
{"off_tactics":{"@context":{"rdfs":"http://www.w3.org/2000/01/rdf-schema#","owl":"http://www.w3.org/2002/07/owl#","d3f":"http://d3fend.mitre.org/ontologies/d3fend.owl#","skos":"http://www.w3.org/2004/02/skos/core#"},"@graph":[{"@id":"d3f:AML.TA0000","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0000","d3f:definition":"The adversary is attempting to gain some level of access to an AI model.\n\nAI Model Access enables techniques that use various types of access to the AI model that can be used by the adversary to gain information, develop attacks, and as a means to input data to the model.\nThe level of access can range from the full knowledge of the internals of the model to access to the physical environment where data is collected for use in the AI model.\nThe adversary may use varying levels of model access during the course of their attack, from staging the attack to impacting the target system.\n\nAccess to an AI model may require access to the system housing the model, the model may be publicly accessible via an API, or it may be accessed indirectly via interaction with a product or service that utilizes AI as part of its processes.","rdfs:label":"AI Model Access - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0000"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"AI Model Access"},{"@id":"d3f:AML.TA0001","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0001","d3f:definition":"The adversary is leveraging their knowledge of and access to the target system to tailor the attack.\n\nAI Attack Staging consists of techniques adversaries use to prepare their attack on the target AI model.\nTechniques can include training proxy models, poisoning the target model, and crafting adversarial data to feed the target model.\nSome of these techniques can be performed in an offline manner and are thus difficult to mitigate.\nThese techniques are often used to achieve the adversary's end goal.","rdfs:label":"AI Attack Staging - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0001"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"AI Attack Staging"},{"@id":"d3f:AML.TA0002","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0002","d3f:definition":"The adversary is trying to gather information about the AI system they can use to plan future operations.\n\nReconnaissance consists of techniques that involve adversaries actively or passively gathering information that can be used to support targeting.\nSuch information may include details of the victim organizations' AI capabilities and research efforts.\nThis information can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using gathered information to obtain relevant AI artifacts, targeting AI capabilities used by the victim, tailoring attacks to the particular models used by the victim, or to drive and lead further Reconnaissance efforts.","rdfs:label":"Reconnaissance - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0002"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Reconnaissance"},{"@id":"d3f:AML.TA0003","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0003","d3f:definition":"The adversary is trying to establish resources they can use to support operations.\n\nResource Development consists of techniques that involve adversaries creating,\npurchasing, or compromising/stealing resources that can be used to support targeting.\nSuch resources include AI artifacts, infrastructure, accounts, or capabilities.\nThese resources can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as [AI Attack Staging](/tactics/AML.TA0001).","rdfs:label":"Resource Development - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0003"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Resource Development"},{"@id":"d3f:AML.TA0004","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0004","d3f:definition":"The adversary is trying to gain access to the AI system.\n\nThe target system could be a network, mobile device, or an edge device such as a sensor platform.\nThe AI capabilities used by the system could be local with onboard or cloud-enabled AI capabilities.\n\nInitial Access consists of techniques that use various entry vectors to gain their initial foothold within the system.","rdfs:label":"Initial Access - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0004"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Initial Access"},{"@id":"d3f:AML.TA0005","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0005","d3f:definition":"The adversary is trying to run malicious code embedded in AI artifacts or software.\n\nExecution consists of techniques that result in adversary-controlled code running on a local or remote system.\nTechniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data.\nFor example, an adversary might use a remote access tool to run a PowerShell script that does [Remote System Discovery](https://attack.mitre.org/techniques/T1018/).","rdfs:label":"Execution - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0005"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Execution"},{"@id":"d3f:AML.TA0006","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0006","d3f:definition":"The adversary is trying to maintain their foothold via AI artifacts or software.\n\nPersistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access.\nTechniques used for persistence often involve leaving behind modified ML artifacts such as poisoned training data or manipulated AI models.","rdfs:label":"Persistence - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0006"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Persistence"},{"@id":"d3f:AML.TA0007","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0007","d3f:definition":"The adversary is trying to avoid being detected by AI-enabled security software.