{"metadata": {"mapping_version": "", "technology_domain": "enterprise", "attack_version": "19.1", "mapping_framework": "cis", "mapping_framework_version": "8.1.2", "author": null, "contact": null, "organization": null, "creation_date": "08/31/2026", "last_update": "09/25/2026", "mapping_types": {"mitigates": {"name": "mitigates", "description": "The security control may prevent successful execution of the technique or sub-technique."}, "non_mappable": {"name": "non_mappable", "description": "The control is out of scope (e.g., does not provide security capabilities) or does not provide mitigation of specific threats as contained in ATT&CK."}}, "capability_groups": {"CIS-1": "Inventory and Control of Enterprise Assets", "CIS-2": "Inventory and Control of Software Assets", "CIS-3": "Data Protection", "CIS-4": "Secure Configuration of Enterprise Assets and Software", "CIS-5": "Account Management", "CIS-6": "Access Control Management", "CIS-7": "Continuous Vulnerability Management", "CIS-8": "Audit Log Management", "CIS-9": "Email and Web Browser Protections", "CIS-10": "Malware Defenses", "CIS-11": "Data Recovery", "CIS-12": "Network Infrastructure Management", "CIS-13": "Network Monitoring and Defense", "CIS-14": "Security Awareness and Skills Training", "CIS-15": "Service Provider Management", "CIS-16": "Application Software Security", "CIS-17": "Incident Response Management", "CIS-18": "Penetration Testing"}}, "mapping_objects": [{"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1547.006", "attack_object_name": "Kernel Modules and Extensions", "capability_group": "CIS-13", "comments": "Adversaries load malicious kernel modules or extensions for persistence or privilege escalation. Host-based security solutions can monitor module loading, detect known rootkits or unauthorized kernel modifications, and block or alert on suspicious kernel-extension activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1059.006", "attack_object_name": "Python", "capability_group": "CIS-13", "comments": "Adversaries use Python interpreters and scripts to execute malicious commands and payloads. EDR/HIPS can monitor anomalous Python execution, unusual parent-child relationships, network activity, and other suspicious behaviors, and can block or quarantine malicious payloads.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1059.001", "attack_object_name": "PowerShell", "capability_group": "CIS-13", "comments": "Adversaries use PowerShell to execute commands, scripts, and payloads. EDR/HIPS can monitor PowerShell process behavior, command lines, script activity, child processes, and suspicious follow-on actions, and can block or quarantine malicious activity", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1187", "attack_object_name": "Forced Authentication", "capability_group": "CIS-13", "comments": " Adversaries coerce systems into authenticating to attacker-controlled SMB or WebDAV resources in order to capture credential material. This control requires traffic filtering between network segments, which can block or tightly restrict SMB and WebDAV communications to untrusted or unauthorized destinations, directly preventing the outbound authentication path required by the technique.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1563.002", "attack_object_name": "RDP Hijacking", "capability_group": "CIS-12", "comments": "Dedicated administrative workstations and segmented management networks reduce who can reach hosts carrying privileged RDP sessions and separate administrative activity from ordinary user networks. This does not prevent hijacking after the admin host itself is compromised, but it directly reduces network exposure of those sessions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1563", "attack_object_name": "Remote Service Session Hijacking", "capability_group": "CIS-12", "comments": "Adversaries hijack existing SSH, RDP, or other remote-management sessions. Keeping administrative sessions on dedicated, segmented resources reduces exposure of those sessions to compromised user endpoints and limits unnecessary network paths to privileged remote services. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-12", "comments": "Dedicated administrative resources are explicitly segmented from the primary enterprise network and denied Internet access. That separation reduces opportunities for adversaries on user or Internet-connected networks to position themselves between administrative systems and managed infrastructure, directly shrinking the attack surface for interception of privileged sessions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1599.001", "attack_object_name": "Network Address Translation Traversal", "capability_group": "CIS-12", "comments": "This sub-technique concerns traversing or bypassing network boundaries implemented through NAT and perimeter devices. Secure architecture using explicit trust zones, controlled routing, segmentation, and restricted inbound/outbound paths directly constrains the network reachability needed for NAT traversal.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1599", "attack_object_name": "Network Boundary Bridging", "capability_group": "CIS-12", "comments": "This technique directly concerns adversaries compromising network devices to bypass segmentation and route prohibited traffic across trust boundaries. Because this control requires network segmentation and least privilege, designing and maintaining strong trust boundaries directly constrains the traffic paths the adversary is attempting to bridge. ATT&CK describes the technique specifically in terms of bypassing segmentation and boundary-device policy", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-12", "comments": "ATT&CK recommends network segmentation, traffic filtering, restricted access to network infrastructure, encryption, and network intrusion prevention for AiTM activity. Segmentation under this control reduces the network scope in which an adversary can position itself between communicating systems and restricts access to infrastructure capable of reshaping traffic", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1556.004", "attack_object_name": "Network Device Authentication", "capability_group": "CIS-12", "comments": "This sub-technique specifically targets authentication on network devices. ATT&CK recommends MFA, privileged-account restriction, TACACS+/RADIUS, and vendor hardening; a secure network architecture that isolates the management plane and applies least-privilege administrative access directly constrains the access needed to modify network-device authentication.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1542.005", "attack_object_name": "TFTP Boot", "capability_group": "CIS-12", "comments": "Adversaries can manipulate network-device boot configuration to load an unauthorized image from a malicious TFTP server. ATT&CK recommends limiting access to administrative interfaces, restricting insecure protocols, AAA/command authorization, and network-level filtering which are mechanisms that can be implemented as part of a secure management-plane architecture under this control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1200", "attack_object_name": "Hardware Additions", "capability_group": "CIS-12", "comments": "Adversaries may introduce unauthorized devices onto the network. ATT&CK recommends network access controls such as 802.1X, device certificates, and restricting DHCP to registered devices; these are architectural admission-control mechanisms that directly prevent unauthorized hardware from communicating with trusted systems.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1059.008", "attack_object_name": "Network Device CLI", "capability_group": "CIS-12", "comments": " Adversaries use network-device CLIs to execute commands and modify device behavior. ATT&CK recommends AAA, least privilege, and command authorization such as TACACS+ to restrict which administrative commands users may execute. Because this control explicitly requires least privilege within the network architecture, this is a strong mapping when that architecture includes management-plane and command-access controls.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1021.002", "attack_object_name": "SMB/Windows Admin Shares", "capability_group": "CIS-12", "comments": "Adversaries use SMB and administrative shares for remote access and lateral movement. A secure network architecture that enforces segmentation and least-privilege network access can restrict SMB connectivity to approved source/destination relationships, directly reducing the network reachability required for unauthorized lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1530", "attack_object_name": "Data from Cloud Storage", "capability_group": "CIS-11", "comments": "Adversaries collect data directly from improperly secured or compromised cloud storage. When backup or recovery data is stored in cloud object storage, this safeguard requires that recovery data be protected with controls such as encryption and separation, directly reducing unauthorized access to those backup objects", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1003.003", "attack_object_name": "NTDS", "capability_group": "CIS-11", "comments": "Adversaries may obtain NTDS.dit from Domain Controller backups rather than directly from a live Domain Controller and extract credential material from the database. This safeguard requires recovery data to receive equivalent protections, including encryption or separation, which directly restricts unauthorized access to Domain Controller backup copies containing NTDS data", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1490", "attack_object_name": "Inhibit System Recovery", "capability_group": "CIS-11", "comments": "Adversaries inhibit recovery by deleting or disabling backups, snapshots, recovery catalogs, and related recovery mechanisms. This safeguard requires automated, recurring backups of in-scope enterprise assets, ensuring that recoverable copies are created on a regular basis and thereby reducing the effectiveness of attempts to eliminate available recovery data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#112-perform-automated-backups"]}, {"capability_id": "CIS-10.1", "capability_description": "Deploy and Maintain Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1027", "attack_object_name": "Obfuscated Files or Information", "capability_group": "CIS-10", "comments": "Anti-malware software can detect and quarantine malicious files or commands that use encoding, packing, encryption, or other obfuscation techniques to evade detection. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/#101-deploy-and-maintain-anti-malware-software"]}, {"capability_id": "CIS-10.7", "capability_description": "Use Behavior-Based Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1027", "attack_object_name": "Obfuscated Files or Information", "capability_group": "CIS-10", "comments": "Behavior-based anti-malware can identify malicious activity after obfuscated content is decoded, unpacked, interpreted, or executed, allowing detection or blocking based on runtime behavior rather than relying solely on static signatures.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/#107-use-behavior-based-anti-malware-software"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1602", "attack_object_name": "Data from Configuration Repository", "capability_group": "CIS-7", "comments": "When known vulnerabilities affect network-device software, system images, or management components that expose configuration repositories, applying patches or supported software upgrades removes those weaknesses and reduces vulnerability dependent access to configuration data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-7", "comments": "When known vulnerabilities affect SNMP-enabled network-device software or system images, applying patches or supported software upgrades removes those weaknesses and reduces opportunities to collect MIB data through vulnerable implementations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1602.002", "attack_object_name": "Network Device Configuration Dump", "capability_group": "CIS-7", "comments": "When known vulnerabilities affect network-device software or system images used to expose or retrieve device configurations, applying patches or supported software upgrades removes those weaknesses and reduces exploit-based opportunities to obtain configuration data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1003.006", "attack_object_name": "DCSync", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can restrict Active Directory replication permissions, including Replicating Directory Changes rights, to authorized administrative roles. Enforcing these permissions limits which identities can perform the directory replication operations required for DCSync.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1021.002", "attack_object_name": "SMB/Windows Admin Shares", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can restrict local administrator membership and administrative-share access to authorized roles. These enforced permissions limit the accounts that can use SMB and Windows administrative shares for remote administration and lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1021.006", "attack_object_name": "Windows Remote Management", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can restrict WinRM accounts and permissions to authorized administrative roles. Enforced WinRM permissions limit which identities can use the service for remote execution and lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1218.007", "attack_object_name": "Msiexec", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can restrict execution of Msiexec.exe to privileged accounts or groups with an authorized operational need. Enforcing this entitlement reduces opportunities for adversaries to abuse Windows Installer for proxy execution.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1525", "attack_object_name": "Implant Internal Image", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can limit permissions to create, modify, or publish platform and container images to authorized roles. Enforcing these permissions reduces an adversary's ability to implant malicious images within enterprise repositories.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1538", "attack_object_name": "Cloud Service Dashboard", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can enforce least-privilege dashboard visibility so users can access only the cloud resources required for their assigned roles. This limits the information and resources exposed through a cloud service dashboard when an account is compromised.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1548.002", "attack_object_name": "Bypass User Account Control", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can restrict local administrator membership to authorized roles. Removing unnecessary administrative rights reduces the accounts from which adversaries can leverage UAC bypass techniques to obtain elevated privileges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1548.003", "attack_object_name": "Sudo and Sudo Caching", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can enforce which users or groups are authorized for sudo privileges and which elevated commands they may run. Restricting these entitlements limits the identities and operations available for privilege elevation through sudo.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1556.004", "attack_object_name": "Network Device Authentication", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can restrict network-device administrator privileges to narrowly scoped authorized roles. Enforcing least-privilege administrative access reduces the identities capable of modifying network-device authentication mechanisms.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-10.5", "capability_description": "Enable Anti-Exploitation Features", "mapping_type": "mitigates", "attack_object_id": "T1211", "attack_object_name": "Exploitation for Stealth", "capability_group": "CIS-10", "comments": "Security anti-exploitation tools and applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to help mitigate some exploitation behavior to evade detection.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/#105-enable-anti-exploitation-features"]}, {"capability_id": "CIS-10.3", "capability_description": "Disable Autorun and Autoplay for Removable Media", "mapping_type": "mitigates", "attack_object_id": "T1092", "attack_object_name": "Communication Through Removable Media", "capability_group": "CIS-10", "comments": "Disable Autoruns if it is unnecessary to help prevent adversaries from performing command and control between compromised hosts on potentially disconnected networks by using removable media to transfer commands from system to system.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/#103-disable-autorun-and-autoplay-for-removable-media"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.008", "attack_object_name": "Network Provider DLL", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.007", "attack_object_name": "Hybrid Identity", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., hybrid identity environment admin, synchronization service, cloud tenant) to patch, modify, or otherwise backdoor cloud authentication processes", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.006", "attack_object_name": "Multi-Factor Authentication", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify MFA mechanisms and enable persistent access to compromised accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.005", "attack_object_name": "Reversible Encryption", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., domain/identity policy administrator, local security policy administrator) to abuse Active Directory encryption properties and gain access to credentials on Windows systems.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.004", "attack_object_name": "Network Device Authentication", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to bypass of native authentication mechanisms for tenant/device management accounts on network devices.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.003", "attack_object_name": "Pluggable Authentication Modules", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.002", "attack_object_name": "Password Filter DLL", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious password filter dynamic link libraries (DLLs) into the authentication process.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.001", "attack_object_name": "Domain Controller Authentication", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556", "attack_object_name": "Modify Authentication Process", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify authentication processes or mechanisms.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1110.004", "attack_object_name": "Credential Stuffing", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using credentials obtained from breach dumps to gain access to admin accounts through credential overlap.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1110.003", "attack_object_name": "Password Spraying", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using commonly used passwords to attempt to acquire valid admin credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1110.002", "attack_object_name": "Password Cracking", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password cracking to recover admin credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1110.001", "attack_object_name": "Password Guessing", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password guessing to access admin accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1110", "attack_object_name": "Brute Force", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from brute forcing admin credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to provide system and access isolation for critical network systems.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.009", "attack_object_name": "Conditional Access Policies", "capability_group": "CIS-6", "comments": "Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify conditional access policies.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1059.011", "attack_object_name": "Lua", "capability_group": "CIS-2", "comments": "Adversaries use Lua interpreters to execute Lua code. An application-control policy denying unauthorized Lua interpreters prevents those binaries from running, directly restricting Lua execution.\u00a0", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1059.006", "attack_object_name": "Python", "capability_group": "CIS-2", "comments": "Adversaries use Python interpreters to execute malicious commands and payloads. An enforced allowlist denying Python prevents the interpreter from executing, directly removing the prerequisite for Python-based execution.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1176", "attack_object_name": "Software Extensions", "capability_group": "CIS-2", "comments": "Adversaries install or use malicious browser or IDE extensions to obtain execution or persistence. The implementation to explicitly allowlists authorized extensions and blocks all others, unauthorized extensions cannot be installed or loaded, directly constraining the technique.  ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1564.003", "attack_object_name": "Hidden Window", "capability_group": "CIS-2", "comments": "Adversaries may hide application windows while malicious programs execute. Where an unauthorized program is responsible for the hidden-window behavior, application allowlisting prevents that program from running and therefore prevents that implementation of the technique.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1548.004", "attack_object_name": "Elevated Execution with Prompt", "capability_group": "CIS-2", "comments": "Adversaries may persuade users to approve elevated execution of malicious applications. If application control prevents the unapproved application from executing regardless of user approval, the malicious program cannot reach the elevation stage through this path. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1546.002", "attack_object_name": "Screensaver", "capability_group": "CIS-2", "comments": "Adversaries can establish execution or persistence using malicious .scr screensaver files. Application-control rules can prevent unauthorized .scr files from executing, directly blocking the malicious executable used by the technique", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218.014", "attack_object_name": "MMC", "capability_group": "CIS-2", "comments": "Adversaries can abuse Microsoft Management Console to execute malicious content through a trusted system binary. Application allowlisting can block MMC on systems where its use is not authorized, directly preventing the executable from being used for proxy execution.  ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218.013", "attack_object_name": "Mavinject", "capability_group": "CIS-2", "comments": "Adversaries abuse mavinject.exe to inject malicious code into another process through a trusted Microsoft executable. Application allowlisting can deny execution of mavinject.exe where it is not authorized, directly preventing use of that binary for the technique.  ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218.012", "attack_object_name": "Verclsid", "capability_group": "CIS-2", "comments": "Adversaries abuse verclsid.exe to execute malicious COM objects through a trusted Windows binary. Application allowlisting can block verclsid.exe where it is unnecessary, directly preventing its use as the proxy executable.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218.009", "attack_object_name": "Regsvcs/Regasm", "capability_group": "CIS-2", "comments": "Adversaries use Regsvcs.exe or Regasm.exe to proxy execution of malicious .NET code. Application allowlisting can prevent these binaries from executing on systems where they are not authorized, directly preventing this execution path.  ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218.008", "attack_object_name": "Odbcconf", "capability_group": "CIS-2", "comments": "Adversaries abuse odbcconf.exe to execute malicious code through a trusted Windows utility. Application allowlisting can deny execution of odbcconf.exe where it is not required, directly preventing use of that proxy-execution mechanism. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218.005", "attack_object_name": "Mshta", "capability_group": "CIS-2", "comments": "Adversaries abuse mshta.exe to execute HTML application or script content through a trusted Windows binary. Application allowlisting can explicitly deny mshta.exe, preventing the executable from being used for proxy execution.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218.004", "attack_object_name": "InstallUtil", "capability_group": "CIS-2", "comments": "Adversaries use InstallUtil.exe to execute malicious .NET code while proxying execution through a trusted binary. Application allowlisting can block InstallUtil where it is not authorized, directly preventing use of the utility for this behavior.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218.003", "attack_object_name": "CMSTP", "capability_group": "CIS-2", "comments": "Adversaries abuse cmstp.exe to proxy execution of malicious code through a trusted Windows utility. Application allowlisting can prevent cmstp.exe from executing on systems where it is not required, directly removing the proxy-execution mechanism. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218.001", "attack_object_name": "Compiled HTML File", "capability_group": "CIS-2", "comments": "Adversaries abuse hh.exe to execute malicious compiled HTML content through a trusted Windows binary. Application allowlisting can block hh.exe where it is not authorized, preventing use of that binary for proxy execution. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1127.001", "attack_object_name": "MSBuild", "capability_group": "CIS-2", "comments": "Adversaries abuse msbuild.exe to execute malicious code through a trusted Microsoft developer utility. Application allowlisting can deny execution of MSBuild on systems where it is not authorized, directly eliminating the binary used for proxy execution. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1059.010", "attack_object_name": "AutoHotKey & AutoIT", "capability_group": "CIS-2", "comments": "Adversaries use AutoHotKey and AutoIT interpreters to execute automated commands and malicious scripts. Application allowlisting can block AutoHotkey.exe, AutoIt3.exe, and related unauthorized executables, directly preventing those interpreters from executing.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.3", "capability_description": "Address Unauthorized Software", "mapping_type": "mitigates", "attack_object_id": "T1127.001", "attack_object_name": "MSBuild", "capability_group": "CIS-2", "comments": "Adversaries abuse MSBuild to execute malicious code through a trusted developer utility. When MSBuild is unnecessary, explicitly classified as unauthorized, and removed under this safeguard, the executable required for this proxy-execution technique is eliminated.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#23-address-unauthorized-software"]}, {"capability_id": "CIS-2.3", "capability_description": "Address Unauthorized Software", "mapping_type": "mitigates", "attack_object_id": "T1059.011", "attack_object_name": "Lua", "capability_group": "CIS-2", "comments": "Adversaries can use a Lua interpreter to execute malicious Lua commands or scripts. When Lua is unauthorized on the asset and is removed through this safeguard, the interpreter required to execute Lua code is no longer available, directly restricting the technique. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#23-address-unauthorized-software"]}, {"capability_id": "CIS-2.3", "capability_description": "Address Unauthorized Software", "mapping_type": "mitigates", "attack_object_id": "T1059.006", "attack_object_name": "Python", "capability_group": "CIS-2", "comments": "Adversaries use installed Python interpreters to execute commands, scripts, and payloads. When Python is classified as unauthorized and removed under this safeguard, the local interpreter required for Python-based execution is eliminated, directly restricting this execution path.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#23-address-unauthorized-software"]}, {"capability_id": "CIS-2.3", "capability_description": "Address Unauthorized Software", "mapping_type": "mitigates", "attack_object_id": "T1021.005", "attack_object_name": "VNC", "capability_group": "CIS-2", "comments": "Adversaries use VNC server software to establish remote interactive access to systems. When VNC server software is classified as unauthorized, this safeguard requires it to be removed, eliminating the VNC server endpoint required to establish the remote session.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#23-address-unauthorized-software"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1071.001", "attack_object_name": "Web Protocols", "capability_group": "CIS-12", "comments": "Adversaries use HTTP or HTTPS to communicate with command-and-control infrastructure. Default-deny Internet egress on dedicated administrative resources prevents direct connections to external HTTP/S C2 infrastructure, directly disrupting the communication channel.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1105", "attack_object_name": "Ingress Tool Transfer", "capability_group": "CIS-12", "comments": "Adversaries transfer tools and payloads onto compromised systems from external infrastructure. Dedicated administrative resources have no direct Internet access and permit file transfer only through controlled internal mechanisms, directly preventing arbitrary external payload retrieval.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1021.006", "attack_object_name": "Windows Remote Management", "capability_group": "CIS-12", "comments": "Adversaries use WinRM to execute commands remotely and move laterally. Administrative network controls permit WinRM only over approved management paths, directly denying unauthorized WinRM connectivity.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-12", "comments": "Adversaries use RDP for lateral movement into privileged systems. Administrative enclave ACLs restrict RDP to explicitly authorized source and destination relationships, directly preventing arbitrary RDP access into or through the enclave.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-12", "comments": "Adversaries use alternate network protocols to transfer data outside the environment. Protocol-aware egress filtering and destination restrictions in the administrative enclave directly block unauthorized alternate-protocol exfiltration channels.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1571", "attack_object_name": "Non-Standard Port", "capability_group": "CIS-12", "comments": "Adversaries use unexpected ports for command-and-control to evade standard network restrictions. The administrative enclave permits only explicitly approved ports and denies all others, directly preventing outbound communication over unauthorized ports.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1095", "attack_object_name": "Non-Application Layer Protocol", "capability_group": "CIS-12", "comments": "Adversaries use non-application-layer protocols for command-and-control or data transfer. The administrative enclave enforces default-deny egress with explicit protocol allowlisting, directly blocking unauthorized low-level communications.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-12", "comments": "Adversaries use externally accessible remote services to reach internal or privileged resources. Dedicated administrative systems are not externally reachable and accept access only through controlled administrative paths, directly preventing external remote-service access to the enclave.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1567", "attack_object_name": "Exfiltration Over Web Service", "capability_group": "CIS-12", "comments": "Adversaries transfer stolen data to external Web services. Dedicated administrative resources have no Internet egress, directly preventing connections to the external Web destinations required by the technique.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1102", "attack_object_name": "Web Service", "capability_group": "CIS-12", "comments": "Adversaries use external Web services as command-and-control infrastructure. Dedicated administrative systems have no direct Internet access, directly preventing them from establishing command-and-control sessions with external Web services.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1557.001", "attack_object_name": "Name Resolution Poisoning and SMB Relay", "capability_group": "CIS-12", "comments": "Adversaries manipulate local name-resolution traffic and relay authentication to reachable services. Separating administrative systems from general-user broadcast domains and restricting SMB paths directly reduces poisoning opportunities and viable privileged relay targets.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-12", "comments": "Adversaries capture traffic visible from a compromised privileged system to collect credentials or operational information. Isolating administrative resources from the primary network reduces the traffic and broadcast domains visible to those systems, directly limiting passive collection opportunities.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1046", "attack_object_name": "Network Service Discovery", "capability_group": "CIS-12", "comments": "Adversaries probe network systems to identify accessible services and hosts. Administrative enclave segmentation restricts network visibility and reachability across the enclave boundary, directly reducing the systems and services available for discovery.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-12", "comments": "Adversaries exploit vulnerable remote services on reachable systems to move laterally. Segmentation of administrative resources restricts the remote services reachable into and out of the privileged enclave, directly reducing lateral exploitation opportunities.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.8", "capability_description": "Establish and Maintain Dedicated Computing Resources for All Administrative Work", "mapping_type": "mitigates", "attack_object_id": "T1189", "attack_object_name": "Drive-by Compromise", "capability_group": "CIS-12", "comments": "Adversaries compromise systems when users access malicious or compromised Internet content. Dedicated administrative resources are prohibited from general Internet access, directly removing ordinary Web browsing as an initial-access path to privileged systems.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#128-establish-and-maintain-dedicated-computing-resources-for-all-administrative-work"]}, {"capability_id": "CIS-12.7", "capability_description": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1021.006", "attack_object_name": "Windows Remote Management", "capability_group": "CIS-12", "comments": "Adversaries may use WinRM for remote command execution and lateral movement. WinRM is not externally reachable and can only be accessed through authenticated enterprise VPN connectivity, directly restricting unauthorized remote WinRM sessions.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#127-ensure-remote-devices-utilize-a-vpn-and-are-connecting-to-an-enterprises-aaa-infrastructure"]}, {"capability_id": "CIS-12.7", "capability_description": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-12", "comments": "Adversaries use RDP for remote access or lateral movement into enterprise systems. RDP is inaccessible directly from external networks and reachable remotely only after authenticated VPN access through approved paths, directly preventing unauthenticated external RDP connectivity.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#127-ensure-remote-devices-utilize-a-vpn-and-are-connecting-to-an-enterprises-aaa-infrastructure"]}, {"capability_id": "CIS-12.7", "capability_description": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1659", "attack_object_name": "Content Injection", "capability_group": "CIS-12", "comments": "Adversaries can inject malicious content into network traffic through a compromised or hostile upstream communication path. VPN integrity protection prevents unauthorized modification of enterprise-bound tunneled traffic, directly blocking injected content from becoming part of the protected session.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#127-ensure-remote-devices-utilize-a-vpn-and-are-connecting-to-an-enterprises-aaa-infrastructure"]}, {"capability_id": "CIS-12.7", "capability_description": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-12", "comments": "Adversaries positioned along the remote user's network path attempt to intercept or modify enterprise communications. An authenticated VPN tunnel provides confidentiality and integrity protection, directly preventing useful interception or alteration of tunneled traffic.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#127-ensure-remote-devices-utilize-a-vpn-and-are-connecting-to-an-enterprises-aaa-infrastructure"]}, {"capability_id": "CIS-12.7", "capability_description": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-12", "comments": "Adversaries capture traffic traversing untrusted remote networks to obtain sensitive enterprise information. The enterprise VPN encrypts traffic between the endpoint and enterprise gateway, directly preventing passive observers from recovering protected traffic.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#127-ensure-remote-devices-utilize-a-vpn-and-are-connecting-to-an-enterprises-aaa-infrastructure"]}, {"capability_id": "CIS-12.7", "capability_description": "Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-12", "comments": "Adversaries can use externally accessible remote-access services to enter enterprise networks. Requiring remote devices to authenticate through an enterprise-managed VPN and centralized AAA confines remote access to a controlled gateway, directly eliminating unmanaged direct access paths.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#127-ensure-remote-devices-utilize-a-vpn-and-are-connecting-to-an-enterprises-aaa-infrastructure"]}, {"capability_id": "CIS-12.6", "capability_description": "Use of Secure Network Management and Communication Protocols", "mapping_type": "mitigates", "attack_object_id": "T1542.005", "attack_object_name": "TFTP Boot", "capability_group": "CIS-12", "comments": "Adversaries can abuse unauthenticated network-boot mechanisms to load malicious or unauthorized system images. Disabling insecure TFTP/PXE boot or restricting it to authenticated management infrastructure directly prevents unauthorized network boot operations.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#126-use-of-secure-network-management-and-communication-protocols"]}, {"capability_id": "CIS-12.6", "capability_description": "Use of Secure Network Management and Communication Protocols", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-12", "comments": "Adversaries can query SNMP to collect network-device and topology information. Enforced SNMPv3 authentication, encryption, and management-source restrictions directly prevent unauthorized systems from successfully issuing or reading management queries.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#126-use-of-secure-network-management-and-communication-protocols"]}, {"capability_id": "CIS-12.6", "capability_description": "Use of Secure Network Management and Communication Protocols", "mapping_type": "mitigates", "attack_object_id": "T1557.004", "attack_object_name": "Evil Twin", "capability_group": "CIS-12", "comments": "Adversaries can deploy a rogue access point impersonating the legitimate enterprise WLAN to capture credentials or intercept communications. Managed 802.1X supplicants validate the trusted RADIUS/EAP server certificate and approved wireless profile, directly preventing endpoints from authenticating to the rogue infrastructure.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#126-use-of-secure-network-management-and-communication-protocols"]}, {"capability_id": "CIS-12.6", "capability_description": "Use of Secure Network Management and Communication Protocols", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-12", "comments": "Adversaries can intercept or manipulate communications between wireless clients and enterprise infrastructure. Enterprise authentication and encrypted wireless communications provide confidentiality and integrity protections that directly constrain interception and modification.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#126-use-of-secure-network-management-and-communication-protocols"]}, {"capability_id": "CIS-12.6", "capability_description": "Use of Secure Network Management and Communication Protocols", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-12", "comments": "Adversaries can capture wireless network traffic to recover credentials or sensitive information. WPA2 Enterprise or stronger encryption protects wireless frames from passive observers, directly preventing useful plaintext recovery from captured traffic.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#126-use-of-secure-network-management-and-communication-protocols"]}, {"capability_id": "CIS-12.6", "capability_description": "Use of Secure Network Management and Communication Protocols", "mapping_type": "mitigates", "attack_object_id": "T1669", "attack_object_name": "Wi-Fi Networks", "capability_group": "CIS-12", "comments": "Adversaries can gain initial access by associating with the target organization's wireless network. Secure network management protocols like 802.1X and enterprise wireless authentication require authorized credentials or device identity before admission, directly preventing unauthorized wireless access.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#126-use-of-secure-network-management-and-communication-protocols"]}, {"capability_id": "CIS-12.6", "capability_description": "Use of Secure Network Management and Communication Protocols", "mapping_type": "mitigates", "attack_object_id": "T1200", "attack_object_name": "Hardware Additions", "capability_group": "CIS-12", "comments": "Adversaries can attach rogue computers, appliances, or networking hardware to obtain enterprise network connectivity. Secure network management protocols like 802.1X requires successful user or device authentication before network admission, directly denying unauthorized hardware access.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#126-use-of-secure-network-management-and-communication-protocols"]}, {"capability_id": "CIS-12.5", "capability_description": "Centralize Network Authentication, Authorization, and Auditing network AAA", "mapping_type": "mitigates", "attack_object_id": "T1601.002", "attack_object_name": "Downgrade System Image", "capability_group": "CIS-12", "comments": "Adversaries may install an older network-device image to restore vulnerable functionality or bypass newer protections. AAA authorization restricts downgrade and image-installation commands to approved roles, directly preventing unauthorized rollback operations.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#125-centralize-network-authentication-authorization-and-aucentralize-network-aaa"]}, {"capability_id": "CIS-12.5", "capability_description": "Centralize Network Authentication, Authorization, and Auditing network AAA", "mapping_type": "mitigates", "attack_object_id": "T1601.001", "attack_object_name": "Patch System Image", "capability_group": "CIS-12", "comments": "Adversaries may install malicious or unauthorized network-device images to modify device operation. AAA command authorization restricts image upload and installation functions to approved administrative roles, directly preventing unauthorized system-image replacement.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#125-centralize-network-authentication-authorization-and-aucentralize-network-aaa"]}, {"capability_id": "CIS-12.5", "capability_description": "Centralize Network Authentication, Authorization, and Auditing network AAA", "mapping_type": "mitigates", "attack_object_id": "T1602.002", "attack_object_name": "Network Device Configuration Dump", "capability_group": "CIS-12", "comments": "Adversaries may retrieve network-device configurations to collect topology, credentials, routes, and security policy. AAA command authorization denies configuration-display and export operations to identities without explicit permission, directly restricting configuration collection.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#125-centralize-network-authentication-authorization-and-aucentralize-network-aaa"]}, {"capability_id": "CIS-12.5", "capability_description": "Centralize Network Authentication, Authorization, and Auditing network AAA", "mapping_type": "mitigates", "attack_object_id": "T1686.002", "attack_object_name": "Network Device Firewall", "capability_group": "CIS-12", "comments": "Adversaries may change firewall rules, ACLs, or security zones to weaken network restrictions. Centralized AAA authorization limits those configuration commands to approved roles, directly preventing unauthorized identities from modifying firewall policy.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#125-centralize-network-authentication-authorization-and-aucentralize-network-aaa"]}, {"capability_id": "CIS-12.5", "capability_description": "Centralize Network Authentication, Authorization, and Auditing network AAA", "mapping_type": "mitigates", "attack_object_id": "T1059.008", "attack_object_name": "Network Device CLI", "capability_group": "CIS-12", "comments": "Adversaries may use network-device CLIs to execute privileged administrative commands. Centralized AAA with command-level authorization restricts which commands each identity may execute, directly preventing unauthorized CLI operations.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#125-centralize-network-authentication-authorization-and-aucentralize-network-aaa"]}, {"capability_id": "CIS-12.3", "capability_description": "Securely Manage Network Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1686.002", "attack_object_name": "Network Device Firewall", "capability_group": "CIS-12", "comments": "Adversaries can alter ACLs, firewall rules, or network security zones to create unauthorized access paths. Enforced IaC/GitOps configuration management validates approved firewall state and rejects or automatically reverses unauthorized policy changes, directly disrupting the modification.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#123-securely-manage-network-infrastructure"]}, {"capability_id": "CIS-12.3", "capability_description": "Securely Manage Network Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1059.008", "attack_object_name": "Network Device CLI", "capability_group": "CIS-12", "comments": "Adversaries can use network-device command-line interfaces to make malicious configuration changes. Enforced version-controlled Infrastructure-as-Code with direct configuration disabled or automatically reconciled prevents unauthorized CLI changes from becoming persistent device state.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#123-securely-manage-network-infrastructure"]}, {"capability_id": "CIS-12.3", "capability_description": "Securely Manage Network Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1659", "attack_object_name": "Content Injection", "capability_group": "CIS-12", "comments": "Adversaries can inject malicious content into network communications while positioned along the traffic path. Integrity-protected SSH or HTTPS management sessions reject unauthorized modifications, directly preventing injected content from becoming part of the protected administrative session.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#123-securely-manage-network-infrastructure"]}, {"capability_id": "CIS-12.3", "capability_description": "Securely Manage Network Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-12", "comments": "Adversaries can position themselves between communicating systems to intercept or alter network traffic. Authenticated and encrypted management sessions provide confidentiality, peer authentication, and integrity protection, directly preventing useful interception or modification of administrative communications.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#123-securely-manage-network-infrastructure"]}, {"capability_id": "CIS-12.3", "capability_description": "Securely Manage Network Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-12", "comments": "Adversaries can passively capture management traffic to obtain credentials, commands, or configuration information. SSH, HTTPS, and equivalent encrypted management protocols make captured administrative traffic unreadable, directly reducing the value of network sniffing.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#123-securely-manage-network-infrastructure"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1669", "attack_object_name": "Wi-Fi Networks", "capability_group": "CIS-12", "comments": "Adversaries obtain initial access by connecting to an organization's wireless network. Separating wireless access networks from sensitive enterprise segments with enforced routing and firewall controls directly limits what an attacker can reach after establishing wireless connectivity.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1199", "attack_object_name": "Trusted Relationship", "capability_group": "CIS-12", "comments": "Adversaries abuse connectivity granted to trusted third parties or external organizations to reach enterprise resources. Segmented third-party access restricts those connections to explicitly authorized services and network zones, directly preventing movement beyond the intended trust boundary.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-12", "comments": "Adversaries abuse centralized deployment or management systems to execute software or move laterally. Placing those systems in a restricted management segment and allowing access only from approved administrative hosts directly limits unauthorized interaction with the deployment infrastructure.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1048.003", "attack_object_name": "Exfiltration Over Unencrypted Non-C2 Protocol", "capability_group": "CIS-12", "comments": "Adversaries use unencrypted alternate protocols to transfer stolen data. Inter-zone and egress filtering blocks unauthorized protocols and destinations, directly disrupting the exfiltration channel.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1048.002", "attack_object_name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-12", "comments": "Adversaries use asymmetrically encrypted non-C2 protocols to move data outside the environment. Network controls restrict permitted protocols and destinations, directly blocking unauthorized encrypted exfiltration channels.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1048.001", "attack_object_name": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-12", "comments": "Adversaries exfiltrate data through encrypted non-C2 protocols that use symmetric encryption. Enforced protocol and destination allowlists deny unauthorized encrypted outbound channels, directly preventing the required network transfer.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-12", "comments": "Adversaries exfiltrate data using protocols other than their primary command-and-control channel. Protocol-aware egress and inter-zone controls restrict communications to approved protocols and destinations, directly blocking unauthorized alternate-protocol exfiltration paths.