CIS Controls

The CIS Critical Security Controls® (CIS Controls®) are a prioritized set of actions that collectively form a defense-in-depth set of best practices that mitigate the most common attacks against systems and networks. These mappings provide resources for assessing effective technical defenses against actual real-world threats as described in the MITRE ATT&CK® knowledge base and provide a foundation for integrating ATT&CK-based threat intelligence into the process. The connection of ATT&CK with the CIS Controls empowers threat-informed analysis and decision-making for cybersecurity control program design and implementation.

CIS Controls Versions: 8.1.2 ATT&CK Versions: 19.1 ATT&CK Domain: Enterprise

Mapping Methodology | Mapping Scope | CIS Controls (External link)

Capability Groups

ID Capability Group Name Number of Mappings Number of Capabilities
CIS-2 Inventory and Control of Software Assets 55 4
CIS-3 Data Protection 46 9
CIS-4 Secure Configuration of Enterprise Assets and Software 217 9
CIS-5 Account Management 24 3
CIS-6 Access Control Management 162 5
CIS-7 Continuous Vulnerability Management 79 3
CIS-9 Email and Web Browser Protections 91 7
CIS-10 Malware Defenses 28 5
CIS-11 Data Recovery 38 3
CIS-12 Network Infrastructure Management 72 7
CIS-13 Network Monitoring and Defense 212 6
CIS-15 Service Provider Management 3 1
CIS-16 Application Software Security 96 7
CIS-18 Penetration Testing 20 1

All Mappings

This is a very large mapping. To reduce the size, we have only downloaded the first 550 of 1,143 mappings. Load all data (1.9 MB)

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1547.006 Kernel Modules and Extensions
Comments
Adversaries load malicious kernel modules or extensions for persistence or privilege escalation. Host-based security solutions can monitor module loading, detect known rootkits or unauthorized kernel modifications, and block or alert on suspicious kernel-extension activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.006 Python
Comments
Adversaries use Python interpreters and scripts to execute malicious commands and payloads. EDR/HIPS can monitor anomalous Python execution, unusual parent-child relationships, network activity, and other suspicious behaviors, and can block or quarantine malicious payloads.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.001 PowerShell
Comments
Adversaries use PowerShell to execute commands, scripts, and payloads. EDR/HIPS can monitor PowerShell process behavior, command lines, script activity, child processes, and suspicious follow-on actions, and can block or quarantine malicious activity
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1187 Forced Authentication
Comments
Adversaries coerce systems into authenticating to attacker-controlled SMB or WebDAV resources in order to capture credential material. This control requires traffic filtering between network segments, which can block or tightly restrict SMB and WebDAV communications to untrusted or unauthorized destinations, directly preventing the outbound authentication path required by the technique.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1563.002 RDP Hijacking
Comments
Dedicated administrative workstations and segmented management networks reduce who can reach hosts carrying privileged RDP sessions and separate administrative activity from ordinary user networks. This does not prevent hijacking after the admin host itself is compromised, but it directly reduces network exposure of those sessions.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1563 Remote Service Session Hijacking
Comments
Adversaries hijack existing SSH, RDP, or other remote-management sessions. Keeping administrative sessions on dedicated, segmented resources reduces exposure of those sessions to compromised user endpoints and limits unnecessary network paths to privileged remote services.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1557 Adversary-in-the-Middle
Comments
Dedicated administrative resources are explicitly segmented from the primary enterprise network and denied Internet access. That separation reduces opportunities for adversaries on user or Internet-connected networks to position themselves between administrative systems and managed infrastructure, directly shrinking the attack surface for interception of privileged sessions.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1599.001 Network Address Translation Traversal
Comments
This sub-technique concerns traversing or bypassing network boundaries implemented through NAT and perimeter devices. Secure architecture using explicit trust zones, controlled routing, segmentation, and restricted inbound/outbound paths directly constrains the network reachability needed for NAT traversal.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1599 Network Boundary Bridging
Comments
This technique directly concerns adversaries compromising network devices to bypass segmentation and route prohibited traffic across trust boundaries. Because this control requires network segmentation and least privilege, designing and maintaining strong trust boundaries directly constrains the traffic paths the adversary is attempting to bridge. ATT&CK describes the technique specifically in terms of bypassing segmentation and boundary-device policy