\n\nDefense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise.\nTechniques used for defense evasion include evading AI-enabled security software such as malware detectors.","rdfs:label":"Defense Evasion - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0007"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Defense Evasion"},{"@id":"d3f:AML.TA0008","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0008","d3f:definition":"The adversary is trying to figure out your AI environment.\n\nDiscovery consists of techniques an adversary may use to gain knowledge about the system and internal network.\nThese techniques help adversaries observe the environment and orient themselves before deciding how to act.\nThey also allow adversaries to explore what they can control and what's around their entry point in order to discover how it could benefit their current objective.\nNative operating system tools are often used toward this post-compromise information-gathering objective.","rdfs:label":"Discovery - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0008"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Discovery"},{"@id":"d3f:AML.TA0009","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0009","d3f:definition":"The adversary is trying to gather AI artifacts and other related information relevant to their goal.\n\nCollection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives.\nFrequently, the next goal after collecting data is to steal (exfiltrate) the AI artifacts, or use the collected information to stage future operations.\nCommon target sources include software repositories, container registries, model repositories, and object stores.","rdfs:label":"Collection - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0009"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Collection"},{"@id":"d3f:AML.TA0010","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0010","d3f:definition":"The adversary is trying to steal AI artifacts or other information about the AI system.\n\nExfiltration consists of techniques that adversaries may use to steal data from your network.\nData may be stolen for its valuable intellectual property, or for use in staging future operations.\n\nTechniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission.","rdfs:label":"Exfiltration - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0010"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Exfiltration"},{"@id":"d3f:AML.TA0011","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0011","d3f:definition":"The adversary is trying to manipulate, interrupt, erode confidence in, or destroy your AI systems and data.\n\nImpact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes.\nTechniques used for impact can include destroying or tampering with data.\nIn some cases, business processes can look fine, but may have been altered to benefit the adversaries' goals.\nThese techniques might be used by adversaries to follow through on their end goal or to provide cover for a confidentiality breach.","rdfs:label":"Impact - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0011"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Impact"},{"@id":"d3f:AML.TA0012","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0012","d3f:definition":"The adversary is trying to gain higher-level permissions.\n\nPrivilege Escalation consists of techniques that adversaries use to gain higher-level permissions on a system or network. Adversaries can often enter and explore a network with unprivileged access but require elevated permissions to follow through on their objectives. Common approaches are to take advantage of system weaknesses, misconfigurations, and vulnerabilities. Examples of elevated access include:\n- SYSTEM/root level\n- local administrator\n- user account with admin-like access\n- user accounts with access to specific system or perform specific function\n\nThese techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context.","rdfs:label":"Privilege Escalation - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0012"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Privilege Escalation"},{"@id":"d3f:AML.TA0013","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0013","d3f:definition":"The adversary is trying to steal account names and passwords.\n\nCredential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.","rdfs:label":"Credential Access - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0013"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Credential Access"},{"@id":"d3f:AML.TA0014","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0014","d3f:definition":"The adversary is trying to communicate with compromised AI systems to control them.\n\nCommand and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim's network structure and defenses.","rdfs:label":"Command and Control - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0014"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Command and Control"},{"@id":"d3f:AML.TA0015","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:attack-id":"AML.TA0015","d3f:definition":"The adversary is trying to move through your AI environment.\n\nLateral Movement consists of techniques that adversaries may use to gain access to and control other systems or components in the environment. Adversaries may pivot towards AI Ops infrastructure such as model registries, experiment trackers, vector databases, notebooks, or training pipelines. As the adversary moves through the environment, they may discover means of accessing additional AI-related tools, services, or applications. AI agents may also be a valuable target as they commonly have more permissions than standard user accounts on the system.","rdfs:label":"Lateral Movement - ATLAS","rdfs:seeAlso":{"@id":"https://atlas.mitre.org/tactics/AML.TA0015"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATLASTactic"}],"skos:prefLabel":"Lateral Movement"},{"@id":"d3f:ST0001","@type":["owl:NamedIndividual","d3f:SPARTATactic","owl:Class"],"d3f:definition":"Threat actor is trying to gather information they can use to plan future operations.