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1571", "attack_object_name": "Non-Standard Port", "capability_group": "CIS-12", "comments": "Adversaries communicate over unusual ports to evade expected network controls. Explicit port allowlists and default-deny inter-zone filtering block unapproved ports, directly preventing those communications from traversing protected network boundaries.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1095", "attack_object_name": "Non-Application Layer Protocol", "capability_group": "CIS-12", "comments": "Adversaries use lower-layer protocols for command-and-control or data transfer. Deny-by-default inter-segment filtering permits only explicitly authorized protocols, directly blocking unauthorized non-application-layer communications across security boundaries.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1021.006", "attack_object_name": "Windows Remote Management", "capability_group": "CIS-12", "comments": "Adversaries use WinRM to execute commands remotely and move laterally. Segmentation restricts WinRM connectivity to designated administrative zones and systems, directly preventing unauthorized remote WinRM sessions.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1021.003", "attack_object_name": "Distributed Component Object Model", "capability_group": "CIS-12", "comments": "Adversaries use DCOM to remotely execute actions on accessible Windows systems. Network segmentation blocks DCOM traffic outside explicitly authorized relationships, directly restricting the network connectivity required for remote DCOM execution.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-12", "comments": "Adversaries use RDP for remote access and lateral movement between systems. Segmentation and inter-zone ACLs permit RDP only across approved administrative paths, directly preventing unauthorized RDP connectivity between network zones.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1602.002", "attack_object_name": "Network Device Configuration Dump", "capability_group": "CIS-12", "comments": "Adversaries retrieve network-device configurations to obtain topology, credentials, routing information, or security policy. Isolating management interfaces and permitting access only from approved administrative systems directly prevents unauthorized systems from reaching the configuration interface.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-12", "comments": "Adversaries query SNMP to obtain device, interface, routing, and network information. Restricting SNMP to an isolated management plane with ACLs permitting only authorized management systems directly prevents unauthorized hosts from issuing MIB queries.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-12", "comments": "Adversaries use externally accessible VPNs, gateways, and remote-access services to enter enterprise networks. The architecture forces external access through designated controlled gateways while denying direct connectivity to internal resources, directly restricting unauthorized remote entry paths.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1557.001", "attack_object_name": "Name Resolution Poisoning and SMB Relay", "capability_group": "CIS-12", "comments": "Adversaries poison local name-resolution traffic and relay authentication attempts to reachable services. Layer-2/Layer-3 segmentation and SMB access restrictions constrain the poisoning domain and relay destinations, directly reducing viable poisoning and relay paths.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-12", "comments": "Adversaries capture traffic visible from their network position to obtain credentials, sessions, or operational information. Segmentation reduces the broadcast domains, traffic flows, and network segments visible from a compromised system, directly limiting the traffic available for passive collection.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1046", "attack_object_name": "Network Service Discovery", "capability_group": "CIS-12", "comments": "Adversaries probe remote systems to identify accessible hosts, ports, and services. Enforced segmentation limits probe reachability across security boundaries, directly reducing the systems and services that can be discovered.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#122-establish-and-maintain-a-secure-network-architecture"]}, {"capability_id": "CIS-12.2", "capability_description": "Establish and Maintain a Secure Network Architecture", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-12", "comments": "Adversaries must reach a vulnerable remote service before exploiting it for lateral movement or execution. Network segmentation and least-privilege ACLs restrict which systems can communicate with those services, directly reducing exploitable network paths.\n", "references": []}, {"capability_id": "CIS-12.1", "capability_description": "Ensure Network Infrastructure is Up-to-Date", "mapping_type": "mitigates", "attack_object_id": "T1601.002", "attack_object_name": "Downgrade System Image", "capability_group": "CIS-12", "comments": "Adversaries downgrade network-device software to reintroduce vulnerable or weaker code. Enforced anti-rollback and approved-version controls prevent installation of older unauthorized images, directly blocking the downgrade behavior.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#121-ensure-network-infrastructure-is-up-to-date"]}, {"capability_id": "CIS-12.1", "capability_description": "Ensure Network Infrastructure is Up-to-Date", "mapping_type": "mitigates", "attack_object_id": "T1686.002", "attack_object_name": "Network Device Firewall", "capability_group": "CIS-12", "comments": "Adversaries may exploit vulnerable network firewalls to gain the privileged access required to alter ACLs, zones, or firewall policy. Maintaining supported and patched firewall software removes known vulnerability-based access paths, directly reducing the adversary's ability to reach the configuration state required to modify the firewall.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#121-ensure-network-infrastructure-is-up-to-date"]}, {"capability_id": "CIS-12.1", "capability_description": "Ensure Network Infrastructure is Up-to-Date", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-12", "comments": "Adversaries exploit vulnerabilities in remotely reachable services to execute code or move laterally. Updating network-device software removes known vulnerabilities from those services, directly preventing exploitation paths that depend on obsolete or vulnerable software.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#121-ensure-network-infrastructure-is-up-to-date"]}, {"capability_id": "CIS-12.1", "capability_description": "Ensure Network Infrastructure is Up-to-Date", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-12", "comments": "Adversaries exploit vulnerabilities in Internet-facing services or network-device management interfaces to gain initial access. Keeping network infrastructure on supported, current software removes known exploitable vulnerabilities, directly reducing the adversary's ability to successfully exploit those exposed services.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls12/#121-ensure-network-infrastructure-is-up-to-date"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1561.002", "attack_object_name": "Disk Structure Wipe", "capability_group": "CIS-11", "comments": "Disk structure wiping damages partitions, filesystems, or boot structures required to access a system. Recovery data stored on an isolated repository remains unaffected by those disk-level changes and can be used to rebuild the system.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1561.001", "attack_object_name": "Disk Content Wipe", "capability_group": "CIS-11", "comments": "Disk content wiping destroys data on the affected storage device. An isolated recovery repository is not dependent on that disk and preserves the data needed to restore the wiped system.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1561", "attack_object_name": "Disk Wipe", "capability_group": "CIS-11", "comments": "Adversaries erase disk data or structures to make systems unusable. Offline, cloud-separated, or off-site recovery copies remain outside the disk-wipe operation, directly preserving data required for restoration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#114-establish-and-maintain-an-isolated-instance-of-recovery-data"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1491.002", "attack_object_name": "External Defacement", "capability_group": "CIS-11", "comments": "External defacement modifies public-facing web or application content. Where an isolated recovery instance contains the affected content and configuration, known-good copies can be restored and the attacker-controlled state removed.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1491.001", "attack_object_name": "Internal Defacement", "capability_group": "CIS-11", "comments": "Internal defacement changes internal application or web content visible to users. Where an isolated recovery instance preserves known-good versions of that content, the altered files or configuration can be replaced with trusted copies.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1491", "attack_object_name": "Defacement", "capability_group": "CIS-11", "comments": "Adversaries alter operational or visible data to damage integrity. An isolated recovery copy preserves the trusted pre-defacement state, directly enabling restoration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#114-establish-and-maintain-an-isolated-instance-of-recovery-data"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1490", "attack_object_name": "Inhibit System Recovery", "capability_group": "CIS-11", "comments": "Recovery inhibition relies on eliminating backups, snapshots, or other recovery resources available to the victim. An isolated recovery instance remains outside the compromised recovery path, preventing the attacker from removing every usable recovery copy through the same access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1486", "attack_object_name": "Data Encrypted for Impact", "capability_group": "CIS-11", "comments": "Encryption for impact depends on the attacker being able to reach and modify usable data. An isolated recovery copy that is inaccessible through the compromised production path remains unencrypted and available for restoration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1485.001", "attack_object_name": "Lifecycle-Triggered Deletion", "capability_group": "CIS-11", "comments": "Lifecycle-triggered deletion relies on cloud policies automatically removing stored objects. Where the isolated recovery copy resides in a separate account, vault, or lifecycle boundary, those deletion rules do not affect the recovery copy.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1485", "attack_object_name": "Data Destruction", "capability_group": "CIS-11", "comments": "Data destruction removes or overwrites production data to make it unrecoverable. An isolated recovery copy sits outside the same destructive access path, preserving data that can be restored after production copies are destroyed.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1565.001", "attack_object_name": "Stored Data Manipulation", "capability_group": "CIS-11", "comments": "Stored data manipulation relies on altered data remaining authoritative or being used by downstream systems. Where the isolated recovery environment retains versioned or known-good data from before the manipulation, the modified production copy can be replaced with a trusted version.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.4", "capability_description": "Establish and Maintain an Isolated Instance of Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1565", "attack_object_name": "Data Manipulation", "capability_group": "CIS-11", "comments": "Adversaries manipulate data to affect operations or hide activity. An isolated recovery copy remains outside the compromised production write path, preserving a trusted version that can replace manipulated data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#114-establish-and-maintain-an-isolated-instance-of-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1561.002", "attack_object_name": "Disk Structure Wipe", "capability_group": "CIS-11", "comments": "Adversaries destroy file-system or partition structures to make data inaccessible. Recovery copies protected independently from the affected storage remain usable, directly enabling restoration despite destruction of the disk structure.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1561.001", "attack_object_name": "Disk Content Wipe", "capability_group": "CIS-11", "comments": "Adversaries overwrite disk contents to eliminate stored information. Protected recovery copies remain unavailable to the local wiping operation, directly preserving recoverable versions of the destroyed data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1561", "attack_object_name": "Disk Wipe", "capability_group": "CIS-11", "comments": "Adversaries wipe disks to destroy data or render systems unusable. Recovery data protected on separate storage remains outside the affected disk's destructive operation, directly preserving the data required to rebuild the system.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1491.002", "attack_object_name": "External Defacement", "capability_group": "CIS-11", "comments": "Adversaries modify externally visible content. Protected recovery copies preserve the legitimate content and enable replacement of the defaced version, directly reducing the duration and effectiveness of the attack", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1491.001", "attack_object_name": "Internal Defacement", "capability_group": "CIS-11", "comments": "Adversaries alter internally used content or systems. Protected backup copies maintain a trusted version outside the attacker's ordinary modification path, directly enabling restoration of internally defaced data", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1491", "attack_object_name": "Defacement", "capability_group": "CIS-11", "comments": "Adversaries alter content to disrupt operations or damage integrity. Protected recovery copies preserve trusted versions that remain available for restoration, directly limiting the persistence of the defacement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1486", "attack_object_name": "Data Encrypted for Impact", "capability_group": "CIS-11", "comments": "Encryption for impact depends on write access to the data the attacker wants to render unusable. Where recovery repositories are immutable, write-protected, or administered through separate credentials, ransomware cannot encrypt or overwrite the protected recovery copy.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1485.001", "attack_object_name": "Lifecycle-Triggered Deletion", "capability_group": "CIS-11", "comments": "Adversaries manipulate cloud lifecycle policies or similar automation to cause stored data to be deleted. Immutable/versioned recovery storage and restricted lifecycle-policy modification preserve prior backup objects, directly preventing automated deletion from eliminating the recovery copy.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1485", "attack_object_name": "Data Destruction", "capability_group": "CIS-11", "comments": "Data destruction depends on the attacker being able to delete or overwrite stored data. Where recovery data is held on immutable storage, deletion-protected repositories, or tightly restricted backup systems, those controls can prevent destruction of the protected copy.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1565.001", "attack_object_name": "Stored Data Manipulation", "capability_group": "CIS-11", "comments": "Stored data manipulation changes data at rest so the altered state is trusted or used operationally. Where recovery repositories enforce immutability, integrity validation, or write restrictions, unauthorized changes to the recovery copy can be blocked or detected.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1565", "attack_object_name": "Data Manipulation", "capability_group": "CIS-11", "comments": "Adversaries alter enterprise data to affect operations or hide activity. Integrity controls, access restrictions, and protected recovery copies preserve trusted versions that cannot be modified through ordinary production access, directly reducing the lasting effect of manipulation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#113-protect-recovery-data"]}, {"capability_id": "CIS-11.3", "capability_description": "Protect Recovery Data", "mapping_type": "mitigates", "attack_object_id": "T1490", "attack_object_name": "Inhibit System Recovery", "capability_group": "CIS-11", "comments": "Recovery inhibition commonly relies on deleting, modifying, or disabling backup and recovery resources. Where recovery data is protected with immutability, write restrictions, separate credentials, or access isolation, those controls can prevent the compromised access path from removing or altering the recovery copy.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1565.001", "attack_object_name": "Stored Data Manipulation", "capability_group": "CIS-11", "comments": "Adversaries alter data stored in files, databases, or other repositories. Automated backups preserve historical versions of the stored data, directly enabling recovery of the unmodified state.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#112-perform-automated-backups"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1565", "attack_object_name": "Data Manipulation", "capability_group": "CIS-11", "comments": "Adversaries alter data to affect decisions, processes, or system outcomes. Automated backups preserve earlier trusted versions of that data, directly enabling defenders to replace manipulated information with a known-good state.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#112-perform-automated-backups"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1491.002", "attack_object_name": "External Defacement", "capability_group": "CIS-11", "comments": "External defacement changes public-facing website or application content. Where the affected content and configuration are included in automated backups, known-good versions can be restored and the defaced state can be removed.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1491.001", "attack_object_name": "Internal Defacement", "capability_group": "CIS-11", "comments": "Internal defacement modifies organizational web, application, or other internal content. Where that content is included in automated backups, known-good versions can replace the altered resources and shorten the duration of the defacement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1491", "attack_object_name": "Defacement", "capability_group": "CIS-11", "comments": "Automated backups preserve trusted versions of the modified data or content, directly enabling restoration of the pre-defacement state.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#112-perform-automated-backups"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1485.001", "attack_object_name": "Lifecycle-Triggered Deletion", "capability_group": "CIS-11", "comments": "Lifecycle-triggered deletion relies on cloud retention or lifecycle rules deleting stored objects. Where automated backups retain the same data outside the affected lifecycle policy or account, those copies survive the deletion and can be restored.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#112-perform-automated-backups"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1561.002", "attack_object_name": "Disk Structure Wipe", "capability_group": "CIS-11", "comments": "Disk structure wiping corrupts partitions, filesystems, or other structures needed to access stored data. Automated backups preserve recoverable copies independent of the damaged disk structure, directly supporting restoration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#112-perform-automated-backups"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1561.001", "attack_object_name": "Disk Content Wipe", "capability_group": "CIS-11", "comments": "Disk content wiping destroys the data stored on an affected device. Automated backups preserve prior copies of the overwritten data, directly enabling restoration.", "references": []}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1561", "attack_object_name": "Disk Wipe", "capability_group": "CIS-11", "comments": "Adversaries erase disk data or structures to render systems unusable. Automated backups preserve data outside the destroyed disk state, directly enabling restoration after the wipe.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/#112-perform-automated-backups"]}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1486", "attack_object_name": "Data Encrypted for Impact", "capability_group": "CIS-11", "comments": "Ransomware and similar impact activity encrypt accessible production data to deny legitimate use. Automated backups preserve recoverable copies from before encryption, directly reducing the attacker's ability to make the encrypted data permanently unavailable.", "references": []}, {"capability_id": "CIS-11.2", "capability_description": "Perform Automated Backups", "mapping_type": "mitigates", "attack_object_id": "T1485", "attack_object_name": "Data Destruction", "capability_group": "CIS-11", "comments": "Adversaries destroy data to impair operations or deny access to information. Automated backups preserve earlier copies of the affected data, directly enabling restoration and reducing the operational effectiveness of the destruction.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls11/"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1565.001", "attack_object_name": "Stored Data Manipulation", "capability_group": "CIS-3", "comments": "Adversaries modify stored data to affect outcomes or conceal activity. At-rest encryption may hinder offline manipulation where the adversary lacks the decryption key, but it does not prevent modification through an authorized application, database write access, or transparently decrypted storage", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/#311-encrypt-sensitive-data-at-rest"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1565", "attack_object_name": "Data Manipulation", "capability_group": "CIS-3", "comments": "Adversaries insert, delete, or manipulate data to influence outcomes or conceal activity. Encrypting sensitive data at rest can prevent an adversary who lacks the decryption capability from understanding the protected content sufficiently to perform targeted or meaningful modifications, reducing the effectiveness of the manipulation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/#311-encrypt-sensitive-data-at-rest"]}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1553.003", "attack_object_name": "SIP and Trust Provider Hijacking", "capability_group": "CIS-2", "comments": "Trust Provider Hijacking can replace or introduce malicious DLLs used by Windows trust-validation mechanisms. Where these libraries are governed, allowlisting approved trust-provider DLLs can directly prevent unauthorized components from loading.", "references": []}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1505.004", "attack_object_name": "IIS Components", "capability_group": "CIS-2", "comments": "Malicious IIS components commonly use ISAPI extensions, filters, or modules implemented as DLLs loaded by IIS worker processes. Where library allowlisting governs IIS library loads, blocking unauthorized DLLs directly prevents those malicious components from loading.", "references": []}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1547.008", "attack_object_name": "LSASS Driver", "capability_group": "CIS-2", "comments": "LSASS Driver persistence relies on malicious DLLs or LSA plug-ins being loaded into the LSASS process. Library allowlisting can prevent unauthorized libraries from loading into LSASS, directly disrupting this persistence mechanism.", "references": []}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1547.002", "attack_object_name": "Authentication Package", "capability_group": "CIS-2", "comments": "Authentication Package persistence relies on a malicious authentication DLL being loaded by the Windows authentication subsystem. Where these DLLs are subject to allowlisting, unauthorized authentication packages can be blocked at load time.", "references": []}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1546.006", "attack_object_name": "LC_LOAD_DYLIB Addition", "capability_group": "CIS-2", "comments": "LC_LOAD_DYLIB abuse causes a modified Mach-O binary to load an attacker-controlled dylib. Where macOS libraries are covered by the allowlist, blocking the unauthorized dylib directly limits this technique.", "references": []}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1129", "attack_object_name": "Shared Modules", "capability_group": "CIS-2", "comments": "Adversaries load DLLs, shared objects, and other modules into processes to execute malicious code. Library allowlisting directly restricts this behavior by permitting only approved modules to load.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1535", "attack_object_name": "Unused/Unsupported Cloud Regions", "capability_group": "CIS-16", "comments": "Apply cloud configuration baselines that deactivate unused regions to reduce unmanaged cloud attack surface and help prevent adversaries from creating cloud instances in unused geographic service regions in order to evade detection.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1537", "attack_object_name": "Transfer Data to Cloud Account", "capability_group": "CIS-16", "comments": "Apply cloud service configuration templates that restrict or disable external data sharing and limit sharing to authorized users or domains to help prevent adversaries from exfiltrating data by transferring the data. ", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1666", "attack_object_name": "Modify Cloud Resource Hierarchy", "capability_group": "CIS-16", "comments": "Use standard cloud hardening templates to block unauthorized subscription transfers in Azure and prevent use of the AWS LeaveOrganization API through Service Control Policies to help prevent adversaries from modifying hierarchical structures in infrastructure-as-a-service (IaaS) environments.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1689", "attack_object_name": "Downgrade Attack", "capability_group": "CIS-16", "comments": "Apply hardened web server templates that implement policies on internal web servers, such HTTP Strict Transport Security, that enforce the use of HTTPS/network traffic encryption to prevent insecure connections.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1677", "attack_object_name": "Poisoned Pipeline Execution", "capability_group": "CIS-16", "comments": "Use standard hardening templates for continuous integration / continuous development (CI/CD) infrastructure that block unreviewed code execution, isolate untrusted builds, restrict secret access, and prohibit unsafe pipeline triggers to help prevent adversaries from manipulating CI/CD processes.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1685", "attack_object_name": "Disable or Modify Tools", "capability_group": "CIS-16", "comments": "Apply controlled baseline configurations and change management for security-related forwarding mechanisms and firewall rules to help prevent disabling, degrading, or tampering with security tools or applications.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1590.002", "attack_object_name": "DNS", "capability_group": "CIS-16", "comments": "Use standard hardening templates for DNS servers to implement zone transfer policies that permit zone transfers only to validated servers to help prevent adversaries from gathering DNS information.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1213", "attack_object_name": "Data from Information Repositories", "capability_group": "CIS-16", "comments": "Apply standard, industry-recommended hardening templates that enforce information repository data retention, archival, and deletion settings to limit accessible data.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1213.006", "attack_object_name": "Databases", "capability_group": "CIS-16", "comments": "Apply standard, industry-recommended databases hardening templates that enforce information repository data retention, archival, and deletion settings to limit accessible data.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1213.004", "attack_object_name": "Customer Relationship Management Software", "capability_group": "CIS-16", "comments": "Apply standard, industry-recommended customer relationship management software hardening templates that enforce data retention, archival, and deletion settings to limit accessible data.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-16", "comments": "Use standard hardening templates for application infrastructure components to allowlist MIB objects and implement SNMP views, restricting access to configuration information.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1543", "attack_object_name": "Create or Modify System Process", "capability_group": "CIS-16", "comments": "Use standard hardening templates for application infrastructure components to allowlist MIB objects and implement SNMP views, restricting access to configuration information.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1602", "attack_object_name": "Data from Configuration Repository", "capability_group": "CIS-16", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1602.002", "attack_object_name": "Network Device Configuration Dump", "capability_group": "CIS-16", "comments": "Use standard hardening templates to allowlist MIB objects, implement SNMP views, and disable Smart Install when it is not used, reducing exposure of network-device configuration data.", "references": []}, {"capability_id": "CIS-16.7", "capability_description": "Use Standard Hardening Configuration Templates for Application Infrastructure", "mapping_type": "mitigates", "attack_object_id": "T1543.005", "attack_object_name": "Container Service", "capability_group": "CIS-16", "comments": "Using standard, industry-recommended hardening templates for cloud containers to enforce the use of container services in rootless mode can help mitigate the effects of adversaries creating or modifying system-level processes. ", "references": []}, {"capability_id": "CIS-16.5", "capability_description": "Use Up-to-Date and Trusted Third-Party Software Components", "mapping_type": "mitigates", "attack_object_id": "T1195.001", "attack_object_name": "Compromise Software Dependencies and Development Tools", "capability_group": "CIS-16", "comments": "Selecting and maintaining trusted software components helps prevent integration of malicious or compromised libraries, packages, and software.", "references": []}, {"capability_id": "CIS-16.5", "capability_description": "Use Up-to-Date and Trusted Third-Party Software Components", "mapping_type": "mitigates", "attack_object_id": "T1195", "attack_object_name": "Supply Chain Compromise", "capability_group": "CIS-16", "comments": "Selecting and maintaining trusted software components helps prevent integration of malicious or compromised libraries, packages, and software.", "references": []}, {"capability_id": "CIS-16.5", "capability_description": "Use Up-to-Date and Trusted Third-Party Software Components", "mapping_type": "mitigates", "attack_object_id": "T1195.002", "attack_object_name": "Compromise Software Supply Chain", "capability_group": "CIS-16", "comments": "Selecting and maintaining trusted software components helps prevent integration of malicious or compromised libraries, packages, and software.", "references": []}, {"capability_id": "CIS-16.3", "capability_description": "Perform Root Cause Analysis on Security Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1212", "attack_object_name": "Exploitation for Credential Access", "capability_group": "CIS-16", "comments": "Application developers can use root-cause analysis to identify and remediate recurring authentication-validation weaknesses, such as missing replay protections, weak session controls, or flawed request validation. This reduces opportunities for adversaries to replay authentication messages, impersonate authorized parties, and conduct exploitation for credential access.", "references": []}, {"capability_id": "CIS-16.3", "capability_description": "Perform Root Cause Analysis on Security Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1195.001", "attack_object_name": "Compromise Software Dependencies and Development Tools", "capability_group": "CIS-16", "comments": "Application developers should exercise caution when selecting and integrating third-party libraries, using root-cause analysis of identified vulnerabilities to strengthen dependency-selection and management practices. This helps prevent supply-chain compromise through vulnerable or malicious software dependencies and development tools.", "references": []}, {"capability_id": "CIS-16.3", "capability_description": "Perform Root Cause Analysis on Security Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1195", "attack_object_name": "Supply Chain Compromise", "capability_group": "CIS-16", "comments": "Application developers should exercise caution when selecting and integrating third-party libraries, using root-cause analysis of identified vulnerabilities to strengthen dependency-selection and management practices. This helps prevent supply chain compromise through vulnerable or malicious software dependencies and development tools.", "references": []}, {"capability_id": "CIS-16.3", "capability_description": "Perform Root Cause Analysis on Security Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-16", "comments": "Application developers can use root cause analysis to address code or build process practices that expose credentials to ensure that applications do not store sensitive data or credentials insecurely.", "references": []}, {"capability_id": "CIS-15.7", "capability_description": "Securely Decommission Service Providers", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-15", "comments": "Securely decommissioning service providers with service accounts or other access to software deployment, endpoint management, or configuration management platforms prevents residual provider access from being abused through these centralized software suites.", "references": []}, {"capability_id": "CIS-15.7", "capability_description": "Securely Decommission Service Providers", "mapping_type": "mitigates", "attack_object_id": "T1199", "attack_object_name": "Trusted Relationship", "capability_group": "CIS-15", "comments": "Remove accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party and if the party is compromised by an adversary.", "references": []}, {"capability_id": "CIS-15.7", "capability_description": "Securely Decommission Service Providers", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-15", "comments": "Disabling provider user and service accounts and revoking associated credentials, tokens, and access permissions prevents residual provider identities from being abused by adversaries to access enterprise resources.", "references": []}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1659", "attack_object_name": "Content Injection", "capability_group": "CIS-13", "comments": "Application-layer filtering can block uncommon, unauthorized, or malicious content and transferred file types at web proxies, application gateways, or similar inspection points before the content reaches protected systems.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1555.003", "attack_object_name": "Credentials from Web Browsers", "capability_group": "CIS-13", "comments": "Web filtering and application-layer gateways can block malicious web content and destinations used to deliver browser-based credential theft or session-stealing content.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1189", "attack_object_name": "Drive-by Compromise", "capability_group": "CIS-13", "comments": "Web proxies and application-layer gateways can prevent access to known malicious or unnecessary websites and block malicious web content used to compromise users through drive-by activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1568", "attack_object_name": "Dynamic Resolution", "capability_group": "CIS-13", "comments": "DNS filtering and sinkholing can prevent systems from resolving domains associated with dynamically changing adversary command-and-control infrastructure.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1568.002", "attack_object_name": "Domain Generation Algorithms", "capability_group": "CIS-13", "comments": "DNS filtering and sinkholing can block domains generated by known domain-generation algorithms when those domains or generation patterns can be identified.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1567", "attack_object_name": "Exfiltration Over Web Service", "capability_group": "CIS-13", "comments": "Web proxies and application-layer gateways can restrict which external web services are permitted, reducing unauthorized use of web services for data exfiltration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1567.001", "attack_object_name": "Exfiltration to Code Repository", "capability_group": "CIS-13", "comments": "Application-layer filtering can block or restrict access to unauthorized external code repositories, limiting their use as destinations for data exfiltration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1567.002", "attack_object_name": "Exfiltration to Cloud Storage", "capability_group": "CIS-13", "comments": "Application-layer filtering can block or restrict access to unauthorized cloud-storage services, limiting their use as destinations for data exfiltration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1567.003", "attack_object_name": "Exfiltration to Text Storage Sites", "capability_group": "CIS-13", "comments": "Application-layer filtering can block or restrict access to unauthorized text-storage and paste services, limiting their use as destinations for data exfiltration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-13", "comments": "Application-layer firewalls and proxies can restrict access to unauthorized remote-access services, anonymization services, and other external services used to access enterprise resources.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1566", "attack_object_name": "Phishing", "capability_group": "CIS-13", "comments": "Application-layer filtering can block malicious websites, links, attachments, and other web or email content used in phishing activity before that content reaches users.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1566.001", "attack_object_name": "Spearphishing Attachment", "capability_group": "CIS-13", "comments": "Mail and application-layer gateways can inspect and block dangerous attachment types, malicious archives, and other suspicious content delivered through spearphishing attachments.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1566.002", "attack_object_name": "Spearphishing Link", "capability_group": "CIS-13", "comments": "Web proxies and application-layer gateways can block access to malicious or unnecessary websites reached through spearphishing links.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1566.003", "attack_object_name": "Spearphishing via Service", "capability_group": "CIS-13", "comments": "Application-layer filtering can restrict access to personal webmail, social media, and other external services that may be abused to deliver spearphishing messages.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1539", "attack_object_name": "Steal Web Session Cookie", "capability_group": "CIS-13", "comments": "Web filtering and application-layer gateways can block malicious content or destinations used to deliver browser-based session-cookie theft activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1218", "attack_object_name": "System Binary Proxy Execution", "capability_group": "CIS-13", "comments": "Application-layer filtering can restrict malicious sites, downloads, attachments, and scripts that may deliver payloads later executed through trusted system binaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1218.001", "attack_object_name": "Compiled HTML File", "capability_group": "CIS-13", "comments": "Application-layer filtering can block CHM and other uncommon or risky file types in transit, reducing delivery of content that may be executed through Compiled HTML Help.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1204", "attack_object_name": "User Execution", "capability_group": "CIS-13", "comments": "Application-layer filtering can prevent malicious web or email content from reaching users, reducing opportunities for users to execute or interact with adversary-delivered content.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1204.001", "attack_object_name": "Malicious Link", "capability_group": "CIS-13", "comments": "Web proxies and application-layer gateways can block requests to malicious links and prevent associated content from being downloaded.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1204.004", "attack_object_name": "Malicious Copy and Paste", "capability_group": "CIS-13", "comments": "Application-layer filtering can block malicious web content or destinations used to provide commands, scripts, or other content that users are instructed to copy and execute.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1102", "attack_object_name": "Web Service", "capability_group": "CIS-13", "comments": "Web proxies and application-layer gateways can restrict access to unauthorized external web services, limiting their use for adversary command and control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1102.001", "attack_object_name": "Dead Drop Resolver", "capability_group": "CIS-13", "comments": "Application-layer filtering can block access to unauthorized web services used as dead-drop resolvers for adversary command-and-control infrastructure.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1102.002", "attack_object_name": "Bidirectional Communication", "capability_group": "CIS-13", "comments": "Application-layer filtering can block unauthorized web services used for bidirectional command-and-control communications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1102.003", "attack_object_name": "One-Way Communication", "capability_group": "CIS-13", "comments": "Application-layer filtering can block unauthorized web services used for one-way command-and-control communications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1071", "attack_object_name": "Application Layer Protocol", "capability_group": "CIS-13", "comments": "Application-aware gateways can inspect and restrict unauthorized application-layer protocols, services, and destinations used for adversary command and control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1071.001", "attack_object_name": "Web Protocols", "capability_group": "CIS-13", "comments": "Web proxies and application-layer firewalls can inspect and restrict HTTP and HTTPS traffic to unauthorized or malicious destinations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1071.002", "attack_object_name": "File Transfer Protocols", "capability_group": "CIS-13", "comments": "Application-layer filtering can restrict FTP, SFTP, and related file-transfer protocol traffic to approved services and destinations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1071.003", "attack_object_name": "Mail Protocols", "capability_group": "CIS-13", "comments": "Application-layer filtering can restrict SMTP, IMAP, POP3, and related mail-protocol traffic to approved infrastructure and expected communication paths.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1071.004", "attack_object_name": "DNS", "capability_group": "CIS-13", "comments": "DNS proxies and filtering services can block malicious domains and restrict systems to approved name-resolution services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1071.005", "attack_object_name": "Publish/Subscribe Protocols", "capability_group": "CIS-13", "comments": "Application-aware filtering can restrict publish/subscribe protocols to approved brokers, destinations, and expected service ports.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-13", "comments": "Application proxies and gateways can require use of approved protocol services and restrict unauthorized application-layer protocols or destinations used for data exfiltration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1048.001", "attack_object_name": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-13", "comments": "Application-layer gateways can restrict symmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1048.002", "attack_object_name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-13", "comments": "Application-layer gateways can restrict asymmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1048.003", "attack_object_name": "Exfiltration Over Unencrypted Non-C2 Protocol", "capability_group": "CIS-13", "comments": "Application-layer filtering can directly restrict unencrypted non-command-and-control protocols to approved services and destinations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-13", "comments": "Web application firewalls and application-layer gateways can inspect inbound application requests and block known malicious request patterns or exploit payloads targeting public-facing applications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1187", "attack_object_name": "Forced Authentication", "capability_group": "CIS-13", "comments": "Application and protocol filtering can block outbound WebDAV and related requests that may be abused to force systems to authenticate to attacker-controlled resources.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1105", "attack_object_name": "Ingress Tool Transfer", "capability_group": "CIS-13", "comments": "Web proxies and application-layer gateways can block unauthorized downloads, file-transfer services, and malicious content used to transfer adversary tools into the environment.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1572", "attack_object_name": "Protocol Tunneling", "capability_group": "CIS-13", "comments": "Application-aware filtering can identify and restrict unauthorized tunneling through otherwise permitted application protocols and services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1090", "attack_object_name": "Proxy", "capability_group": "CIS-13", "comments": "Application-layer gateways can block known anonymization services, unauthorized proxy services, and other proxy destinations used to conceal adversary communications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1090.003", "attack_object_name": "Multi-hop Proxy", "capability_group": "CIS-13", "comments": "Application-layer gateways can restrict known anonymization and proxy services that may be chained together to form multi-hop proxy infrastructure.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1219", "attack_object_name": "Remote Access Tools", "capability_group": "CIS-13", "comments": "Application firewalls and proxies can restrict access to websites, services, and destinations associated with unauthorized remote-access tools.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1219.002", "attack_object_name": "Remote Desktop Software", "capability_group": "CIS-13", "comments": "Application-layer firewalls and proxies can restrict access to unauthorized remote-desktop services and destinations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1552", "attack_object_name": "Unsecured Credentials", "capability_group": "CIS-13", "comments": "Web application firewalls and application-layer controls can block server-side request forgery paths that would otherwise expose credential-bearing cloud metadata services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1552.005", "attack_object_name": "Cloud Instance Metadata API", "capability_group": "CIS-13", "comments": "A properly configured web application firewall can block external server-side request forgery attempts that target the cloud instance metadata API and expose temporary credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1499.003", "attack_object_name": "Application Exhaustion Flood", "capability_group": "CIS-13", "comments": "Application-layer firewalls and web application firewalls can inspect, rate-limit, or block abusive application requests that attempt to exhaust application resources.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.10", "capability_description": "Perform Application Layer Filtering", "mapping_type": "mitigates", "attack_object_id": "T1499.004", "attack_object_name": "Application or System Exploitation", "capability_group": "CIS-13", "comments": "Application-layer firewalls and web application firewalls can inspect and block known malicious request patterns or exploit payloads intended to cause application or system resource exhaustion.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#1310-perform-application-layer-filtering"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1021.004", "attack_object_name": "SSH", "capability_group": "CIS-13", "comments": "Conditional access policies for remote enterprise assets can deny authentication attempts to the SSH service if external SSH access is reachable through a remote-access control plane that can evaluates device posture", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1110", "attack_object_name": "Brute Force", "capability_group": "CIS-13", "comments": "Conditional access policies for remote enterprise assets can deny authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use brute-force activity from non-compliant remote endpoints.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1110.001", "attack_object_name": "Password Guessing", "capability_group": "CIS-13", "comments": "Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use guessed passwords from non-compliant remote endpoints.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1110.003", "attack_object_name": "Password Spraying", "capability_group": "CIS-13", "comments": "Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use password spraying from non-compliant remote endpoints.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1110.004", "attack_object_name": "Credential Stuffing", "capability_group": "CIS-13", "comments": "Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use compromised credential pairs from non-compliant remote endpoints.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1621", "attack_object_name": "Multi-Factor Authentication Request Generation", "capability_group": "CIS-13", "comments": "Conditional access policies can prevent authentication attempts from non-compliant remote devices from proceeding, thereby preventing associated multi-factor authentication requests from being generated.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-13", "comments": "Access control policies for remote enterprise assets can evaluate device compliance before permitting access to enterprise resources. Requiring current anti-malware protection, secure configuration compliance, and current operating system and application versions can prevent valid credentials from being used from remote devices that do not meet enterprise security requirements.