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1557 Adversary-in-the-Middle
Comments
ATT&CK recommends network segmentation, traffic filtering, restricted access to network infrastructure, encryption, and network intrusion prevention for AiTM activity. Segmentation under this control reduces the network scope in which an adversary can position itself between communicating systems and restricts access to infrastructure capable of reshaping traffic
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1556.004 Network Device Authentication
Comments
This sub-technique specifically targets authentication on network devices. ATT&CK recommends MFA, privileged-account restriction, TACACS+/RADIUS, and vendor hardening; a secure network architecture that isolates the management plane and applies least-privilege administrative access directly constrains the access needed to modify network-device authentication.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1542.005 TFTP Boot
Comments
Adversaries can manipulate network-device boot configuration to load an unauthorized image from a malicious TFTP server. ATT&CK recommends limiting access to administrative interfaces, restricting insecure protocols, AAA/command authorization, and network-level filtering which are mechanisms that can be implemented as part of a secure management-plane architecture under this control.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1200 Hardware Additions
Comments
Adversaries may introduce unauthorized devices onto the network. ATT&CK recommends network access controls such as 802.1X, device certificates, and restricting DHCP to registered devices; these are architectural admission-control mechanisms that directly prevent unauthorized hardware from communicating with trusted systems.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1059.008 Network Device CLI
Comments
Adversaries use network-device CLIs to execute commands and modify device behavior. ATT&CK recommends AAA, least privilege, and command authorization such as TACACS+ to restrict which administrative commands users may execute. Because this control explicitly requires least privilege within the network architecture, this is a strong mapping when that architecture includes management-plane and command-access controls.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1021.002 SMB/Windows Admin Shares
Comments
Adversaries use SMB and administrative shares for remote access and lateral movement. A secure network architecture that enforces segmentation and least-privilege network access can restrict SMB connectivity to approved source/destination relationships, directly reducing the network reachability required for unauthorized lateral movement.
References
CIS-11.3 Protect Recovery Data mitigates T1530 Data from Cloud Storage
Comments
Adversaries collect data directly from improperly secured or compromised cloud storage. When backup or recovery data is stored in cloud object storage, this safeguard requires that recovery data be protected with controls such as encryption and separation, directly reducing unauthorized access to those backup objects
References
CIS-11.3 Protect Recovery Data mitigates T1003.003 NTDS
Comments
Adversaries may obtain NTDS.dit from Domain Controller backups rather than directly from a live Domain Controller and extract credential material from the database. This safeguard requires recovery data to receive equivalent protections, including encryption or separation, which directly restricts unauthorized access to Domain Controller backup copies containing NTDS data
References
CIS-11.2 Perform Automated Backups mitigates T1490 Inhibit System Recovery
Comments
Adversaries inhibit recovery by deleting or disabling backups, snapshots, recovery catalogs, and related recovery mechanisms. This safeguard requires automated, recurring backups of in-scope enterprise assets, ensuring that recoverable copies are created on a regular basis and thereby reducing the effectiveness of attempts to eliminate available recovery data.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1027 Obfuscated Files or Information
Comments
Anti-malware software can detect and quarantine malicious files or commands that use encoding, packing, encryption, or other obfuscation techniques to evade detection.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1027 Obfuscated Files or Information
Comments
Behavior-based anti-malware can identify malicious activity after obfuscated content is decoded, unpacked, interpreted, or executed, allowing detection or blocking based on runtime behavior rather than relying solely on static signatures.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1602 Data from Configuration Repository
Comments
When known vulnerabilities affect network-device software, system images, or management components that expose configuration repositories, applying patches or supported software upgrades removes those weaknesses and reduces vulnerability dependent access to configuration data.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1602.001 SNMP (MIB Dump)
Comments
When known vulnerabilities affect SNMP-enabled network-device software or system images, applying patches or supported software upgrades removes those weaknesses and reduces opportunities to collect MIB data through vulnerable implementations.