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"1"},"rdfs:label":"Reconnaissance - SPARTA","rdfs:seeAlso":{"@id":"https://sparta.aerospace.org/tactic/ST0001"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:SPARTATactic"}],"skos:prefLabel":"Reconnaissance"},{"@id":"d3f:ST0002","@type":["owl:NamedIndividual","d3f:SPARTATactic","owl:Class"],"d3f:definition":"Threat actor is trying to establish resources they can use to support operations.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"2"},"rdfs:label":"Resource Development - SPARTA","rdfs:seeAlso":{"@id":"https://sparta.aerospace.org/tactic/ST0002"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:SPARTATactic"}],"skos:prefLabel":"Resource Development"},{"@id":"d3f:ST0003","@type":["owl:NamedIndividual","d3f:SPARTATactic","owl:Class"],"d3f:definition":"Threat actor is trying to get point of presence/command execution on the spacecraft.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"3"},"rdfs:label":"Initial Access - SPARTA","rdfs:seeAlso":{"@id":"https://sparta.aerospace.org/tactic/ST0003"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:SPARTATactic"}],"skos:prefLabel":"Initial Access"},{"@id":"d3f:ST0004","@type":["owl:NamedIndividual","d3f:SPARTATactic","owl:Class"],"d3f:definition":"Threat actor is trying to execute malicious code on the spacecraft.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"4"},"rdfs:label":"Execution - SPARTA","rdfs:seeAlso":{"@id":"https://sparta.aerospace.org/tactic/ST0004"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:SPARTATactic"}],"skos:prefLabel":"Execution"},{"@id":"d3f:ST0005","@type":["owl:NamedIndividual","d3f:SPARTATactic","owl:Class"],"d3f:definition":"Threat actor is trying to maintain their foothold/access to command/execute code on the spacecraft.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"5"},"rdfs:label":"Persistence - SPARTA","rdfs:seeAlso":{"@id":"https://sparta.aerospace.org/tactic/ST0005"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:SPARTATactic"}],"skos:prefLabel":"Persistence"},{"@id":"d3f:ST0006","@type":["owl:NamedIndividual","d3f:SPARTATactic","owl:Class"],"d3f:definition":"Threat actor is trying to avoid being detected.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"6"},"rdfs:label":"Defense Evasion - SPARTA","rdfs:seeAlso":{"@id":"https://sparta.aerospace.org/tactic/ST0006"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:SPARTATactic"}],"skos:prefLabel":"Defense Evasion"},{"@id":"d3f:ST0007","@type":["owl:NamedIndividual","d3f:SPARTATactic","owl:Class"],"d3f:definition":"Threat actor is trying to move through across sub-systems of the spacecraft.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"7"},"rdfs:label":"Lateral Movement - SPARTA","rdfs:seeAlso":{"@id":"https://sparta.aerospace.org/tactic/ST0007"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:SPARTATactic"}],"skos:prefLabel":"Lateral Movement"},{"@id":"d3f:ST0008","@type":["owl:NamedIndividual","d3f:SPARTATactic","owl:Class"],"d3f:definition":"Threat actor is trying to steal information.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"8"},"rdfs:label":"Exfiltration - SPARTA","rdfs:seeAlso":{"@id":"https://sparta.aerospace.org/tactic/ST0008"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:SPARTATactic"}],"skos:prefLabel":"Exfiltration"},{"@id":"d3f:ST0009","@type":["owl:NamedIndividual","d3f:SPARTATactic","owl:Class"],"d3f:definition":"Threat actor is trying to manipulate, interrupt, or destroy the space system(s) and/or data.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"9"},"rdfs:label":"Impact - SPARTA","rdfs:seeAlso":{"@id":"https://sparta.aerospace.org/tactic/ST0009"},"rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:SPARTATactic"}],"skos:prefLabel":"Impact"},{"@id":"d3f:TA0001","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to get into your network.\n\nInitial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"1"},"rdfs:label":"Initial Access","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0002","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to run malicious code.\n\nExecution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"2"},"rdfs:label":"Execution","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0003","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to maintain their foothold.\n\nPersistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"3"},"rdfs:label":"Persistence","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0004","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to gain higher-level permissions.\n\nPrivilege Escalation consists of techniques that adversaries use to gain higher-level permissions on a system or network. Adversaries can often enter and explore a network with unprivileged access but require elevated permissions to follow through on their objectives. Common approaches are to take advantage of system weaknesses, misconfigurations, and vulnerabilities. Examples of elevated access include:\n\n* SYSTEM/root level\n* local administrator\n* user account with admin-like access\n* user accounts with access to specific system or perform specific function\n\nThese techniques often overlap with Persistence techniques, as OS features that let an adversary persist can execute in an elevated context.