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1078.004", "attack_object_name": "Cloud Accounts", "capability_group": "CIS-13", "comments": "Conditional access policies can evaluate device compliance before permitting cloud-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1078.002", "attack_object_name": "Domain Accounts", "capability_group": "CIS-13", "comments": "Conditional access policies can evaluate device compliance before permitting domain-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1078.003", "attack_object_name": "Local Accounts", "capability_group": "CIS-13", "comments": "Conditional access policies can evaluate device compliance before permitting local-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-13", "comments": "Centrally managed authorization systems can restrict access to enterprise remote services based on the security posture of the connecting asset, including anti-malware status, secure-configuration compliance, and operating system or application update status.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1021", "attack_object_name": "Remote Services", "capability_group": "CIS-13", "comments": "Centrally managed remote-access controls can restrict access to enterprise remote services so remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-13", "comments": "Remote Desktop access can be restricted through centrally managed authorization controls so that remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1550", "attack_object_name": "Use Alternate Authentication Material", "capability_group": "CIS-13", "comments": "Conditional access policies can evaluate the context and compliance state of a remote device when alternate authentication material is used, reducing the ability to use authentication material from devices that do not satisfy enterprise security requirements.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.5", "capability_description": "Manage Access Control for Remote Access", "mapping_type": "mitigates", "attack_object_id": "T1550.001", "attack_object_name": "Application Access Token", "capability_group": "CIS-13", "comments": "Conditional access policies can evaluate device compliance and expected access context when application access tokens are used, reducing the ability to use valid tokens from non-compliant remote endpoints or outside approved access conditions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#135-manage-assets-remotely-connecting-to-enterprise-infrastructure"]}, {"capability_id": "CIS-13.9", "capability_description": "Deploy Port-Level Access Control", "mapping_type": "mitigates", "attack_object_id": "T1200", "attack_object_name": "Hardware Additions", "capability_group": "CIS-13", "comments": "Port-level access control using 802.1X, device certificates, or similar network access control mechanisms can prevent unauthorized hardware from authenticating to and communicating on trusted enterprise networks.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1059", "attack_object_name": "Command and Scripting Interpreter", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral controls such as Attack Surface Reduction rules to prevent Visual Basic and JavaScript from executing potentially malicious downloaded content.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1059.005", "attack_object_name": "Visual Basic", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Visual Basic scripts from executing potentially malicious downloaded content.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1059.007", "attack_object_name": "JavaScript", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent JavaScript scripts from executing potentially malicious downloaded content.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1543", "attack_object_name": "Create or Modify System Process", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can block applications from writing signed vulnerable drivers and can enforce vulnerable-driver blocklists to reduce abuse of system processes and services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1543.003", "attack_object_name": "Windows Service", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can block applications from writing signed vulnerable service drivers and can enforce vulnerable-driver blocklists to reduce abuse of Windows services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1486", "attack_object_name": "Data Encrypted for Impact", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can use cloud-delivered protection and behavioral rules to block execution of files that exhibit ransomware-like behavior.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1006", "attack_object_name": "Direct Volume Access", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block behaviors associated with direct volume or backup-related access, including suspicious command execution or API calls targeting backup services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1546.003", "attack_object_name": "Windows Management Instrumentation Event Subscription", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that prevent malware from abusing Windows Management Instrumentation to establish persistence.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1564.014", "attack_object_name": "Extended Attributes", "capability_group": "CIS-13", "comments": "Host-based security controls can inspect extended attributes alongside file contents during artifact review, packaging, or deployment to identify hidden payloads, obfuscated data, or suspicious attribute keys.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1574", "attack_object_name": "Hijack Execution Flow", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block behaviors associated with process injection or memory tampering based on common sequences of indicators such as suspicious API usage.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1574.013", "attack_object_name": "KernelCallbackTable", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block behaviors associated with KernelCallbackTable abuse and related memory-tampering activity based on common sequences of indicators and suspicious API usage.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1559", "attack_object_name": "Inter-Process Communication", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1559.002", "attack_object_name": "Dynamic Data Exchange", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1036", "attack_object_name": "Masquerading", "capability_group": "CIS-13", "comments": "Host intrusion prevention systems can identify and prevent execution of potentially malicious files, including files whose signatures do not match their apparent file type.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1036.008", "attack_object_name": "Masquerade File Type", "capability_group": "CIS-13", "comments": "Host intrusion prevention systems can identify and prevent execution of files whose signatures do not match their apparent file type.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1106", "attack_object_name": "Native API", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office VBA macros from calling Win32 APIs.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1027", "attack_object_name": "Obfuscated Files or Information", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1027.009", "attack_object_name": "Embedded Payloads", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts containing embedded payloads.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1027.010", "attack_object_name": "Command Obfuscation", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that block execution of potentially obfuscated scripts or commands.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1027.012", "attack_object_name": "LNK Icon Smuggling", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads delivered through LNK-based techniques.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1027.013", "attack_object_name": "Encrypted/Encoded File", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can block execution of potentially obfuscated scripts and analyze file-encoding properties for anomalies that deviate from expected encoding practices.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1027.014", "attack_object_name": "Polymorphic Code", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated or polymorphic payloads.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1137", "attack_object_name": "Office Application Startup", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1137.001", "attack_object_name": "Office Template Macros", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1137.002", "attack_object_name": "Office Test", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1137.003", "attack_object_name": "Outlook Forms", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1137.004", "attack_object_name": "Outlook Home Page", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1137.005", "attack_object_name": "Outlook Rules", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1137.006", "attack_object_name": "Add-ins", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1003", "attack_object_name": "OS Credential Dumping", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent credential-stealing activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1003.001", "attack_object_name": "LSASS Memory", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent attempts to steal credentials from LSASS memory.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055", "attack_object_name": "Process Injection", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block process-injection behavior based on common sequences of activity, including suspicious API use and code injection from applications such as Microsoft Office.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.001", "attack_object_name": "Dynamic-link Library Injection", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block dynamic-link library injection based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.002", "attack_object_name": "Portable Executable Injection", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block portable executable injection based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.003", "attack_object_name": "Thread Execution Hijacking", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block thread execution hijacking based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.004", "attack_object_name": "Asynchronous Procedure Call", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block process injection using asynchronous procedure calls based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.005", "attack_object_name": "Thread Local Storage", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block process injection using thread local storage based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.008", "attack_object_name": "Ptrace System Calls", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block process injection using ptrace system calls based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.009", "attack_object_name": "Proc Memory", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block process injection through proc memory based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.011", "attack_object_name": "Extra Window Memory Injection", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block extra window memory injection based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.012", "attack_object_name": "Process Hollowing", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block process hollowing based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.013", "attack_object_name": "Process Doppelg\u00e4nging", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block process doppelg\u00e4nging based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.014", "attack_object_name": "VDSO Hijacking", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block VDSO hijacking based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1055.015", "attack_object_name": "ListPlanting", "capability_group": "CIS-13", "comments": "Endpoint security solutions can block ListPlanting based on common behavioral sequences and suspicious memory-manipulation activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1091", "attack_object_name": "Replication Through Removable Media", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can block unsigned or untrusted executable files from running from removable media such as USB drives.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1216.001", "attack_object_name": "PubPrn", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce application-control policies that block older or vulnerable versions of PubPrn from executing.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1569", "attack_object_name": "System Services", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1569.002", "attack_object_name": "Service Execution", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1204", "attack_object_name": "User Execution", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running based on prevalence, age, trust, or behavioral criteria and can block Office applications from writing malicious executable content to disk.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1204.002", "attack_object_name": "Malicious File", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running when they are downloaded or launched by Office applications, scripting interpreters, email clients, or fail prevalence, age, or trust criteria.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.7", "capability_description": "Deploy a Host-Based Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1047", "attack_object_name": "Windows Management Instrumentation", "capability_group": "CIS-13", "comments": "Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that block processes created by Windows Management Instrumentation commands from running.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#137-deploy-a-host-based-intrusion-prevention-solution"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can identify traffic patterns associated with adversary-in-the-middle activity and block the activity at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1557.001", "attack_object_name": "Name Resolution Poisoning and SMB Relay", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can identify traffic patterns associated with name-resolution poisoning and SMB relay activity and block the activity at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1557.002", "attack_object_name": "ARP Cache Poisoning", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can identify traffic patterns associated with ARP cache poisoning and block the activity where the relevant network traffic is monitored.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1557.003", "attack_object_name": "DHCP Spoofing", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can identify traffic patterns associated with DHCP spoofing and block the activity where the relevant network traffic is monitored.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1557.004", "attack_object_name": "Evil Twin", "capability_group": "CIS-13", "comments": "Wireless intrusion prevention capabilities can identify rogue access points and traffic patterns associated with evil-twin activity and block or contain the unauthorized wireless connection.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1071", "attack_object_name": "Application Layer Protocol", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known malicious application-layer traffic to block adversary command-and-control communications at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1071.001", "attack_object_name": "Web Protocols", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for malicious HTTP or HTTPS traffic associated with specific adversary tools to block command-and-control activity at the network boundary.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1071.002", "attack_object_name": "File Transfer Protocols", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for malicious file-transfer protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1071.003", "attack_object_name": "Mail Protocols", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for malicious mail-protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1071.004", "attack_object_name": "DNS", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for malicious DNS traffic associated with specific adversary tools to block command-and-control activity at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1071.005", "attack_object_name": "Publish/Subscribe Protocols", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for malicious publish/subscribe protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1132", "attack_object_name": "Data Encoding", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use protocol and malware-specific signatures to identify encoded command-and-control traffic and block matching activity at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1132.001", "attack_object_name": "Standard Encoding", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known protocol indicators and standard encoding patterns used by adversary tools to block matching network activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1132.002", "attack_object_name": "Non-Standard Encoding", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known protocol indicators and non-standard encoding patterns used by adversary tools to block matching network activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1602", "attack_object_name": "Data from Configuration Repository", "capability_group": "CIS-13", "comments": "Configure network intrusion prevention solutions to identify and block unauthorized management queries and commands used to access network-device configuration repositories.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-13", "comments": "Configure network intrusion prevention solutions to identify and block SNMP queries and commands originating from unauthorized sources.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1602.002", "attack_object_name": "Network Device Configuration Dump", "capability_group": "CIS-13", "comments": "Configure network intrusion prevention solutions to identify and block unauthorized SNMP activity and unexpected Smart Install usage directed at network devices.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1001", "attack_object_name": "Data Obfuscation", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block obfuscated command-and-control activity that remains identifiable at the network level.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1001.001", "attack_object_name": "Junk Data", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control communications that use junk data for obfuscation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1001.002", "attack_object_name": "Steganography", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block network activity that uses identifiable steganographic methods.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1001.003", "attack_object_name": "Protocol or Service Impersonation", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control activity that impersonates legitimate protocols or services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1030", "attack_object_name": "Data Transfer Size Limits", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures associated with known adversary infrastructure and malware to block command-and-control traffic that varies transfer size to evade controls.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1568", "attack_object_name": "Dynamic Resolution", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures and known indicators associated with dynamically resolved adversary infrastructure to block matching command-and-control traffic.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1568.002", "attack_object_name": "Domain Generation Algorithms", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can block traffic to domains or patterns associated with known domain-generation algorithms when those indicators can be identified in advance or during network activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1573", "attack_object_name": "Encrypted Channel", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block encrypted command-and-control traffic at monitored boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1573.001", "attack_object_name": "Symmetric Cryptography", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with symmetric cryptography.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1573.002", "attack_object_name": "Asymmetric Cryptography", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with asymmetric cryptography.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over alternative protocols.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1048.001", "attack_object_name": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over symmetrically encrypted non-command-and-control protocols.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1048.002", "attack_object_name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over asymmetrically encrypted non-command-and-control protocols.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1048.003", "attack_object_name": "Exfiltration Over Unencrypted Non-C2 Protocol", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over unencrypted non-command-and-control protocols.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1041", "attack_object_name": "Exfiltration Over C2 Channel", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable exfiltration occurring over command-and-control channels.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1008", "attack_object_name": "Fallback Channels", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable fallback command-and-control channels at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1105", "attack_object_name": "Ingress Tool Transfer", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over protocols such as FTP and block the associated tool-transfer activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1570", "attack_object_name": "Lateral Tool Transfer", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over common tools and protocols and block lateral tool-transfer activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1104", "attack_object_name": "Multi-Stage Channels", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic associated with multi-stage command-and-control channels.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1046", "attack_object_name": "Network Service Discovery", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can identify and block remote service scanning that crosses monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1095", "attack_object_name": "Non-Application Layer Protocol", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary malware to block malicious use of non-application-layer protocols at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1571", "attack_object_name": "Non-Standard Port", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary malware to block malicious traffic using non-standard ports at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1566", "attack_object_name": "Phishing", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions and network-based content controls can block malicious email links or attachments before they reach or execute on enterprise assets.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1566.001", "attack_object_name": "Spearphishing Attachment", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions and network-based content controls can block malicious email attachments before they reach or execute on enterprise assets.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1542.004", "attack_object_name": "ROMMONkit", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for protocols such as TFTP to block identifiable network activity associated with unauthorized modification of network-device boot components.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1542.005", "attack_object_name": "TFTP Boot", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for protocols such as TFTP to block unauthorized TFTP traffic associated with network-device boot activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1572", "attack_object_name": "Protocol Tunneling", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary malware and tunneling traffic to block identifiable protocol-tunneling activity at monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1090", "attack_object_name": "Proxy", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable proxy communications used for adversary command and control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1090.001", "attack_object_name": "Internal Proxy", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable internal proxy communications used for adversary command and control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1090.002", "attack_object_name": "External Proxy", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable external proxy communications used for adversary command and control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1219", "attack_object_name": "Remote Access Tools", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use network signatures to block traffic associated with unauthorized remote-access services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1029", "attack_object_name": "Scheduled Transfer", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary infrastructure and malware to block identifiable scheduled command-and-control or data-transfer activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1221", "attack_object_name": "Template Injection", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can block network activity that attempts to fetch or execute malicious payloads through externally referenced document templates.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1204", "attack_object_name": "User Execution", "capability_group": "CIS-13", "comments": "When user execution depends on visiting a malicious link or retrieving malicious content, network intrusion prevention solutions can block the associated network request or download.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1204.001", "attack_object_name": "Malicious Link", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can block requests to malicious links and prevent associated content from being downloaded across monitored network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1204.003", "attack_object_name": "Malicious Image", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can block malicious image downloads when the content or associated network activity matches known malicious indicators.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1204.004", "attack_object_name": "Malicious Copy and Paste", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can block network requests for malicious content used in copy-and-paste execution workflows when the destination or traffic matches known malicious indicators.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1204.005", "attack_object_name": "Malicious Library", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can block malicious library downloads when the content or associated network activity matches known malicious indicators.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1102", "attack_object_name": "Web Service", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable command-and-control traffic using web services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1102.001", "attack_object_name": "Dead Drop Resolver", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic to web services used as dead-drop resolvers.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1102.002", "attack_object_name": "Bidirectional Communication", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable bidirectional command-and-control traffic using web services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.8", "capability_description": "Deploy a Network Intrusion Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1102.003", "attack_object_name": "One-Way Communication", "capability_group": "CIS-13", "comments": "Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable one-way command-and-control traffic using web services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#138-deploy-a-network-intrusion-prevention-solutions"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-13", "comments": "Filtering unnecessary and legacy network traffic between network segments reduces opportunities for adversaries to establish adversary-in-the-middle conditions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1071", "attack_object_name": "Application Layer Protocol", "capability_group": "CIS-13", "comments": "Use network filtering between segments to permit only required application-layer protocols and authorized communications, limiting adversary use of application protocols for command and control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1071.001", "attack_object_name": "Web Protocols", "capability_group": "CIS-13", "comments": "Restrict HTTP and HTTPS traffic crossing network-segment boundaries from critical systems to approved destinations, reducing unauthorized outbound web communications used for command and control or payload transfer.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1071.002", "attack_object_name": "File Transfer Protocols", "capability_group": "CIS-13", "comments": "Filter FTP and SFTP traffic between network segments so sensitive systems can transfer files only to trusted internal systems or other explicitly approved destinations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1071.003", "attack_object_name": "Mail Protocols", "capability_group": "CIS-13", "comments": "Restrict SMTP, IMAP, and POP3 traffic between segments so servers and critical systems communicate only with trusted mail infrastructure, reducing unauthorized mail-based command, control, or exfiltration paths.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1071.004", "attack_object_name": "DNS", "capability_group": "CIS-13", "comments": "Restrict DNS traffic between segments to approved resolvers and filter requests to unknown, untrusted, or known malicious resources, reducing adversary use of DNS for command and control or concealed data transfer.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1071.005", "attack_object_name": "Publish/Subscribe Protocols", "capability_group": "CIS-13", "comments": "Filter publish/subscribe protocol traffic crossing segment boundaries to approved brokers, destinations, and expected ports, reducing use of untrusted resources or irregular ports for command and control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1602", "attack_object_name": "Data from Configuration Repository", "capability_group": "CIS-13", "comments": "Apply network access-control rules between trusted and untrusted segments to block unauthorized management protocols used to reach configuration repositories and managed network devices.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-13", "comments": "Apply network access-control rules to restrict SNMP traffic across segment boundaries to authorized management systems, preventing unauthorized retrieval of Management Information Base data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1602.002", "attack_object_name": "Network Device Configuration Dump", "capability_group": "CIS-13", "comments": "Apply network access-control rules to restrict management protocols used to retrieve network-device configurations to approved management segments and authorized systems.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-13", "comments": "Enforce network segmentation, proxies, and dedicated protocol services so only approved systems can communicate over protocols such as DNS, reducing opportunities to exfiltrate data through alternative protocols.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1048.001", "attack_object_name": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-13", "comments": "Enforce proxies or dedicated services and restrict encrypted non-command-and-control protocol traffic between segments to systems with a legitimate requirement to use those protocols.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1048.002", "attack_object_name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-13", "comments": "Enforce proxies or dedicated services and restrict asymmetric encrypted non-command-and-control protocol traffic between segments to approved systems and destinations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1048.003", "attack_object_name": "Exfiltration Over Unencrypted Non-C2 Protocol", "capability_group": "CIS-13", "comments": "Restrict unencrypted alternative-protocol traffic between network segments and allow those protocols only where required for approved business communications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-13", "comments": "Restrict outbound traffic from public-facing or DMZ network segments to approved internal and external destinations, limiting post-exploitation communication from a compromised public-facing server.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1570", "attack_object_name": "Lateral Tool Transfer", "capability_group": "CIS-13", "comments": "Restrict file-sharing communications such as SMB between network segments to systems with a legitimate requirement, reducing adversary opportunities to transfer tools laterally.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1599", "attack_object_name": "Network Boundary Bridging", "capability_group": "CIS-13", "comments": "Use unaffected firewalls or routers to block unauthorized traffic that attempts to bridge established network-segment boundaries and continue monitoring to ensure the filtering remains effective.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1599.001", "attack_object_name": "Network Address Translation Traversal", "capability_group": "CIS-13", "comments": "Use unaffected network filtering devices to block unauthorized traffic attempting to traverse network boundaries through NAT or related boundary-bridging mechanisms.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1095", "attack_object_name": "Non-Application Layer Protocol", "capability_group": "CIS-13", "comments": "Filter traffic at network-segment boundaries to prevent use of non-application-layer protocols that are not required for business operations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1572", "attack_object_name": "Protocol Tunneling", "capability_group": "CIS-13", "comments": "Filter network traffic between segments to untrusted, unauthorized, or known malicious destinations and restrict protocols that can be abused to tunnel communications across network boundaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1219", "attack_object_name": "Remote Access Tools", "capability_group": "CIS-13", "comments": "Configure network firewalls and proxies at segment boundaries to restrict outgoing traffic to sites and services associated with unauthorized remote-access software.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1219.002", "attack_object_name": "Remote Desktop Software", "capability_group": "CIS-13", "comments": "Restrict remote-desktop software traffic between network segments to authorized systems, destinations, and management paths using firewalls and proxy controls.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1021.002", "attack_object_name": "SMB/Windows Admin Shares", "capability_group": "CIS-13", "comments": "Restrict SMB and Windows administrative-share communications between network segments to explicitly authorized systems and management paths.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1021.005", "attack_object_name": "VNC", "capability_group": "CIS-13", "comments": "Filter or block VNC traffic across network-segment boundaries, including commonly used VNC ports, except where the communication is explicitly required.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1205", "attack_object_name": "Traffic Signaling", "capability_group": "CIS-13", "comments": "Use stateful filtering at network-segment boundaries to block traffic patterns used by traffic-signaling mechanisms when the signaling implementation can be identified and constrained.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1205.001", "attack_object_name": "Port Knocking", "capability_group": "CIS-13", "comments": "Use stateful filtering at network-segment boundaries to prevent port-knocking sequences from reaching protected systems where the signaling pattern can be constrained.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1205.002", "attack_object_name": "Socket Filters", "capability_group": "CIS-13", "comments": "Use stateful filtering at network-segment boundaries to block crafted traffic used to trigger socket-filter-based communication when the signaling implementation can be identified.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1537", "attack_object_name": "Transfer Data to Cloud Account", "capability_group": "CIS-13", "comments": "Implement network-based filtering restrictions between trusted and untrusted VPCs or equivalent network segments to prohibit unauthorized data transfers to external cloud accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1197", "attack_object_name": "BITS Jobs", "capability_group": "CIS-13", "comments": "Configure network filtering controls so only legitimate BITS traffic is permitted across network boundaries, restricting unauthorized BITS communications used for background transfer or execution activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1530", "attack_object_name": "Data from Cloud Storage", "capability_group": "CIS-13", "comments": "Use network-based source restrictions and expected IP ranges when accessing cloud resources so data access is limited to authorized network locations in addition to valid user accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1090", "attack_object_name": "Proxy", "capability_group": "CIS-13", "comments": "Use network allow and block lists to prevent traffic between network segments and known anonymity networks or command-and-control infrastructure that may be used as proxy destinations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1090.003", "attack_object_name": "Multi-hop Proxy", "capability_group": "CIS-13", "comments": "Use network allow and block lists to restrict traffic to known anonymity networks and command-and-control infrastructure that may be chained together as multi-hop proxy destinations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1218", "attack_object_name": "System Binary Proxy Execution", "capability_group": "CIS-13", "comments": "Use network appliances at segment boundaries to filter ingress and egress traffic and restrict unnecessary protocols or destinations that trusted system binaries could otherwise use for malicious communications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1218.012", "attack_object_name": "Verclsid", "capability_group": "CIS-13", "comments": "Restrict unnecessary outbound traffic from systems that do not require external communications through Verclsid, using network filtering controls where the relevant traffic crosses a managed segment boundary.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1552", "attack_object_name": "Unsecured Credentials", "capability_group": "CIS-13", "comments": "Restrict network access paths to cloud instance metadata services and use filtering controls to reduce exposure of metadata interfaces that may contain temporary credentials or other authentication material.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-13.4", "capability_description": "Perform Traffic Filtering Between Network Segments", "mapping_type": "mitigates", "attack_object_id": "T1552.005", "attack_object_name": "Cloud Instance Metadata API", "capability_group": "CIS-13", "comments": "Restrict network access to the Cloud Instance Metadata API so only workloads with a legitimate requirement can reach the service, reducing adversary access to credentials and metadata through unintended network paths.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls13/#134-perform-traffic-filtering-between-network-segments"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1550.004", "attack_object_name": "Web Session Cookie", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and the remediation configures applications and browsers to reduce persistent sessions, shorten cookie validity, require reauthentication, and invalidate session material more aggressively. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1543", "attack_object_name": "Create or Modify System Process", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and the remediation restricts insecure service/process behavior. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1606", "attack_object_name": "Forge Web Credentials", "capability_group": "CIS-18", "comments": "Application and browser configuration can reduce persistent or weakly protected web credential artifacts such as cookies that were found/forged during penetration testing. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1543.005", "attack_object_name": "Container Service", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and the remediation is related to configuring container services to run rootless or otherwise reduce unnecessary service privileges, directly constraining persistence or privilege abuse through the container service. The mapping does not apply when the finding requires patching or architectural changes rather than configuration correction.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1555.005", "attack_object_name": "Password Managers", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and the remediation deals with enforcing password-manager locking, timeout, vault-access, and related security settings that reduce exposure of stored or decrypted credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1685", "attack_object_name": "Disable or Modify Tools", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation relates to hardening security, logging, and monitoring tools so they are harder to disable or reconfigure, including by enforcing permissions, persistence settings, and service configuration. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1667", "attack_object_name": "Email Bombing", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens mail service configuration, sender authentication policy, filtering, throttling, and related controls that reduce abusive high-volume email delivery. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1546.013", "attack_object_name": "PowerShell Profile", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software-configuration weakness and remediation of the finding removes unnecessary PowerShell profiles, restrict profile modification, or configure PowerShell execution so untrusted profile content is not loaded. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1606.001", "attack_object_name": "Web Cookies", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the applications and browsers to minimize persistent cookies, shorten cookie lifetime, and apply secure cookie settings that reduce reusable credential material. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1590.002", "attack_object_name": "DNS", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the DNS zone transfers to explicitly authorized servers and correct other DNS service settings that expose internal naming information. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1559.002", "attack_object_name": "Dynamic Data Exchange", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding restricts the unnecessary DDE and embedded-content functionality in affected applications, directly reducing an execution path that relies on permissive application configuration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1566.001", "attack_object_name": "Spearphishing Attachment", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthen mail system sender-authentication, attachment-handling, and filtering policies that reduce delivery of malicious attachments.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1566.002", "attack_object_name": "Spearphishing Link", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens mail authentication, URL-handling, and browser or mail-client policy to reduce delivery or successful use of malicious links. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1598.002", "attack_object_name": "Spearphishing Attachment", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens sender-authentication and attachment-filtering configuration to reduce spoofed or malicious messages used to solicit sensitive information.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1677", "attack_object_name": "Poisoned Pipeline Execution", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding hardens CI/CD pipeline settings by restricting unreviewed code execution, isolating runners, reducing secrets exposure, constraining triggers, and preventing user-controlled input from being implicitly trusted.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1688", "attack_object_name": "Safe Mode Boot", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding configure system settings so defensive services remain active or recover correctly when Windows is booted into Safe Mode.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1684.002", "attack_object_name": "Email Spoofing", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes and enforces SPF, DKIM, DMARC, and related mail-domain protections to reduce successful sender impersonation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1539", "attack_object_name": "Steal Web Session Cookie", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes by configuring secure cookie attributes, shorter lifetimes, session invalidation, and reduced persistence in affected applications or browsers.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1537", "attack_object_name": "Transfer Data to Cloud Account", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the cloud applications and services to restrict external sharing, cross account transfers, and unapproved destinations, directly constraining data movement to adversary controlled cloud accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-18.3", "capability_description": "Remediate Penetration Test Findings", "mapping_type": "mitigates", "attack_object_id": "T1535", "attack_object_name": "Unused/Unsupported Cloud Regions", "capability_group": "CIS-18", "comments": "This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes disables or restricts unused cloud regions and services so adversaries cannot create or operate resources in locations outside the organization's intended monitoring and governance scope. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls18/#183-remediate-penetration-test-findings"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1550.003", "attack_object_name": "Pass the Ticket", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries\u2019 ability to reuse Kerberos tickets for lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1550.002", "attack_object_name": "Pass the Hash", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries\u2019 ability to reuse NTLM hashes for lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1550", "attack_object_name": "Use Alternate Authentication Material", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to enforce least privilege and prevent domain users from holding local-administrator rights across multiple systems can help limit an adversary\u2019s ability to use alternate authentication material for lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1552.007", "attack_object_name": "Container API", "capability_group": "CIS-6", "comments": "Enforce authentication and role-based access control (RBAC) on the container API to restrict users to the least privileges required to help prevent adversaries from gathering credentials via APIs within a containers environment.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1537", "attack_object_name": "Transfer Data to Cloud Account", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit user-account and identity access management (IAM) permissions to the least privileges required can help prevent adversaries from transferring organizational data to cloud accounts they control.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1199", "attack_object_name": "Trusted Relationship", "capability_group": "CIS-6", "comments": "Implement role-based access control (RBAC) to manage accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party or if the party is compromised by an adversary.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1569.003", "attack_object_name": "Systemctl", "capability_group": "CIS-6", "comments": "Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing systemctl to execute commands or programs.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1569.001", "attack_object_name": "Launchctl", "capability_group": "CIS-6", "comments": "Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing launchctl to execute commands or programs.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1047", "attack_object_name": "Windows Management Instrumentation", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to restrict remote WMI access to authorized administrative roles can help prevent adversaries from abusing Windows Management Instrumentation (WMI) to execute malicious commands and payloads.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1195", "attack_object_name": "Supply Chain Compromise", "capability_group": "CIS-6", "comments": "Implement role-based access control (RBAC) to ensure software and development tools run with the lowest necessary privileges to help limit an adversary\u2019s ability to propagate or perform unauthorized actions in the event of a supply chain compromise.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1528", "attack_object_name": "Steal Application Access Token", "capability_group": "CIS-6", "comments": "Enforce role-based access control (RBAC) to limit accounts to the least privileges they require to help prevent adversaries from obtaining or abusing application access tokens. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1489", "attack_object_name": "Service Stop", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit user accounts and groups so that only authorized administrators can interact with service changes and service configurations can help prevent adversaries from stopping or disabling services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1648", "attack_object_name": "Serverless Execution", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create, modify, or run serverless resources only to users that explicitly require them can help prevent adversaries from abusing serverless computing, integration, and automation services to execute arbitrary code in cloud environments.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1505.003", "attack_object_name": "Web Shell", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to upload, create, or modify content in web-server application directories to users with a legitimate need can help prevent adversaries from backdooring web servers with web shells.