Skip to main content
Cyber Defense TacticsCyber Defense Tactics
HomeLearnResourcesBlogCommunity
Cyber Defense TacticsCyber Defense Tactics

Learn defensive security, leverage AI for cyber defense, and join a community of security professionals.

Learning

  • Blog
  • Resources
  • Newsletter

Community

  • Community
  • YouTube
  • About

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Cyber Defense Tactics. All rights reserved.

A Carbene.AI Project

Back to D3FEND Hub
D3-HBPI

Host-Based Process Isolation

Isolate Tactic

Restrict process permissions and capabilities to limit the impact of compromised applications.

View on MITRE D3FEND

Implementation Guidance

  • Implement application control policies
  • Use mandatory access controls
  • Deploy endpoint detection and response
  • Enable process sandboxing
  • Monitor for privilege escalation

Tools & Technologies

Windows Defender Application ControlAppLockerSELinux/AppArmorCrowdStrikeCarbon Black

ATT&CK Techniques Countered

This defensive technique helps protect against the following adversary techniques:

T1068

Exploitation for Privilege Escalation

T1548

Abuse Elevation Control Mechanism

Explore Purple Team Matrix for full mappings

Related Techniques in Isolate

D3-NI

Network Isolation

D3-EI

Execution Isolation

D3-DNSAL

DNS Allowlisting

Ready to build a comprehensive defense strategy?