Threat Intelligence
MITRE D3FEND
Defensive Countermeasures Knowledge Graph
A knowledge graph of defensive techniques across seven tactics (model, harden, detect, isolate, deceive, evict, restore) with explicit digital artefact relationships linking each countermeasure to the offensive techniques it addresses.
Where ATT&CK tells you what attackers do, D3FEND gives you a vocabulary for what your controls actually do about it. Adoption in commercial tooling is growing but not yet the default.
At a glance
- Category
- Threat Intelligence
- Jurisdiction
- Global
- Governance
- MITRE
- Status
- 1.0 released January 2025; matrix at version 1.4
- First released
- 2021
Links
Related frameworks
Other entries under Threat Intelligence.
- MITRE ATT&CK: Adversarial Tactics, Techniques and Common Knowledge
- CWE: Common Weakness Enumeration
- CAPEC: Common Attack Pattern Enumeration and Classification
- STIX: Structured Threat Information Expression
- TAXII: Trusted Automated Exchange of Intelligence Information
See MITRE D3FEND in context
Open the interactive Data Landscape for Regulation to compare MITRE D3FEND against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.