{
  "technique_id": "T1553",
  "mappings": [
    {
      "attack_technique": "T1553 Subvert Trust Controls",
      "d3fend_technique": "Content Quarantine",
      "soc_action": "Apply Content Quarantine to contain the blast radius once this technique is observed.",
      "tooling": [
        "Defender for Endpoint"
      ]
    },
    {
      "attack_technique": "T1553 Subvert Trust Controls",
      "d3fend_technique": "Restore Configuration",
      "soc_action": "Use Restore Configuration to recover affected systems or data after containment.",
      "tooling": [
        "Defender for Endpoint"
      ]
    },
    {
      "attack_technique": "T1553 Subvert Trust Controls",
      "d3fend_technique": "Configuration Inventory",
      "soc_action": "Use Configuration Inventory to establish a baseline that makes this technique's deviations easier to spot.",
      "tooling": [
        "Defender for Endpoint"
      ]
    }
  ]
}