Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

MITRE D3FEND tables

MITRE D3FEND integration uses various tables to capture data.

Defend Tactics

FieldDescription
Tactic IDID of the defend tactic.
Tactic NameName of the defend tactic
DefinitionDescription of the defend tactic.

Defend Techniques

FieldDescription
NameName of the defend technique.
Defend TacticTactic to which the defend technique belongs.
Technique IDID of the technique.
DefinitionDescription of the defend technique.
KB ArticleLink to a knowledge base article or other additional information about this technique.
Parent Defend TechniqueParent technique of the defend technique.
SynonymsSynonym of the defend technique.

Defend Artifacts

FieldDescription
Artifact IDID of the defend artifact.
Artifact NameName of the defend artifact.
DefinitionDescription or the use of the defend technique.
RevokedRevoked status of the defend artifact.
DomainDomain of the defend artifact.

Defend Techniques Artifacts

FieldDescription
Defend ArtifactName of the defend artifact.
Defend TechniqueDefend technique to which the artifact belongs to.
Relationship LabelAction that the defend technique takes on the defend artifact.
RevokedRevoked status of the defend artifact.
DomainDomain of the defend artifact.
FieldDescription
Automatically addedIndicates whether the defend technique was automatically added to the table.
Defend TechniqueName of the defend technique.
Inheritance countNumber of times this technique is inherited.
DomainDomain of the defend technique.
TaskRelated security incident.

Defend ATT&CK Techniques

FieldDescription
ATTACK TechniqueATT&CK technique name.
Defend TechniqueDefend techniques that correspond to the ATT&CK technique.