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1505", "attack_object_name": "Server Software Component", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to add or modify server software components to users with a legitimate need can help prevent adversaries from abusing legitimate extensible development features of servers.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit Remote Desktop Users group membership and Remote Desktop Protocol (RDP) permissions to users with a legitimate need can help prevent adversaries from using RDP for lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1053.006", "attack_object_name": "Systemd Timers", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via system utilities to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1053.003", "attack_object_name": "Cron", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the cron utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1053", "attack_object_name": "Scheduled Task/Job", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks and jobs on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1053.002", "attack_object_name": "At", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the at utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1053.005", "attack_object_name": "Scheduled Task", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1021.004", "attack_object_name": "SSH", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit SSH access and permitted commands to users with a legitimate need can help prevent adversaries from using SSH for lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1053.007", "attack_object_name": "Container Orchestration Job", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via container orchestration tools to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit access to and use of centralized software suites to a limited number of authorized administrators with a verified business need can help prevent adversaries from accessing and abusing software deployment tools.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1021", "attack_object_name": "Remote Services", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit which accounts can use remote services and restrict the commands or resources available to those accounts to help prevent adversaries from using remote services for lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1563.001", "attack_object_name": "SSH Hijacking", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1563.002", "attack_object_name": "RDP Hijacking", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1563", "attack_object_name": "Remote Service Session Hijacking", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1677", "attack_object_name": "Poisoned Pipeline Execution", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit write access to internal repositories and CI/CD pipeline permissions to users and services with a legitimate need can help prevent adversaries from modifying pipelines to execute malicious code.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1566.003", "attack_object_name": "Spearphishing via Service", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit third-party messaging and collaboration-service account privileges to users with a legitimate need can help prevent adversaries from abusing compromised service accounts for spearphishing.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1566.002", "attack_object_name": "Spearphishing Link", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to apply limitations on which roles can grant consent to third-party applications can help prevent users from granting consent to unfamiliar or unverified third-party applications through spearphishing links.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1566.001", "attack_object_name": "Spearphishing Attachment", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit file-opening and execution permissions to only the accounts that require them can help reduce the impact of malicious email attachments by preventing unauthorized execution or spread of malware.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-6", "comments": "In cloud environments, using role-based access control (RBAC) to ensure that users are not granted permissions to create or modify traffic mirrors unless explicitly required can help prevent adversaries from capturing network traffic.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1666", "attack_object_name": "Modify Cloud Resource Hierarchy", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to add, delete, or modify cloud resource groups and hierarchy structures to authorized roles can help prevent adversaries from evading organizational guardrails and cloud security policies.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1578.005", "attack_object_name": "Modify Cloud Compute Configurations", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to modify cloud compute settings, quotas, and tenant-level configurations to authorized roles can help prevent adversaries from altering infrastructure resources or bypassing restrictions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1578.003", "attack_object_name": "Delete Cloud Instance", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to delete cloud instances to authorized roles can help prevent adversaries from removing instances to destroy evidence of malicious activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1578.002", "attack_object_name": "Create Cloud Instance", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create cloud instances to authorized roles can help prevent adversaries from deploying new instances to evade defenses or conduct unauthorized activity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1578.001", "attack_object_name": "Create Snapshot", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create cloud snapshots and backups to authorized roles can help prevent adversaries from creating copies of cloud resources for unauthorized access or data collection.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1578", "attack_object_name": "Modify Cloud Compute Infrastructure", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to create, delete, and modify cloud compute infrastructure to authorized roles can help prevent adversaries from altering cloud resources to evade defenses or gain unauthorized access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1021.008", "attack_object_name": "Direct Cloud VM Connections", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit direct cloud-native VM connection permissions to users with a legitimate need can help prevent adversaries from accessing cloud compute infrastructure for lateral movement.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1556.006", "attack_object_name": "Multi-Factor Authentication", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to enroll, disable, or modify multi-factor authentication (MFA) methods and policies to authorized administrative roles can help prevent adversaries from weakening MFA protections on compromised accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1556", "attack_object_name": "Modify Authentication Process", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to modify authentication processes and identity-provider settings to authorized administrative roles can help prevent adversaries from altering authentication controls to gain unauthorized access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1654", "attack_object_name": "Log Enumeration", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to access and export sensitive system and service logs to privileged roles can help prevent adversaries from enumerating logs for valuable information.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1490", "attack_object_name": "Inhibit System Recovery", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to backups to only required users with a legitimate need can help prevent adversaries from deleting or removing built-in data and turning off services designed to aid in the recovery of a corrupted system.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1574.012", "attack_object_name": "COR_PROFILER", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to modify COR_PROFILER environment variables and related .NET configuration settings to users with a legitimate need can help prevent adversaries from loading malicious DLLs into .NET processes.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1574.010", "attack_object_name": "Services File Permissions Weakness", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to modify service executables and their file paths to users with a legitimate need can help prevent adversaries from replacing service binaries with malicious payloads.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1574.005", "attack_object_name": "Executable Installer File Permissions Weakness", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to modify installer executables and their file paths to users with a legitimate need can help prevent adversaries from replacing installer binaries with malicious payloads.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1574", "attack_object_name": "Hijack Execution Flow", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to modify service configurations, registry settings, and protected file paths to users with a legitimate need can help prevent adversaries from hijacking execution flow.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1530", "attack_object_name": "Data from Cloud Storage", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage to only users with a legitimate need can help prevent adversaries from accessing and collecting data from cloud storage solutions.\r\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1606", "attack_object_name": "Forge Web Credentials", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge credential materials.\r\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1657", "attack_object_name": "Financial Theft", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit sensitive financial transactions and approval privileges to narrowly scoped roles can mitigate use of a compromised account to initiate or authorize unauthorized payments.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1556.009", "attack_object_name": "Conditional Access Policies", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit permissions to modify conditional access policies to authorized administrative roles can help prevent adversaries from removing multi-factor authentication (MFA) requirements or adding exclusions that enable persistent access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1606.002", "attack_object_name": "SAML Tokens", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge SAML tokens.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage systems and objects to only users with a legitimate need can help prevent adversaries from exfiltrating data from cloud storage.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1484.001", "attack_object_name": "Group Policy Modification", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can be used to limit which users and computers can access Group Policy Objects (GPOs), helping to prevent adversaries from modifying GPOs.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1484", "attack_object_name": "Domain or Tenant Policy Modification", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can be used to limit which users and computers can access domain and identity tenant settings, helping to prevent adversaries from modifying their configuration settings.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1610", "attack_object_name": "Deploy Container", "capability_group": "CIS-6", "comments": "Enforcing role-based access control (RBAC) to limit container dashboard access to only necessary users can prevent adversaries from deploying a container into an environment.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1213.006", "attack_object_name": "Databases", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit database access to only authorized users helps prevent adversaries from leveraging these databases to mine valuable information.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1213.001", "attack_object_name": "Confluence", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit Confluence repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1484.002", "attack_object_name": "Trust Modification", "capability_group": "CIS-6", "comments": "In cloud environments, role-based access control (RBAC) can be used to limit permissions to create new identity providers to only those accounts that require them. This can prevent adversaries from adding new domain trusts, modifying the properties of existing domain trusts, or otherwise changing the configuration of trust relationships between domains and tenants.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1213.004", "attack_object_name": "Customer Relationship Management Software", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit Customer Relationship Management (CRM) software access to only authorized users helps prevent adversaries from leveraging CRM software to mine valuable information.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1213.003", "attack_object_name": "Code Repositories", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit code repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1213", "attack_object_name": "Data from Information Repositories", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit information repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1543", "attack_object_name": "Create or Modify System Process", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with system-level process changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1485.001", "attack_object_name": "Lifecycle-Triggered Deletion", "capability_group": "CIS-6", "comments": "In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying all objects stored within buckets.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1485", "attack_object_name": "Data Destruction", "capability_group": "CIS-6", "comments": "In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying data and files.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1543.005", "attack_object_name": "Container Service", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit user access to utilities such as docker to only users with a legitimate need helps prevent adversaries from creating or modifying container or cluster management tools to establish persistence or escalate privileges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1543.004", "attack_object_name": "Launch Daemon", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to ensure only authorized administrator roles can create new Launch Daemons helps prevent adversaries from creating or modifying Launch Daemons to establish persistence or escalate privileges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1543.003", "attack_object_name": "Windows Service", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with service changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1543.002", "attack_object_name": "Systemd Service", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit user access to system utilities to only users with a legitimate need helps prevent adversaries from creating or modifying systemd services to establish persistence or escalate privileges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1213.002", "attack_object_name": "Sharepoint", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to limit SharePoint repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1134.002", "attack_object_name": "Create Process with Token", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create new processes with tokens and limiting privileges to a small set of tightly controlled roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1609", "attack_object_name": "Container Administration Command", "capability_group": "CIS-6", "comments": "Enforcing authentication and role-based access control (RBAC) on the container administration service to restrict users to the least privileges required can help prevent adversaries from abusing the service to execute commands within the container.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1059.008", "attack_object_name": "Network Device CLI", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) helps mitigate this technique by enforcing least privilege and command authorization on network device CLI access, limiting which roles can run perform authorization changes.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1619", "attack_object_name": "Cloud Storage Object Discovery", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate discovery of cloud storage objects by limiting cloud storage list permissions to narrowly scoped roles, reducing who can enumerate storage objects for discovery.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1580", "attack_object_name": "Cloud Infrastructure Discovery", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate discovery of cloud infrastructure and resources by limiting which roles can access, manage, or query cloud infrastructure metadata and enforcing who can see and do what in cloud service dashboards.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1185", "attack_object_name": "Browser Session Hijacking", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate browser session hijacking techniques by enforcing least privilege so that hijacked browser sessions are associated with minimally scoped roles, limiting what an adversary can do with a captured session.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1547.012", "attack_object_name": "Print Processors", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or unload device drivers by disabling SeLoadDriverPrivilege.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1613", "attack_object_name": "Container and Resource Discovery", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate this technique by tightly controlling which roles can view or query container APIs and dashboards and restricting discovery of cluster resources to narrowly scoped roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1547.009", "attack_object_name": "Shortcut Modification", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate this technique by limiting shortcut creation and modification to narrowly scoped roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1547.006", "attack_object_name": "Kernel Modules and Extensions", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or configure kernel modules and extensions to tightly controlled admin roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1547.004", "attack_object_name": "Winlogon Helper DLL", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate this technique by restricting Winlogon configuration changes to a small set of tightly controlled admin roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1547.013", "attack_object_name": "XDG Autostart Entries", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate this technique by limiting which roles can can create and modify XDG autostart entries to narrowly scoped privileged roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1098.004", "attack_object_name": "SSH Authorized Keys", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles in cloud environments are allowed to modify SSH authorized_keys files and ensuring that only users who explicitly require the permissions to update instance metadata or configurations can do so.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1197", "attack_object_name": "BITS Jobs", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate abuse of BITS jobs by limiting access to the BITS interface to specific user roles or groups. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1098.003", "attack_object_name": "Additional Cloud Roles", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add permissions to accounts or update IAM policies.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1098.001", "attack_object_name": "Additional Cloud Credentials", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add access keys to accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1098", "attack_object_name": "Account Manipulation", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to modify accounts or account-related policies.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1087.004", "attack_object_name": "Cloud Account", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1087", "attack_object_name": "Account Discovery", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1098.006", "attack_object_name": "Additional Container Cluster Roles", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to add additional roles or permissions and ensuring that low-privileged accounts do not have permissions to add permissions to accounts or to update container cluster roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1546.003", "attack_object_name": "Windows Management Instrumentation Event Subscription", "capability_group": "CIS-6", "comments": "Using role-based access control (RBAC) to restrict or disallow user groups allowed to connect to WMI can help prevent adversaries from maliciously using WMI event subscription capabilities.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1134.001", "attack_object_name": "Token Impersonation/Theft", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or impersonate tokens and limiting privileges to a small set of tightly controlled roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1134", "attack_object_name": "Access Token Manipulation", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or modify tokens and limiting privileges to a small set of tightly controlled roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1548.005", "attack_object_name": "Temporary Elevated Cloud Access", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1548", "attack_object_name": "Abuse Elevation Control Mechanism", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-6.8", "capability_description": "Define and Maintain Role-Based Access Control", "mapping_type": "mitigates", "attack_object_id": "T1134.003", "attack_object_name": "Make and Impersonate Token", "capability_group": "CIS-6", "comments": "Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create and impersonate tokens and limiting privileges to a small set of tightly controlled roles.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#68-define-and-maintain-role-based-access-control"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1003", "attack_object_name": "OS Credential Dumping", "capability_group": "CIS-3", "comments": "Encrypting sensitive data at rest prevents dumping credentials from OS caches, memory, or credential structures to obtain hashes or plaintext passwords on domain controller backups. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/#311-encrypt-sensitive-data-at-rest"]}, {"capability_id": "CIS-10.7", "capability_description": "Use Behavior-Based Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1059", "attack_object_name": "Command and Scripting Interpreter", "capability_group": "CIS-10", "comments": "Behavioral anti-malware commonly monitors scripting engines and detects malicious script execution through behavioral indicators rather than signatures.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.7", "capability_description": "Use Behavior-Based Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1059.006", "attack_object_name": "Python", "capability_group": "CIS-10", "comments": "Products that explicitly monitor Python process behavior, command execution, child processes, and resulting system changes can detect or block malicious Python activity. Generic behavioral monitoring alone is insufficient.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.1", "capability_description": "Deploy and Maintain Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1055", "attack_object_name": "Process Injection", "capability_group": "CIS-10", "comments": "Some anti-malware products monitor cross-process memory writes, remote-thread creation, process hollowing, and similar injection behavior. Where these protections are enabled, the safeguard directly detects or blocks process injection.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.1", "capability_description": "Deploy and Maintain Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1547.006", "attack_object_name": "Kernel Modules and Extensions", "capability_group": "CIS-10", "comments": "Anti-malware products may detect malicious kernel drivers or unsigned modules during installation or loading. However, preventing unauthorized kernel module loading relies more heavily on platform integrity and driver enforcement controls (anti-malware product monitors and blocks malicious kernel modules, drivers, or extensions) than standard anti-malware alone.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-5.5", "capability_description": "Establish and Maintain an Inventory of Service Accounts", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-5", "references": []}, {"capability_id": "CIS-5.1", "capability_description": "Establish and Maintain an Inventory of Accounts", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-5", "references": []}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1068", "attack_object_name": "Exploitation for Privilege Escalation", "capability_group": "CIS-7", "comments": "Remediating known vulnerabilities in kernels, drivers, services, and privileged applications directly removes exploit paths that adversaries could use to obtain elevated privileges. This does not prevent exploitation of unknown vulnerabilities or weaknesses that remain outside the remediation scope.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1189", "attack_object_name": "Drive-by Compromise", "capability_group": "CIS-7", "comments": "Remediating detected vulnerabilities in browsers, plug-ins, and other client software reduces successful exploitation when users visit malicious or compromised websites. This does not prevent drive-by activity that relies on zero-day vulnerabilities, social engineering, or malicious content that does not require exploitation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-7", "comments": "Correcting identified vulnerabilities in internet-facing applications, services, and appliances directly removes known initial-access paths. Remediation may include patching, upgrading, replacing, disabling, or isolating the vulnerable component.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1203", "attack_object_name": "Exploitation for Client Execution", "capability_group": "CIS-7", "comments": "Remediating known vulnerabilities in browsers, Office products, PDF readers, and other client applications reduces successful exploit-based code execution. This does not prevent exploitation of unknown vulnerabilities or unremediated unsupported software.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-7", "comments": "Patching or otherwise correcting vulnerabilities in remotely reachable services removes known lateral-movement and remote-execution paths. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1211", "attack_object_name": "Exploitation for Stealth", "capability_group": "CIS-7", "comments": "Remediation can remove vulnerabilities in operating systems, applications, security tools, and logging components that adversaries could exploit to conceal activity or impair visibility. This relationship applies only when the stealth behavior depends on an identified vulnerability.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1212", "attack_object_name": "Exploitation for Credential Access", "capability_group": "CIS-7", "comments": "Correcting vulnerabilities in authentication systems, credential-handling software, kernels, and related components prevents exploit-based access to credentials. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1611", "attack_object_name": "Escape to Host", "capability_group": "CIS-7", "comments": "Remediating vulnerabilities in host kernels, hypervisors, and container runtimes reduces successful container or virtual-machine escape. This does not prevent escapes caused solely by unsafe configuration, privileged containers, or exposed management sockets.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1495", "attack_object_name": "Firmware Corruption", "capability_group": "CIS-7", "comments": "Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1542", "attack_object_name": "Pre-OS Boot", "capability_group": "CIS-7", "comments": "This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1542.001", "attack_object_name": "System Firmware", "capability_group": "CIS-7", "comments": "Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1542.002", "attack_object_name": "Component Firmware", "capability_group": "CIS-7", "comments": "Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1548", "attack_object_name": "Abuse Elevation Control Mechanism", "capability_group": "CIS-7", "comments": "This is a partial parent mapping because remediation can remove known vulnerabilities and implementation weaknesses used to bypass elevation controls. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1548.002", "attack_object_name": "Bypass User Account Control", "capability_group": "CIS-7", "comments": "Applying current Windows security updates and supported platform upgrades removes known UAC-bypass and auto-elevation weaknesses. This does not prevent every UAC bypass or activity performed by an account that already has administrative privileges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1546", "attack_object_name": "Event Triggered Execution", "capability_group": "CIS-7", "comments": "Remediation can remove specific vulnerable event-triggered execution mechanisms, including known AppInit DLL and Application Shimming behaviors. Most event-triggered persistence also depends on configuration and permissions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1546.010", "attack_object_name": "AppInit DLLs", "capability_group": "CIS-7", "comments": "Upgrading or patching affected Windows platforms removes older AppInit DLL behaviors and weaknesses that adversaries could abuse for persistence or execution. Configuration controls remain necessary where the feature is still supported.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1546.011", "attack_object_name": "Application Shimming", "capability_group": "CIS-7", "comments": "Applying the relevant Windows security updates removes known auto-elevation behavior associated with application-shim installation. Remediation does not prevent all shim abuse by an adversary that already has sufficient privileges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1552", "attack_object_name": "Unsecured Credentials", "capability_group": "CIS-7", "comments": "Remediation can correct specific software weaknesses that store credentials insecurely, including the Group Policy Preferences implementation. Most unsecured credential exposures require separate configuration, access-control, or secret-management controls.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1552.006", "attack_object_name": "Group Policy Preferences", "capability_group": "CIS-7", "comments": "Applying the applicable Microsoft security update prevents newly configured Group Policy Preferences from storing credentials in a recoverable form. Previously stored credentials may still require separate identification, removal, and rotation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1550.002", "attack_object_name": "Pass the Hash", "capability_group": "CIS-7", "comments": "Applying relevant Windows security updates can restrict default remote access available to local administrator accounts and reduce some pass-the-hash activity. Remediation does not eliminate hash theft, NTLM use, or pass-the-hash through accounts that retain applicable privileges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1574", "attack_object_name": "Hijack Execution Flow", "capability_group": "CIS-7", "comments": "Remediation can correct vulnerable library-loading behavior and unsafe execution paths in affected software. Many other execution-flow hijacking methods depend on writable paths, permissions, or configuration rather than a software vulnerability.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1574.001", "attack_object_name": "DLL", "capability_group": "CIS-7", "comments": "Vendor patches can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. This does not prevent DLL hijacking in unsupported software.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-7", "comments": "Remediating vulnerabilities in centralized software-deployment and endpoint-management products prevents exploit-based privileged access and enterprise-wide remote execution. This does not prevent abuse through stolen administrator credentials or legitimate product functionality.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1137", "attack_object_name": "Office Application Startup", "capability_group": "CIS-7", "comments": "This is a partial parent mapping because product remediation can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup methods may require configuration and application-control safeguards.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1137.003", "attack_object_name": "Outlook Forms", "capability_group": "CIS-7", "comments": "Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. Unsupported or unpatched Outlook installations remain exposed.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1137.004", "attack_object_name": "Outlook Home Page", "capability_group": "CIS-7", "comments": "Applying the relevant Outlook updates removes or restricts the legacy Home Page functionality used to load malicious content when a folder is accessed.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1137.005", "attack_object_name": "Outlook Rules", "capability_group": "CIS-7", "comments": "Applying current Outlook updates reduces abuse of rule-triggered execution mechanisms. This does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1555", "attack_object_name": "Credentials from Password Stores", "capability_group": "CIS-7", "comments": "Remediation can correct vulnerabilities in browsers, password managers, and other credential-storage applications. It does not address every operating-system, application, or cloud credential store.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1555.003", "attack_object_name": "Credentials from Web Browsers", "capability_group": "CIS-7", "comments": "Correcting identified browser vulnerabilities reduces exploit-based extraction of stored passwords, tokens, and other authentication data. This does not prevent theft by malware that already has sufficient access to the browser profile.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1555.005", "attack_object_name": "Password Managers", "capability_group": "CIS-7", "comments": "Updating, upgrading, or replacing a vulnerable password-manager product removes known credential-exposure vulnerabilities. This does not prevent theft through a compromised master password, an unlocked vault, or an authorized session.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1539", "attack_object_name": "Steal Web Session Cookie", "capability_group": "CIS-7", "comments": "Remediating vulnerabilities in browsers and related applications reduces exploit-based extraction of session cookies. This does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.7", "capability_description": "Remediate Detected Vulnerabilities", "mapping_type": "mitigates", "attack_object_id": "T1686.002", "attack_object_name": "Network Device Firewall", "capability_group": "CIS-7", "comments": "Applying security patches or supported software upgrades to vulnerable firewall appliances and network-device operating environments reduces exploit-based modification or disabling of firewall policy. This does not prevent changes made with valid administrative access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1189", "attack_object_name": "Drive-by Compromise", "capability_group": "CIS-7", "comments": "Automated application patching keeps browsers and browser plug-ins current, removing known vulnerabilities that malicious or compromised websites could exploit for client execution. The safeguard does not prevent drive-by attacks relying on zero-day vulnerabilities, social engineering, or malicious browser notifications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-7", "comments": "Automated application patching removes known vulnerabilities from externally exposed web applications, databases, VPN products, management platforms, and other application services. It does not correct insecure configurations, unsupported custom code, or vulnerabilities for which no vendor patch exists.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1203", "attack_object_name": "Exploitation for Client Execution", "capability_group": "CIS-7", "comments": "Applying current security updates to browsers, Office products, PDF readers, and other client applications reduces successful exploitation of known application vulnerabilities. Operating-system vulnerabilities and unknown application vulnerabilities require separate protections.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-7", "comments": "Patching centralized deployment and endpoint-management applications removes known vulnerabilities that could provide adversaries with privileged access or enterprise-wide remote execution. The safeguard does not prevent abuse through stolen administrator credentials or legitimate product functionality.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1137.003", "attack_object_name": "Outlook Forms", "capability_group": "CIS-7", "comments": "Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. The safeguard does not prevent all malicious Office content or abuse of an unpatched or unsupported Outlook installation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1137.004", "attack_object_name": "Outlook Home Page", "capability_group": "CIS-7", "comments": "Outlook application updates remove or restrict the legacy Home Page feature used to load malicious content when a folder is accessed. The relationship depends on deploying the relevant Outlook security updates.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1137.005", "attack_object_name": "Outlook Rules", "capability_group": "CIS-7", "comments": "Applying current Outlook patches reduces abuse of rule-triggered Visual Basic and related persistence mechanisms. It does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1555.003", "attack_object_name": "Credentials from Web Browsers", "capability_group": "CIS-7", "comments": "Automated browser updates remove known vulnerabilities that could expose stored passwords, tokens, or browser authentication data. Patching does not prevent credential theft by malware already executing with sufficient access to the browser profile.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1555.005", "attack_object_name": "Password Managers", "capability_group": "CIS-7", "comments": "Automated updates to password-manager applications remove known vulnerabilities that could expose stored or decrypted credentials. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1574.001", "attack_object_name": "DLL", "capability_group": "CIS-7", "comments": "Applying vendor patches to vulnerable applications can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. It does not prevent DLL hijacking in unpatched software or through writable application directories.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1068", "attack_object_name": "Exploitation for Privilege Escalation", "capability_group": "CIS-7", "comments": "Application patching removes known vulnerabilities in privileged applications, agents, services, and third-party drivers that could allow escalation of privileges. Operating-system and kernel vulnerabilities are addressed separately through operating-system patch management.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-7", "comments": "Application patching removes known vulnerabilities from third-party database, web, virtualization, file-transfer, remote-management, and similar services used for lateral movement. Vulnerabilities in operating-system-supplied remote services require operating-system patching.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1211", "attack_object_name": "Exploitation for Stealth", "capability_group": "CIS-7", "comments": "Updating applications and security products can remove known vulnerabilities that adversaries could exploit to conceal activity or impair application-level visibility. Operating-system and kernel implementations are outside this safeguard's application scope.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1212", "attack_object_name": "Exploitation for Credential Access", "capability_group": "CIS-7", "comments": "Application patching removes known vulnerabilities in authentication products, browsers, identity applications, network-management products, and other credential-handling software. Vulnerabilities in operating-system authentication components require operating-system patching.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1137", "attack_object_name": "Office Application Startup", "capability_group": "CIS-7", "comments": "Application patches can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup mechanisms that rely on macros, add-ins, templates, or configuration changes are not necessarily prevented by patching.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1555", "attack_object_name": "Credentials from Password Stores", "capability_group": "CIS-7", "comments": "Application patching can remove browser and password-manager vulnerabilities used to extract stored credentials. Operating-system credential stores and cloud secrets platforms may require different update mechanisms.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management", "https://attack.mitre.org/techniques/T1555/"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1574", "attack_object_name": "Hijack Execution Flow", "capability_group": "CIS-7", "comments": "Application updates can correct unsafe DLL search paths and other software defects that permit DLL side-loading. Most other execution-flow hijacking implementations require permissions, application control, or operating-system configuration protections.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1176", "attack_object_name": "Software Extensions", "capability_group": "CIS-7", "comments": "Updating browsers and IDEs can remove insecure extension mechanisms, but it does not prevent a user or adversary from installing an otherwise permitted malicious extension.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1176.001", "attack_object_name": "Browser Extensions", "capability_group": "CIS-7", "comments": "Automated browser updates can remove deprecated extension-loading mechanisms and strengthen extension permission and installation controls. Extension allowlisting and trusted-source restrictions remain necessary to prevent malicious extensions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1176.002", "attack_object_name": "IDE Extensions", "capability_group": "CIS-7", "comments": "Updating IDE applications can correct vulnerabilities in extension loading and provide improved extension security controls. The safeguard does not independently prevent installation of a malicious or compromised extension from an approved marketplace.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.4", "capability_description": "Perform Automated Application Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1539", "attack_object_name": "Steal Web Session Cookie", "capability_group": "CIS-7", "comments": "Updating browsers, password managers, and related applications reduces exploitation of known vulnerabilities used to extract session cookies. It does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#74-perform-automated-application-patch-management"]}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1495", "attack_object_name": "Firmware Corruption", "capability_group": "CIS-7", "comments": "Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1542", "attack_object_name": "Pre-OS Boot", "capability_group": "CIS-7", "comments": "This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1542.001", "attack_object_name": "System Firmware", "capability_group": "CIS-7", "comments": "Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1542.002", "attack_object_name": "Component Firmware", "capability_group": "CIS-7", "comments": "Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls7/#77-remediate-detected-vulnerabilities"]}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1176.002", "attack_object_name": "IDE Extensions", "capability_group": "CIS-7", "comments": "ATT&CK mentions ensuring operating systems and software are using the most current version.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1176.001", "attack_object_name": "Browser Extensions", "capability_group": "CIS-7", "comments": "ATT&CK mentions ensuring operating systems and software are using the most current version.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1176", "attack_object_name": "Software Extensions", "capability_group": "CIS-7", "comments": "ATT&CK mentions ensuring operating systems and software are using the most current version.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-7", "comments": "ATT&CK mentions having a patch deployment systems regularly to prevent potential remote access through Exploitation for Privilege Escalation.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1195.002", "attack_object_name": "Compromise Software Supply Chain", "capability_group": "CIS-7", "comments": "ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1195.001", "attack_object_name": "Compromise Software Dependencies and Development Tools", "capability_group": "CIS-7", "comments": "ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1195", "attack_object_name": "Supply Chain Compromise", "capability_group": "CIS-7", "comments": "ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1546", "attack_object_name": "Event Triggered Execution", "capability_group": "CIS-7", "comments": "OS patches that address specific Windows event-triggered execution mechanisms, particularly Application Shimming.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1552", "attack_object_name": "Unsecured Credentials", "capability_group": "CIS-7", "comments": "ATT&CK specifically recommends applying patch KB2962486 which prevents credentials from being stored in GPPs. ", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1686.002", "attack_object_name": "Network Device Firewall", "capability_group": "CIS-7", "comments": "ATT&CK specifically recommends maintaining network firewalls with current security patches. Include this where network firewall appliances and their operating systems are considered enterprise assets covered by the automated an OS-patching process.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1548", "attack_object_name": "Abuse Elevation Control Mechanism", "capability_group": "CIS-7", "comments": "OS updates can close vulnerabilities and implementation weaknesses used to bypass native elevation mechanisms, especially UAC, but they do not prevent abuse of sudo permissions, temporary cloud elevation, or other correctly functioning mechanisms.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1211", "attack_object_name": "Exploitation for Stealth", "capability_group": "CIS-7", "comments": "OS updates can correct vulnerabilities in kernels, logging components, security tools, and system services that could be exploited to conceal activity. Application-specific exploitation remains outside 7.3.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-7", "comments": "OS patching directly addresses vulnerabilities in operating-system services such as SMB, RDP, RPC, SSH components, and other built-in remote services. The technique also includes independently installed applications that would fall under application patch management instead.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1550.002", "attack_object_name": "Pass the Hash", "capability_group": "CIS-7", "comments": "ATT&CK identifies Windows 7 and higher system patch KB2871997 as limiting default access available to local administrator accounts, reducing some pass-the-hash lateral movement.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1552.006", "attack_object_name": "Group Policy Preferences", "capability_group": "CIS-7", "comments": "ATT&CK identifies Windows patch KB2962486, which prevents credentials from being stored in Group Policy Preferences. This is a direct OS-patch implementation.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1546.011", "attack_object_name": "Application Shimming", "capability_group": "CIS-7", "comments": "ATT&CK identifies a specific Windows patch, KB3045645, that removes an auto-elevation behavior used to abuse application shims. Automated OS patch deployment directly applies this type of mitigation.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1548.002", "attack_object_name": "Bypass User Account Control", "capability_group": "CIS-7", "comments": "Windows updates include changes that close known UAC-bypass methods and improve elevation protections. ATT&CK directly recommends maintaining the latest Windows version and patch level.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1611", "attack_object_name": "Escape to Host", "capability_group": "CIS-7", "comments": "Container and VM escapes may exploit vulnerabilities in the host kernel, hypervisor, or operating-system components. ATT&CK explicitly recommends keeping hosts current with security patches.", "references": []}, {"capability_id": "CIS-7.3", "capability_description": "Perform Automated Operating System Patch Management", "mapping_type": "mitigates", "attack_object_id": "T1068", "attack_object_name": "Exploitation for Privilege Escalation", "capability_group": "CIS-7", "comments": "OS and kernel vulnerabilities are a primary means of escalating from user privileges to SYSTEM or root. Automated OS patching directly removes known vulnerable code paths. ATT&CK specifically recommends patch management for internal endpoints and servers.", "references": []}, {"capability_id": "CIS-10.7", "capability_description": "Use Behavior-Based Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1204.002", "attack_object_name": "Malicious File", "capability_group": "CIS-10", "comments": "When a user executes a malicious file, behavior-based anti-malware can identify suspicious runtime activity and terminate or contain the process. This directly reduces the effectiveness of the malicious file after execution begins.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.7", "capability_description": "Use Behavior-Based Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1055", "attack_object_name": "Process Injection", "capability_group": "CIS-10", "comments": "Process injection produces observable behaviors such as cross-process memory writes, remote-thread creation, process hollowing, and abnormal memory execution. Behavior-based anti-malware can directly detect or block these actions.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.7", "capability_description": "Use Behavior-Based Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1547.006", "attack_object_name": "Kernel Modules and Extensions", "capability_group": "CIS-10", "comments": "Behavior-based products may monitor driver installation, kernel module loading, and suspicious kernel-level changes. Where these events are blocked or detected, the safeguard directly addresses malicious kernel persistence.