References
CIS-7.7 Remediate Detected Vulnerabilities mitigates T1602.002 Network Device Configuration Dump
Comments
When known vulnerabilities affect network-device software or system images used to expose or retrieve device configurations, applying patches or supported software upgrades removes those weaknesses and reduces exploit-based opportunities to obtain configuration data.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1003.006 DCSync
Comments
Role-based access control (RBAC) can restrict Active Directory replication permissions, including Replicating Directory Changes rights, to authorized administrative roles. Enforcing these permissions limits which identities can perform the directory replication operations required for DCSync.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.002 SMB/Windows Admin Shares
Comments
Role-based access control (RBAC) can restrict local administrator membership and administrative-share access to authorized roles. These enforced permissions limit the accounts that can use SMB and Windows administrative shares for remote administration and lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.006 Windows Remote Management
Comments
Role-based access control (RBAC) can restrict WinRM accounts and permissions to authorized administrative roles. Enforced WinRM permissions limit which identities can use the service for remote execution and lateral movement.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1218.007 Msiexec
Comments
Role-based access control (RBAC) can restrict execution of Msiexec.exe to privileged accounts or groups with an authorized operational need. Enforcing this entitlement reduces opportunities for adversaries to abuse Windows Installer for proxy execution.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1525 Implant Internal Image
Comments
Role-based access control (RBAC) can limit permissions to create, modify, or publish platform and container images to authorized roles. Enforcing these permissions reduces an adversary's ability to implant malicious images within enterprise repositories.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1538 Cloud Service Dashboard
Comments
Role-based access control (RBAC) can enforce least-privilege dashboard visibility so users can access only the cloud resources required for their assigned roles. This limits the information and resources exposed through a cloud service dashboard when an account is compromised.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548.002 Bypass User Account Control
Comments
Role-based access control (RBAC) can restrict local administrator membership to authorized roles. Removing unnecessary administrative rights reduces the accounts from which adversaries can leverage UAC bypass techniques to obtain elevated privileges.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548.003 Sudo and Sudo Caching
Comments
Role-based access control (RBAC) can enforce which users or groups are authorized for sudo privileges and which elevated commands they may run. Restricting these entitlements limits the identities and operations available for privilege elevation through sudo.
References
CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556.004 Network Device Authentication
Comments
Role-based access control (RBAC) can restrict network-device administrator privileges to narrowly scoped authorized roles. Enforcing least-privilege administrative access reduces the identities capable of modifying network-device authentication mechanisms.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1211 Exploitation for Stealth
Comments
Security anti-exploitation tools and applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to help mitigate some exploitation behavior to evade detection.
References
CIS-10.3 Disable Autorun and Autoplay for Removable Media mitigates T1092 Communication Through Removable Media
Comments
Disable Autoruns if it is unnecessary to help prevent adversaries from performing command and control between compromised hosts on potentially disconnected networks by using removable media to transfer commands from system to system.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.008 Network Provider DLL
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.007 Hybrid Identity
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., hybrid identity environment admin, synchronization service, cloud tenant) to patch, modify, or otherwise backdoor cloud authentication processes
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.006 Multi-Factor Authentication
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify MFA mechanisms and enable persistent access to compromised accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.005 Reversible Encryption
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials (e.g., domain/identity policy administrator, local security policy administrator) to abuse Active Directory encryption properties and gain access to credentials on Windows systems.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.004 Network Device Authentication
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to bypass of native authentication mechanisms for tenant/device management accounts on network devices.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.003 Pluggable Authentication Modules
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.002 Password Filter DLL
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to register malicious password filter dynamic link libraries (DLLs) into the authentication process.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.001 Domain Controller Authentication
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556 Modify Authentication Process
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to modify authentication processes or mechanisms.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.004 Credential Stuffing
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using credentials obtained from breach dumps to gain access to admin accounts through credential overlap.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.003 Password Spraying
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using commonly used passwords to attempt to acquire valid admin credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.002 Password Cracking
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password cracking to recover admin credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110.001 Password Guessing
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from using password guessing to access admin accounts.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1110 Brute Force
Comments
Implement multi-factor authentication (MFA) for administrative accounts to help prevent adversaries from brute forcing admin credentials.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1072 Software Deployment Tools
Comments
Implement multi-factor authentication (MFA) for administrative accounts to provide system and access isolation for critical network systems.
References
CIS-6.5 Require MFA for Administrative Access mitigates T1556.009 Conditional Access Policies
Comments
Integrate multi-factor authentication (MFA) for administrative accounts to reduce the risk of adversaries using compromised privileged credentials to disable or modify conditional access policies.
