{
  "technique_id": "T1542",
  "d3fend_mappings": [
    {
      "id": "D3-FEMC",
      "name": "Firmware Embedded Monitoring Code",
      "relationship": "detect",
      "practical_action": "Monitor for Firmware Embedded Monitoring Code indicators relevant to this technique.",
      "tooling": [
        "Defender for Endpoint"
      ]
    },
    {
      "id": "D3-SU",
      "name": "Software Update",
      "relationship": "harden",
      "practical_action": "Apply Software Update to reduce this technique's viability before an incident occurs.",
      "tooling": [
        "Defender for Endpoint"
      ]
    },
    {
      "id": "D3-NTF",
      "name": "Network Traffic Filtering",
      "relationship": "isolate",
      "practical_action": "Apply Network Traffic Filtering to contain the blast radius once this technique is observed.",
      "tooling": [
        "Sentinel",
        "Defender for Endpoint"
      ]
    },
    {
      "id": "D3-RS",
      "name": "Restore Software",
      "relationship": "restore",
      "practical_action": "Use Restore Software to recover affected systems or data after containment.",
      "tooling": [
        "Defender for Endpoint"
      ]
    }
  ]
}