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.7", "capability_description": "Use Behavior-Based Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1027.002", "attack_object_name": "Software Packing", "capability_group": "CIS-10", "comments": "Behavior-based anti-malware can identify packed malware after it unpacks in memory or begins performing malicious actions. This reduces the effectiveness of packing as a method for evading static detection.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.7", "capability_description": "Use Behavior-Based Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1059.005", "attack_object_name": "Visual Basic", "capability_group": "CIS-10", "comments": "Behavior-based anti-malware can identify suspicious Visual Basic and macro execution chains, such as an Office application spawning interpreters, downloading payloads, or modifying system settings.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.7", "capability_description": "Use Behavior-Based Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1059.001", "attack_object_name": "PowerShell", "capability_group": "CIS-10", "comments": "Behavior-based anti-malware can analyze PowerShell process ancestry, commands, script content, memory activity, and resulting system changes. This enables direct detection or blocking of malicious PowerShell execution.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.5", "capability_description": "Enable Anti-Exploitation Features", "mapping_type": "mitigates", "attack_object_id": "T1687", "attack_object_name": "Exploitation for Defense Impairment", "capability_group": "CIS-10", "comments": "Adversaries may exploit anti-malware, EDR, logging, or other defensive components to disable or impair them. Anti-exploitation controls protecting those components directly restrict this behavior.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.5", "capability_description": "Enable Anti-Exploitation Features", "mapping_type": "mitigates", "attack_object_id": "T1212", "attack_object_name": "Exploitation for Credential Access", "capability_group": "CIS-10", "comments": "Adversaries may exploit authentication, kernel, or security processes to access credentials. Anti-exploitation protections that cover the targeted component directly reduce the likelihood that the exploit succeeds.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.5", "capability_description": "Enable Anti-Exploitation Features", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-10", "comments": "Remote-service exploitation targets vulnerabilities in network-accessible services or protocol handlers. Anti-exploitation protections applied to the targeted service can block the exploit or prevent successful payload execution.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.5", "capability_description": "Enable Anti-Exploitation Features", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-10", "comments": "Public-facing services frequently become initial access vectors through software vulnerabilities. Exploit mitigation technologies increase resistance to successful exploitation by preventing or disrupting exploit execution.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.5", "capability_description": "Enable Anti-Exploitation Features", "mapping_type": "mitigates", "attack_object_id": "T1189", "attack_object_name": "Drive-by Compromise", "capability_group": "CIS-10", "comments": "Drive-by attacks commonly rely on browser or plugin exploitation. DEP, ASLR, CFG, and exploit guards are intended to prevent exploitation of these vulnerabilities before malicious code executes.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.5", "capability_description": "Enable Anti-Exploitation Features", "mapping_type": "mitigates", "attack_object_id": "T1068", "attack_object_name": "Exploitation for Privilege Escalation", "capability_group": "CIS-10", "comments": "Kernel, memory, driver, and control-flow protections can prevent exploitation of vulnerable components used to obtain elevated privileges. This is a direct technical restriction on privilege-escalation exploits.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.5", "capability_description": "Enable Anti-Exploitation Features", "mapping_type": "mitigates", "attack_object_id": "T1203", "attack_object_name": "Exploitation for Client Execution", "capability_group": "CIS-10", "comments": "Data execution prevention, control-flow protections, exploit guards, and similar mechanisms interfere directly with memory corruption and code execution in client applications. These features reduce the ability of an exploit to execute its payload.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.4", "capability_description": "Configure Automatic Anti-Malware Scanning of Removable Media", "mapping_type": "mitigates", "attack_object_id": "T1204.002", "attack_object_name": "Malicious File", "capability_group": "CIS-10", "comments": "Automatic scanning can detect and quarantine a malicious file on removable media before a user opens or executes it. This creates a direct preventive relationship when blocking or quarantine is enforced.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.4", "capability_description": "Configure Automatic Anti-Malware Scanning of Removable Media", "mapping_type": "mitigates", "attack_object_id": "T1091", "attack_object_name": "Replication Through Removable Media", "capability_group": "CIS-10", "comments": "Malware commonly uses removable media to move between systems. Automatic scanning can identify and quarantine malicious files when the media is connected, directly reducing the effectiveness of removable-media propagation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.3", "capability_description": "Disable Autorun and Autoplay for Removable Media", "mapping_type": "mitigates", "attack_object_id": "T1091", "attack_object_name": "Replication Through Removable Media", "capability_group": "CIS-10", "comments": "Many removable-media malware families rely on Autorun/Autoplay to automatically execute malicious code after an infected USB device is inserted. Disabling these operating system features directly interrupts the automatic execution mechanism used to propagate malware through removable media, forcing an attacker to rely on manual execution or another execution vector.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.1", "capability_description": "Deploy and Maintain Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1204.002", "attack_object_name": "Malicious File", "capability_group": "CIS-10", "comments": "Anti-malware can scan a file when it is opened or executed and quarantine or block the file before the malicious payload runs. This directly reduces the effectiveness of malicious files that depend on user execution.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.1", "capability_description": "Deploy and Maintain Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1027.002", "attack_object_name": "Software Packing", "capability_group": "CIS-10", "comments": "Packed executables are a common malware delivery method. Modern anti-malware engines unpack or emulate packed binaries during scanning, making this a direct technical capability of the safeguard.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.1", "capability_description": "Deploy and Maintain Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1059.005", "attack_object_name": "Visual Basic", "capability_group": "CIS-10", "comments": "Malicious VBScript is routinely inspected by anti-malware through script scanning and behavioral analysis prior to execution.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-10.1", "capability_description": "Deploy and Maintain Anti-Malware Software", "mapping_type": "mitigates", "attack_object_id": "T1059.001", "attack_object_name": "PowerShell", "capability_group": "CIS-10", "comments": "Anti-malware integrates with PowerShell logging and AMSI to inspect scripts and commands before execution, making PowerShell malware a primary detection target.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls10/"]}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1110", "attack_object_name": "Brute Force", "capability_group": "CIS-5", "comments": "Unique passwords and minimum password lengths, which directly reduce the effectiveness of brute-force attacks by increasing the number of possible password combinations and limiting the reuse of compromised credentials across systems. This makes online password guessing and offline password cracking more difficult and reduces the success of credential-stuffing attacks.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1110.001", "attack_object_name": "Password Guessing", "capability_group": "CIS-5", "comments": "Enforced minimum password length increases the search space and reduces the effectiveness of password guessing.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1110.002", "attack_object_name": "Password Cracking", "capability_group": "CIS-5", "comments": "Longer passwords materially increase the effort required to recover plaintext passwords from captured hashes or related material.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1110.003", "attack_object_name": "Password Spraying", "capability_group": "CIS-5", "comments": "Unique, non-common passwords reduce success of spraying common passwords across many accounts.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1078.001", "attack_object_name": "Default Accounts", "capability_group": "CIS-5", "comments": "Unique passwords reduce adversary use of default or vendor-provided account credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1078.002", "attack_object_name": "Domain Accounts", "capability_group": "CIS-5", "comments": "Domain accounts can span users, admins, and services; unique passwords reduce domain credential reuse and lateral reuse risk.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1078.003", "attack_object_name": "Local Accounts", "capability_group": "CIS-5", "comments": "Unique local passwords reduce reuse of one compromised local account credential across multiple endpoints or servers.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-5", "comments": "Unique passwords reduce credential reuse across systems and accounts, limiting adversary use of one compromised password to pivot through valid accounts.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.3", "capability_description": "Disable Dormant Accounts", "mapping_type": "mitigates", "attack_object_id": "T1110.004", "attack_object_name": "Credential Stuffing", "capability_group": "CIS-5", "comments": "Disabling dormant accounts removes stale accounts that may still have breached or reused credentials, reducing credential-stuffing success against abandoned identities.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.3", "capability_description": "Disable Dormant Accounts", "mapping_type": "mitigates", "attack_object_id": "T1078.004", "attack_object_name": "Cloud Accounts", "capability_group": "CIS-5", "comments": "Disabling inactive cloud/SaaS accounts removes abandoned identities usable for access, persistence, or privilege abuse.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.3", "capability_description": "Disable Dormant Accounts", "mapping_type": "mitigates", "attack_object_id": "T1078.003", "attack_object_name": "Local Accounts", "capability_group": "CIS-5", "comments": "Disabling inactive local accounts reduces stale local credential abuse, dependent on endpoint/server coverage.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.3", "capability_description": "Disable Dormant Accounts", "mapping_type": "mitigates", "attack_object_id": "T1078.002", "attack_object_name": "Domain Accounts", "capability_group": "CIS-5", "comments": "Dormant domain accounts can retain broad access; disabling them removes stale domain credentials from the attack surface.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.3", "capability_description": "Disable Dormant Accounts", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-5", "comments": "Disabling stale accounts removes valid authentication paths available to adversaries.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.4", "capability_description": "Restrict Administrator Privileges to Dedicated Administrator Accounts", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-5", "comments": "Separating privileged accounts from daily-use accounts limits the privilege available if a primary account is compromised.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.4", "capability_description": "Restrict Administrator Privileges to Dedicated Administrator Accounts", "mapping_type": "mitigates", "attack_object_id": "T1078.002", "attack_object_name": "Domain Accounts", "capability_group": "CIS-5", "comments": "Dedicated domain admin accounts reduce the chance that routine domain account compromise yields domain-level privileges.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.4", "capability_description": "Restrict Administrator Privileges to Dedicated Administrator Accounts", "mapping_type": "mitigates", "attack_object_id": "T1078.003", "attack_object_name": "Local Accounts", "capability_group": "CIS-5", "comments": "Restricting local admin rights to dedicated accounts reduces local privilege availability in routine user sessions.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.4", "capability_description": "Restrict Administrator Privileges to Dedicated Administrator Accounts", "mapping_type": "mitigates", "attack_object_id": "T1078.004", "attack_object_name": "Cloud Accounts", "capability_group": "CIS-5", "comments": "Dedicated cloud admin accounts reduce privileged cloud exposure during normal user activity, though cloud-specific PAM controls are not required by the safeguard.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.4", "capability_description": "Restrict Administrator Privileges to Dedicated Administrator Accounts", "mapping_type": "mitigates", "attack_object_id": "T1548", "attack_object_name": "Abuse Elevation Control Mechanism", "capability_group": "CIS-5", "comments": "The safeguard limits which accounts can legitimately elevate, reducing the opportunity to abuse elevation paths from compromised routine accounts.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.4", "capability_description": "Restrict Administrator Privileges to Dedicated Administrator Accounts", "mapping_type": "mitigates", "attack_object_id": "T1548.002", "attack_object_name": "Bypass User Account Control", "capability_group": "CIS-5", "comments": "If routine accounts lack admin rights, UAC bypass from normal browsing/email sessions is less useful to an adversary.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.4", "capability_description": "Restrict Administrator Privileges to Dedicated Administrator Accounts", "mapping_type": "mitigates", "attack_object_id": "T1548.003", "attack_object_name": "Sudo and Sudo Caching", "capability_group": "CIS-5", "comments": "Dedicated admin accounts reduce privileged sudo exposure during routine activity, though sudo policy hardening is outside the safeguard.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.4", "capability_description": "Restrict Administrator Privileges to Dedicated Administrator Accounts", "mapping_type": "mitigates", "attack_object_id": "T1548.005", "attack_object_name": "Temporary Elevated Cloud Access", "capability_group": "CIS-5", "comments": "If dedicated administrator accounts include cloud privileged-access workflows or separate privileged cloud identities, the safeguard can reduce abuse of temporary elevated cloud access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1552.004", "attack_object_name": "Private Keys", "capability_group": "CIS-3", "score_category": "protect", "related_score": "T1552", "comments": "Private keys are frequently stored on disk. Encrypting storage can reduce exposure from theft of key files, especially during offline access or storage compromise.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/#311-encrypt-sensitive-data-at-rest"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1649", "attack_object_name": "Steal or Forge Authentication Certificates", "capability_group": "CIS-3", "score_category": "protect", "comments": "Certificates and private keys are commonly stored on disk. Encryption at rest can reduce exposure when attackers attempt to steal certificate material from storage.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/#311-encrypt-sensitive-data-at-rest"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1119", "attack_object_name": "Automated Collection", "capability_group": "CIS-3", "comments": "Adversaries use automated methods to search for and copy data across systems, cloud APIs, pipelines, or RAT functionality. Encryption at rest can mitigate the automated collection of files/storage objects from being usable when the adversary lacks access to the decryption key. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1003.003", "attack_object_name": "NTDS", "capability_group": "CIS-3", "comments": "NTDS dumping targets Active Directory credential material. Encryption and secure storage of DC backups can prevent an adversary who obtains an offline backup from directly accessing NTDS credential material. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1550.001", "attack_object_name": "Application Access Token", "capability_group": "CIS-3", "comments": "Application access tokens are sensitive credential material commonly stored in databases, configuration stores, browser profiles, caches, or application files. Encrypting those tokens at rest can prevent an adversary who obtains raw storage, a database backup, snapshot, or filesystem access from reading and reusing the tokens.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1078.004", "attack_object_name": "Cloud Accounts", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1078.003", "attack_object_name": "Local Accounts", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1078.002", "attack_object_name": "Domain Accounts", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.2", "capability_description": "Establish an Access Revoking Process", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-6", "comments": "Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#62-establish-an-access-revoking-process"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1098", "attack_object_name": "Account Manipulation", "capability_group": "CIS-6", "comments": "Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to maintain or elevate access using compromised credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1599", "attack_object_name": "Network Boundary Bridging", "capability_group": "CIS-6", "comments": "Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to reconfigure or bypass network boundaries by limiting their ability to log in.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1601.002", "attack_object_name": "Downgrade System Image", "capability_group": "CIS-6", "comments": "Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to install older operating systems by limiting their ability to log in.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1601.001", "attack_object_name": "Patch System Image", "capability_group": "CIS-6", "comments": "Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images and introduce new capabilities or weaken defenses by limiting their ability to log in.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1601", "attack_object_name": "Modify System Image", "capability_group": "CIS-6", "comments": "Using multi-factor authentication on administrator accounts helps prevent adversaries from using compromised credentials to modify system images by limiting their ability to log in.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1556.004", "attack_object_name": "Network Device Authentication", "capability_group": "CIS-6", "comments": "Requiring multi-factor authentication on administrator accounts ensures that adversaries cannot rely on a single implanted or backdoor password to gain access to network devices without also satisfying an independent second factor.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.2", "capability_description": "Establish an Access Revoking Process", "mapping_type": "mitigates", "attack_object_id": "T1555.005", "attack_object_name": "Password Managers", "capability_group": "CIS-6", "comments": "Inactive accounts may be targeted by attackers to gain unauthorized access. Disabling inactive accounts can prevent attackers from obtaining the user credentials from third-party password managers.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#62-establish-an-access-revoking-process"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1098.005", "attack_object_name": "Device Registration", "capability_group": "CIS-6", "comments": "Requiring multi-factor authentication (MFA) to register devices in Entra ID, configuring MFA systems to disallow enrolling new devices for inactive accounts, and using conditional access policies to restrict initial MFA device enrollment to trusted locations or devices reduces the success of adversary attempts to add additional devices to an adversary-controlled account.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1136.002", "attack_object_name": "Domain Account", "capability_group": "CIS-6", "comments": "Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1136.001", "attack_object_name": "Local Account", "capability_group": "CIS-6", "comments": "Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1136", "attack_object_name": "Create Account", "capability_group": "CIS-6", "comments": "Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1199", "attack_object_name": "Trusted Relationship", "capability_group": "CIS-6", "comments": "Using multi-factor authentication for administrative accounts reduces the success of adversaries breaching trusted third party relationships to compromise those networks and gain access to intended victims.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.4", "capability_description": "Require MFA for Remote Network Access", "mapping_type": "mitigates", "attack_object_id": "T1021.004", "attack_object_name": "SSH", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication for SSH connections helps minimize the adversary's ability to leverage stolen credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#64-require-mfa-for-remote-network-access"]}, {"capability_id": "CIS-6.4", "capability_description": "Require MFA for Remote Network Access", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication for remote logins helps minimize the adversary's ability to leverage stolen credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#64-require-mfa-for-remote-network-access"]}, {"capability_id": "CIS-6.4", "capability_description": "Require MFA for Remote Network Access", "mapping_type": "mitigates", "attack_object_id": "T1021", "attack_object_name": "Remote Services", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication for remote service logons helps minimize the adversary's ability to leverage stolen credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#64-require-mfa-for-remote-network-access"]}, {"capability_id": "CIS-6.4", "capability_description": "Require MFA for Remote Network Access", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication for external-facing remote service accounts to helps minimize the adversary's ability to leverage stolen credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#64-require-mfa-for-remote-network-access"]}, {"capability_id": "CIS-6.3", "capability_description": "Require MFA for Externally-Exposed Applications", "mapping_type": "mitigates", "attack_object_id": "T1114.002", "attack_object_name": "Remote Email Collection", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#63-require-mfa-for-externally-exposed-applications"]}, {"capability_id": "CIS-6.3", "capability_description": "Require MFA for Externally-Exposed Applications", "mapping_type": "mitigates", "attack_object_id": "T1114", "attack_object_name": "Email Collection", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication for public-facing webmail servers helps minimize the usefulness of email usernames and passwords collected by adversaries.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#63-require-mfa-for-externally-exposed-applications"]}, {"capability_id": "CIS-6.4", "capability_description": "Require MFA for Remote Network Access", "mapping_type": "mitigates", "attack_object_id": "T1021.007", "attack_object_name": "Cloud Services", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication on cloud services helps minimize the adversary's ability to leverage stolen credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#64-require-mfa-for-remote-network-access"]}, {"capability_id": "CIS-6.3", "capability_description": "Require MFA for Externally-Exposed Applications", "mapping_type": "mitigates", "attack_object_id": "T1110.003", "attack_object_name": "Password Spraying", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password spraying attacks against authentication interfaces on externally facing services.\r\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#63-require-mfa-for-externally-exposed-applications"]}, {"capability_id": "CIS-6.3", "capability_description": "Require MFA for Externally-Exposed Applications", "mapping_type": "mitigates", "attack_object_id": "T1110.002", "attack_object_name": "Password Cracking", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password cracking attacks against authentication interfaces on externally facing services.\r\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#63-require-mfa-for-externally-exposed-applications"]}, {"capability_id": "CIS-6.3", "capability_description": "Require MFA for Externally-Exposed Applications", "mapping_type": "mitigates", "attack_object_id": "T1110.001", "attack_object_name": "Password Guessing", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication can prevent adversaries from gaining access through brute force password guessing attacks against authentication interfaces on externally facing services.\r\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#63-require-mfa-for-externally-exposed-applications"]}, {"capability_id": "CIS-6.3", "capability_description": "Require MFA for Externally-Exposed Applications", "mapping_type": "mitigates", "attack_object_id": "T1110", "attack_object_name": "Brute Force", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication can prevent adversaries from gaining access through brute force attacks against authentication interfaces on externally facing services.\r\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#63-require-mfa-for-externally-exposed-applications"]}, {"capability_id": "CIS-6.3", "capability_description": "Require MFA for Externally-Exposed Applications", "mapping_type": "mitigates", "attack_object_id": "T1110.004", "attack_object_name": "Credential Stuffing", "capability_group": "CIS-6", "comments": "Enabling multi-factor authentication can prevent adversaries from gaining access through brute force credential stuffing attacks against authentication interfaces on externally facing services.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#63-require-mfa-for-externally-exposed-applications"]}, {"capability_id": "CIS-6.2", "capability_description": "Establish an Access Revoking Process", "mapping_type": "mitigates", "attack_object_id": "T1555.003", "attack_object_name": "Credentials from Web Browsers", "capability_group": "CIS-6", "comments": "Inactive accounts may be targeted by attackers to gain unauthorized access. Disabling inactive accounts can prevent attackers from acquiring credentials from web browsers.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#62-establish-an-access-revoking-process"]}, {"capability_id": "CIS-6.2", "capability_description": "Establish an Access Revoking Process", "mapping_type": "mitigates", "attack_object_id": "T1556.006", "attack_object_name": "Multi-Factor Authentication", "capability_group": "CIS-6", "comments": "Removing accounts that are no longer needed helps to accounts that adversaries could abuse to disable or modify MFA and maintain persistent access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#62-establish-an-access-revoking-process"]}, {"capability_id": "CIS-6.2", "capability_description": "Establish an Access Revoking Process", "mapping_type": "mitigates", "attack_object_id": "T1078.004", "attack_object_name": "Cloud Accounts", "capability_group": "CIS-6", "comments": "Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#62-establish-an-access-revoking-process"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1078.001", "attack_object_name": "Default Accounts", "capability_group": "CIS-6", "comments": "Implement multi-factor authentication (MFA) for administrative accounts to help prevent unauthorized access, even if credentials are compromised.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.2", "capability_description": "Establish an Access Revoking Process", "mapping_type": "mitigates", "attack_object_id": "T1078.003", "attack_object_name": "Local Accounts", "capability_group": "CIS-6", "comments": "Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#62-establish-an-access-revoking-process"]}, {"capability_id": "CIS-6.2", "capability_description": "Establish an Access Revoking Process", "mapping_type": "mitigates", "attack_object_id": "T1078.002", "attack_object_name": "Domain Accounts", "capability_group": "CIS-6", "comments": "Disabling accounts that are no longer needed immediately upon termination, rights revocation, or role change prevents adversaries from gaining and using those accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#62-establish-an-access-revoking-process"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1098.003", "attack_object_name": "Additional Cloud Roles", "capability_group": "CIS-6", "comments": "Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add additional roles or permissions to an adversary-controlled cloud account to maintain or elevate access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1098.002", "attack_object_name": "Additional Email Delegate Permissions", "capability_group": "CIS-6", "comments": "Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to grant additional permission levels to an adversary-controlled email account.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1098.001", "attack_object_name": "Additional Cloud Credentials", "capability_group": "CIS-6", "comments": "Using multi-factor authentication for privileged administrative access reduces the success of adversary attempts to add adversary-owned credentials to a cloud account to maintain or elevate access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1136.003", "attack_object_name": "Cloud Account", "capability_group": "CIS-6", "comments": "Using multi-factor authentication for administrative accounts reduces the likelihood that adversaries can use a compromised admin credential to sign in and create additional accounts by preventing access at login.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-6.5", "capability_description": "Require MFA for Administrative Access", "mapping_type": "mitigates", "attack_object_id": "T1599.001", "attack_object_name": "Network Address Translation Traversal", "capability_group": "CIS-6", "comments": "Using multi-factor authentication on accounts that administer network devices helps prevent adversaries from using compromised credentials to modify a network device\u2019s Network Address Translation (NAT) configuration by limiting their ability to log in.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls6/#65-require-mfa-for-administrative-access"]}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1566.001", "attack_object_name": "Spearphishing Attachment", "capability_group": "CIS-9", "comments": "Email-server attachment scanning and sandboxing can identify, quarantine, or remove malicious attachments before they reach the recipient.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1204.002", "attack_object_name": "Malicious File", "capability_group": "CIS-9", "comments": "Removing a malicious attachment before delivery prevents the user from opening the file and initiating its execution chain. The safeguard is limited to malicious files delivered through the protected email environment.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1203", "attack_object_name": "Exploitation for Client Execution", "capability_group": "CIS-9", "comments": "Email sandboxing can detonate weaponized Office documents, PDFs, archives, and other attachments to identify exploit behavior before delivery.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1221", "attack_object_name": "Template Injection", "capability_group": "CIS-9", "comments": "Email detonation chambers can open suspicious documents and observe attempts to retrieve or execute remote templates and payloads before the message reaches the recipient.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1027.012", "attack_object_name": "LNK Icon Smuggling", "capability_group": "CIS-9", "comments": "Email scanning can identify suspicious LNK attachments and inspect icon-location or target fields that reference remote payloads.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1036.008", "attack_object_name": "Masquerade File Type", "capability_group": "CIS-9", "comments": "Anti-malware scanners can compare file headers, MIME types, extensions, and content to detect attachments disguised as benign file formats.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1566", "attack_object_name": "Phishing", "capability_group": "CIS-9", "comments": "Email-server anti-malware directly addresses malicious attachments.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1204", "attack_object_name": "User Execution", "capability_group": "CIS-9", "comments": "Blocking malicious attachments prevents one major form of user execution. ", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1027", "attack_object_name": "Obfuscated Files or Information", "capability_group": "CIS-9", "comments": "Email anti-malware can use static, heuristic, and behavioral analysis to identify obfuscated files before delivery.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1027.002", "attack_object_name": "Software Packing", "capability_group": "CIS-9", "comments": "Heuristic scanning and sandbox detonation can identify packed executables attached to messages, even when packing changes their static signature. ", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1027.006", "attack_object_name": "HTML Smuggling", "capability_group": "CIS-9", "comments": "A sandbox capable of executing active HTML attachments may detect JavaScript that reconstructs and writes a malicious payload to disk. ", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1027.009", "attack_object_name": "Embedded Payloads", "capability_group": "CIS-9", "comments": "Attachment scanners and sandboxes can identify malicious payloads hidden within documents, scripts, executables, or other carrier files.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1027.013", "attack_object_name": "Encrypted/Encoded File", "capability_group": "CIS-9", "comments": "Anti-malware can identify encoded or high-entropy attachments and may block encrypted archives that cannot be inspected. ", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1027.015", "attack_object_name": "Compression", "capability_group": "CIS-9", "comments": "Email anti-malware capable of recursively unpacking ZIP, RAR, 7z, self-extracting archives, and nested archives can identify malicious files before delivery. ", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1027.017", "attack_object_name": "SVG Smuggling", "capability_group": "CIS-9", "comments": "A sandbox that renders SVG attachments and executes their embedded scripts may identify payload construction or malicious follow-on behavior. ", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1036", "attack_object_name": "Masquerading", "capability_group": "CIS-9", "comments": "Anti-malware analysis can identify malicious attachments whose content, signature, or behavior conflicts with their apparent name or file type. ", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1036.007", "attack_object_name": "Double File Extension", "capability_group": "CIS-9", "comments": "Email gateways can inspect the complete filename and actual file type rather than relying on the first visible extension, allowing attachments such as invoice.pdf.exe or report.pdf.lnk to be blocked.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1059.005", "attack_object_name": "Visual Basic", "capability_group": "CIS-9", "comments": "Email anti-malware and sandboxing can analyze Visual Basic scripts and macro-enabled attachments and quarantine files that exhibit malicious behavior. This does not prevent Visual Basic abuse originating outside email.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1059", "attack_object_name": "Command and Scripting Interpreter", "capability_group": "CIS-9", "comments": "Email anti-malware can block suspicious script attachments before they reach an interpreter. Most command and scripting activity occurs after compromise or through channels unrelated to email.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1059.001", "attack_object_name": "PowerShell", "capability_group": "CIS-9", "comments": "Email scanning or sandboxing may identify PowerShell script attachments or documents that launch PowerShell. ", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1059.006", "attack_object_name": "Python", "capability_group": "CIS-9", "comments": "Email anti-malware may quarantine malicious Python scripts or packed Python payloads sent specifically as email attachments. Python activity originating from installed tools or post-compromise execution remains unaffected.", "references": []}, {"capability_id": "CIS-9.7", "capability_description": "Deploy and Maintain Email Server Anti-Malware Protections", "mapping_type": "mitigates", "attack_object_id": "T1059.007", "attack_object_name": "JavaScript", "capability_group": "CIS-9", "comments": "A sandbox may execute JavaScript, JScript, HTA, HTML, or SVG attachments and identify malicious file creation or process execution. Depends on the email security product supporting active-content detonation.", "references": []}, {"capability_id": "CIS-9.4", "capability_description": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions", "mapping_type": "mitigates", "attack_object_id": "T1176.001", "attack_object_name": "Browser Extensions", "capability_group": "CIS-9", "comments": "Browser extension allowlists, denylists, installation restrictions, and removal of unauthorized extensions directly prevent malicious browser extensions from establishing persistence or abusing inherited browser permissions.", "references": []}, {"capability_id": "CIS-9.4", "capability_description": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions", "mapping_type": "mitigates", "attack_object_id": "T1137.006", "attack_object_name": "Add-ins", "capability_group": "CIS-9", "comments": "Disabling unauthorized Outlook add-ins prevents those add-ins from automatically loading code when the email client starts. This directly reduces persistence through email-client add-on functionality.", "references": []}, {"capability_id": "CIS-9.4", "capability_description": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions", "mapping_type": "mitigates", "attack_object_id": "T1176", "attack_object_name": "Software Extensions", "capability_group": "CIS-9", "comments": "This technique includes browser extensions, which are directly addressed by the safeguard. ", "references": []}, {"capability_id": "CIS-9.4", "capability_description": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions", "mapping_type": "mitigates", "attack_object_id": "T1137", "attack_object_name": "Office Application Startup", "capability_group": "CIS-9", "comments": "Restricting email-client add-ins mitigates the add-in portion of this parent technique. ", "references": []}, {"capability_id": "CIS-9.4", "capability_description": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions", "mapping_type": "mitigates", "attack_object_id": "T1539", "attack_object_name": "Steal Web Session Cookie", "capability_group": "CIS-9", "comments": "Malicious browser extensions may access browser cookies and session information. Restricting extensions removes one important cookie-theft path.", "references": []}, {"capability_id": "CIS-9.4", "capability_description": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions", "mapping_type": "mitigates", "attack_object_id": "T1555.003", "attack_object_name": "Credentials from Web Browsers", "capability_group": "CIS-9", "comments": "Malicious extensions may access credentials stored in browsers. Extension restrictions reduce that attack surface, but malware already executing with access to the browser profile may still extract stored credentials.", "references": []}, {"capability_id": "CIS-9.4", "capability_description": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions", "mapping_type": "mitigates", "attack_object_id": "T1189", "attack_object_name": "Drive-by Compromise", "capability_group": "CIS-9", "comments": "Removing unnecessary or vulnerable browser plug-ins reduces components that a malicious website can enumerate and exploit during a drive-by attack. ", "references": []}, {"capability_id": "CIS-9.4", "capability_description": "Restrict Unnecessary or Unauthorized Browser and Email Client Extensions", "mapping_type": "mitigates", "attack_object_id": "T1203", "attack_object_name": "Exploitation for Client Execution", "capability_group": "CIS-9", "comments": "Uninstalling unnecessary browser or email-client plug-ins removes potential client-side exploitation targets. ", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1071.004", "attack_object_name": "DNS", "capability_group": "CIS-9", "comments": "DNS filtering can prevent resolution of known malicious domains used for DNS-based command and control and can sinkhole requests before an endpoint reaches adversary infrastructure.", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1189", "attack_object_name": "Drive-by Compromise", "capability_group": "CIS-9", "comments": "Blocking known malicious or compromised domains prevents browsers from reaching websites used to exploit users or deliver malicious content. ", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1566.002", "attack_object_name": "Spearphishing Link", "capability_group": "CIS-9", "comments": "DNS filtering can block the destination of a malicious link delivered through email before the user reaches a credential-harvesting page, exploit site, or malware download. Newly registered, compromised, or uncategorized domains may initially evade filtering.", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1204.001", "attack_object_name": "Malicious Link", "capability_group": "CIS-9", "comments": "Even when a user clicks a malicious link, DNS filtering can prevent successful navigation when the destination domain is known to be malicious. ", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1071", "attack_object_name": "Application Layer Protocol", "capability_group": "CIS-9", "comments": "DNS filtering directly affects DNS and can also prevent connections to malicious domains used for web-based application-layer command and control. ", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1071.001", "attack_object_name": "Web Protocols", "capability_group": "CIS-9", "comments": "DNS filtering can prevent HTTP, HTTPS, and WebSocket command-and-control connections when the destination domain has been classified as malicious. ", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-9", "comments": "DNS and other domain-based destinations may be used as alternative exfiltration channels. DNS filtering only impedes implementations that depend on resolving a known malicious domain.", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1048.003", "attack_object_name": "Exfiltration Over Unencrypted Non-C2 Protocol", "capability_group": "CIS-9", "comments": "DNS can carry encoded exfiltrated data over an unencrypted non-command-and-control protocol. Blocking resolution of an adversary-controlled domain can interrupt DNS-based exfiltration, although newly registered or uncategorized domains may initially be allowed.", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1105", "attack_object_name": "Ingress Tool Transfer", "capability_group": "CIS-9", "comments": "DNS filtering can prevent a compromised endpoint from resolving known malicious domains used to host tools or secondary payloads. Transfers over direct IP addresses, approved cloud services, compromised legitimate domains, or uncategorized domains may still succeed.", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1566", "attack_object_name": "Phishing", "capability_group": "CIS-9", "comments": "DNS filtering materially mitigates phishing that directs users to malicious domains. It does not mitigate phishing attachments, voice phishing, or messages that do not require visiting a domain.", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1572", "attack_object_name": "Protocol Tunneling", "capability_group": "CIS-9", "comments": "DNS filtering can block tunnels that depend on resolving known malicious domains, including some DNS and web-based tunnels. Tunnels using direct IP addresses, trusted domains, or infrastructure not yet classified as malicious may still succeed.", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1568", "attack_object_name": "Dynamic Resolution", "capability_group": "CIS-9", "comments": "DNS sinkholing and reputation-based filtering can prevent resolution of identified dynamic-DNS and generated domains used to reestablish command and control.", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1568.002", "attack_object_name": "Domain Generation Algorithms", "capability_group": "CIS-9", "comments": "DNS filtering services may block or sinkhole known and predicted algorithmically generated domains, for example those that have high entropy in the name. ", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1048.001", "attack_object_name": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-9", "comments": "DNS filtering can block resolution of a known malicious exfiltration destination regardless of whether the transmitted data is encrypted.", "references": []}, {"capability_id": "CIS-9.2", "capability_description": "Use DNS Filtering Services", "mapping_type": "mitigates", "attack_object_id": "T1048.002", "attack_object_name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-9", "comments": "Blocking a known malicious destination domain may interrupt an asymmetric encrypted exfiltration channel. ", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1212", "attack_object_name": "Exploitation for Credential Access", "capability_group": "CIS-9", "comments": "Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1068", "attack_object_name": "Exploitation for Privilege Escalation", "capability_group": "CIS-9", "comments": "Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1211", "attack_object_name": "Exploitation for Stealth", "capability_group": "CIS-9", "comments": "Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1189", "attack_object_name": "Drive-by Compromise", "capability_group": "CIS-9", "comments": "Fully supported, current browsers contain vendor patches and modern security features that reduce successful exploitation when users visit compromised or malicious websites.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1203", "attack_object_name": "Exploitation for Client Execution", "capability_group": "CIS-9", "comments": "Browsers and email clients are common targets for vulnerabilities that provide adversary code execution. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1137.003", "attack_object_name": "Outlook Forms", "capability_group": "CIS-9", "comments": "Current Outlook versions include vendor changes that restrict or warn about custom Outlook forms that may otherwise be abused for persistence and execution. The safeguard ensures those security updates are present.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1137.004", "attack_object_name": "Outlook Home Page", "capability_group": "CIS-9", "comments": "Microsoft updates removed or restricted the legacy Outlook Home Page functionality used for persistence. Preventing obsolete Outlook versions from executing directly prevents continued access to older vulnerable implementations.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1137.005", "attack_object_name": "Outlook Rules", "capability_group": "CIS-9", "comments": "Vendor patches address Outlook mechanisms that adversaries may use to establish rule-triggered persistence or execution. Requiring current supported Outlook versions ensures the relevant security changes are applied.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1689", "attack_object_name": "Downgrade Attack", "capability_group": "CIS-9", "comments": "Allowing only the latest supported browser and email-client versions prevents adversaries or users from running obsolete versions that lack current protections. This directly reduces downgrade opportunities involving older, weaker software versions.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1137", "attack_object_name": "Office Application Startup", "capability_group": "CIS-9", "comments": "This is a partial mapping because several sub-techniques specifically abuse Outlook features addressed by vendor patches. Other Office startup methods involving templates, test keys, and general add-ins are outside the browser-and-email-client scope.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1176.001", "attack_object_name": "Browser Extensions", "capability_group": "CIS-9", "comments": "Current browsers incorporate newer extension permission models, security controls, and protections against outdated installation methods. This does not prevent users or adversaries from installing an otherwise permitted malicious extension.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1539", "attack_object_name": "Steal Web Session Cookie", "capability_group": "CIS-9", "comments": "Updating browsers reduces the likelihood that known vulnerabilities can be exploited to extract cookies from browser storage or memory. It does not prevent malware with sufficient local access from directly reading cookies or browser data.