References
CIS-2.5 Allowlist Authorized Software mitigates T1059.011 Lua
Comments
Adversaries use Lua interpreters to execute Lua code. An application-control policy denying unauthorized Lua interpreters prevents those binaries from running, directly restricting Lua execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1059.006 Python
Comments
Adversaries use Python interpreters to execute malicious commands and payloads. An enforced allowlist denying Python prevents the interpreter from executing, directly removing the prerequisite for Python-based execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1176 Software Extensions
Comments
Adversaries install or use malicious browser or IDE extensions to obtain execution or persistence. The implementation to explicitly allowlists authorized extensions and blocks all others, unauthorized extensions cannot be installed or loaded, directly constraining the technique.
References
CIS-2.5 Allowlist Authorized Software mitigates T1564.003 Hidden Window
Comments
Adversaries may hide application windows while malicious programs execute. Where an unauthorized program is responsible for the hidden-window behavior, application allowlisting prevents that program from running and therefore prevents that implementation of the technique.
References
CIS-2.5 Allowlist Authorized Software mitigates T1548.004 Elevated Execution with Prompt
Comments
Adversaries may persuade users to approve elevated execution of malicious applications. If application control prevents the unapproved application from executing regardless of user approval, the malicious program cannot reach the elevation stage through this path.
References
CIS-2.5 Allowlist Authorized Software mitigates T1546.002 Screensaver
Comments
Adversaries can establish execution or persistence using malicious .scr screensaver files. Application-control rules can prevent unauthorized .scr files from executing, directly blocking the malicious executable used by the technique
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.014 MMC
Comments
Adversaries can abuse Microsoft Management Console to execute malicious content through a trusted system binary. Application allowlisting can block MMC on systems where its use is not authorized, directly preventing the executable from being used for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.013 Mavinject
Comments
Adversaries abuse mavinject.exe to inject malicious code into another process through a trusted Microsoft executable. Application allowlisting can deny execution of mavinject.exe where it is not authorized, directly preventing use of that binary for the technique.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.012 Verclsid
Comments
Adversaries abuse verclsid.exe to execute malicious COM objects through a trusted Windows binary. Application allowlisting can block verclsid.exe where it is unnecessary, directly preventing its use as the proxy executable.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.009 Regsvcs/Regasm
Comments
Adversaries use Regsvcs.exe or Regasm.exe to proxy execution of malicious .NET code. Application allowlisting can prevent these binaries from executing on systems where they are not authorized, directly preventing this execution path.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.008 Odbcconf
Comments
Adversaries abuse odbcconf.exe to execute malicious code through a trusted Windows utility. Application allowlisting can deny execution of odbcconf.exe where it is not required, directly preventing use of that proxy-execution mechanism.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.005 Mshta
Comments
Adversaries abuse mshta.exe to execute HTML application or script content through a trusted Windows binary. Application allowlisting can explicitly deny mshta.exe, preventing the executable from being used for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.004 InstallUtil
Comments
Adversaries use InstallUtil.exe to execute malicious .NET code while proxying execution through a trusted binary. Application allowlisting can block InstallUtil where it is not authorized, directly preventing use of the utility for this behavior.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.003 CMSTP
Comments
Adversaries abuse cmstp.exe to proxy execution of malicious code through a trusted Windows utility. Application allowlisting can prevent cmstp.exe from executing on systems where it is not required, directly removing the proxy-execution mechanism.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.001 Compiled HTML File
Comments
Adversaries abuse hh.exe to execute malicious compiled HTML content through a trusted Windows binary. Application allowlisting can block hh.exe where it is not authorized, preventing use of that binary for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1127.001 MSBuild
Comments
Adversaries abuse msbuild.exe to execute malicious code through a trusted Microsoft developer utility. Application allowlisting can deny execution of MSBuild on systems where it is not authorized, directly eliminating the binary used for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1059.010 AutoHotKey & AutoIT
Comments
Adversaries use AutoHotKey and AutoIT interpreters to execute automated commands and malicious scripts. Application allowlisting can block AutoHotkey.exe, AutoIt3.exe, and related unauthorized executables, directly preventing those interpreters from executing.
References
CIS-2.3 Address Unauthorized Software mitigates T1127.001 MSBuild
Comments
Adversaries abuse MSBuild to execute malicious code through a trusted developer utility. When MSBuild is unnecessary, explicitly classified as unauthorized, and removed under this safeguard, the executable required for this proxy-execution technique is eliminated.
