Skip to main content
ENDPOINT-SECURITY5 MIN READ

Map an endpoint alert from ATT&CK to D3FEND

Use ATT&CK and D3FEND to translate an endpoint alert into evidence and defensive action.

An endpoint alert says "Suspicious script execution" after WIN-214 opens Word, spawns PowerShell, connects to a paste site, and writes a Run key. Behavior -> ATT&CK mapping -> evidence test -> defensive action The common shortcut is to close or escalate based on the alert title alone. That hides whether the endpoint shows execution, persistence, credential access, or merely an unusual admin action. Normalize behavior Write the behavior in plain language: Word spawned PowerShell; PowerShell reached an external paste site; the same process wrote to a Run key. This removes vendor wording and gives the analyst facts that can be…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us