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"4"},"rdfs:label":"Privilege Escalation","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0005","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to hide and conceal their actions, appearing as normal behavior.\n\nStealth consists of techniques that reduce the likelihood of detection by blending in with legitimate activity or minimizing observable signals. These techniques are characterized by concealment behaviors, such as avoiding, obfuscating, or mimicking normal operations, without modifying security controls or compromising collection and monitoring feeds. The goal is to remain indistinguishable from benign activity while leaving defensive systems intact.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"5"},"rdfs:label":"Stealth","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0006","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to steal account names and passwords.\n\nCredential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"7"},"rdfs:label":"Credential Access","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0007","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to figure out your environment.\n\nDiscovery consists of techniques an adversary may use to gain knowledge about the system and internal network. These techniques help adversaries observe the environment and orient themselves before deciding how to act. They also allow adversaries to explore what they can control and what’s around their entry point in order to discover how it could benefit their current objective. Native operating system tools are often used toward this post-compromise information-gathering objective.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"8"},"rdfs:label":"Discovery","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0008","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to move through your environment.\n\nLateral Movement consists of techniques that adversaries use to enter and control remote systems on a network. Following through on their primary objective often requires exploring the network to find their target, then pivoting through multiple systems and accounts to gain access to it. Adversaries might install their own remote access tools to accomplish Lateral Movement or use legitimate credentials with native network and operating system tools, which may be stealthier.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"9"},"rdfs:label":"Lateral Movement","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0009","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to gather data of interest to their goal.\n\nCollection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to either steal (exfiltrate) the data or to use the data to gain more information about the target environment. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"10"},"rdfs:label":"Collection","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0010","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to steal data.\n\nExfiltration consists of techniques that adversaries may use to steal data from your network. Once they’ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"12"},"rdfs:label":"Exfiltration","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0011","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to communicate with compromised systems to control them.\n\nCommand and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim’s network structure and defenses.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"11"},"rdfs:label":"Command and Control","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0027","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Initial Access - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Initial Access"},{"@id":"d3f:TA0028","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Persistence - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Persistence"},{"@id":"d3f:TA0029","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Privilege Escalation - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Privilege Escalation"},{"@id":"d3f:TA0030","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Defense Evasion - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Defense Evasion"},{"@id":"d3f:TA0031","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Credential Access - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Credential Access"},{"@id":"d3f:TA0032","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Discovery - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Discovery"},{"@id":"d3f:TA0033","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Lateral Movement - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Lateral Movement"},{"@id":"d3f:TA0034","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Impact - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Impact"},{"@id":"d3f:TA0035","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Collection - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Collection"},{"@id":"d3f:TA0036","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Exfiltration - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Exfiltration"},{"@id":"d3f:TA0037","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Command and Control - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}],"skos:prefLabel":"Command and Control"},{"@id":"d3f:TA0040","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to manipulate, interrupt, or destroy your systems and data.\n\nImpact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes. Techniques used for impact can include destroying or tampering with data. In some cases, business processes can look fine, but may have been altered to benefit the adversaries’ goals. These techniques might be used by adversaries to follow through on their end goal or to provide cover for a confidentiality breach.