Esc
Platform Hardening
Definition
Hardening components of a Platform with the intention of making them more difficult to exploit.
Platforms includes components such as:
- BIOS UEFI Subsystems
- Hardware security devices such as Trusted Platform Modules
- Boot process logic or code
- Kernel software components
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 13 techniques in this category, Platform Hardening.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| Platform Hardening | D3-PH | Hardening components of a Platform with the intention of making them more difficult to exploit. Platforms includes components such as: * BIOS UEFI Subsystems * Hardware security devices such as Trusted Platform Modules * Boot process logic or code * Kernel software components | System Hardening , and Endpoint Hardening |
| - Software Update | D3-SU | Replacing old software on a computer system component. | |
| - Hardware-based Write Protection | D3-HBWP | Physical methods of preventing data from being written to computer storage. | |
| - RF Shielding | D3-RFS | Adding physical barriers to a platform to prevent undesired radio interference. | |
| - Physical Enclosure Hardening | D3-PEH | Physical changes to a computer enclosure which reduce the ability for agents or the environment to affect the contained computer system. | |
| - System Configuration Permissions | D3-SCP | Restricting system configuration modifications to a specific user or group of users. | |
| - Radiation Hardening | D3-RH | Radiation hardening is the process of making electronic components and circuits resistant to damage or malfunction caused by high levels of ionizing radiation. | |
| - File Encryption | D3-FE | Encrypting a file using a cryptographic key. | |
| - Disk Encryption | D3-DENCR | Encrypting a hard disk partition to prevent cleartext access to a file system. | |
| - Bootloader Authentication | D3-BA | Cryptographically authenticating the bootloader software before system boot. | Secure Boot |
| - TPM Boot Integrity | D3-TBI | Assuring the integrity of a platform by demonstrating that the boot process starts from a trusted combination of hardware and software and continues until the operating system has fully booted and applications are running. Sometimes called Static Root of Trust Measurement (STRM). | STRM , and Static Root of Trust Measurement |
| - Electromagnetic Radiation Hardening | D3-EMH | The application of physical and material-level design measures to electronic systems, components, or facilities to reduce their susceptibility to damage or disruption from electromagnetic threats. | EM Hardening |
| - Driver Load Integrity Checking | D3-DLIC | Ensuring the integrity of drivers loaded during initialization of the operating system. |
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , , and .
Persistence
Server Software Component
Event Triggered Execution
Boot or Logon Autostart Execution
Modify Authentication Process
Modify Registry
Create or Modify System Process
Office Application Startup
Pre-OS Boot
Compromise Host Software Binary
Boot or Logon Initialization Scripts
Scheduled Task/Job
Software Extensions
Collection
Email Collection
Archive Collected Data
Automated Collection
Data Staged
Data from Local System
Video Capture
Input Capture
Data from Removable Media
Audio Capture
Credential Access
OS Credential Dumping
Modify Authentication Process
Unsecured Credentials
Input Capture
Multi-Factor Authentication Interception
Steal or Forge Authentication Certificates
Credentials from Password Stores
Exploitation for Credential Access
Forced Authentication
Stealth
Process Injection
Obfuscated Files or Information
Deobfuscate/Decode Files or Information
Hijack Execution Flow
Masquerading
Indicator Removal
Rootkit
Hide Artifacts
XSL Script Processing
System Binary Proxy Execution
Trusted Developer Utilities Proxy Execution
Pre-OS Boot
Virtualization/Sandbox Evasion
Impair Defenses
Privilege Escalation
Process Injection
Abuse Elevation Control Mechanism
Event Triggered Execution
Boot or Logon Initialization Scripts
Boot or Logon Autostart Execution
Create or Modify System Process
Scheduled Task/Job
Execution
User Execution
Hijack Execution Flow
Software Deployment Tools
Trusted Developer Utilities Proxy Execution
Command and Scripting Interpreter
Scheduled Task/Job
Impact
Data Manipulation
Data Encrypted for Impact
Inhibit System Recovery
Service Stop
Defense Impairment
Modify Authentication Process
Modify Registry
Rogue Domain Controller
Lateral Movement
Software Deployment Tools
Replication Through Removable Media
Internal Spearphishing
Discovery
File and Directory Discovery
Cloud Storage Object Discovery
System Location Discovery
Query Registry
System Network Configuration Discovery
System Owner/User Discovery
Remote System Discovery
Virtualization/Sandbox Evasion
Initial Access
Phishing
Replication Through Removable Media
Supply Chain Compromise
Hardware Additions
Exfiltration
Exfiltration Over Physical Medium
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol
Command and Control
Communication Through Removable Media
Encrypted Channel
Application Layer Protocol