Segment Address Offset Randomization
Description
Randomizing the base (start) address of one or more segments of memory during the initialization of a process.
Mapped SPARTA techniques
4 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that Segment Address Offset Randomization counters T1190 Exploit Public-Facing Application; SafeMode's curated mapping records EX-0009 as addressing that same adversary behaviour in the space domain. Address-space randomisation is a software build property, though deterministic real-time flight builds often forgo it; the transfer is real but weaker than the other memory-safety controls. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Segment Address Offset Randomization counters T1203 Exploitation for Client Execution; SafeMode's curated mapping records EX-0009.01 as addressing that same adversary behaviour in the space domain. Address-space randomisation is a software build property, though deterministic real-time flight builds often forgo it; the transfer is real but weaker than the other memory-safety controls. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Segment Address Offset Randomization counters T1203 Exploitation for Client Execution; SafeMode's curated mapping records EX-0009.02 as addressing that same adversary behaviour in the space domain. Address-space randomisation is a software build property, though deterministic real-time flight builds often forgo it; the transfer is real but weaker than the other memory-safety controls. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that Segment Address Offset Randomization counters T1190 Exploit Public-Facing Application; SafeMode's curated mapping records EX-0009.03 as addressing that same adversary behaviour in the space domain. Address-space randomisation is a software build property, though deterministic real-time flight builds often forgo it; the transfer is real but weaker than the other memory-safety controls. Recorded at low confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 12 in MITRE ATT&CK Enterprise
- T1033System Owner/User Discovery
- T1055.012Process Hollowing
- T1056.004Credential API Hooking
- T1068Exploitation for Privilege Escalation
- T1189Drive-by Compromise
- T1190Exploit Public-Facing Application
- T1203Exploitation for Client Execution
- T1210Exploitation of Remote Services
- T1211Exploitation for Defense Evasion
- T1212Exploitation for Credential Access
- T1218.013Mavinject
- T1620Reflective Code Loading
Cite as SafeMode Space, d3fend D3-SAOR.