References
CIS-2.3 Address Unauthorized Software mitigates T1059.011 Lua
Comments
Adversaries can use a Lua interpreter to execute malicious Lua commands or scripts. When Lua is unauthorized on the asset and is removed through this safeguard, the interpreter required to execute Lua code is no longer available, directly restricting the technique.
References
CIS-2.3 Address Unauthorized Software mitigates T1059.006 Python
Comments
Adversaries use installed Python interpreters to execute commands, scripts, and payloads. When Python is classified as unauthorized and removed under this safeguard, the local interpreter required for Python-based execution is eliminated, directly restricting this execution path.
References
CIS-2.3 Address Unauthorized Software mitigates T1021.005 VNC
Comments
Adversaries use VNC server software to establish remote interactive access to systems. When VNC server software is classified as unauthorized, this safeguard requires it to be removed, eliminating the VNC server endpoint required to establish the remote session.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1071.001 Web Protocols
Comments
Adversaries use HTTP or HTTPS to communicate with command-and-control infrastructure. Default-deny Internet egress on dedicated administrative resources prevents direct connections to external HTTP/S C2 infrastructure, directly disrupting the communication channel.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1105 Ingress Tool Transfer
Comments
Adversaries transfer tools and payloads onto compromised systems from external infrastructure. Dedicated administrative resources have no direct Internet access and permit file transfer only through controlled internal mechanisms, directly preventing arbitrary external payload retrieval.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1021.006 Windows Remote Management
Comments
Adversaries use WinRM to execute commands remotely and move laterally. Administrative network controls permit WinRM only over approved management paths, directly denying unauthorized WinRM connectivity.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1021.001 Remote Desktop Protocol
Comments
Adversaries use RDP for lateral movement into privileged systems. Administrative enclave ACLs restrict RDP to explicitly authorized source and destination relationships, directly preventing arbitrary RDP access into or through the enclave.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Adversaries use alternate network protocols to transfer data outside the environment. Protocol-aware egress filtering and destination restrictions in the administrative enclave directly block unauthorized alternate-protocol exfiltration channels.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1571 Non-Standard Port
Comments
Adversaries use unexpected ports for command-and-control to evade standard network restrictions. The administrative enclave permits only explicitly approved ports and denies all others, directly preventing outbound communication over unauthorized ports.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1095 Non-Application Layer Protocol
Comments
Adversaries use non-application-layer protocols for command-and-control or data transfer. The administrative enclave enforces default-deny egress with explicit protocol allowlisting, directly blocking unauthorized low-level communications.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1133 External Remote Services
Comments
Adversaries use externally accessible remote services to reach internal or privileged resources. Dedicated administrative systems are not externally reachable and accept access only through controlled administrative paths, directly preventing external remote-service access to the enclave.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1567 Exfiltration Over Web Service
Comments
Adversaries transfer stolen data to external Web services. Dedicated administrative resources have no Internet egress, directly preventing connections to the external Web destinations required by the technique.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1102 Web Service
Comments
Adversaries use external Web services as command-and-control infrastructure. Dedicated administrative systems have no direct Internet access, directly preventing them from establishing command-and-control sessions with external Web services.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1557.001 Name Resolution Poisoning and SMB Relay
Comments
Adversaries manipulate local name-resolution traffic and relay authentication to reachable services. Separating administrative systems from general-user broadcast domains and restricting SMB paths directly reduces poisoning opportunities and viable privileged relay targets.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1040 Network Sniffing
Comments
Adversaries capture traffic visible from a compromised privileged system to collect credentials or operational information. Isolating administrative resources from the primary network reduces the traffic and broadcast domains visible to those systems, directly limiting passive collection opportunities.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1046 Network Service Discovery
Comments
Adversaries probe network systems to identify accessible services and hosts. Administrative enclave segmentation restricts network visibility and reachability across the enclave boundary, directly reducing the systems and services available for discovery.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1210 Exploitation of Remote Services
Comments
Adversaries exploit vulnerable remote services on reachable systems to move laterally. Segmentation of administrative resources restricts the remote services reachable into and out of the privileged enclave, directly reducing lateral exploitation opportunities.
