logo

MITRE ATT&CK®


Summary

MITRE ATT&CK® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations and is used as a cybersecurity product and service community. This mitigation describes any guidance or training given to developers of applications to avoid introducing security weaknesses that an adversary may be able to take advantage of.


Definitions

DefinitionRequirements
MITRE-M1036. Account use policies
MITRE-M1049. Antivirus/antimalware
MITRE-M1048. Application isolation and sandboxing
MITRE-M1047. Audit
MITRE-M1040. Behavior prevention on endpoint
MITRE-M1046. Boot integrity
MITRE-M1045. Code signing
MITRE-M1043. Credential access protection
MITRE-M1057. Data loss prevention
MITRE-M1041. Encrypt sensitive information
MITRE-M1039. Environment variable permissions
MITRE-M1038. Execution prevention
MITRE-M1037. Filter network traffic
MITRE-M1035. Limit access to resource over network
MITRE-M1034. Limit hardware installation
MITRE-M1033. Limit software installation
MITRE-M1032. Multi-factor authentication
MITRE-M1031. Network intrusion prevention
MITRE-M1030. Network segmentation
MITRE-M1027. Password policies
MITRE-M1026. Privileged account management
MITRE-M1025. Privileged process integrity
MITRE-M1029. Remote data storage
MITRE-M1022. Restrict file and directory permissions
MITRE-M1021. Restrict web-based content
MITRE-M1020. SSL/TLS inspection
MITRE-M1051. Update software
MITRE-M1018. User account management
MITRE-M1016. Vulnerability scanning
MITRE-M1015. Active directory configuration
MITRE-M1013. Application developer guidance
MITRE-M1042. Disable or remove feature or program
MITRE-M1028. Operating system configuration
MITRE-M1056. Pre-compromise
MITRE-M1044. Restrict library loading
MITRE-M1024. Restrict registry permissions
MITRE-M1054. Software configuration
MITRE-M1052. User account control

Last updated

2023/09/18