Injection
- T1137.001Office Template Macros
- T1137.002Office Test
- T1137.004Outlook Home Page
- T1137.005Outlook Rules
- T1218.002Control Panel
- T1222File and Directory Permissions Modification
- T1484Domain or Tenant Policy Modification
- T1490Inhibit System Recovery
- T1518.001Security Software Discovery
- T1526Cloud Service Discovery
- T1538Cloud Service Dashboard
- T1546.001Change Default File Association
- T1546.002Screensaver
- T1546.007Netsh Helper DLL
- T1546.008Accessibility Features
- T1546.009AppCert DLLs
- T1546.010AppInit DLLs
- T1546.011Application Shimming
- T1546.014Emond
- T1547.001Registry Run Keys / Startup Folder
- T1547.002Authentication Package
- T1547.003Time Providers
- T1547.004Winlogon Helper DLL
- T1547.005Security Support Provider
- T1547.010Port Monitors
- T1548.001Setuid and Setgid
- T1548.002Bypass User Account Control
- T1548.005Temporary Elevated Cloud Access
- T1552.005Cloud Instance Metadata API
- T1552.006Group Policy Preferences
- T1553.003SIP and Trust Provider Hijacking
- T1556.002Password Filter DLL
- T1556.009Conditional Access Policies
- T1562.002Disable Windows Event Logging
- T1562.003Impair Command History Logging
- T1562.004Disable or Modify System Firewall
- T1562.007Disable or Modify Cloud Firewall
- T1562.008Disable or Modify Cloud Logs
- T1562.009Safe Mode Boot
- T1564.008Email Hiding Rules
- T1574.011Services Registry Permissions Weakness
- T1574.012COR_PROFILER
- T1578.002Create Cloud Instance
- T1578.003Delete Cloud Instance
- T1578.004Revert Cloud Instance
- T1578.005Modify Cloud Compute Configurations
- T1614System Location Discovery
- T1615Group Policy Discovery
- T1666Modify Cloud Resource Hierarchy
Cite as SafeMode Space, d3fend D3-RC.