References
CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work mitigates T1189 Drive-by Compromise
Comments
Adversaries compromise systems when users access malicious or compromised Internet content. Dedicated administrative resources are prohibited from general Internet access, directly removing ordinary Web browsing as an initial-access path to privileged systems.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1021.006 Windows Remote Management
Comments
Adversaries may use WinRM for remote command execution and lateral movement. WinRM is not externally reachable and can only be accessed through authenticated enterprise VPN connectivity, directly restricting unauthorized remote WinRM sessions.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1021.001 Remote Desktop Protocol
Comments
Adversaries use RDP for remote access or lateral movement into enterprise systems. RDP is inaccessible directly from external networks and reachable remotely only after authenticated VPN access through approved paths, directly preventing unauthenticated external RDP connectivity.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1659 Content Injection
Comments
Adversaries can inject malicious content into network traffic through a compromised or hostile upstream communication path. VPN integrity protection prevents unauthorized modification of enterprise-bound tunneled traffic, directly blocking injected content from becoming part of the protected session.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1557 Adversary-in-the-Middle
Comments
Adversaries positioned along the remote user's network path attempt to intercept or modify enterprise communications. An authenticated VPN tunnel provides confidentiality and integrity protection, directly preventing useful interception or alteration of tunneled traffic.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1040 Network Sniffing
Comments
Adversaries capture traffic traversing untrusted remote networks to obtain sensitive enterprise information. The enterprise VPN encrypts traffic between the endpoint and enterprise gateway, directly preventing passive observers from recovering protected traffic.
References
CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure mitigates T1133 External Remote Services
Comments
Adversaries can use externally accessible remote-access services to enter enterprise networks. Requiring remote devices to authenticate through an enterprise-managed VPN and centralized AAA confines remote access to a controlled gateway, directly eliminating unmanaged direct access paths.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1542.005 TFTP Boot
Comments
Adversaries can abuse unauthenticated network-boot mechanisms to load malicious or unauthorized system images. Disabling insecure TFTP/PXE boot or restricting it to authenticated management infrastructure directly prevents unauthorized network boot operations.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1602.001 SNMP (MIB Dump)
Comments
Adversaries can query SNMP to collect network-device and topology information. Enforced SNMPv3 authentication, encryption, and management-source restrictions directly prevent unauthorized systems from successfully issuing or reading management queries.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1557.004 Evil Twin
Comments
Adversaries can deploy a rogue access point impersonating the legitimate enterprise WLAN to capture credentials or intercept communications. Managed 802.1X supplicants validate the trusted RADIUS/EAP server certificate and approved wireless profile, directly preventing endpoints from authenticating to the rogue infrastructure.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1557 Adversary-in-the-Middle
Comments
Adversaries can intercept or manipulate communications between wireless clients and enterprise infrastructure. Enterprise authentication and encrypted wireless communications provide confidentiality and integrity protections that directly constrain interception and modification.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1040 Network Sniffing
Comments
Adversaries can capture wireless network traffic to recover credentials or sensitive information. WPA2 Enterprise or stronger encryption protects wireless frames from passive observers, directly preventing useful plaintext recovery from captured traffic.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1669 Wi-Fi Networks
Comments
Adversaries can gain initial access by associating with the target organization's wireless network. Secure network management protocols like 802.1X and enterprise wireless authentication require authorized credentials or device identity before admission, directly preventing unauthorized wireless access.
References
CIS-12.6 Use of Secure Network Management and Communication Protocols mitigates T1200 Hardware Additions
Comments
Adversaries can attach rogue computers, appliances, or networking hardware to obtain enterprise network connectivity. Secure network management protocols like 802.1X requires successful user or device authentication before network admission, directly denying unauthorized hardware access.
References
CIS-12.5 Centralize Network Authentication, Authorization, and Auditing network AAA mitigates T1601.002 Downgrade System Image
Comments
Adversaries may install an older network-device image to restore vulnerable functionality or bypass newer protections. AAA authorization restricts downgrade and image-installation commands to approved roles, directly preventing unauthorized rollback operations.
References
CIS-12.5 Centralize Network Authentication, Authorization, and Auditing network AAA mitigates T1601.001 Patch System Image
Comments
Adversaries may install malicious or unauthorized network-device images to modify device operation. AAA command authorization restricts image upload and installation functions to approved administrative roles, directly preventing unauthorized system-image replacement.
References
CIS-12.5 Centralize Network Authentication, Authorization, and Auditing network AAA mitigates T1602.002 Network Device Configuration Dump
Comments
Adversaries may retrieve network-device configurations to collect topology, credentials, routes, and security policy. AAA command authorization denies configuration-display and export operations to identities without explicit permission, directly restricting configuration collection.