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"13"},"rdfs:label":"Impact","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0041","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Execution - ATTACK Mobile","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKMobileTactic"}]},{"@id":"d3f:TA0042","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to establish resources they can use to support operations.\n\nResource Development consists of techniques that involve adversaries creating, purchasing, or compromising/stealing resources that can be used to support targeting. Such resources include infrastructure, accounts, or capabilities. These resources can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using purchased domains to support Command and Control, email accounts for phishing as a part of Initial Access, or stealing code signing certificates to help with Defense Evasion.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"0"},"rdfs:label":"Resource Development","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0043","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to gather information they can use to plan future operations.\n\nReconnaissance consists of techniques that involve adversaries actively or passively gathering information that can be used to support targeting. Such information may include details of the victim organization, infrastructure, or staff/personnel. This information can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using gathered information to plan and execute Initial Access, to scope and prioritize post-compromise objectives, or to drive and lead further Reconnaissance efforts.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"-1"},"rdfs:label":"Reconnaissance","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]},{"@id":"d3f:TA0100","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Collection - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Collection"},{"@id":"d3f:TA0101","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Command and Control - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Command and Control"},{"@id":"d3f:TA0102","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Discovery - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Discovery"},{"@id":"d3f:TA0103","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Evasion - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Evasion"},{"@id":"d3f:TA0104","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Execution - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Execution"},{"@id":"d3f:TA0105","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Impact - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Impact"},{"@id":"d3f:TA0106","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Impair Process Control - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Impair Process Control"},{"@id":"d3f:TA0107","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Inhibit Response Function - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Inhibit Response Function"},{"@id":"d3f:TA0108","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Initial Access - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Initial Access"},{"@id":"d3f:TA0109","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Lateral Movement - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Lateral Movement"},{"@id":"d3f:TA0110","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Persistence - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Persistence"},{"@id":"d3f:TA0111","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"rdfs:label":"Privilege Escalation - ATTACK ICS","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKICSTactic"}],"skos:prefLabel":"Privilege Escalation"},{"@id":"d3f:TA0112","@type":["d3f:OffensiveTactic","owl:NamedIndividual","owl:Class"],"d3f:definition":"The adversary is trying to break security mechanisms, pipelines, and tooling so defenders can’t see or trust what’s happening.\n\nDefense Impairment consists of techniques that degrade, disable, or undermine the effectiveness and trustworthiness of security controls and monitoring mechanisms. These techniques are characterized by direct interference with defensive systems. The goal is to reduce defenders’ ability to detect, interpret, or respond to adversary activity.","d3f:display-order":{"@type":"http://www.w3.org/2001/XMLSchema#integer","@value":"6"},"rdfs:label":"Defense Impairment","rdfs:subClassOf":[{"@id":"d3f:OffensiveTactic"},{"@id":"d3f:ATTACKEnterpriseTactic"}]}]},"def_to_off":{"head":{"vars":["query_def_tech_label","top_def_tech_label","def_tactic_label","def_tactic_rel_label","def_tech_label","def_artifact_rel_label","def_artifact_label","off_artifact_label","off_artifact_rel_label","off_tech_label","off_tech_id","framework_root_iri","off_tech_parent_label","off_tech_parent_is_toplevel","off_tactic_rel_label","off_tactic_label","def_tactic","def_tactic_rel","def_tech","def_artifact_rel","def_artifact","off_artifact","off_artifact_rel","off_tech","off_tech_parent","off_tactic_rel","off_tactic"]},"results":{"bindings":[{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"off_artifact_label":{"type":"literal","value":"Stored Procedure"},"off_artifact_rel_label":{"type":"literal","value":"creates"},"off_tech_label":{"type":"literal","value":"SQL Stored Procedures"},"off_tech_id":{"type":"literal","value":"T1505.001"},"framework_root_iri":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#ATTACKEnterpriseTechnique"},"off_tech_parent_label":{"type":"literal","value":"Server Software