{
  "technique_id": "T1207",
  "mappings": [
    {
      "attack_technique": "T1207 Rogue Domain Controller",
      "d3fend_technique": "User Geolocation Logon Pattern Analysis",
      "soc_action": "Monitor for User Geolocation Logon Pattern Analysis indicators relevant to this technique.",
      "tooling": [
        "Defender for Endpoint"
      ]
    },
    {
      "attack_technique": "T1207 Rogue Domain Controller",
      "d3fend_technique": "System Configuration Permissions",
      "soc_action": "Apply System Configuration Permissions to reduce this technique's viability before an incident occurs.",
      "tooling": [
        "Defender for Endpoint"
      ]
    },
    {
      "attack_technique": "T1207 Rogue Domain Controller",
      "d3fend_technique": "Network Traffic Filtering",
      "soc_action": "Apply Network Traffic Filtering to contain the blast radius once this technique is observed.",
      "tooling": [
        "Sentinel",
        "Defender for Endpoint"
      ]
    },
    {
      "attack_technique": "T1207 Rogue Domain Controller",
      "d3fend_technique": "Restore Database",
      "soc_action": "Use Restore Database to recover affected systems or data after containment.",
      "tooling": [
        "Defender for Endpoint"
      ]
    }
  ]
}