{
  "technique_id": "T1040",
  "d3fend_mappings": [
    {
      "id": "D3-DNSTA",
      "name": "DNS Traffic Analysis",
      "relationship": "detect",
      "practical_action": "Monitor for DNS Traffic Analysis indicators relevant to this technique.",
      "tooling": [
        "Sentinel",
        "Defender for Endpoint"
      ]
    }
  ]
}