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1555.003", "attack_object_name": "Credentials from Web Browsers", "capability_group": "CIS-9", "comments": "Current browser versions reduce exploitation of known weaknesses that expose stored passwords and authentication data. Updating the browser does not prevent credential theft by malware already executing with access to the user's browser profile.", "references": []}, {"capability_id": "CIS-9.1", "capability_description": "Ensure Use of Only Fully Supported Browsers and Email Clients", "mapping_type": "mitigates", "attack_object_id": "T1176", "attack_object_name": "Software Extensions", "capability_group": "CIS-9", "comments": "Keeping browsers current affects browser extensions. ", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1005", "attack_object_name": "Data from Local System", "capability_group": "CIS-4", "comments": "A successful remote wipe removes enterprise files, local databases, cached content, and other managed data before an adversary with possession of the device can collect it. ", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1114.001", "attack_object_name": "Local Email Collection", "capability_group": "CIS-4", "comments": "Wiping managed email applications and locally cached mailbox files can prevent collection of Outlook PST or OST files and other locally stored enterprise email. ", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1539", "attack_object_name": "Steal Web Session Cookie", "capability_group": "CIS-4", "comments": "Wiping managed browsers and application data removes locally stored enterprise session cookies before they can be extracted from a lost or stolen device. ", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1552.001", "attack_object_name": "Credentials In Files", "capability_group": "CIS-4", "comments": "Remote wipe can remove managed files containing passwords, API keys, connection strings, or other credential material. The mitigation is limited to files covered by the wipe and does not address credentials stored elsewhere.", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1552.002", "attack_object_name": "Credentials in Registry", "capability_group": "CIS-4", "comments": "A full Windows device wipe removes local Registry hives containing enterprise credential material before they can be searched or exported. A selective enterprise-data wipe may not remove operating-system Registry data.", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1552.004", "attack_object_name": "Private Keys", "capability_group": "CIS-4", "comments": "Wiping enterprise-managed key files, certificates, VPN profiles, and application containers can prevent private keys from being obtained from a lost device. Keys synchronized elsewhere or already exported remain exposed and should be revoked separately.", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1555.001", "attack_object_name": "Keychain", "capability_group": "CIS-4", "comments": "A full wipe of a managed macOS device removes locally stored Keychain databases and enterprise certificates. Items synchronized to other devices or already extracted are not revoked merely by wiping the device.", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1555.003", "attack_object_name": "Credentials from Web Browsers", "capability_group": "CIS-4", "comments": "Remote wipe of managed browser profiles can remove locally stored enterprise passwords and related authentication data. Browser-synchronized credentials and already extracted copies require separate account or server-side action.", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1555.004", "attack_object_name": "Windows Credential Manager", "capability_group": "CIS-4", "comments": "A full Windows wipe removes local Credential Manager vault files and associated enterprise credentials. Selective wipe implementations may not remove credentials stored outside managed application containers.", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1552.003", "attack_object_name": "Shell History", "capability_group": "CIS-4", "comments": "A full device wipe removes local shell-history files that may contain passwords, tokens, or sensitive commands. Selective enterprise wipes may not remove operating-system shell histories.", "references": []}, {"capability_id": "CIS-4.11", "capability_description": "Enforce Remote Wipe Capability on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1555.005", "attack_object_name": "Password Managers", "capability_group": "CIS-4", "comments": "Remote wipe can remove a managed password-manager application, its local vault, and cached decrypted data. Cloud-hosted vault contents remain available and require account revocation, device removal, or token invalidation.", "references": []}, {"capability_id": "CIS-4.10", "capability_description": "Enforce Automatic Device Lockout on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1110.004", "attack_object_name": "Credential Stuffing", "capability_group": "CIS-4", "comments": "Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated breached username password attempts will succeed.", "references": []}, {"capability_id": "CIS-4.10", "capability_description": "Enforce Automatic Device Lockout on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1110.003", "attack_object_name": "Password Spraying", "capability_group": "CIS-4", "comments": "Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.", "references": []}, {"capability_id": "CIS-4.10", "capability_description": "Enforce Automatic Device Lockout on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1110.001", "attack_object_name": "Password Guessing", "capability_group": "CIS-4", "comments": "Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.", "references": []}, {"capability_id": "CIS-4.10", "capability_description": "Enforce Automatic Device Lockout on Portable End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1110", "attack_object_name": "Brute Force", "capability_group": "CIS-4", "comments": "Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.", "references": []}, {"capability_id": "CIS-4.9", "capability_description": "Configure Trusted DNS Servers on Enterprise Assets", "mapping_type": "mitigates", "attack_object_id": "T1071.004", "attack_object_name": "DNS", "capability_group": "CIS-4", "comments": "Directing DNS traffic through trusted enterprise resolvers can prevent systems from communicating directly with adversary-controlled DNS servers and can support blocking or sinkholing malicious DNS requests.", "references": []}, {"capability_id": "CIS-4.9", "capability_description": "Configure Trusted DNS Servers on Enterprise Assets", "mapping_type": "mitigates", "attack_object_id": "T1071", "attack_object_name": "Application Layer Protocol", "capability_group": "CIS-4", "comments": "This is a partial mapping because DNS is one of the application-layer protocols covered by this technique. Configuring trusted DNS servers affects DNS-based command and control but does not mitigate web, mail, file-transfer, or publish-subscribe protocols.", "references": []}, {"capability_id": "CIS-4.9", "capability_description": "Configure Trusted DNS Servers on Enterprise Assets", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-4", "comments": "Enforcing use of trusted DNS resolvers reduces the ability of enterprise assets to communicate directly with adversary-controlled DNS infrastructure for exfiltration. The mitigation applies only to implementations that use DNS or depend on unauthorized DNS servers.", "references": []}, {"capability_id": "CIS-4.9", "capability_description": "Configure Trusted DNS Servers on Enterprise Assets", "mapping_type": "mitigates", "attack_object_id": "T1048.003", "attack_object_name": "Exfiltration Over Unencrypted Non-C2 Protocol", "capability_group": "CIS-4", "comments": "DNS can carry encoded exfiltrated data over an unencrypted non-command-and-control protocol. Routing requests through controlled resolvers provides an enforcement point for blocking unauthorized DNS servers, suspicious domains, or abnormal query activity.", "references": []}, {"capability_id": "CIS-4.9", "capability_description": "Configure Trusted DNS Servers on Enterprise Assets", "mapping_type": "mitigates", "attack_object_id": "T1572", "attack_object_name": "Protocol Tunneling", "capability_group": "CIS-4", "comments": "DNS can be used to tunnel command-and-control traffic or other protocols. Enforcing trusted resolvers and preventing direct DNS communication can disrupt conventional DNS tunneling, ", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021", "attack_object_name": "Remote Services", "capability_group": "CIS-4", "comments": "Disabling unnecessary remote services eliminates the corresponding authentication and remote-access path, directly reducing lateral movement opportunities.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-4", "comments": "Disabling Remote Desktop Services where RDP is not operationally required prevents adversaries from connecting through that service.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.002", "attack_object_name": "SMB/Windows Admin Shares", "capability_group": "CIS-4", "comments": "Disabling unnecessary SMB file sharing and administrative shares directly removes common lateral movement, file-transfer, and remote-management paths.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.003", "attack_object_name": "Distributed Component Object Model", "capability_group": "CIS-4", "comments": "Disabling DCOM when it is not required removes a remote RPC-based execution and management interface that adversaries may abuse.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.004", "attack_object_name": "SSH", "capability_group": "CIS-4", "comments": "Disabling the SSH daemon or Remote Login on systems that do not require it eliminates an SSH-based remote-access path.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.005", "attack_object_name": "VNC", "capability_group": "CIS-4", "comments": "Uninstalling unnecessary VNC server software removes the listener and prevents remote control through that implementation.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.006", "attack_object_name": "Windows Remote Management", "capability_group": "CIS-4", "comments": "Disabling the WinRM service where it is unnecessary removes a remote command-execution and administration interface.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.008", "attack_object_name": "Direct Cloud VM Connections", "capability_group": "CIS-4", "comments": "Disabling unnecessary cloud-native VM connection types, serial consoles, or direct management services eliminates those remote-administration paths.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1080", "attack_object_name": "Taint Shared Content", "capability_group": "CIS-4", "comments": "Removing unnecessary shared folders and file-sharing services prevents adversaries from placing malicious content in those shares for other users or systems to execute.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-4", "comments": "Uninstalling or disabling unnecessary externally accessible VPN, remote desktop, SSH, and management services directly reduces external entry points.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-4", "comments": "Removing unused public-facing applications, services, and web modules eliminates exploitable listeners and reduces the externally exposed attack surface.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-4", "comments": "A remote service that has been disabled or uninstalled can no longer be reached and exploited through its network interface.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1219", "attack_object_name": "Remote Access Tools", "capability_group": "CIS-4", "comments": "Removing unauthorized or unnecessary remote-access products and disabling embedded remote-support functionality directly eliminates those access channels.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1219.002", "attack_object_name": "Remote Desktop Software", "capability_group": "CIS-4", "comments": "Uninstalling unnecessary remote desktop products prevents adversaries from abusing that specific software for persistent or interactive access.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1505", "attack_object_name": "Server Software Component", "capability_group": "CIS-4", "comments": "Disabling unnecessary server extension mechanisms and components reduces the features adversaries can abuse to establish persistent server-side access.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1505.003", "attack_object_name": "Web Shell", "capability_group": "CIS-4", "comments": "Disabling unnecessary web server functionality, scripting engines, and dangerous application functions can prevent particular web shell implementations from executing.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1505.004", "attack_object_name": "IIS Components", "capability_group": "CIS-4", "comments": "Removing unused IIS modules, handlers, filters, and extensions directly reduces opportunities to install or abuse malicious IIS components.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1552.005", "attack_object_name": "Cloud Instance Metadata API", "capability_group": "CIS-4", "comments": "Disabling unnecessary metadata services or insecure metadata-service versions directly prevents adversary access through those endpoints.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1602", "attack_object_name": "Data from Configuration Repository", "capability_group": "CIS-4", "comments": "Removing unnecessary configuration-management protocols and repositories reduces the systems and services from which adversaries can collect configuration data.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-4", "comments": "Disabling SNMP where it is unnecessary removes the management service used to retrieve MIB and configuration information.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1602.002", "attack_object_name": "Network Device Configuration Dump", "capability_group": "CIS-4", "comments": "Removing unnecessary Telnet, HTTP management, TFTP, legacy SNMP, or similar configuration services reduces direct collection of network-device configurations.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1011", "attack_object_name": "Exfiltration Over Other Network Medium", "capability_group": "CIS-4", "comments": "Disabling unnecessary Wi-Fi, cellular, modem, Bluetooth, or other secondary network services removes potential alternative exfiltration channels.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1011.001", "attack_object_name": "Exfiltration Over Bluetooth", "capability_group": "CIS-4", "comments": "Disabling the Bluetooth service and adapter functionality where it is unnecessary prevents Bluetooth-based data transfer from that asset.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.007", "attack_object_name": "Cloud Services", "capability_group": "CIS-4", "comments": "Disabling unnecessary cloud services, command-line integrations, and administrative applications reduces available cloud-management paths, although required web consoles may remain accessible.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1039", "attack_object_name": "Data from Network Shared Drive", "capability_group": "CIS-4", "comments": "Removing unnecessary file-sharing services and shares reduces the network data repositories available for adversary collection.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-4", "comments": "Removing unnecessary plaintext and broadcast-based services reduces sensitive service traffic available for interception, although it does not prevent sniffing of remaining traffic.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1047", "attack_object_name": "Windows Management Instrumentation", "capability_group": "CIS-4", "comments": "Disabling unnecessary remote WMI and dependent management services reduces remote WMI execution, while local WMI functionality may remain available.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1059.008", "attack_object_name": "Network Device CLI", "capability_group": "CIS-4", "comments": "Disabling unnecessary network-device command-line services, especially Telnet or direct CLI access, removes a command interface adversaries could abuse.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-4", "comments": "Uninstalling unnecessary deployment agents and disabling unused remote-deployment functionality reduces the number of centralized execution mechanisms available to an adversary.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1090", "attack_object_name": "Proxy", "capability_group": "CIS-4", "comments": "Removing unnecessary proxy, relay, port-forwarding, and tunneling services reduces the ability to turn an enterprise asset into a network intermediary.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1090.001", "attack_object_name": "Internal Proxy", "capability_group": "CIS-4", "comments": "Disabling unnecessary internal proxy listeners, SSH forwarding, port proxies, and routing functions impedes the use of a compromised asset as an internal pivot.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1187", "attack_object_name": "Forced Authentication", "capability_group": "CIS-4", "comments": "Disabling unnecessary SMB, WebClient, WebDAV, LLMNR, NBT-NS, and related services reduces mechanisms that can coerce outbound authentication.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1197", "attack_object_name": "BITS Jobs", "capability_group": "CIS-4", "comments": "Disabling the Background Intelligent Transfer Service where it is genuinely unnecessary prevents adversary use of BITS for transfer, execution, or persistence.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1570", "attack_object_name": "Lateral Tool Transfer", "capability_group": "CIS-4", "comments": "Removing unnecessary SMB, SSH, WinRM, file-sharing, and deployment services reduces common channels used to move tools between systems.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1505.001", "attack_object_name": "SQL Stored Procedures", "capability_group": "CIS-4", "comments": "Disabling unnecessary extended stored procedures, scripting extensions, or database execution features reduces opportunities to establish persistence through the database server.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1505.002", "attack_object_name": "Transport Agent", "capability_group": "CIS-4", "comments": "Removing unused mail transport agents and extension points reduces the components available for adversary persistence in messaging infrastructure.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1505.005", "attack_object_name": "Terminal Services DLL", "capability_group": "CIS-4", "comments": "Disabling unnecessary Terminal Services functionality reduces opportunities to replace or abuse associated DLL components, although required RDP systems remain exposed.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1505.006", "attack_object_name": "vSphere Installation Bundles", "capability_group": "CIS-4", "comments": "Removing unnecessary vSphere Installation Bundles and disabling unused ESXi extension functionality reduces the components available for hypervisor persistence.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1609", "attack_object_name": "Container Administration Command", "capability_group": "CIS-4", "comments": "Removing unnecessary container-management utilities, exposed APIs, and administrative services reduces the mechanisms available for remote container commands.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1611", "attack_object_name": "Escape to Host", "capability_group": "CIS-4", "comments": "Minimal container images and removal of unnecessary tools, shells, runtimes, and privileged services reduce some prerequisites and post-exploitation options for container escape.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1563", "attack_object_name": "Remote Service Session Hijacking", "capability_group": "CIS-4", "comments": "Disabling unnecessary remote services prevents sessions from being established through those services and therefore removes sessions that could later be hijacked.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1563.001", "attack_object_name": "SSH Hijacking", "capability_group": "CIS-4", "comments": "Disabling unnecessary SSH and agent-forwarding functions removes some SSH sessions and forwarding sockets that adversaries could hijack.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1563.002", "attack_object_name": "RDP Hijacking", "capability_group": "CIS-4", "comments": "Disabling unnecessary RDP services prevents creation of RDP sessions on those assets, eliminating that session-hijacking opportunity.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1649", "attack_object_name": "Steal or Forge Authentication Certificates", "capability_group": "CIS-4", "comments": "Disabling unnecessary Active Directory Certificate Services web enrollment, enrollment agents, legacy authentication protocols, and certificate-service roles reduces certificate abuse paths.", "references": []}, {"capability_id": "CIS-4.8", "capability_description": "Uninstall or Disable Unnecessary Services on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1671", "attack_object_name": "Cloud Application Integration", "capability_group": "CIS-4", "comments": "Disabling unnecessary SaaS integrations, plug-ins, application consent features, and service connections reduces the number of integrations an adversary can authorize or abuse.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-4", "comments": "Replacing plaintext administrative protocols such as Telnet and HTTP with SSH and HTTPS prevents captured management traffic from directly exposing credentials, commands, and configuration data. Encryption does not prevent packet capture, but it materially reduces the value of the captured traffic.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-4", "comments": "Safeguard 4.6 directly concerns securely managing software and configuration-management platforms, including tools integrated with CI/CD systems. Restricting administrative access and managing deployment configuration through controlled, versioned mechanisms reduces unauthorized use of these platforms for execution and lateral movement.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-4", "comments": "Disabling obsolete management protocols and securely configuring required administrative services reduces the number of remotely reachable and vulnerable services. The safeguard does not patch vulnerabilities, but it directly removes insecure management paths that could be exploited.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1552.007", "attack_object_name": "Container API", "capability_group": "CIS-4", "comments": "Disabling unauthenticated Docker and Kubernetes API access and requiring secured channels such as SSH or TLS directly reduces unauthorized access to container-management interfaces. This closely matches the safeguard's requirement to access administrative interfaces through secure protocols.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-4", "comments": "Authenticated encryption through SSH, HTTPS, and TLS limits an adversary's ability to read or alter administrative traffic even after obtaining a network interception position. Certificate and SSH host-key validation remain essential to the effectiveness of the mitigation.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1565.002", "attack_object_name": "Transmitted Data Manipulation", "capability_group": "CIS-4", "comments": "SSH and HTTPS provide confidentiality and integrity protection for management commands and configuration data in transit. This makes undetected modification of administrative traffic substantially more difficult.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1602", "attack_object_name": "Data from Configuration Repository", "capability_group": "CIS-4", "comments": "Secure management protocols, authenticated access, and controlled configuration repositories directly reduce unauthorized collection of device and infrastructure configuration. Version-controlled Infrastructure-as-Code can also reduce the need to retrieve configurations through insecure management interfaces.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-4", "comments": "Migrating from insecure SNMP versions to SNMPv3 with authentication and privacy protection directly reduces unauthorized MIB collection. Restricting management access to approved systems further limits successful enumeration.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1602.002", "attack_object_name": "Network Device Configuration Dump", "capability_group": "CIS-4", "comments": "Using SSH, HTTPS, SNMPv3, and securely managed configuration repositories reduces exposure of network-device configurations and embedded credentials. Insecure services such as Telnet, HTTP, TFTP, or legacy management protocols create substantially greater collection risk.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1609", "attack_object_name": "Container Administration Command", "capability_group": "CIS-4", "comments": "Restricting Docker and Kubernetes administration to authenticated TLS, SSH, local sockets, or other secured management channels directly reduces unauthorized remote container commands. Version-controlled manifests and Infrastructure-as-Code also reduce unreviewed administrative changes.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1659", "attack_object_name": "Content Injection", "capability_group": "CIS-4", "comments": "HTTPS and other authenticated encrypted protocols make it more difficult for an adversary positioned in the network path to inject malicious content into management downloads or administrative sessions. This is a direct benefit of prohibiting plaintext HTTP management.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1689", "attack_object_name": "Downgrade Attack", "capability_group": "CIS-4", "comments": "This safeguard explicitly prohibits fallback to insecure protocols such as HTTP and Telnet. Enforcing HTTPS, modern TLS, SSH, and policies such as HSTS directly limits attempts to downgrade management communications to weaker or plaintext alternatives.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021", "attack_object_name": "Remote Services", "capability_group": "CIS-4", "comments": "Securely managing which remote services are permitted and requiring authenticated encrypted protocols reduces exposed administrative paths. The safeguard does not independently prevent adversaries from using valid credentials through an approved service.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-4", "comments": "Secure RDP configuration, gateways, TLS, and restricted administrative access reduce interception and direct exposure. RDP remains usable by an adversary who possesses authorized credentials or an active session.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.002", "attack_object_name": "SMB/Windows Admin Shares", "capability_group": "CIS-4", "comments": "Secure management can disable unnecessary administrative shares and require modern SMB signing or encryption where remote administration is needed. It does not fully prevent abuse of an authorized SMB management path.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.003", "attack_object_name": "Distributed Component Object Model", "capability_group": "CIS-4", "comments": "Securely managing DCOM availability and restricting it to approved administrative workflows reduces remote abuse. DCOM does not have a simple SSH or HTTPS replacement, so effectiveness depends on disabling or tightly constraining it.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.004", "attack_object_name": "SSH", "capability_group": "CIS-4", "comments": "SSH protects administrative credentials and commands from plaintext interception and should replace Telnet. It does not prevent an adversary with valid credentials or an unauthorized SSH key from using the service.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.005", "attack_object_name": "VNC", "capability_group": "CIS-4", "comments": "Secure management can prohibit unencrypted VNC deployments or require encrypted tunnels and approved administrative tooling. The relationship is partial because some VNC implementations or tunnels remain accessible with valid credentials.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.006", "attack_object_name": "Windows Remote Management", "capability_group": "CIS-4", "comments": "Requiring WinRM over HTTPS rather than unencrypted HTTP protects management credentials and commands in transit. Authorized-account abuse remains possible through the secured channel.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.007", "attack_object_name": "Cloud Services", "capability_group": "CIS-4", "comments": "Securing cloud administrative consoles and APIs, using controlled automation, and managing resources through version-controlled Infrastructure-as-Code reduces ad hoc and insecure administration. It does not prevent malicious activity performed through a compromised authorized cloud account.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1021.008", "attack_object_name": "Direct Cloud VM Connections", "capability_group": "CIS-4", "comments": "Approved and securely configured cloud-native VM connection methods reduce exposure from direct or insecure management services. Cloud control-plane access may bypass the guest operating system's network controls, so identity and cloud policy protections are also required.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1059.008", "attack_object_name": "Network Device CLI", "capability_group": "CIS-4", "comments": "Requiring SSH rather than Telnet protects command-line interface credentials and commands in transit and reduces interception or manipulation. Once an adversary has authorized administrative access, the encrypted CLI still permits malicious commands.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-4", "comments": "Requiring secure protocols and centrally managed administrative access reduces risk from externally accessible management services. Additional protections such as multi-factor authentication, gateways, and network restrictions remain necessary.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-4", "comments": "Administrative web interfaces should use HTTPS and should not be exposed through unnecessary plaintext or legacy services. HTTPS does not remediate an application vulnerability, so this mitigation primarily reduces unnecessary exposure and traffic manipulation.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1098.004", "attack_object_name": "SSH Authorized Keys", "capability_group": "CIS-4", "comments": "Version-controlled SSH configuration and managed deployment of approved keys can prevent or identify unauthorized additions to authorized_keys. File permissions and privileged access controls are still needed to prevent local modification.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1213.003", "attack_object_name": "Code Repositories", "capability_group": "CIS-4", "comments": "Infrastructure-as-Code repositories may reveal infrastructure topology, administrative endpoints, configuration, and embedded credentials. Secure repository administration and keeping secrets outside version control reduce the value and accessibility of these repositories.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1219", "attack_object_name": "Remote Access Tools", "capability_group": "CIS-4", "comments": "Secure software management can limit administration to approved and securely configured remote-access products. The safeguard does not prevent an approved tool or account from being abused by an adversary.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1219.001", "attack_object_name": "IDE Tunneling", "capability_group": "CIS-4", "comments": "Securely managing development tools can disable unnecessary tunneling functions and restrict approved remote-development services. Legitimate HTTPS or SSH development channels may still be abused.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1219.002", "attack_object_name": "Remote Desktop Software", "capability_group": "CIS-4", "comments": "Organizations can centrally approve, configure, and secure remote-support software while removing unauthorized products. An adversary may still misuse an approved product or compromised support account.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1552.001", "attack_object_name": "Credentials In Files", "capability_group": "CIS-4", "comments": "Infrastructure code, configuration files, deployment manifests, and automation scripts frequently create a risk of embedded passwords or tokens. Secure management should keep credentials out of source-controlled configuration and use protected secret stores or runtime injection.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1552.004", "attack_object_name": "Private Keys", "capability_group": "CIS-4", "comments": "SSH administration depends on protecting private keys and preventing them from being embedded in repositories or widely distributed. Managed key storage, permissions, and rotation reduce the likelihood that stolen keys can be used for administration.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1610", "attack_object_name": "Deploy Container", "capability_group": "CIS-4", "comments": "Requiring container deployments through approved, authenticated orchestration interfaces and version-controlled manifests reduces unauthorized container creation. A compromised orchestrator account or approved pipeline may still deploy a malicious container.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1612", "attack_object_name": "Build Image on Host", "capability_group": "CIS-4", "comments": "Securing container-management APIs and restricting builds to controlled Infrastructure-as-Code or pipeline processes reduces unauthorized image construction on managed hosts. It does not prevent misuse by a compromised authorized build identity.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1651", "attack_object_name": "Cloud Administration Command", "capability_group": "CIS-4", "comments": "Version-controlled Infrastructure-as-Code and controlled cloud-administration interfaces reduce unreviewed interactive commands and restrict administration to approved mechanisms. The technique remains possible through a compromised privileged cloud account.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1677", "attack_object_name": "Poisoned Pipeline Execution", "capability_group": "CIS-4", "comments": "Version-controlled infrastructure and reviewed changes can prevent untrusted code or malicious Infrastructure-as-Code modifications from automatically reaching privileged deployment pipelines. Additional CI/CD isolation, branch protection, and secrets controls are required.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1557.001", "attack_object_name": "Name Resolution Poisoning and SMB Relay", "capability_group": "CIS-4", "comments": "SSH host-key validation, HTTPS certificate validation, SMB signing, and encrypted management channels reduce the ability to capture or relay administrative authentication. Disabling LLMNR, NBT-NS, and unnecessary SMB remains an important complementary control.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1557.002", "attack_object_name": "ARP Cache Poisoning", "capability_group": "CIS-4", "comments": "An adversary may still redirect management traffic through ARP poisoning, but properly validated SSH and HTTPS sessions protect the confidentiality and integrity of that traffic. The safeguard does not prevent the underlying ARP manipulation.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1557.003", "attack_object_name": "DHCP Spoofing", "capability_group": "CIS-4", "comments": "Secure protocols reduce credential theft and command manipulation even if DHCP spoofing redirects traffic. DHCP snooping and network-level controls are still required to prevent the spoofing behavior itself.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1565", "attack_object_name": "Data Manipulation", "capability_group": "CIS-4", "comments": "Version-controlled configuration and authenticated encrypted management channels reduce unauthorized or undetected changes to enterprise configuration. The safeguard does not protect every type of business or application data.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1565.001", "attack_object_name": "Stored Data Manipulation", "capability_group": "CIS-4", "comments": "Version-controlled Infrastructure-as-Code provides history, review, comparison, and restoration for managed configurations, reducing the persistence of unauthorized configuration changes. This applies only where the affected configuration is actually managed as code.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1563", "attack_object_name": "Remote Service Session Hijacking", "capability_group": "CIS-4", "comments": "Securely configuring remote services can reduce unnecessary sessions and restrict features that facilitate hijacking. Encryption does not prevent an adversary already executing on a system from taking control of an existing session.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1563.001", "attack_object_name": "SSH Hijacking", "capability_group": "CIS-4", "comments": "Disabling SSH agent forwarding and tightly managing SSH configuration reduces some hijacking paths. It does not prevent local theft or reuse of an established SSH socket or session.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1563.002", "attack_object_name": "RDP Hijacking", "capability_group": "CIS-4", "comments": "Secure RDP gateways and restricted administration reduce access to RDP sessions. They do not prevent a locally privileged adversary from taking control of an existing session.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1090.001", "attack_object_name": "Internal Proxy", "capability_group": "CIS-4", "comments": "Secure SSH configuration can disable unnecessary forwarding and proxy features, reducing the ability to turn a managed asset into a pivot. ", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1572", "attack_object_name": "Protocol Tunneling", "capability_group": "CIS-4", "comments": "Securely configuring SSH, VPN, and administrative tools can disable unnecessary port forwarding and tunneling functions. The safeguard does not prevent tunneling through an otherwise approved secure protocol when that capability is operationally required.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1484", "attack_object_name": "Domain or Tenant Policy Modification", "capability_group": "CIS-4", "comments": "Version-controlled domain or tenant configuration can make unauthorized policy changes visible and allow restoration to approved state. Many identity policies are still managed directly through consoles or APIs rather than Infrastructure-as-Code.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1484.001", "attack_object_name": "Group Policy Modification", "capability_group": "CIS-4", "comments": "Managing Group Policy definitions through controlled configuration processes can identify or reverse unauthorized changes. Version control does not prevent direct modification by an account that retains write access to the policy.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1578", "attack_object_name": "Modify Cloud Compute Infrastructure", "capability_group": "CIS-4", "comments": "Version-controlled Infrastructure-as-Code can define expected compute infrastructure and identify or reverse out-of-band changes. An adversary with sufficient cloud permissions may still modify resources directly.", "references": []}, {"capability_id": "CIS-4.6", "capability_description": "Securely Manage Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1578.005", "attack_object_name": "Modify Cloud Compute Configurations", "capability_group": "CIS-4", "comments": "Infrastructure-as-Code provides an approved baseline for quotas, instance settings, and compute configurations, allowing unauthorized drift to be identified or corrected.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1021", "attack_object_name": "Remote Services", "capability_group": "CIS-4", "comments": "A default-deny endpoint firewall directly restricts unsolicited remote-service connections and permits access only through explicitly approved services, ports, and management paths.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-4", "comments": "Restricting TCP 3389 to approved management sources directly prevents unauthorized RDP connections and reduces RDP-based lateral movement.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1021.002", "attack_object_name": "SMB/Windows Admin Shares", "capability_group": "CIS-4", "comments": "Blocking or tightly restricting TCP 445 and 139 directly impedes access to administrative shares and other SMB-based lateral movement paths.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1021.004", "attack_object_name": "SSH", "capability_group": "CIS-4", "comments": "A default-deny firewall can block inbound SSH or restrict TCP 22 to approved management systems, directly limiting remote access to SSH-enabled end-user devices.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1021.005", "attack_object_name": "VNC", "capability_group": "CIS-4", "comments": "VNC requires an accessible listener, commonly on TCP 5900 and related ports. Blocking those ports unless specifically authorized directly prevents unauthorized VNC access.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1021.006", "attack_object_name": "Windows Remote Management", "capability_group": "CIS-4", "comments": "Restricting TCP 5985 and 5986 to approved systems directly limits adversary use of WinRM for remote administration and lateral movement.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-4", "comments": "Exploiting a remote service requires network reachability to that service. Default-deny endpoint rules remove unnecessary exposure and can restrict necessary services to trusted source systems.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1571", "attack_object_name": "Non-Standard Port", "capability_group": "CIS-4", "comments": "Default-deny rules directly block arbitrary and unexpected ports unless they have been explicitly approved, limiting adversary communications over non-standard ports.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1021.003", "attack_object_name": "Distributed Component Object Model", "capability_group": "CIS-4", "comments": "A firewall can restrict DCOM by controlling RPC endpoint mapper traffic and dynamic RPC ports. The relationship is direct, but implementation is more complex than filtering a single fixed port.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-4", "comments": "Restrictive outbound rules can prevent an endpoint from using unapproved protocols and ports for data exfiltration. The technique remains possible over protocols the organization must allow.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1048.001", "attack_object_name": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-4", "comments": "The firewall can block unapproved encrypted protocols, ports, or destinations used for exfiltration. It generally cannot identify malicious content inside an allowed encrypted connection.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1048.002", "attack_object_name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-4", "comments": "Default-deny egress controls can prevent asymmetric encrypted sessions using unauthorized ports or services. Connections through an approved service may still succeed.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1048.003", "attack_object_name": "Exfiltration Over Unencrypted Non-C2 Protocol", "capability_group": "CIS-4", "comments": "Unapproved outbound services and ports used for cleartext exfiltration can be directly blocked. Effectiveness decreases when the adversary uses an operationally required protocol.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1071", "attack_object_name": "Application Layer Protocol", "capability_group": "CIS-4", "comments": "Endpoint firewalls can restrict which application protocols and services may communicate externally. The mapping is partial because common application protocols may need to remain available.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1071.002", "attack_object_name": "File Transfer Protocols", "capability_group": "CIS-4", "comments": "FTP, SFTP, FTPS, and related file-transfer traffic can be denied or limited to approved destinations. File transfer over a generally permitted web protocol may remain possible.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1071.003", "attack_object_name": "Mail Protocols", "capability_group": "CIS-4", "comments": "SMTP, IMAP, and POP traffic can be restricted to authorized mail infrastructure, reducing adversary use of attacker-controlled mail services for command and control.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1071.004", "attack_object_name": "DNS", "capability_group": "CIS-4", "comments": "The firewall can force devices to use approved DNS resolvers and block direct DNS traffic to external systems. It does not by itself identify malicious data embedded in DNS traffic sent through an approved resolver.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1071.005", "attack_object_name": "Publish/Subscribe Protocols", "capability_group": "CIS-4", "comments": "Default-deny policies can block MQTT and other publish/subscribe services unless they are explicitly required. An approved publish/subscribe service could still be misused.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1090.001", "attack_object_name": "Internal Proxy", "capability_group": "CIS-4", "comments": "Restricting inbound listeners and lateral outbound connections makes it more difficult for a compromised endpoint to act as an unauthorized proxy for other systems.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1095", "attack_object_name": "Non-Application Layer Protocol", "capability_group": "CIS-4", "comments": "A host firewall can deny unnecessary ICMP, GRE, raw IP, and other non-application protocols that adversaries may use for command and control.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1105", "attack_object_name": "Ingress Tool Transfer", "capability_group": "CIS-4", "comments": "Default-deny egress policies can prevent compromised endpoints from retrieving payloads from unapproved systems, ports, or protocols. Transfers from an approved destination remain possible.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1187", "attack_object_name": "Forced Authentication", "capability_group": "CIS-4", "comments": "Blocking outbound SMB, NetBIOS, and unnecessary WebDAV traffic prevents many attempts to coerce an endpoint into authenticating to an attacker-controlled system. WebDAV over permitted web ports may require application-aware filtering.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1205", "attack_object_name": "Traffic Signaling", "capability_group": "CIS-4", "comments": "Stateful default-deny firewalls can block unsolicited signaling traffic and the resulting unauthorized connections for some implementations of this technique. Effectiveness depends on the signaling mechanism.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1205.001", "attack_object_name": "Port Knocking", "capability_group": "CIS-4", "comments": "A managed firewall can prevent unauthorized knock sequences from opening services and can preserve the default-deny state. The relationship becomes weaker if malware has already obtained privileges to modify firewall rules.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1219", "attack_object_name": "Remote Access Tools", "capability_group": "CIS-4", "comments": "Application-aware or destination-restricted firewall policies can block communications to unauthorized remote-access services. Tools communicating through generally permitted HTTPS may bypass basic port filtering.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1219.002", "attack_object_name": "Remote Desktop Software", "capability_group": "CIS-4", "comments": "The firewall can block application traffic, service endpoints, or dedicated ports associated with unauthorized remote-desktop products. Effectiveness depends on whether the product uses an otherwise permitted web connection.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-4", "comments": "Blocking unnecessary local-link, legacy name-resolution, and file-sharing protocols reduces the network conditions available for several adversary-in-the-middle behaviors. Other sub-techniques require switch or network-infrastructure protections.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1557.001", "attack_object_name": "Name Resolution Poisoning and SMB Relay", "capability_group": "CIS-4", "comments": "Blocking LLMNR, NBT-NS, mDNS, NetBIOS, and unnecessary SMB traffic reduces poisoning and relay opportunities involving end-user devices. Disabling the protocols and enforcing SMB signing remain stronger complementary mitigations.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1570", "attack_object_name": "Lateral Tool Transfer", "capability_group": "CIS-4", "comments": "Restricting SMB, WinRM, SSH, VNC, and other peer-to-peer services impedes common channels used to transfer adversary tools between endpoints.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1572", "attack_object_name": "Protocol Tunneling", "capability_group": "CIS-4", "comments": "Limiting approved ports, protocols, services, and destinations can prevent many unauthorized tunnels. Tunnels encapsulated within an approved HTTPS, DNS, or SSH connection may still succeed.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1071.001", "attack_object_name": "Web Protocols", "capability_group": "CIS-4", "comments": "Destination-aware or application-aware firewall restrictions can disrupt web-based command and control, but basic port filtering cannot distinguish malicious traffic from legitimate browsing.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1090", "attack_object_name": "Proxy", "capability_group": "CIS-4", "comments": "Blocking known proxy infrastructure and unauthorized listeners can disrupt some proxy usage. Proxies operating through approved web services or destinations may remain accessible.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1090.002", "attack_object_name": "External Proxy", "capability_group": "CIS-4", "comments": "Firewall egress restrictions can block known or unauthorized external proxy destinations. External proxies commonly operate over permitted HTTP or HTTPS, limiting basic port-filtering effectiveness.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1090.003", "attack_object_name": "Multi-hop Proxy", "capability_group": "CIS-4", "comments": "Destination filtering may prevent access to identified anonymity or command-and-control infrastructure. ", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-4", "comments": "Host firewall map help when an external remote service terminates directly on the end-user device. Many VPN, VDI, and access-gateway implementations terminate on centralized infrastructure outside the endpoint firewall's control.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1197", "attack_object_name": "BITS Jobs", "capability_group": "CIS-4", "comments": "Process-aware firewall rules may restrict BITS to approved destinations. The firewall does not prevent local creation or execution of a BITS job and may not distinguish BITS traffic over allowed web ports.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1205.002", "attack_object_name": "Socket Filters", "capability_group": "CIS-4", "comments": "Stateful firewall may block the triggering traffic or resulting connection. Socket filters may observe raw traffic or reuse an already permitted protocol, limiting the safeguard's effectiveness.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1218.012", "attack_object_name": "Verclsid", "capability_group": "CIS-4", "comments": "Process-aware host firewall can prevent verclsid.exe from making outbound connections which is part of the outcomes of this technique. But it does not prevent the local signed-binary proxy-execution behavior that defines the technique.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1219.001", "attack_object_name": "IDE Tunneling", "capability_group": "CIS-4", "comments": "Firewall policy can block unapproved IDE-tunneling services or destinations. Developer endpoints may legitimately require the same HTTPS or SSH channels, reducing the usefulness of simple port filtering.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1499", "attack_object_name": "Endpoint Denial of Service", "capability_group": "CIS-4", "comments": "Host firewall can discard traffic targeting blocked ports, protocols, or identified hostile sources, reducing malicious traffic processed by the endpoint.