System Call Filtering
Description
Controlling access to local computer system resources with kernel-level capabilities.
Mapped SPARTA techniques
4 techniques
Derived by composition, not from a source that names this pair. D3FEND publishes that System Call Filtering counters T1556 Modify Authentication Process; SafeMode's curated mapping records EX-0003 as addressing that same adversary behaviour in the space domain. Restricting which system services a task may invoke applies to a partitioned flight executive as well as a ground kernel. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that System Call Filtering counters T1106 Native API; SafeMode's curated mapping records EX-0010 as addressing that same adversary behaviour in the space domain. Restricting which system services a task may invoke applies to a partitioned flight executive as well as a ground kernel. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that System Call Filtering counters T1550 Use Alternate Authentication Material; SafeMode's curated mapping records LM-0007 as addressing that same adversary behaviour in the space domain. Restricting which system services a task may invoke applies to a partitioned flight executive as well as a ground kernel. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Derived by composition, not from a source that names this pair. D3FEND publishes that System Call Filtering counters T1556 Modify Authentication Process; SafeMode's curated mapping records PER-0004 as addressing that same adversary behaviour in the space domain. Restricting which system services a task may invoke applies to a partitioned flight executive as well as a ground kernel. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.
Cross-framework references
Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.
Counters 52 in MITRE ATT&CK Enterprise
- T1003.001LSASS Memory
- T1003.002Security Account Manager
- T1003.004LSA Secrets
- T1007System Service Discovery
- T1010Application Window Discovery
- T1012Query Registry
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1033System Owner/User Discovery
- T1036.005Match Legitimate Resource Name or Location
- T1047Windows Management Instrumentation
- T1049System Network Connections Discovery
- T1053Scheduled Task/Job
- T1053.005Scheduled Task
- T1055.001Dynamic-link Library Injection
- T1055.003Thread Execution Hijacking
- T1055.004Asynchronous Procedure Call
- T1055.005Thread Local Storage
- T1055.008Ptrace System Calls
- T1055.013Process Doppelgänging
- T1055.014VDSO Hijacking
- T1057Process Discovery
- T1074.001Local Data Staging
- T1082System Information Discovery
- T1106Native API
- T1113Screen Capture
- T1124System Time Discovery
- T1134.004Parent PID Spoofing
- T1140Deobfuscate/Decode Files or Information
- T1212Exploitation for Credential Access
- T1218.001Compiled HTML File
- T1218.002Control Panel
- T1218.003CMSTP
- T1218.005Mshta
- T1218.011Rundll32
- T1218.013Mavinject
- T1220XSL Script Processing
- T1497.003Time Based Checks
- T1505.001SQL Stored Procedures
- T1505.002Transport Agent
- T1505.003Web Shell
- T1518.001Security Software Discovery
- T1546.007Netsh Helper DLL
- T1546.009AppCert DLLs
- T1546.010AppInit DLLs
- T1548.002Bypass User Account Control
- T1548.004Elevated Execution with Prompt
- T1550Use Alternate Authentication Material
- T1555.003Credentials from Web Browsers
- T1556Modify Authentication Process
- T1562.001Disable or Modify Tools
- T1621Multi-Factor Authentication Request Generation
Cite as SafeMode Space, d3fend D3-SCF.