Component"},"off_tech_parent_is_toplevel":{"type":"literal","value":"false","datatype":"http://www.w3.org/2001/XMLSchema#boolean"},"off_tactic_rel_label":{"type":"literal","value":"enables"},"off_tactic_label":{"type":"literal","value":"Persistence"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"off_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#StoredProcedure"},"off_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#creates"},"off_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.001"},"off_tech_parent":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#T1505"},"off_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"off_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TA0003"},"framework_key":{"type":"literal","value":"enterprise"},"framework_label":{"type":"literal","value":"Enterprise"},"framework_root":{"type":"literal","value":"d3f:ATTACKEnterpriseTechnique"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"off_artifact_label":{"type":"literal","value":"Raw Memory Access Function"},"off_artifact_rel_label":{"type":"literal","value":"invokes"},"off_tech_label":{"type":"literal","value":"Memory Write/Loads"},"off_tech_id":{"type":"literal","value":"EX-0012.03"},"framework_root_iri":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#SPARTATechnique"},"off_tech_parent_label":{"type":"literal","value":"Modify On-Board Values"},"off_tech_parent_is_toplevel":{"type":"literal","value":"false","datatype":"http://www.w3.org/2001/XMLSchema#boolean"},"off_tactic_rel_label":{"type":"literal","value":"enables"},"off_tactic_label":{"type":"literal","value":"Execution"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"off_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#RawMemoryAccessFunction"},"off_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#invokes"},"off_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#EX-0012.03"},"off_tech_parent":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#EX-0012"},"off_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"off_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#ST0004"},"framework_key":{"type":"literal","value":"sparta"},"framework_label":{"type":"literal","value":"SPARTA"},"framework_root":{"type":"literal","value":"d3f:SPARTATechnique"}}]}},"description":{"@context":{"rdfs":"http://www.w3.org/2000/01/rdf-schema#","owl":"http://www.w3.org/2002/07/owl#","d3f":"http://d3fend.mitre.org/ontologies/d3fend.owl#","skos":"http://www.w3.org/2004/02/skos/core#"},"@graph":[{"@id":"d3f:TrustedLibrary","@type":["owl:NamedIndividual","owl:Class"],"d3f:d3fend-id":"D3-TL","d3f:definition":"A trusted library is a collection of pre-verified and secure code modules or components that are used within software applications to perform specific functions. These libraries are considered reliable and have been vetted for security vulnerabilities, ensuring they do not introduce risks into the application.","d3f:hardens":{"@id":"d3f:Subroutine"},"d3f:kb-article":"## How it Works\nUsing a trusted library can reduce the chances of introducing errors compared to writing code from scratch.\n\n\n\n## Considerations\n\nNote: This resource should not be considered a definitive or exhaustive coding guideline.","d3f:kb-reference":{"@id":"d3f:Reference-LeverageSecurityFrameworksLibraries_OWASP"},"rdfs:label":"Trusted Library","rdfs:subClassOf":{"@id":"d3f:SourceCodeHardening"}}]},"digital_artifacts":{"head":{"vars":["query_def_tech_label","top_def_tech_label","def_tech_label","def_artifact_rel_label","def_artifact_label","def_tactic","def_tactic_rel","def_tech","def_artifact_rel","def_artifact"]},"results":{"bindings":[{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"}}]}},"subtechniques":{"@context":{"rdfs":"http://www.w3.org/2000/01/rdf-schema#","owl":"http://www.w3.org/2002/07/owl#","d3f":"http://d3fend.mitre.org/ontologies/d3fend.owl#","skos":"http://www.w3.org/2004/02/skos/core#"},"@graph":[]},"weaknesses":{"head":{"vars":["query_def_tech_label","top_def_tech_label","def_tactic_label","def_tactic_rel_label","def_tech_label","def_artifact_rel_label","def_artifact_label","weak_artifact_label","weak_artifact_rel_label","weak_label","def_tactic","def_tactic_rel","def_tech","def_artifact_rel","def_artifact","weak_artifact","weak_artifact_rel","weak","weak_id"]},"results":{"bindings":[{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Authentication Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Use of Hard-coded Credentials"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-798"},"weak_id":{"type":"literal","value":"CWE-798"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Raw Memory Access Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Out-of-bounds Read"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#RawMemoryAccessFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-125"},"weak_id":{"type":"literal","value":"CWE-125"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Eval Function"},"weak_artifact_rel_label":{"type":"literal","value":"may-be-weakness-of"},"weak_label":{"type":"literal","value":"Improper Control of Generation of Code ('Code Injection')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#EvalFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-94"},"weak_id":{"type":"literal","value":"CWE-94"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Eval Function"},"weak_artifact_rel_label":{"type":"literal","value":"may-be-weakness-of"},"weak_label":{"type":"literal","value":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#EvalFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-78"},"weak_id":{"type":"literal","value":"CWE-78"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Raw Memory Access Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Improper Restriction of