Skip to main content
SECURITY-OPERATIONS-SOC5 MIN READ

Sort D3FEND Countermeasures

Categorize defensive follow-ups by D3FEND-style action: harden, detect, isolate, deceive, or evict.

Place each follow-up in the defensive action type it best represents. Harden Detect Isolate Deceive Evict Require phishing-resistant MFA for admins Alert on LSASS access by unsigned processes Quarantine endpoint from peer-to-peer traffic after confirmed beacon Deploy a fake credential canary in a monitored share Invalidate refresh tokens after account compromise Remove local admin from standard workstation users Block command-and-control domain at resolver during active incident Remove unauthorized scheduled task persistence Monitor suspicious OAuth consent grants Create honey mailbox rule that alerts on adversary search terms

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us