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1499.001", "attack_object_name": "OS Exhaustion Flood", "capability_group": "CIS-4", "comments": "Dropping unwanted inbound traffic through dynamic host based firewalls may reduce some operating-system resource floods. ", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1499.002", "attack_object_name": "Service Exhaustion Flood", "capability_group": "CIS-4", "comments": "The firewall can block floods against services that do not need to be exposed or restrict permitted sources.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1499.003", "attack_object_name": "Application Exhaustion Flood", "capability_group": "CIS-4", "comments": "Application-aware or source-restricted firewall rules may reduce hostile requests reaching an exposed endpoint application. Basic port filtering cannot distinguish an exhaustion attack from legitimate requests to an explicitly allowed application service.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1537", "attack_object_name": "Transfer Data to Cloud Account", "capability_group": "CIS-4", "comments": "Destination-aware egress rules may block connections to unauthorized cloud environments. Basic port filtering cannot determine which cloud account owns an HTTPS destination, and some transfers occur entirely within the cloud.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1563", "attack_object_name": "Remote Service Session Hijacking", "capability_group": "CIS-4", "comments": "Blocking unnecessary remote-service connectivity reduces the opportunity to reach a session that could be hijacked.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1563.001", "attack_object_name": "SSH Hijacking", "capability_group": "CIS-4", "comments": "Restricting SSH reachability reduces remote paths to SSH sessions.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1563.002", "attack_object_name": "RDP Hijacking", "capability_group": "CIS-4", "comments": "Restricting RDP to approved sources limits remote access to sessions.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1021.007", "attack_object_name": "Cloud Services", "capability_group": "CIS-4", "comments": "Destination-aware or application-aware endpoint firewall can restrict access to unauthorized cloud consoles, APIs, and command-line management endpoints.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1021.008", "attack_object_name": "Direct Cloud VM Connections", "capability_group": "CIS-4", "comments": "Endpoint egress rules can prevent a compromised end-user device from reaching cloud-native VM connection services, APIs, or management endpoints. Cloud-native console access targets the cloud control plane and may not traverse the destination VM's host firewall.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1102", "attack_object_name": "Web Service", "capability_group": "CIS-4", "comments": "An application-aware or destination-restricted endpoint firewall can block unauthorized web, cloud, file-sharing, or social-media services used for command and control. ", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1102.001", "attack_object_name": "Dead Drop Resolver", "capability_group": "CIS-4", "comments": "A firewall that restricts outbound applications or destinations can prevent malware from contacting unauthorized web services used to retrieve secondary command-and-control addresses. ", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1102.002", "attack_object_name": "Bidirectional Communication", "capability_group": "CIS-4", "comments": "Blocking unauthorized web-service destinations or preventing unapproved processes from accessing the network can disrupt bidirectional command-and-control communications. ", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1102.003", "attack_object_name": "One-Way Communication", "capability_group": "CIS-4", "comments": "Endpoint firewall policy can prevent malware from sending data or retrieving instructions through unauthorized web services. One-way traffic to an approved and commonly used service may be difficult to distinguish from legitimate activity through basic port filtering.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1498", "attack_object_name": "Network Denial of Service", "capability_group": "CIS-4", "comments": "A host firewall can discard traffic targeting blocked ports, protocols, or identified hostile sources, reducing the amount of malicious traffic processed by the endpoint. ", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1498.001", "attack_object_name": "Direct Network Flood", "capability_group": "CIS-4", "comments": "A host firewall rules can block unnecessary protocols, targeted ports, or known attacking sources and may reduce endpoint resource consumption during smaller floods. High-volume floods normally require upstream filtering because traffic may saturate the connection before reaching the device.", "references": []}, {"capability_id": "CIS-4.5", "capability_description": "Implement and Manage a Firewall on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1498.002", "attack_object_name": "Reflection Amplification", "capability_group": "CIS-4", "comments": "A host firewall can drop unsolicited reflected traffic and deny unnecessary UDP protocols used in amplification attacks. It cannot recover bandwidth already consumed by the reflected traffic, and spoofed or distributed sources reduce source-based filtering effectiveness.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1021.002", "attack_object_name": "SMB/Windows Admin Shares", "capability_group": "CIS-4", "comments": "Blocking inbound SMB (TCP 445/139) is a primary server firewall function and directly reduces lateral movement via administrative shares.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-4", "comments": "Restricting TCP 3389 to authorized management hosts directly limits unauthorized RDP access to servers.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1021", "attack_object_name": "Remote Services", "capability_group": "CIS-4", "comments": "A default-deny host firewall directly restricts inbound remote service access to servers, reducing opportunities for remote administration and lateral movement.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1021.003", "attack_object_name": "Distributed Component Object Model", "capability_group": "CIS-4", "comments": "DCOM relies on RPC communications that can be restricted through host firewall rules, limiting remote DCOM access to authorized systems. Dynamic RPC ports make the effectiveness dependent on careful firewall configuration.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1021.004", "attack_object_name": "SSH", "capability_group": "CIS-4", "comments": "A default-deny server firewall can directly restrict inbound SSH, normally TCP 22, to approved management systems. This reduces unauthorized remote administration and lateral movement against Linux, macOS, and other SSH-enabled servers.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1021.005", "attack_object_name": "VNC", "capability_group": "CIS-4", "comments": "A server firewall prevents unauthorized inbound VNC connections unless the relevant service and source systems are explicitly permitted.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1021.006", "attack_object_name": "Windows Remote Management", "capability_group": "CIS-4", "comments": "Restricting WinRM ports, commonly TCP 5985 and 5986, to approved administrative systems directly limits unauthorized remote management of servers.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-4", "comments": "When outbound filtering is configured, a server firewall can block unauthorized protocols used to exfiltrate data. Effectiveness depends on whether egress rules are enforced rather than allowing unrestricted outbound traffic.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1048.001", "attack_object_name": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-4", "comments": "Outbound firewall restrictions can block unapproved encrypted non-C2 protocols or destinations used for exfiltration. The control is less effective when the traffic uses an explicitly permitted protocol and destination.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1048.002", "attack_object_name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-4", "comments": "A managed egress policy can prevent servers from establishing unapproved asymmetric encrypted connections used to transfer data. This mitigation depends on restrictive outbound rules and destination controls.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1048.003", "attack_object_name": "Exfiltration Over Unencrypted Non-C2 Protocol", "capability_group": "CIS-4", "comments": "A host firewall can block unauthorized outbound protocols and ports used for unencrypted data exfiltration. Exfiltration over an explicitly permitted service may remain possible.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1071", "attack_object_name": "Application Layer Protocol", "capability_group": "CIS-4", "comments": "Application-aware or restrictive outbound firewall rules can limit unauthorized HTTP, HTTPS, DNS, SMTP, and other application-layer communications used for command and control. A basic port-only policy provides limited protection when adversaries use permitted protocols.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1090", "attack_object_name": "Proxy", "capability_group": "CIS-4", "comments": "Restricting outbound server connections can prevent malware from reaching unauthorized proxy infrastructure or accepting proxy traffic on unapproved ports. Proxy activity over approved channels may still succeed.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1095", "attack_object_name": "Non-Application Layer Protocol", "capability_group": "CIS-4", "comments": "Host firewalls can restrict raw IP, ICMP, GRE, and other non-application-layer protocols used for command and control. The mitigation depends on denying protocols that the server does not explicitly require.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1105", "attack_object_name": "Ingress Tool Transfer", "capability_group": "CIS-4", "comments": "Restrictive outbound firewall rules can prevent a compromised server from downloading tools or payloads from unapproved external systems. The mapping is partial because transfers over approved destinations and protocols may still be possible.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-4", "comments": "A default-deny host firewall reduces the exposure of externally accessible remote services by permitting only explicitly authorized ports, protocols, and source systems.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-4", "comments": "A host firewall cannot remove vulnerabilities in a public-facing application, but it can ensure that only intended application ports are reachable and restrict access by source where operationally feasible. This reduces unnecessary exposure and possible exploitation paths.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1205.001", "attack_object_name": "Port Knocking", "capability_group": "CIS-4", "comments": "Port knocking relies on specific traffic patterns that cause a firewall or related mechanism to expose a service port. Managed default-deny rules and monitoring of unauthorized firewall changes can restrict the trigger traffic and prevent unapproved ports from being opened.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-4", "comments": "Exploitation of a remote service requires network reachability to the vulnerable service. A default-deny server firewall reduces the number of reachable services and limits access to authorized source systems.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1219", "attack_object_name": "Remote Access Tools", "capability_group": "CIS-4", "comments": "Host firewall rules can block inbound or outbound communications associated with unauthorized remote access software. The firewall does not prevent the software from being installed or executed when it communicates over an allowed channel.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1537", "attack_object_name": "Transfer Data to Cloud Account", "capability_group": "CIS-4", "comments": "Egress filtering can restrict server connections to unauthorized cloud services or accounts, making cloud-based data transfer more difficult. The mitigation depends on destination-aware outbound controls.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1557.001", "attack_object_name": "Name Resolution Poisoning and SMB Relay", "capability_group": "CIS-4", "comments": "Blocking unnecessary LLMNR, NBT-NS, mDNS, NetBIOS, and SMB traffic can reduce name-resolution poisoning and relay opportunities involving servers. Disabling the protocols and enforcing SMB signing remain stronger primary mitigations.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1557.002", "attack_object_name": "ARP Cache Poisoning", "capability_group": "CIS-4", "comments": "A host firewall may restrict follow-on connections created through ARP poisoning, but it has limited ability to prevent manipulation of Layer 2 address resolution itself. This is therefore a weak and environment-dependent mitigation.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1557.003", "attack_object_name": "DHCP Spoofing", "capability_group": "CIS-4", "comments": "A host firewall may limit some follow-on communications after a malicious DHCP configuration is accepted, but it does not directly prevent DHCP spoofing. Network access controls and DHCP protections are the primary mitigations.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1570", "attack_object_name": "Lateral Tool Transfer", "capability_group": "CIS-4", "comments": "Lateral tool transfers often rely on SMB, WinRM, SSH, or other network services that are directly governed by server firewall rules. Restricting those services to approved systems impedes common transfer channels.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1571", "attack_object_name": "Non-Standard Port", "capability_group": "CIS-4", "comments": "A default-deny firewall blocks communication over arbitrary or non-standard ports unless they are explicitly permitted, directly limiting adversary use of unexpected ports.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1572", "attack_object_name": "Protocol Tunneling", "capability_group": "CIS-4", "comments": "Restricting permitted ports, protocols, and destinations can impede protocol tunneling from compromised servers. Tunnels carried inside an explicitly allowed protocol may still bypass simple port-based filtering.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-4", "comments": "Blocking unnecessary SNMP traffic and restricting authorized SNMP sources reduces the ability to query management information from servers or server-hosted management services. The applicability depends on whether the server exposes SNMP.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1686", "attack_object_name": "Disable or Modify System Firewall", "capability_group": "CIS-4", "comments": "Adversaries may disable or alter host firewall configurations to expose services or enable unrestricted network communication, directly undermining the safeguard. Implementing and actively managing the firewall establishes the required configuration and supports identifying or correcting unauthorized changes.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1686.001", "attack_object_name": "Cloud Firewall", "capability_group": "CIS-4", "comments": "This sub-technique concerns changes to cloud firewall rules or security groups rather than a host-based firewall installed on a server. The relationship to Safeguard 4.4 is therefore indirect and primarily relevant where server firewall management also encompasses associated cloud firewall controls.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1686.002", "attack_object_name": "Network Device Firewall", "capability_group": "CIS-4", "comments": "This sub-technique targets firewalls implemented on network infrastructure rather than host-based firewalls on servers. Its relationship to Safeguard 4.4 is weak and applies only where the server firewall management process also governs supporting network firewall policy.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1686.003", "attack_object_name": "Windows Host Firewall", "capability_group": "CIS-4", "comments": "This sub-technique explicitly covers disabling or modifying the Windows host firewall, including changing profiles or rules to expose services or permit command-and-control traffic. Implementing and managing the required firewall configuration helps identify, prevent, or reverse unauthorized changes.", "references": []}, {"capability_id": "CIS-4.7", "capability_description": "Manage Default Accounts on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1586.003", "attack_object_name": "Cloud Accounts", "capability_group": "CIS-4", "comments": "Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.", "references": []}, {"capability_id": "CIS-4.7", "capability_description": "Manage Default Accounts on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1078.003", "attack_object_name": "Local Accounts", "capability_group": "CIS-4", "comments": "Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.", "references": []}, {"capability_id": "CIS-4.7", "capability_description": "Manage Default Accounts on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1078.002", "attack_object_name": "Domain Accounts", "capability_group": "CIS-4", "comments": "Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.", "references": []}, {"capability_id": "CIS-9.5", "capability_description": "Implement DMARC", "mapping_type": "mitigates", "attack_object_id": "T1667", "attack_object_name": "Email Bombing", "capability_group": "CIS-9", "comments": "ATT&CK explicitly discusses DMARC, SPF, and DKIM on the Email bombing technique page, including how enabling these mechanisms within an organization (through policies such as DMARC) may enable recipients (intra-org and cross domain) to perform similar message filtering and validation to mitigate this technique. ", "references": []}, {"capability_id": "CIS-4.7", "capability_description": "Manage Default Accounts on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1078.001", "attack_object_name": "Default Accounts", "capability_group": "CIS-4", "comments": "Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.", "references": []}, {"capability_id": "CIS-4.7", "capability_description": "Manage Default Accounts on Enterprise Assets and Software", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-4", "comments": "Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.", "references": []}, {"capability_id": "CIS-4.3", "capability_description": "Configure Automatic Session Locking on Enterprise Assets", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-4", "comments": "The safeguard forces a renewed authentication checkpoint after inactivity and therefore reduces any possibility of opportunistic use of a still-authenticated user on an open unlocked enterprise asset.", "references": []}, {"capability_id": "CIS-9.5", "capability_description": "Implement DMARC", "mapping_type": "mitigates", "attack_object_id": "T1566.002", "attack_object_name": "Spearphishing Link", "capability_group": "CIS-9", "comments": "DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains. DMARC may reduce link-led spearphishing at the sender-authentication and mail acceptance time. It does not inspect the attachment itself though. ", "references": []}, {"capability_id": "CIS-9.5", "capability_description": "Implement DMARC", "mapping_type": "mitigates", "attack_object_id": "T1566.001", "attack_object_name": "Spearphishing Attachment", "capability_group": "CIS-9", "comments": "DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains. DMARC may reduce attachment-led spearphishing when the campaign depends on spoofed sender trust and domain authentication failure. It does not inspect the attachment itself though. ", "references": []}, {"capability_id": "CIS-9.5", "capability_description": "Implement DMARC", "mapping_type": "mitigates", "attack_object_id": "T1566", "attack_object_name": "Phishing", "capability_group": "CIS-9", "comments": "DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains.", "references": []}, {"capability_id": "CIS-9.5", "capability_description": "Implement DMARC", "mapping_type": "mitigates", "attack_object_id": "T1684", "attack_object_name": "Social Engineering", "capability_group": "CIS-9", "comments": "Social engineering is broadly defined as influencing users into actions while minimizing technical indicators, DMARC can be a meaningful control against the email-spoofing branch of this broader technique. ", "references": []}, {"capability_id": "CIS-9.5", "capability_description": "Implement DMARC", "mapping_type": "mitigates", "attack_object_id": "T1684.001", "attack_object_name": "Impersonation", "capability_group": "CIS-9", "comments": "DMARC may not stop all impersonation, but it reduces a major subset where trust is created through control of the visible sender identity and aligned sending domain.", "references": []}, {"capability_id": "CIS-9.5", "capability_description": "Implement DMARC", "mapping_type": "mitigates", "attack_object_id": "T1684.002", "attack_object_name": "Email Spoofing", "capability_group": "CIS-9", "comments": "ATT&CK explicitly discusses DMARC, SPF, and DKIM on the Email Spoofing technique page, including how weak or absent DMARC leaves spoofed messages deliverable and how DMARC-enabled filtering mitigates the behavior", "references": []}, {"capability_id": "CIS-5.3", "capability_description": "Disable Dormant Accounts", "mapping_type": "mitigates", "attack_object_id": "T1078.001", "attack_object_name": "Default Accounts", "capability_group": "CIS-5", "comments": "Disabling stale accounts removes valid authentication paths available to adversaries.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-18.4", "capability_description": "Validate Security Measures", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-18", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-18.2", "capability_description": "Perform Periodic External Penetration Tests", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-18", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-18.5", "capability_description": "Perform Periodic Internal Penetration Tests", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-18", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-18.1", "capability_description": "Establish and Maintain a Penetration Testing Program", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-18", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-17.8", "capability_description": "Conduct Post-Incident Reviews", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-17", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-17.9", "capability_description": "Establish and Maintain Security Incident Thresholds", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-17", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-17.2", "capability_description": "Establish and Maintain Contact Information for Reporting Security Incidents", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-17", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-17.3", "capability_description": "Establish and Maintain an Enterprise Process for Reporting Incidents", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-17", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-17.4", "capability_description": "Establish and Maintain an Incident Response Process", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-17", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-17.5", "capability_description": "Assign Key Roles and Responsibilities", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-17", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-17.6", "capability_description": "Define Mechanisms for Communicating During Incident Response", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-17", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-17.7", "capability_description": "Conduct Routine Incident Response Exercises", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-17", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-17.1", "capability_description": "Designate Personnel to Manage Incident Handling", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-17", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-16.13", "capability_description": "Conduct Application Penetration Testing", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-16", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-16.14", "capability_description": "Conduct Threat Modeling", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-16", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-16.9", "capability_description": "Train Developers in Application Security Concepts and Secure Coding", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-16", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-16.4", "capability_description": "Establish and Manage an Inventory of Third-Party Software Components", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-16", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-16.6", "capability_description": "Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-16", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-16.2", "capability_description": "Establish and Maintain a Process to Accept and Address Software Vulnerabilities", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-16", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-15.5", "capability_description": "Assess Service Providers", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-15", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-15.6", "capability_description": "Monitor Service Providers", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-15", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-15.3", "capability_description": "Classify Service Providers", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-15", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-15.4", "capability_description": "Ensure Service Provider Contracts Include Security Requirements", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-15", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-15.2", "capability_description": "Establish and Maintain a Service Provider Management Policy", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-15", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-15.1", "capability_description": "Establish and Maintain an Inventory of Service Providers", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-15", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-16.1", "capability_description": "Establish and Maintain a Secure Application Development Process", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-16", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-14.9", "capability_description": "Conduct Role-Specific Security Awareness and Skills Training", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-14", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-14.5", "capability_description": "Train Workforce Members on Causes of Unintentional Data Exposure", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-14", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-14.6", "capability_description": "Train Workforce Members on Recognizing and Reporting Security Incidents", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-14", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-14.7", "capability_description": "Train Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-14", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-14.8", "capability_description": "Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-14", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-14.4", "capability_description": "Train Workforce on Data Handling Best Practices", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-14", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-14.3", "capability_description": "Train Workforce Members on Authentication Best Practices", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-14", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-14.1", "capability_description": "Establish and Maintain a Security Awareness Program", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-14", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-14.2", "capability_description": "Train Workforce Members to Recognize Social Engineering Attacks", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-14", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-13.6", "capability_description": "Collect Network Traffic Flow Logs", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-13", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-13.11", "capability_description": "Tune Security Event Alerting Thresholds", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-13", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-13.2", "capability_description": "Deploy a Host-Based Intrusion Detection Solution", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-13", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-13.3", "capability_description": "Deploy a Network Intrusion Detection Solution", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-13", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-13.1", "capability_description": "Centralize Security Event Alerting", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-13", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-12.4", "capability_description": "Establish and Maintain Architecture Diagram(s)", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-12", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-11.1", "capability_description": "Establish and Maintain a Data Recovery Process", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-11", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-11.5", "capability_description": "Test Data Recovery", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-11", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-10.6", "capability_description": "Centrally Manage Anti-Malware Software", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-10", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-10.2", "capability_description": "Configure Automatic Anti-Malware Signature Updates", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-10", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.10", "capability_description": "Retain Audit Logs", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.11", "capability_description": "Conduct Audit Log Reviews", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.12", "capability_description": "Collect Service Provider Logs", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.2", "capability_description": "Collect Audit Logs", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.3", "capability_description": "Ensure Adequate Audit Log Storage", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.1", "capability_description": "Establish and Maintain an Audit Log Management Process", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.4", "capability_description": "Standardize Time Synchronization", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.5", "capability_description": "Collect Detailed Audit Logs", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.6", "capability_description": "Collect DNS Query Audit Logs", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.7", "capability_description": "Collect URL Request Audit Logs", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.8", "capability_description": "Collect Command-Line Audit Logs", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-8.9", "capability_description": "Centralize Audit Logs", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-8", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-7.2", "capability_description": "Establish and Maintain a Remediation Process", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-7", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-7.5", "capability_description": "Perform Automated Vulnerability Scans of Internal Enterprise Assets", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-7", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-7.6", "capability_description": "Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-7", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-7.1", "capability_description": "Establish and Maintain a Vulnerability Management Process", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-7", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-6.6", "capability_description": "Establish and Maintain an Inventory of Authentication and Authorization Systems", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-6", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-6.7", "capability_description": "Centralize Access Control", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-6", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-6.1", "capability_description": "Establish an Access Granting Process", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-6", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-5.6", "capability_description": "Centralize Account Management", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-5", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-2.2", "capability_description": "Ensure Authorized Software is Currently Supported", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-2", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-2.4", "capability_description": "Utilize Automated Software Inventory Tools", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-2", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-2.1", "capability_description": "Establish and Maintain a Software Inventory", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-2", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-1.3", "capability_description": "Utilize an Active Discovery Tool", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-1", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-1.4", "capability_description": "Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-1", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-1.5", "capability_description": "Use a Passive Asset Discovery Tool", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-1", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-1.1", "capability_description": "Establish and Maintain Detailed Enterprise Asset Inventory", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-1", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1041", "attack_object_name": "Exfiltration Over C2 Channel", "capability_group": "CIS-4", "comments": "This technique may be mitigated depending on where ingress and egress is tightly controlled. For example, the use network signatures such as IP addresses or domain names to identify traffic for specific adversary malware can be used to mitigate activity at the network level.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1205.002", "attack_object_name": "Socket Filters", "capability_group": "CIS-4", "comments": "ATT&CK mentions that the mitigation of some variants of this technique could be achieved through the use of stateful firewalls, depending upon how it is implemented.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1552.005", "attack_object_name": "Cloud Instance Metadata API", "capability_group": "CIS-4", "comments": "ATT&CK mentions to limit access to the Instance Metadata API using a host-based firewall such as iptables. A properly configured Web Application Firewall (WAF) may help prevent external adversaries from exploiting Server-side Request Forgery (SSRF) attacks that allow access to the Cloud Instance Metadata API.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1218.012", "attack_object_name": "Verclsid", "capability_group": "CIS-4", "comments": "Consider modifying host firewall rules to prevent egress traffic from verclsid.exe.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1090.003", "attack_object_name": "Multi-hop Proxy", "capability_group": "CIS-4", "comments": "This technique may be lessened or mitigated though the use of firewall policy that constrains relay and redirect paths. ", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1197", "attack_object_name": "BITS Jobs", "capability_group": "CIS-4", "comments": "Modify network and/or host firewall rules, as well as other network controls, to only allow legitimate BITS traffic.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1205", "attack_object_name": "Traffic Signaling", "capability_group": "CIS-4", "comments": "ATT&CK mentions that the mitigation of some variants of this technique could be achieved through the use of stateful firewalls, depending upon how it is implemented.", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1071.001", "attack_object_name": "Web Protocols", "capability_group": "CIS-4", "comments": "Adversaries use web protocols to blend with normal traffic. A server firewall can partially restrict which destinations, ports, and web services a server may contact, though it will not stop all HTTP/S abuse. ", "references": []}, {"capability_id": "CIS-4.4", "capability_description": "Implement and Manage a Firewall on Servers", "mapping_type": "mitigates", "attack_object_id": "T1563.002", "attack_object_name": "RDP Hijacking", "capability_group": "CIS-4", "comments": "Adversaries leverage RDP if it is reachable. Firewall rules are among the most direct ways to prevent unauthorized RDP reachability to servers. ", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1553.005", "attack_object_name": "Mark-of-the-Web Bypass", "capability_group": "CIS-9", "comments": "Adversaries may abuse container files such as compressed/archive (.arj, .gzip) and/or disk image (.iso, .vhd) file formats to deliver malicious payloads. The execution prevention mitigation mentions the use of blocking container file types at web and/or email gateways which could apply to the implementation of this safeguard.", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1059.005", "attack_object_name": "Visual Basic", "capability_group": "CIS-9", "comments": "Adversaries may use VB payloads to execute malicious commands. Common malicious usage includes automating execution of behaviors with VBScript or embedding VBA content into spearphishing Attachment payloads. If .VB objects are blocked at the email boundary then it can mitigate the spearphishing delivery of this technique. ", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1218.001", "attack_object_name": "Compiled HTML File", "capability_group": "CIS-9", "comments": "A custom CHM file containing embedded payloads could be delivered to a victim through email then triggered by User Execution If those custom CHM files are blocked at the email boundary, then it can mitigate the delivery of this technique. ", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1137.006", "attack_object_name": "Add-ins", "capability_group": "CIS-9", "comments": "dversaries often weaponize Office add-ins (e.g., Excel .xll files or Outlook .wll / .ecf extensions) by sending them via phishing campaigns. Blocking these file types at the email boundary prevents the initial execution and subsequent installation of malicious persistence mechanisms. ", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1027.009", "attack_object_name": "Embedded Payloads", "capability_group": "CIS-9", "comments": "File blocking mitigates embedded payloads by completely stripping high-risk file types at the perimeter, denying attackers the ability to deliver the initial malicious file or its nested, obfuscated components. Attackers frequently embed malicious scripts (e.g., .js, .vbs) inside legitimate document formats (e.g., PDFs, Word docs). By blocking macro-enabled or script-based file types, gateways prevent these malicious combinations from ever reaching the user's inbox", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1027.012", "attack_object_name": "LNK Icon Smuggling", "capability_group": "CIS-9", "comments": "LNK files are used as phishing payloads and when a user invokes them they can download or execute additional payloads. If .lnk objects are blocked at the email boundary then it can mitigate the delivery of this technique. ", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1027.006", "attack_object_name": "HTML Smuggling", "capability_group": "CIS-9", "comments": "For this technique, adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files. If the implementation for 9.3 can mitigate this technique if it disallows .html, .htm, .hta, and similar active content files as email attachments on the block list. ", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1027.015", "attack_object_name": "Compression", "capability_group": "CIS-9", "comments": "9.6 can prevent this type of technique if it blocks RAR, 7z, and other known unauthorized self-extracting archive types from specific machines. ", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1204.002", "attack_object_name": "Malicious File", "capability_group": "CIS-9", "comments": "9.6 enforcement can reduce user exposure by removing risky files upstream at the point of email delivery.", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1204", "attack_object_name": "User Execution", "capability_group": "CIS-9", "comments": "9.6 enforcement can reduce user exposure by removing risky files upstream at the point of email delivery.", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1566.001", "attack_object_name": "Spearphishing Attachment", "capability_group": "CIS-9", "comments": "9.6 is a preventive email-gateway control that blocks disallowed attachment types before delivery.", "references": []}, {"capability_id": "CIS-9.6", "capability_description": "Block Unnecessary File Types", "mapping_type": "mitigates", "attack_object_id": "T1566", "attack_object_name": "Phishing", "capability_group": "CIS-9", "comments": "9.6 is a preventive email-gateway control that blocks disallowed attachment types before delivery.", "references": []}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1070.009", "attack_object_name": "Clear Persistence", "capability_group": "CIS-3", "comments": "This sub-technique removes scheduled tasks or registry keys after use. Retaining system modification logs according to enterprise timelines ensures the lifecycle of the persistence mechanism remains fully reviewable.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1070.008", "attack_object_name": "Clear Mailbox Data", "capability_group": "CIS-3", "score_category": "protect", "related_score": "T1070", "comments": "This sub-technique permanently purges emails to hide phishing or exfiltration. CIS 3.4 requires a minimum retention window for email archives, blocking adversaries from destroying corporate messaging records.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1070.007", "attack_object_name": "Clear Network Connection History and Configurations", "capability_group": "CIS-3", "score_category": "protect", "related_score": "T1070", "comments": "This sub-technique wipes local network state data and active connection logs. Enforcing retention timelines on network telemetry ensures lateral movement records survive local configuration resets.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1070.003", "attack_object_name": "Clear Command History", "capability_group": "CIS-3", "score_category": "protect", "related_score": "T1070", "comments": "This sub-technique purges terminal histories like .bash_history or PowerShell logs. Data retention policies mandate logging shell commands directly to a central repository, preserving the operational history despite local terminal purges.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1685.005", "attack_object_name": "Clear Windows Event Logs", "capability_group": "CIS-3", "score_category": "protect", "related_score": "T1685", "comments": "This technique targets local Windows security and system event logs. Enforcing a minimum retention timeline ensures Windows event data is moved off-host and preserved, defeating local log-clearing attempts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1685.006", "attack_object_name": "Clear Linux or Mac System Logs", "capability_group": "CIS-3", "score_category": "protect", "related_score": "T1685", "comments": "This technique deletes critical Unix artifacts like /var/log system logs. Documented retention processes guarantee that Unix system trails are streamed to a repository where minimum storage timelines are strictly enforced.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1070", "attack_object_name": "Indicator Removal", "capability_group": "CIS-3", "score_category": "protect", "comments": "This overarching technique covers deleting artifacts across an environment. CIS 3.4 protects the evidence chain by establishing mandatory retention periods that an attacker cannot alter or shorten.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1485", "attack_object_name": "Data Destruction", "capability_group": "CIS-3", "score_category": "protect", "comments": "Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker. Data retention policies protect against adversaries deleting logs by mandating strict storage lifecycles, off-site replication, and immutability. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1552", "attack_object_name": "Unsecured Credentials", "capability_group": "CIS-3", "score_category": "protect", "comments": "Credentials and authentication material are often stored within files, databases, configuration repositories, and application data stores. Encrypting sensitive data at rest reduces the usefulness of credential artifacts obtained from protected storage locations by preventing direct access to plaintext credential material.", "references": []}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1110.004", "attack_object_name": "Credential Stuffing", "capability_group": "CIS-5", "comments": "This directly counters password overlap from breached credentials reused across personal, third-party, and enterprise accounts.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-5.2", "capability_description": "Use Unique Passwords", "mapping_type": "mitigates", "attack_object_id": "T1078.004", "attack_object_name": "Cloud Accounts", "capability_group": "CIS-5", "comments": "Unique passwords reduce cloud/SaaS credential overlap and lateral reuse risk", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls5/"]}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1546.013", "attack_object_name": "PowerShell Profile", "capability_group": "CIS-2", "comments": "PowerShell profile persistence relies on executing a script at interpreter startup. Script allowlisting prevents unauthorized profile scripts from executing.", "references": []}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1216", "attack_object_name": "System Script Proxy Execution", "capability_group": "CIS-2", "comments": "If script payload execution is enforced regardless of invoking binary, proxy-based script execution is reduced.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1137.001", "attack_object_name": "Office Template Macros", "capability_group": "CIS-2", "comments": "Macro scripts blocked if script enforcement applies to macro execution policies.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1037", "attack_object_name": "Boot or Logon Initialization Scripts", "capability_group": "CIS-2", "comments": "Startup scripts not on the allowlist cannot execute, disrupting persistence.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1059.007", "attack_object_name": "JavaScript", "capability_group": "CIS-2", "comments": "Script enforcement blocks execution of non-authorized JavaScript files invoked via host interpreters.", "references": []}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1059.006", "attack_object_name": "Python", "capability_group": "CIS-2", "comments": "Unauthorized Python scripts are blocked when interpreter policies enforce script validation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1059.005", "attack_object_name": "Visual Basic", "capability_group": "CIS-2", "comments": "Malicious VB scripts/macros are prevented if not allowlisted.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1059.004", "attack_object_name": "Unix Shell", "capability_group": "CIS-2", "comments": "Unauthorized shell scripts fail execution when enforced through script hash/signature/path validation.", "references": []}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1059.003", "attack_object_name": "Windows Command Shell", "capability_group": "CIS-2", "comments": "Non-authorized batch or shell scripts are blocked.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1059.002", "attack_object_name": "AppleScript", "capability_group": "CIS-2", "comments": "Script allowlisting prevents execution of unauthorized AppleScript files under enforced script validation policies.", "references": []}, {"capability_id": "CIS-2.7", "capability_description": "Allowlist Authorized Scripts", "mapping_type": "mitigates", "attack_object_id": "T1059.001", "attack_object_name": "PowerShell", "capability_group": "CIS-2", "comments": "Unauthorized PowerShell scripts fail execution under enforced script allowlisting.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1546.010", "attack_object_name": "AppInit DLLs", "capability_group": "CIS-2", "comments": "Prevents unauthorized AppInit DLL persistence where load control is enforced.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1546.009", "attack_object_name": "AppCert DLLs", "capability_group": "CIS-2", "comments": "Unauthorized persistence DLLs cannot load if restricted by library allowlisting.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1574.006", "attack_object_name": "Dynamic Linker Hijacking", "capability_group": "CIS-2", "comments": "Enforced library validation prevents execution of malicious shared objects via linker abuse.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1574.012", "attack_object_name": "COR_PROFILER", "capability_group": "CIS-2", "comments": "COR_PROFILER abuse requires loading a malicious profiling DLL. Library enforcement prevents unauthorized profiler DLLs from loading into .NET processes.", "references": []}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1547.005", "attack_object_name": "Security Support Provider", "capability_group": "CIS-2", "comments": "SSP persistence requires loading a malicious authentication DLL. Load validation blocks unauthorized SSP modules from being loaded into LSASS.", "references": []}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1547.004", "attack_object_name": "Winlogon Helper DLL", "capability_group": "CIS-2", "comments": "Winlogon helper persistence relies on loading an unauthorized DLL. Library allowlisting prevents loading of non-authorized modules, directly disrupting this persistence method.", "references": []}, {"capability_id": "CIS-2.6", "capability_description": "Allowlist Authorized Libraries", "mapping_type": "mitigates", "attack_object_id": "T1574.001", "attack_object_name": "DLL", "capability_group": "CIS-2", "comments": "Unauthorized DLLs fail to load if not on the allowlist, directly mitigating search order hijacking. Side-loaded malicious libraries are blocked when load validation is enforced.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1105", "attack_object_name": "Ingress Tool Transfer", "capability_group": "CIS-2", "comments": "Transferred malware payloads cannot execute if not explicitly authorized. Control reduces operational effectiveness post-transfer.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1543", "attack_object_name": "Create or Modify System Process", "capability_group": "CIS-2", "comments": "Services relying on non-allowlisted binaries will fail to execute.