Operations within the Bounds of a Memory Buffer"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#RawMemoryAccessFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-119"},"weak_id":{"type":"literal","value":"CWE-119"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"may-be-weakness-of"},"weak_label":{"type":"literal","value":"Deserialization of Untrusted Data"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-502"},"weak_id":{"type":"literal","value":"CWE-502"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Pointer Dereferencing Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"NULL Pointer Dereference"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#PointerDereferencingFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-476"},"weak_id":{"type":"literal","value":"CWE-476"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Pointer Dereferencing Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Untrusted Pointer Dereference"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#PointerDereferencingFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-822"},"weak_id":{"type":"literal","value":"CWE-822"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Memory Free Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Double Free"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryFreeFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-415"},"weak_id":{"type":"literal","value":"CWE-415"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Pointer Dereferencing Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Access of Uninitialized Pointer"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#PointerDereferencingFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-824"},"weak_id":{"type":"literal","value":"CWE-824"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Process Start Function"},"weak_artifact_rel_label":{"type":"literal","value":"may-be-weakness-of"},"weak_label":{"type":"literal","value":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#ProcessStartFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-78"},"weak_id":{"type":"literal","value":"CWE-78"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Memory Free Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Free of Memory not on the Heap"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryFreeFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-590"},"weak_id":{"type":"literal","value":"CWE-590"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-22"},"weak_id":{"type":"literal","value":"CWE-22"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Cross-Site Request Forgery (CSRF)"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-352"},"weak_id":{"type":"literal","value":"CWE-352"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Expired Pointer Dereference"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-825"},"weak_id":{"type":"literal","value":"CWE-825"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-79"},"weak_id":{"type":"literal","value":"CWE-79"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Shared Resource Access Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#SharedResourceAccessFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-362"},"weak_id":{"type":"literal","value":"CWE-362"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Memory Free Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Free of Pointer not at Start of Buffer"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#MemoryFreeFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-761"},"weak_id":{"type":"literal","value":"CWE-761"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Deserialization Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Deserialization of Untrusted Data"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#DeserializationFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-502"},"weak_id":{"type":"literal","value":"CWE-502"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Improper Neutralization of Special Elements used in a Command ('Command Injection')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-77"},"weak_id":{"type":"literal","value":"CWE-77"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Raw Memory Access Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Out-of-bounds Write"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#RawMemoryAccessFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-787"},"weak_id":{"type":"literal","value":"CWE-787"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Improper Input Validation"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-20"},"weak_id":{"type":"literal","value":"CWE-20"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Server-Side Request Forgery (SSRF)"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-918"},"weak_id":{"type":"literal","value":"CWE-918"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Unrestricted Upload of File with Dangerous Type"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-434"},"weak_id":{"type":"literal","value":"CWE-434"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"may-be-weakness-of"},"weak_label":{"type":"literal","value":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-78"},"weak_id":{"type":"literal","value":"CWE-78"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Authentication Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Improper Authentication"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#AuthenticationFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-287"},"weak_id":{"type":"literal","value":"CWE-287"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"External Content Inclusion Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Improper Restriction