MITRE D3FEND (Defensive Techniques)
D3-SCF

System Call Filtering

Description

Controlling access to local computer system resources with kernel-level capabilities.

Mapped SPARTA techniques

4 techniques

  • Derived by composition, not from a source that names this pair. D3FEND publishes that System Call Filtering counters T1556 Modify Authentication Process; SafeMode's curated mapping records EX-0003 as addressing that same adversary behaviour in the space domain. Restricting which system services a task may invoke applies to a partitioned flight executive as well as a ground kernel. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • EX-0010Malicious CodeST0004
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that System Call Filtering counters T1106 Native API; SafeMode's curated mapping records EX-0010 as addressing that same adversary behaviour in the space domain. Restricting which system services a task may invoke applies to a partitioned flight executive as well as a ground kernel. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • LM-0007Credentialed TraversalST0007
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that System Call Filtering counters T1550 Use Alternate Authentication Material; SafeMode's curated mapping records LM-0007 as addressing that same adversary behaviour in the space domain. Restricting which system services a task may invoke applies to a partitioned flight executive as well as a ground kernel. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    moderate

    Derived by composition, not from a source that names this pair. D3FEND publishes that System Call Filtering counters T1556 Modify Authentication Process; SafeMode's curated mapping records PER-0004 as addressing that same adversary behaviour in the space domain. Restricting which system services a task may invoke applies to a partitioned flight executive as well as a ground kernel. Recorded at moderate confidence because the supporting chain is two documented edges rather than one source attesting the pair directly.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Counters 52 in MITRE ATT&CK Enterprise

Cite as SafeMode Space, d3fend D3-SCF.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.