{
  "technique_id": "T1601",
  "mappings": [
    {
      "attack_technique": "T1601 Modify System Image",
      "d3fend_technique": "Network Traffic Analysis",
      "soc_action": "Monitor for Network Traffic Analysis indicators relevant to this technique.",
      "tooling": [
        "Sentinel",
        "Defender for Endpoint"
      ]
    }
  ]
}