What is MITRE D3FEND?

MITRE D3FEND is a knowledge model for cyber defence techniques developed by MITRE Corporation. It is intended as the counterpart to MITRE ATT&CK and focuses on protection, detection and response measures against cyber threats.

D3FEND provides structured terminology and relationships between defensive measures, allowing organisations to plan, improve and communicate their security architecture in a consistent way.


🧠 How does MITRE D3FEND work?

  1. D3FEND describes techniques that organisations use to defend themselves against attacks
  2. The model is tactical and technical, divided into five main areas:
  • Harden – strengthening systems against abuse
  • Detect – identifying threats
  • Isolate – separating or containing threats
  • Deceive – misleading attackers
  • Evict – removing threats
  1. Each technique is linked to ATT&CK techniques – so you can see which defence works against which attack
  2. The model is publicly available at d3fend.mitre.org

D3FEND is a taxonomy of defensive capabilities, just as ATT&CK is for attacks.


🏭 Application of MITRE D3FEND in industrial networks

In an OT context, D3FEND helps link defensive measures to known attack patterns.


πŸ” D3FEND categories

Category Description Example measures
Harden Reduce the attack surface Least Privilege, RBAC, Whitelisting
Detect Discover unwanted activity SIEM, anomaly detection, EDR
Isolate Limit an attacker’s freedom of movement VLAN, Firewall, microsegmentation
Deceive Mislead attackers Honeypots, decoy credentials, deception grids
Evict Remove intruders and recover Incident Response, re-imaging, blocklists

πŸ” Security considerations

  • D3FEND is not itself a tool, but a knowledge model for structuring defence
  • Helps organisations make risk-driven choices about security measures
  • Supports gap analysis: which layers of defence are missing?
  • Compatible with MITRE ATT&CK, NIST, CISA guidelines and IEC 62443

Linking D3FEND to ATT&CK provides a complete view of both attacks and defence.


πŸ“Œ In summary

MITRE D3FEND is a structured model for cyber defence techniques, intended to organise, link and improve security measures in a logical way. In OT, it helps strengthen systems against known attack techniques from MITRE ATT&CK for ICS.