Esc
Platform Hardening
Definition
Hardening components of a Platform with the intention of making them more difficult to exploit.
Platforms includes components such as:
- BIOS UEFI Subsystems
- Hardware security devices such as Trusted Platform Modules
- Boot process logic or code
- Kernel software components
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 13 techniques in this category, Platform Hardening.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| Platform Hardening | D3-PH | Hardening components of a Platform with the intention of making them more difficult to exploit. Platforms includes components such as: * BIOS UEFI Subsystems * Hardware security devices such as Trusted Platform Modules * Boot process logic or code * Kernel software components | System Hardening , and Endpoint Hardening |
| - Software Update | D3-SU | Replacing old software on a computer system component. | |
| - Hardware-based Write Protection | D3-HBWP | Physical methods of preventing data from being written to computer storage. | |
| - RF Shielding | D3-RFS | Adding physical barriers to a platform to prevent undesired radio interference. | |
| - Physical Enclosure Hardening | D3-PEH | Physical changes to a computer enclosure which reduce the ability for agents or the environment to affect the contained computer system. | |
| - System Configuration Permissions | D3-SCP | Restricting system configuration modifications to a specific user or group of users. | |
| - Radiation Hardening | D3-RH | Radiation hardening is the process of making electronic components and circuits resistant to damage or malfunction caused by high levels of ionizing radiation. | |
| - File Encryption | D3-FE | Encrypting a file using a cryptographic key. | |
| - Disk Encryption | D3-DENCR | Encrypting a hard disk partition to prevent cleartext access to a file system. | |
| - Bootloader Authentication | D3-BA | Cryptographically authenticating the bootloader software before system boot. | Secure Boot |
| - TPM Boot Integrity | D3-TBI | Assuring the integrity of a platform by demonstrating that the boot process starts from a trusted combination of hardware and software and continues until the operating system has fully booted and applications are running. Sometimes called Static Root of Trust Measurement (STRM). | STRM , and Static Root of Trust Measurement |
| - Electromagnetic Radiation Hardening | D3-EMH | The application of physical and material-level design measures to electronic systems, components, or facilities to reduce their susceptibility to damage or disruption from electromagnetic threats. | EM Hardening |
| - Driver Load Integrity Checking | D3-DLIC | Ensuring the integrity of drivers loaded during initialization of the operating system. |
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , , and .
Command and Control
Application Layer Protocol
Encrypted Channel
Communication Through Removable Media
Execution
Software Deployment Tools
Hijack Execution Flow
Trusted Developer Utilities Proxy Execution
Command and Scripting Interpreter
Scheduled Task/Job
User Execution
Persistence
Pre-OS Boot
Boot or Logon Autostart Execution
Compromise Host Software Binary
Event Triggered Execution
Office Application Startup
Software Extensions
Server Software Component
Modify Authentication Process
Create or Modify System Process
Scheduled Task/Job
Boot or Logon Initialization Scripts
Modify Registry
Stealth
Pre-OS Boot
Hijack Execution Flow
Rootkit
Trusted Developer Utilities Proxy Execution
Hide Artifacts
Virtualization/Sandbox Evasion
System Binary Proxy Execution
XSL Script Processing
Process Injection
Masquerading
Obfuscated Files or Information
Impair Defenses
Deobfuscate/Decode Files or Information
Indicator Removal
Lateral Movement
Software Deployment Tools
Internal Spearphishing
Replication Through Removable Media
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol
Exfiltration Over Physical Medium
Initial Access
Supply Chain Compromise
Phishing
Replication Through Removable Media
Hardware Additions
Privilege Escalation
Boot or Logon Autostart Execution
Event Triggered Execution
Process Injection
Create or Modify System Process
Scheduled Task/Job
Boot or Logon Initialization Scripts
Abuse Elevation Control Mechanism
Impact
Inhibit System Recovery
Service Stop
Data Manipulation
Data Encrypted for Impact
Collection
Input Capture
Archive Collected Data
Data from Local System
Email Collection
Automated Collection
Data Staged
Video Capture
Data from Removable Media
Audio Capture
Credential Access
Input Capture
Exploitation for Credential Access
Steal or Forge Authentication Certificates
Modify Authentication Process
Credentials from Password Stores
OS Credential Dumping
Forced Authentication
Unsecured Credentials
Multi-Factor Authentication Interception
Discovery
Virtualization/Sandbox Evasion
System Network Configuration Discovery
System Owner/User Discovery
Remote System Discovery
File and Directory Discovery
Cloud Storage Object Discovery
System Location Discovery
Query Registry
Defense Impairment
Modify Authentication Process
Modify Registry
Rogue Domain Controller