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1219", "attack_object_name": "Remote Access Tools", "capability_group": "CIS-2", "comments": "Application allowlisting prevents execution of unauthorized remote access tools (e.g., AnyDesk, TeamViewer, custom RATs). If not explicitly authorized, these binaries cannot execute, directly reducing adversary persistence and command-and-control capability.", "references": []}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1218", "attack_object_name": "System Binary Proxy Execution", "capability_group": "CIS-2", "comments": "If policy restricts execution to explicitly authorized binaries, unauthorized or abused proxy binaries may be prevented from executing.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1059", "attack_object_name": "Command and Scripting Interpreter", "capability_group": "CIS-2", "comments": "If interpreters themselves are restricted or constrained by allowlisting, adversary-launched unauthorized interpreter binaries are blocked.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1204.002", "attack_object_name": "Malicious File", "capability_group": "CIS-2", "comments": "Malicious binaries fail execution if not on the allowlist.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.5", "capability_description": "Allowlist Authorized Software", "mapping_type": "mitigates", "attack_object_id": "T1204", "attack_object_name": "User Execution", "capability_group": "CIS-2", "comments": "Non-allowlisted executables cannot run, directly preventing execution of malicious binaries delivered via user interaction.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.3", "capability_description": "Address Unauthorized Software", "mapping_type": "mitigates", "attack_object_id": "T1547", "attack_object_name": "Boot or Logon Autostart Execution", "capability_group": "CIS-2", "comments": "If unauthorized startup software is identified and removed, persistence via installed startup components is disrupted.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.3", "capability_description": "Address Unauthorized Software", "mapping_type": "mitigates", "attack_object_id": "T1543.003", "attack_object_name": "Windows Service", "capability_group": "CIS-2", "comments": "Removal of unauthorized service binaries prevents continued execution of adversary-installed services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-2.3", "capability_description": "Address Unauthorized Software", "mapping_type": "mitigates", "attack_object_id": "T1543", "attack_object_name": "Create or Modify System Process", "capability_group": "CIS-2", "comments": "Automated detection and removal of unauthorized installed services can directly disrupt adversary-created system services used for persistence. Enforcement reduces persistence reliability.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls2/#25-allowlist-authorized-software"]}, {"capability_id": "CIS-3.5", "capability_description": "Securely Dispose of Data", "mapping_type": "mitigates", "attack_object_id": "T1530", "attack_object_name": "Data from Cloud Storage", "capability_group": "CIS-3", "comments": "Secure disposal reduces sensitive data retained in cloud object storage, lowering the value of compromised storage access\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/#35-securely-dispose-of-data"]}, {"capability_id": "CIS-3.5", "capability_description": "Securely Dispose of Data", "mapping_type": "mitigates", "attack_object_id": "T1552", "attack_object_name": "Unsecured Credentials", "capability_group": "CIS-3", "comments": "This applies when secure disposal explicitly removes old credential files, keys, exports, secrets, or configuration files that could expose credentials.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/#35-securely-dispose-of-data"]}, {"capability_id": "CIS-3.5", "capability_description": "Securely Dispose of Data", "mapping_type": "mitigates", "attack_object_id": "T1213", "attack_object_name": "Data from Information Repositories", "capability_group": "CIS-3", "score_category": "protect", "comments": "Secure disposal reduces stale sensitive records in repositories such as document stores, collaboration platforms, or knowledge bases.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.5", "capability_description": "Securely Dispose of Data", "mapping_type": "mitigates", "attack_object_id": "T1039", "attack_object_name": "Data from Network Shared Drive", "capability_group": "CIS-3", "score_category": "protect", "comments": "Secure disposal reduces obsolete or unnecessary sensitive data left on shared drives, limiting what an adversary can collect from network shares.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.5", "capability_description": "Securely Dispose of Data", "mapping_type": "mitigates", "attack_object_id": "T1005", "attack_object_name": "Data from Local System", "capability_group": "CIS-3", "score_category": "protect", "comments": "Secure disposal reduces residual sensitive files on endpoints and servers that an adversary could later collect from local storage.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.12", "capability_description": "Segment Data Processing and Storage Based on Sensitivity", "mapping_type": "mitigates", "attack_object_id": "T1530", "attack_object_name": "Data from Cloud Storage", "capability_group": "CIS-3", "score_category": "protect", "comments": "Segregated cloud environments reduce exposure of sensitive cloud storage resources.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.12", "capability_description": "Segment Data Processing and Storage Based on Sensitivity", "mapping_type": "mitigates", "attack_object_id": "T1021", "attack_object_name": "Remote Services", "capability_group": "CIS-3", "score_category": "protect", "comments": "Segmentation directly limits attacker movement between remote-accessible systems and sensitive environments.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1070", "attack_object_name": "Indicator Removal", "capability_group": "CIS-3", "score_category": "protect", "comments": "Data Retention restricts, hardens against, or increases visibility into the adversary behavior. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.4", "capability_description": "Enforce Data Retention", "mapping_type": "mitigates", "attack_object_id": "T1485", "attack_object_name": "Data Destruction", "capability_group": "CIS-3", "score_category": "protect", "comments": "Retention is protective because it limits the time window in which valuable data remains available for destruction, tampering, or cleanup by an attacker.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.13", "capability_description": "Deploy a Data Loss Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1537", "attack_object_name": "Transfer Data to Cloud Account", "capability_group": "CIS-3", "score_category": "protect", "comments": "DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP solutions commonly inspect and restrict uploads to external cloud services. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.13", "capability_description": "Deploy a Data Loss Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-3", "score_category": "protect", "comments": "DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP inspection capabilities may identify sensitive-data transfer across non-standard protocols.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.13", "capability_description": "Deploy a Data Loss Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1567", "attack_object_name": "Exfiltration Over Web Service", "capability_group": "CIS-3", "score_category": "protect", "comments": "DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. Web upload monitoring and restriction are core DLP use cases.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.13", "capability_description": "Deploy a Data Loss Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1052.001", "attack_object_name": "Exfiltration over USB", "capability_group": "CIS-3", "score_category": "protect", "related_score": "T1052", "comments": "DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. Device-control and removable-media DLP policies directly target USB-based exfiltration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.13", "capability_description": "Deploy a Data Loss Prevention Solution", "mapping_type": "mitigates", "attack_object_id": "T1041", "attack_object_name": "Exfiltration Over C2 Channel", "capability_group": "CIS-3", "score_category": "protect", "comments": "DLP is a direct control for blocking or alerting on exfiltration and data staging behaviors. DLP solutions explicitly monitor and restrict unauthorized outbound transfer of sensitive data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1039", "attack_object_name": "Data from Network Shared Drive", "capability_group": "CIS-3", "score_category": "protect", "comments": "Encryption protects sensitive shared-drive data against unauthorized disclosure", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1530", "attack_object_name": "Data from Cloud Storage", "capability_group": "CIS-3", "score_category": "protect", "comments": "Cloud storage encryption directly protects sensitive stored cloud data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1213", "attack_object_name": "Data from Information Repositories", "capability_group": "CIS-3", "score_category": "protect", "comments": "Repository encryption protects stored sensitive data even after unauthorized access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.11", "capability_description": "Encrypt Sensitive Data At Rest", "mapping_type": "mitigates", "attack_object_id": "T1005", "attack_object_name": "Data from Local System", "capability_group": "CIS-3", "score_category": "protect", "comments": "Encryption at rest directly reduces usability of stolen or accessed local data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.10", "capability_description": "Encrypt Sensitive Data in Transit", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-3", "score_category": "protect", "comments": "Transport encryption directly constrains interception and manipulation of communications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.10", "capability_description": "Encrypt Sensitive Data in Transit", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-3", "score_category": "protect", "comments": "Encryption in transit directly mitigates readable interception of network traffic.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.9", "capability_description": "Encrypt Data on Removable Media", "mapping_type": "mitigates", "attack_object_id": "T1052.001", "attack_object_name": "Exfiltration over USB", "capability_group": "CIS-3", "score_category": "protect", "related_score": "T1052", "comments": "Encrypting removable media directly reduces the usefulness of data exfiltrated via USB storage devices.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.9", "capability_description": "Encrypt Data on Removable Media", "mapping_type": "mitigates", "attack_object_id": "T1025", "attack_object_name": "Data from Removable Media", "capability_group": "CIS-3", "score_category": "protect", "comments": "The safeguard explicitly protects removable-media-stored data from unauthorized access.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.6", "capability_description": "Encrypt Data on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1025", "attack_object_name": "Data from Removable Media", "capability_group": "CIS-3", "score_category": "protect", "comments": "Encryption protects copied endpoint data stored on removable media from unauthorized disclosure.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.6", "capability_description": "Encrypt Data on End-User Devices", "mapping_type": "mitigates", "attack_object_id": "T1005", "attack_object_name": "Data from Local System", "capability_group": "CIS-3", "score_category": "protect", "comments": "Encryption on endpoints reduces the value of locally collected data and raises the bar for simple exfiltration after collection.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.5", "capability_description": "Securely Dispose of Data", "mapping_type": "mitigates", "attack_object_id": "T1070.004", "attack_object_name": "File Deletion", "capability_group": "CIS-3", "score_category": "protect", "related_score": "T1070", "comments": "The safeguard specifically concerns secure deletion and sanitization of residual data artifacts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.5", "capability_description": "Securely Dispose of Data", "mapping_type": "mitigates", "attack_object_id": "T1561", "attack_object_name": "Disk Wipe", "capability_group": "CIS-3", "score_category": "protect", "comments": "This control protects against attacker behaviors that destroy or overwrite data and storage media. ", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.5", "capability_description": "Securely Dispose of Data", "mapping_type": "mitigates", "attack_object_id": "T1485", "attack_object_name": "Data Destruction", "capability_group": "CIS-3", "score_category": "protect", "comments": "Secure disposal directly addresses preventing unauthorized recovery or persistence of sensitive data remnants.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.3", "capability_description": "Configure Data Access Control Lists", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-3", "score_category": "protect", "comments": "ACLs constrain which accounts can reach data and therefore directly reduce abuse of valid accounts and local data access for collection.\n", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-3.3", "capability_description": "Configure Data Access Control Lists", "mapping_type": "mitigates", "attack_object_id": "T1005", "attack_object_name": "Data from Local System", "capability_group": "CIS-3", "score_category": "protect", "comments": "The control either restricts, detects, hardens against, or increases visibility into the adversary behavior associated with this technique. The control reduces unauthorized access opportunities and raises the difficulty of account misuse.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls3/"]}, {"capability_id": "CIS-4.2", "capability_description": "Establish and Maintain a Secure Configuration Process for Network Infrastructure", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-4", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-4.1", "capability_description": "Establish and Maintain a Secure Configuration Process", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-4", "comments": "Out of scope", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1189", "attack_object_name": "Drive-by Compromise", "capability_group": "CIS-9", "comments": "CIS 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery.", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1105", "attack_object_name": "Ingress Tool Transfer", "capability_group": "CIS-9", "comments": "9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. \n\nIn practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 implementation blocks outbound traffic from machines to unapproved external destinations. Restricting access to known, trusted IP addresses and protocols can prevent attackers from downloading malicious tools or payloads onto compromised servers after gaining initial access. ", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1567.003", "attack_object_name": "Exfiltration to Text Storage Sites", "capability_group": "CIS-9", "comments": "9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. Adversaries may exfiltrate data to text storage sites instead of their primary command and control channel. If 9.3 implementation blocks unauthorized text storage sites, the technique is defensible. ", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1567.002", "attack_object_name": "Exfiltration to Cloud Storage", "capability_group": "CIS-9", "comments": "9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved sites. If 9.3 implementation blocks the URLs of unauthorized cloud storage services that are not approved by the organization then this technique is defensible. ", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1593.003", "attack_object_name": "Code Repositories", "capability_group": "CIS-9", "comments": "9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content. If 9.3 implementation blocks unapproved code repositories and repository APIs, this is applicable.", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1102.002", "attack_object_name": "Bidirectional Communication", "capability_group": "CIS-9", "comments": "If 9.3 implementation includes outbound web-service use broadly enough to block unauthorized services and risky websites, then this technique is applicable. ATT&CK describes two-way C2 via legitimate web services and again points to web proxies and blocking unauthorized external services as mitigation.", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1102.003", "attack_object_name": "One-Way Communication", "capability_group": "CIS-9", "comments": "Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise.\n\n9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content.  If 9.3 implementation includes outbound web-services used broadly enough to block unauthorized services and restrict access to unsafe websites, then this technique is defensible. ", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1102.001", "attack_object_name": "Dead Drop Resolver", "capability_group": "CIS-9", "comments": "CIS 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content. If 9.3 implementation blocks unapproved social media, code repositories, paste sites, and similar web services across enterprise HTTP/S traffic, this becomes defensible. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.\n\n", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1102", "attack_object_name": "Web Service", "capability_group": "CIS-9", "comments": "CIS 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 implementation includes certain risky or suspicious web-services used broadly enough to block unauthorized services, then this technique is applicable. ", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1204", "attack_object_name": "User Execution", "capability_group": "CIS-9", "comments": "9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 is implemented as a secure web gateway or proxy that can stop the post-click fetch/download, then this technique is applicable. ", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1204.001", "attack_object_name": "Malicious Link", "capability_group": "CIS-9", "comments": " 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 is implemented as a secure web gateway or proxy that can stop the post-click fetch/download, then this technique is applicable. ", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1566.002", "attack_object_name": "Spearphishing Link", "capability_group": "CIS-9", "comments": "9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery.", "references": []}, {"capability_id": "CIS-9.3", "capability_description": "Maintain and Enforce Network-Based URL Filters", "mapping_type": "mitigates", "attack_object_id": "T1566", "attack_object_name": "Phishing", "capability_group": "CIS-9", "comments": "9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery.", "references": []}, {"capability_id": "CIS-16.11", "capability_description": "Leverage Vetted Modules or Services for Application Security Components", "mapping_type": "mitigates", "attack_object_id": "T1574.001", "attack_object_name": "DLL", "capability_group": "CIS-16", "comments": "Use vetted platform and application security modules to validate component integrity; where applicable, include hash values in manifest files to help prevent malicious DLL side-loading.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1611-leverage-vetted-modules-or-services-for-application-security-components"]}, {"capability_id": "CIS-16.11", "capability_description": "Leverage Vetted Modules or Services for Application Security Components", "mapping_type": "mitigates", "attack_object_id": "T1550", "attack_object_name": "Use Alternate Authentication Material", "capability_group": "CIS-16", "comments": "Using vetted authentication modules or services that support token-binding protections that cryptographically bind a token to a secret can help prevent the token from being used without knowledge of the secret or possession of the device the token is tied to.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1611-leverage-vetted-modules-or-services-for-application-security-components"]}, {"capability_id": "CIS-16.11", "capability_description": "Leverage Vetted Modules or Services for Application Security Components", "mapping_type": "mitigates", "attack_object_id": "T1212", "attack_object_name": "Exploitation for Credential Access", "capability_group": "CIS-16", "comments": "Validating authentication requests using vetted platform authentication and identity management services, rather than relying on custom authentication code, can help prevent adversaries from targeting credentialing and authentication mechanisms for exploitation.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1611-leverage-vetted-modules-or-services-for-application-security-components"]}, {"capability_id": "CIS-16.11", "capability_description": "Leverage Vetted Modules or Services for Application Security Components", "mapping_type": "mitigates", "attack_object_id": "T1574", "attack_object_name": "Hijack Execution Flow", "capability_group": "CIS-16", "comments": "Use vetted platform services and trusted application security modules that validate component integrity; where applicable, include hash values in manifest files to help prevent malicious library side-loading.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1611-leverage-vetted-modules-or-services-for-application-security-components"]}, {"capability_id": "CIS-16.11", "capability_description": "Leverage Vetted Modules or Services for Application Security Components", "mapping_type": "mitigates", "attack_object_id": "T1550.001", "attack_object_name": "Application Access Token", "capability_group": "CIS-16", "comments": "Using vetted authentication modules or services that support token-binding protections that cryptographically bind a token to a secret can help prevent the token from being used without knowledge of the secret or possession of the device the token is tied to.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1611-leverage-vetted-modules-or-services-for-application-security-components"]}, {"capability_id": "CIS-16.11", "capability_description": "Leverage Vetted Modules or Services for Application Security Components", "mapping_type": "mitigates", "attack_object_id": "T1195.001", "attack_object_name": "Compromise Software Dependencies and Development Tools", "capability_group": "CIS-16", "comments": "Application developers should be cautious when selecting third-party libraries to integrate into their application. Additionally, where possible, developers should lock software dependencies to specific versions rather than pulling the latest version on build.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1611-leverage-vetted-modules-or-services-for-application-security-components"]}, {"capability_id": "CIS-16.11", "capability_description": "Leverage Vetted Modules or Services for Application Security Components", "mapping_type": "mitigates", "attack_object_id": "T1195", "attack_object_name": "Supply Chain Compromise", "capability_group": "CIS-16", "comments": "Application developers should be cautious when selecting third-party libraries to integrate into their application. Additionally, where possible, developers should lock software dependencies to specific versions rather than pulling the latest version on build.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1611-leverage-vetted-modules-or-services-for-application-security-components"]}, {"capability_id": "CIS-16.11", "capability_description": "Leverage Vetted Modules or Services for Application Security Components", "mapping_type": "mitigates", "attack_object_id": "T1496.003", "attack_object_name": "SMS Pumping", "capability_group": "CIS-16", "comments": "Using a vetted SMS/messaging service that provides and is configured with anti-abuse controls such as CAPTCHA or equivalent bot protection can help prevent adversaries from leveraging messaging services for SMS pumping.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1611-leverage-vetted-modules-or-services-for-application-security-components"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-16", "comments": "Apply secure design principles to ensure that applications do not store sensitive data or credentials insecurely (e.g. plaintext credentials in code, published credentials in repositories, or credentials in public cloud storage) to help prevent adversaries from obtaining valid accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1550", "attack_object_name": "Use Alternate Authentication Material", "capability_group": "CIS-16", "comments": "Apply secure design principles to implement token binding strategies, such as Azure AD token protection or OAuth Proof of Possession, to help prevent the token from being used by adversaries", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1593.003", "attack_object_name": "Code Repositories", "capability_group": "CIS-16", "comments": "Apply secure design principles to prevent exposure of sensitive information by ensuring credentials and API keys are not embedded in or published through public code repositories to help prevent adversaries from finding information online about victims that can be used during targeting.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1593", "attack_object_name": "Search Open Websites/Domains", "capability_group": "CIS-16", "comments": "Apply secure design principles to prevent exposure of sensitive information by ensuring credentials and API keys are not embedded in or published through public code repositories to help prevent adversaries from finding information online about victims that can be used during targeting.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1496.003", "attack_object_name": "SMS Pumping", "capability_group": "CIS-16", "comments": "Applying secure design principles by implementing CAPTCHA protection on forms that send SMS messages to help prevent adversaries from leveraging messaging services for SMS pumping.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1647", "attack_object_name": "Plist File Modification", "capability_group": "CIS-16", "comments": "Applying secure design principles through Apple developer guidance which enables hardened runtime protections for applications to help prevent adversaries from modifying property list files (plist files).", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1559.003", "attack_object_name": "XPC Services", "capability_group": "CIS-16", "comments": "Applying secure design principles by enabling the Hardened Runtime capability and not including the com.apple.security.get-task-allow entitlement with the value set to any value of true can help prevent adversaries from providing malicious content to an XPC service daemon.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1559", "attack_object_name": "Inter-Process Communication", "capability_group": "CIS-16", "comments": "Applying secure design principles by enabling the Hardened Runtime capability and not including the com.apple.security.get-task-allow entitlement with the value set to any value of true can help prevent adversaries from abusing inter-process communication (IPC) mechanisms.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1574.001", "attack_object_name": "DLL", "capability_group": "CIS-16", "comments": "Applying secure design principles to include hash values in manifest files, where possible, can help prevent adversaries from side-loading malicious dynamic-link library (DLL) files.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1574", "attack_object_name": "Hijack Execution Flow", "capability_group": "CIS-16", "comments": "Applying secure design principles to include hash values in manifest files, where possible, can help prevent adversaries from hijacking the way operating systems run programs and executing their own malicious payloads.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1564.012", "attack_object_name": "File/Path Exclusions", "capability_group": "CIS-16", "comments": "Applying secure design principles to limit custom or difficult-to-manage file and folder exclusions and use trusted, access-restricted installation paths can help prevent adversaries from hiding file-based artifacts in specific folders or filenames excluded from defensive capabilities.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1564.009", "attack_object_name": "Resource Forking", "capability_group": "CIS-16", "comments": "Applying secure design principles by using the application bundle structure and its designated /Resources folder can help prevent adversaries from abusing resource forks to hide malicious code or executables.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1564", "attack_object_name": "Hide Artifacts", "capability_group": "CIS-16", "comments": "Applying secure design principles to limit custom file and folder exclusions and installing applications only in trusted paths protected by restricted file and directory permissions can help prevent adversaries from hiding artifacts associated with their behaviors.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1212", "attack_object_name": "Exploitation for Credential Access", "capability_group": "CIS-16", "comments": "Applying secure design principles to validate authentication requests, including one-time passwords, timestamps or sequence numbers for messages sent, digital signatures, and random session keys, can help prevent adversaries from exploiting software vulnerabilities to attempt to collect credentials.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.10", "capability_description": "Apply Secure Design Principles in Application Architectures", "mapping_type": "mitigates", "attack_object_id": "T1550.001", "attack_object_name": "Application Access Token", "capability_group": "CIS-16", "comments": "Apply secure design principles to implement token binding strategies, such as Azure AD token protection or OAuth Proof of Possession, to help prevent the token from being used by adversaries", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1610-apply-secure-design-principles-in-application-architectures"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-16", "comments": "Static and dynamic application security testing can identify exploitable application weaknesses such as injection flaws, unsafe input handling, authentication defects, and other code-level vulnerabilities before or during release, reducing opportunities to exploit public-facing applications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1078", "attack_object_name": "Valid Accounts", "capability_group": "CIS-16", "comments": "Where code-level security checks scan application code, configuration, and repositories for hardcoded or otherwise insecurely stored credentials, exposed authentication material can be identified and removed before release, reducing opportunities for adversaries to obtain and abuse valid accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1195", "attack_object_name": "Supply Chain Compromise", "capability_group": "CIS-16", "comments": "Code-level security checks within the application lifecycle can identify vulnerable, malicious, or unexpected code and software components introduced through software supply-chain compromise. This relationship applies to software and development-chain compromise that can be detected through static, dynamic, dependency, integrity, or release-pipeline analysis.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1195.001", "attack_object_name": "Compromise Software Dependencies and Development Tools", "capability_group": "CIS-16", "comments": "Static analysis, dependency review, and build-pipeline security checks can identify vulnerable, unexpected, or suspicious third-party dependencies and development artifacts before they are incorporated into or released with enterprise software.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1195.002", "attack_object_name": "Compromise Software Supply Chain", "capability_group": "CIS-16", "comments": "Automated or manual code review, static and dynamic testing, and release-pipeline integrity checks can identify unexpected or malicious modifications introduced into software before the compromised build or update is distributed.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1574", "attack_object_name": "Hijack Execution Flow", "capability_group": "CIS-16", "comments": "Code-level and build-time security checks can identify unsafe executable or library search paths, missing integrity values, and other application-loading conditions that permit adversaries to hijack execution flow, allowing those weaknesses to be corrected before release.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1574.001", "attack_object_name": "DLL", "capability_group": "CIS-16", "comments": "Static and build-time checks can identify insecure DLL search behavior and verify expected library paths or manifest integrity information, reducing opportunities for malicious DLL side-loading or search-order hijacking in developed applications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1559", "attack_object_name": "Inter-Process Communication", "capability_group": "CIS-16", "comments": "For applications that use inter-process communication, code-level security checks can verify hardened runtime settings, entitlements, and IPC-related security configuration so insecure development settings that permit unauthorized process interaction can be identified before release.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1559.003", "attack_object_name": "XPC Services", "capability_group": "CIS-16", "comments": "For macOS applications using XPC services, build and code-level checks can verify hardened runtime and entitlement settings and identify insecure configurations that could allow unauthorized interaction with or abuse of XPC services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1550", "attack_object_name": "Use Alternate Authentication Material", "capability_group": "CIS-16", "comments": "Static and dynamic security checks can verify secure implementation of token handling and token-binding or proof-of-possession controls, helping identify application designs that would allow stolen authentication material to be reused without the intended cryptographic or device-bound protections.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1550.001", "attack_object_name": "Application Access Token", "capability_group": "CIS-16", "comments": "Code-level and dynamic security testing can identify insecure application access-token handling and verify token-binding or proof-of-possession protections, reducing the ability to reuse a stolen application token outside its intended security context.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1212", "attack_object_name": "Exploitation for Credential Access", "capability_group": "CIS-16", "comments": "Static and dynamic security testing can verify application controls that validate authentication requests, such as one-time values, timestamps, sequence numbers, digital signatures, or random session keys, helping identify weaknesses that could otherwise be exploited to obtain credential material.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1036.001", "attack_object_name": "Invalid Code Signature", "capability_group": "CIS-16", "comments": "Where development or release pipelines validate code signatures as part of code-level security checks, invalid, missing, or untrusted signatures can be identified before software is released, reducing opportunities to distribute or execute software that misrepresents its authenticity or provenance.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.12", "capability_description": "Implement Code-Level Security Checks", "mapping_type": "mitigates", "attack_object_id": "T1647", "attack_object_name": "Plist File Modification", "capability_group": "CIS-16", "comments": "For macOS applications, code-level and build-pipeline checks can verify hardened runtime, signing, and expected application configuration settings, helping identify insecure development conditions that could make application behavior or configuration more susceptible to malicious plist modification.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#1612-implement-code-level-security-checks"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1098", "attack_object_name": "Account Manipulation", "capability_group": "CIS-16", "comments": "Separating production and non-production environments with enforced network and administrative boundaries can restrict non-production systems and management paths from reaching production identity infrastructure, reducing opportunities to modify production accounts or authentication settings.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1098.001", "attack_object_name": "Additional Cloud Credentials", "capability_group": "CIS-16", "comments": "Separate production cloud environments, VPCs, and control-plane access paths can prevent non-production systems or administrators from reaching production identity interfaces used to add cloud credentials to existing accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1557", "attack_object_name": "Adversary-in-the-Middle", "capability_group": "CIS-16", "comments": "Network separation between production and non-production environments limits the infrastructure and traffic paths visible from either environment, reducing the scope in which an adversary can position for interception or manipulation of communications.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1557.001", "attack_object_name": "Name Resolution Poisoning and SMB Relay", "capability_group": "CIS-16", "comments": "Separating production and non-production broadcast, name-resolution, and SMB communication paths can constrain poisoning activity and prevent non-production systems from directly relaying authentication to production services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1612", "attack_object_name": "Build Image on Host", "capability_group": "CIS-16", "comments": "Production and non-production container or virtualization infrastructure can be placed behind separate gateways, firewalls, or control-plane boundaries so a compromised non-production system cannot directly reach production hosts used to build images.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1613", "attack_object_name": "Container and Resource Discovery", "capability_group": "CIS-16", "comments": "Separating production and non-production container control planes and network paths can prevent a compromised non-production workload from directly querying production container APIs, dashboards, nodes, or resource inventories.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1136", "attack_object_name": "Create Account", "capability_group": "CIS-16", "comments": "Enforced separation can restrict access from non-production systems and administrative paths to production account-management infrastructure, reducing the ability to create accounts in the production environment from a compromised non-production environment.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1136.002", "attack_object_name": "Domain Account", "capability_group": "CIS-16", "comments": "Production domain controllers and account-management services can be isolated from non-production networks so non-production systems cannot directly reach the services used to create or manage production domain accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1136.003", "attack_object_name": "Cloud Account", "capability_group": "CIS-16", "comments": "Separate production cloud environments and restricted control-plane connectivity can limit non-production access to production identity services used to create cloud accounts.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1602", "attack_object_name": "Data from Configuration Repository", "capability_group": "CIS-16", "comments": "Production configuration-management interfaces and repositories can be placed on network or management segments that are not directly reachable from non-production systems, reducing unauthorized collection of production configuration data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1602.001", "attack_object_name": "SNMP (MIB Dump)", "capability_group": "CIS-16", "comments": "Separating production management traffic from non-production networks can restrict SNMP access to approved production management systems and prevent non-production hosts from directly querying production MIB data.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1602.002", "attack_object_name": "Network Device Configuration Dump", "capability_group": "CIS-16", "comments": "Production network-device management interfaces can be isolated from non-production environments so non-production systems cannot directly access SNMP, Smart Install, or other interfaces used to retrieve production device configurations.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1565", "attack_object_name": "Data Manipulation", "capability_group": "CIS-16", "comments": "Separating production from non-production systems reduces unauthorized cross-environment access to production data and business processes, limiting the ability of a compromise in development or test infrastructure to directly manipulate production information.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1565.003", "attack_object_name": "Runtime Data Manipulation", "capability_group": "CIS-16", "comments": "Enforced production boundaries can prevent non-production systems from directly reaching production applications and runtime services, reducing opportunities to alter data while it is being processed in the production environment.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1610", "attack_object_name": "Deploy Container", "capability_group": "CIS-16", "comments": "Separate production and non-production container control planes can prevent compromised non-production systems from directly accessing production APIs or orchestrators used to deploy containers.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1482", "attack_object_name": "Domain Trust Discovery", "capability_group": "CIS-16", "comments": "Separating sensitive production identity infrastructure from non-production networks can restrict the connectivity required for systems in non-production environments to enumerate production domains and trust relationships.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1048", "attack_object_name": "Exfiltration Over Alternative Protocol", "capability_group": "CIS-16", "comments": "Firewalls and access controls between production and non-production environments can permit only required protocols and destinations, blocking unauthorized alternate-protocol transfers across the production boundary.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1048.001", "attack_object_name": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-16", "comments": "Production/non-production boundary controls can deny unapproved encrypted protocols, ports, and destinations, limiting exfiltration over symmetrically encrypted non-command-and-control channels across environments.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1048.002", "attack_object_name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol", "capability_group": "CIS-16", "comments": "Production/non-production boundary controls can restrict unapproved encrypted protocols and destinations, limiting exfiltration over asymmetrically encrypted non-command-and-control channels across environments.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1048.003", "attack_object_name": "Exfiltration Over Unencrypted Non-C2 Protocol", "capability_group": "CIS-16", "comments": "Production/non-production segmentation can block unnecessary plaintext protocols and destinations across the environment boundary, directly restricting unencrypted non-command-and-control exfiltration paths.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1190", "attack_object_name": "Exploit Public-Facing Application", "capability_group": "CIS-16", "comments": "Production services can be placed on separate hosting or security zones from non-production systems so exploitation of an exposed application does not provide unrestricted network reachability into other production resources.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1210", "attack_object_name": "Exploitation of Remote Services", "capability_group": "CIS-16", "comments": "Separating production and non-production systems with controlled network paths reduces the remote services reachable across environments and limits exploitation-based movement from a compromised non-production system into production.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1133", "attack_object_name": "External Remote Services", "capability_group": "CIS-16", "comments": "Production remote-access services can be exposed only through dedicated gateways, proxies, or approved access paths that are separate from non-production access, preventing direct remote connectivity from less-trusted environments into production.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1046", "attack_object_name": "Network Service Discovery", "capability_group": "CIS-16", "comments": "Network segmentation between production and non-production systems limits host and service reachability, reducing the production systems that can be discovered from a compromised development or test environment.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1040", "attack_object_name": "Network Sniffing", "capability_group": "CIS-16", "comments": "Separating production and non-production network segments limits the traffic, broadcasts, and multicast communications visible from either environment, reducing opportunities to capture production traffic from non-production systems.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1095", "attack_object_name": "Non-Application Layer Protocol", "capability_group": "CIS-16", "comments": "Production/non-production firewalls and gateways can restrict communication to approved interfaces and protocols, blocking unauthorized non-application-layer traffic across the environment boundary.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1571", "attack_object_name": "Non-Standard Port", "capability_group": "CIS-16", "comments": "Boundary firewalls between production and non-production environments can allow only explicitly required ports, preventing arbitrary cross-environment communication over non-standard or unauthorized ports.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1563", "attack_object_name": "Remote Service Session Hijacking", "capability_group": "CIS-16", "comments": "Restricting remote-service traffic between production and non-production security zones reduces the ability of an adversary in one environment to reach and hijack remote sessions in the other.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1563.002", "attack_object_name": "RDP Hijacking", "capability_group": "CIS-16", "comments": "Blocking unnecessary RDP traffic between production and non-production environments prevents non-production systems from directly reaching production RDP sessions that could otherwise be hijacked.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1021.001", "attack_object_name": "Remote Desktop Protocol", "capability_group": "CIS-16", "comments": "Production/non-production segmentation can restrict RDP to explicitly approved administrative paths and block ordinary cross-environment RDP connectivity.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1021.003", "attack_object_name": "Distributed Component Object Model", "capability_group": "CIS-16", "comments": "Firewall rules between production and non-production environments can restrict DCOM and RPC connectivity, reducing opportunities for remote DCOM execution across the environment boundary.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1021.006", "attack_object_name": "Windows Remote Management", "capability_group": "CIS-16", "comments": "Production systems can use separate WinRM management paths and firewall rules that permit access only from approved administrative systems, preventing general non-production systems from reaching production WinRM services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1489", "attack_object_name": "Service Stop", "capability_group": "CIS-16", "comments": "Separating production systems and supporting security or response infrastructure from non-production networks can reduce the ability of an adversary who compromises non-production systems to reach and stop critical production or defensive services.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1072", "attack_object_name": "Software Deployment Tools", "capability_group": "CIS-16", "comments": "Production deployment and management infrastructure can be isolated from non-production systems and reachable only through approved administrative paths, reducing the ability to abuse a compromised non-production deployment tool to execute software in production.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1199", "attack_object_name": "Trusted Relationship", "capability_group": "CIS-16", "comments": "Separating production and non-production environments prevents a trusted integration or relationship available in a less-restricted non-production environment from automatically providing equivalent network reachability into production.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1552.007", "attack_object_name": "Container API", "capability_group": "CIS-16", "comments": "Production container APIs can be isolated behind separate gateways, firewalls, or control-plane networks so non-production workloads cannot directly access production container interfaces that may expose credentials or sensitive configuration.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-16.8", "capability_description": "Separate Production and Non-Production Systems", "mapping_type": "mitigates", "attack_object_id": "T1669", "attack_object_name": "Wi-Fi Networks", "capability_group": "CIS-16", "comments": "Where non-production or general wireless access is separated from production network segments, enforced segmentation prevents systems that gain Wi-Fi connectivity from directly reaching sensitive production resources.", "references": ["https://cas.docs.cisecurity.org/en/latest/source/Controls16/#168-separate-production-and-non-production-systems"]}, {"capability_id": "CIS-1.2", "capability_description": "Address Unauthorized Assets", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-1", "references": []}, {"capability_id": "CIS-3.1", "capability_description": "Establish and Maintain a Data Management Process", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-3", "references": []}, {"capability_id": "CIS-3.2", "capability_description": "Establish and Maintain a Data Inventory", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-3", "references": []}, {"capability_id": "CIS-3.7", "capability_description": "Establish and Maintain a Data Classification Scheme", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-3", "references": []}, {"capability_id": "CIS-3.8", "capability_description": "Document Data Flows", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-3", "references": []}, {"capability_id": "CIS-3.14", "capability_description": "Log Sensitive Data Access", "mapping_type": "non_mappable", "attack_object_id": null, "attack_object_name": null, "capability_group": "CIS-3", "references": []}]}