of XML External Entity Reference"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#ExternalContentInclusionFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-611"},"weak_id":{"type":"literal","value":"CWE-611"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"Mathematical Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Integer Overflow or Wraparound"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#MathematicalFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-190"},"weak_id":{"type":"literal","value":"CWE-190"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"weakness-of"},"weak_label":{"type":"literal","value":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-89"},"weak_id":{"type":"literal","value":"CWE-89"}},{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"weak_artifact_label":{"type":"literal","value":"User Input Function"},"weak_artifact_rel_label":{"type":"literal","value":"may-be-weakness-of"},"weak_label":{"type":"literal","value":"Improper Control of Generation of Code ('Code Injection')"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"weak_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#UserInputFunction"},"weak_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#may-be-weakness-of"},"weak":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#CWE-94"},"weak_id":{"type":"literal","value":"CWE-94"}}]}},"related_offensive_matrix":{"Persistence":[["Server Software Component",[{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"off_artifact_label":{"type":"literal","value":"Stored Procedure"},"off_artifact_rel_label":{"type":"literal","value":"creates"},"off_tech_label":{"type":"literal","value":"SQL Stored Procedures"},"off_tech_id":{"type":"literal","value":"T1505.001"},"framework_root_iri":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#ATTACKEnterpriseTechnique"},"off_tech_parent_label":{"type":"literal","value":"Server Software Component"},"off_tech_parent_is_toplevel":{"type":"literal","value":"false","datatype":"http://www.w3.org/2001/XMLSchema#boolean"},"off_tactic_rel_label":{"type":"literal","value":"enables"},"off_tactic_label":{"type":"literal","value":"Persistence"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"off_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#StoredProcedure"},"off_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#creates"},"off_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#T1505.001"},"off_tech_parent":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#T1505"},"off_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"off_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TA0003"},"framework_key":{"type":"literal","value":"enterprise"},"framework_label":{"type":"literal","value":"Enterprise"},"framework_root":{"type":"literal","value":"d3f:ATTACKEnterpriseTechnique"}}]]],"Execution":[["Modify On-Board Values",[{"query_def_tech_label":{"type":"literal","value":"Trusted Library"},"top_def_tech_label":{"type":"literal","value":"Source Code Hardening"},"def_tactic_label":{"type":"literal","value":"Harden"},"def_tactic_rel_label":{"type":"literal","value":"enables"},"def_tech_label":{"type":"literal","value":"Trusted Library"},"def_artifact_rel_label":{"type":"literal","value":"hardens"},"def_artifact_label":{"type":"literal","value":"Subroutine"},"off_artifact_label":{"type":"literal","value":"Raw Memory Access Function"},"off_artifact_rel_label":{"type":"literal","value":"invokes"},"off_tech_label":{"type":"literal","value":"Memory Write/Loads"},"off_tech_id":{"type":"literal","value":"EX-0012.03"},"framework_root_iri":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#SPARTATechnique"},"off_tech_parent_label":{"type":"literal","value":"Modify On-Board Values"},"off_tech_parent_is_toplevel":{"type":"literal","value":"false","datatype":"http://www.w3.org/2001/XMLSchema#boolean"},"off_tactic_rel_label":{"type":"literal","value":"enables"},"off_tactic_label":{"type":"literal","value":"Execution"},"def_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Harden"},"def_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"def_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#TrustedLibrary"},"def_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#hardens"},"def_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#Subroutine"},"off_artifact":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#RawMemoryAccessFunction"},"off_artifact_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#invokes"},"off_tech":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#EX-0012.03"},"off_tech_parent":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#EX-0012"},"off_tactic_rel":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#enables"},"off_tactic":{"type":"uri","value":"http://d3fend.mitre.org/ontologies/d3fend.owl#ST0004"},"framework_key":{"type":"literal","value":"sparta"},"framework_label":{"type":"literal","value":"SPARTA"},"framework_root":{"type":"literal","value":"d3f:SPARTATechnique"}}]]]},"references":{"@context":{"rdfs":"http://www.w3.org/2000/01/rdf-schema#","d3f":"http://d3fend.mitre.org/ontologies/d3fend.owl#"},"@graph":[{"@id":"d3f:Reference-LeverageSecurityFrameworksLibraries_OWASP","@type":["d3f:GuidelineReference","http://www.w3.org/2002/07/owl#NamedIndividual"],"d3f:has-link":{"@type":"http://www.w3.org/2001/XMLSchema#anyURI","@value":"https://top10proactive.owasp.org/archive/2018/c2-leverage-security-frameworks-libraries/"},"d3f:kb-organization":"OWASP","d3f:kb-reference-of":{"@id":"d3f:TrustedLibrary"},"d3f:kb-reference-title":"Leverage Security Frameworks and Libraries","d3f:reference-type-label":"Guideline","rdfs:label":"Reference - Leverage Security Frameworks and Libraries - OWASP"}]},"references_meta":{"Guideline":1}}