Sort D3FEND Countermeasures
Categorize defensive follow-ups by D3FEND-style action: harden, detect, isolate, deceive, or evict.
Place each follow-up in the defensive action type it best represents. Harden Detect Isolate Deceive Evict Require phishing-resistant MFA for admins Alert on LSASS access by unsigned processes Quarantine endpoint from peer-to-peer traffic after confirmed beacon Deploy a fake credential canary in a monitored share Invalidate refresh tokens after account compromise Remove local admin from standard workstation users Block command-and-control domain at resolver during active incident Remove unauthorized scheduled task persistence Monitor suspicious OAuth consent grants Create honey mailbox rule that alerts on adversary search terms
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in