References
CIS-12.5 Centralize Network Authentication, Authorization, and Auditing network AAA mitigates T1686.002 Network Device Firewall
Comments
Adversaries may change firewall rules, ACLs, or security zones to weaken network restrictions. Centralized AAA authorization limits those configuration commands to approved roles, directly preventing unauthorized identities from modifying firewall policy.
References
CIS-12.5 Centralize Network Authentication, Authorization, and Auditing network AAA mitigates T1059.008 Network Device CLI
Comments
Adversaries may use network-device CLIs to execute privileged administrative commands. Centralized AAA with command-level authorization restricts which commands each identity may execute, directly preventing unauthorized CLI operations.
References
CIS-12.3 Securely Manage Network Infrastructure mitigates T1686.002 Network Device Firewall
Comments
Adversaries can alter ACLs, firewall rules, or network security zones to create unauthorized access paths. Enforced IaC/GitOps configuration management validates approved firewall state and rejects or automatically reverses unauthorized policy changes, directly disrupting the modification.
References
CIS-12.3 Securely Manage Network Infrastructure mitigates T1059.008 Network Device CLI
Comments
Adversaries can use network-device command-line interfaces to make malicious configuration changes. Enforced version-controlled Infrastructure-as-Code with direct configuration disabled or automatically reconciled prevents unauthorized CLI changes from becoming persistent device state.
References
CIS-12.3 Securely Manage Network Infrastructure mitigates T1659 Content Injection
Comments
Adversaries can inject malicious content into network communications while positioned along the traffic path. Integrity-protected SSH or HTTPS management sessions reject unauthorized modifications, directly preventing injected content from becoming part of the protected administrative session.
References
CIS-12.3 Securely Manage Network Infrastructure mitigates T1557 Adversary-in-the-Middle
Comments
Adversaries can position themselves between communicating systems to intercept or alter network traffic. Authenticated and encrypted management sessions provide confidentiality, peer authentication, and integrity protection, directly preventing useful interception or modification of administrative communications.
References
CIS-12.3 Securely Manage Network Infrastructure mitigates T1040 Network Sniffing
Comments
Adversaries can passively capture management traffic to obtain credentials, commands, or configuration information. SSH, HTTPS, and equivalent encrypted management protocols make captured administrative traffic unreadable, directly reducing the value of network sniffing.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1669 Wi-Fi Networks
Comments
Adversaries obtain initial access by connecting to an organization's wireless network. Separating wireless access networks from sensitive enterprise segments with enforced routing and firewall controls directly limits what an attacker can reach after establishing wireless connectivity.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1199 Trusted Relationship
Comments
Adversaries abuse connectivity granted to trusted third parties or external organizations to reach enterprise resources. Segmented third-party access restricts those connections to explicitly authorized services and network zones, directly preventing movement beyond the intended trust boundary.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1072 Software Deployment Tools
Comments
Adversaries abuse centralized deployment or management systems to execute software or move laterally. Placing those systems in a restricted management segment and allowing access only from approved administrative hosts directly limits unauthorized interaction with the deployment infrastructure.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Comments
Adversaries use unencrypted alternate protocols to transfer stolen data. Inter-zone and egress filtering blocks unauthorized protocols and destinations, directly disrupting the exfiltration channel.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Comments
Adversaries use asymmetrically encrypted non-C2 protocols to move data outside the environment. Network controls restrict permitted protocols and destinations, directly blocking unauthorized encrypted exfiltration channels.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Comments
Adversaries exfiltrate data through encrypted non-C2 protocols that use symmetric encryption. Enforced protocol and destination allowlists deny unauthorized encrypted outbound channels, directly preventing the required network transfer.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Adversaries exfiltrate data using protocols other than their primary command-and-control channel. Protocol-aware egress and inter-zone controls restrict communications to approved protocols and destinations, directly blocking unauthorized alternate-protocol exfiltration paths.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1571 Non-Standard Port
Comments
Adversaries communicate over unusual ports to evade expected network controls. Explicit port allowlists and default-deny inter-zone filtering block unapproved ports, directly preventing those communications from traversing protected network boundaries.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1095 Non-Application Layer Protocol
Comments
Adversaries use lower-layer protocols for command-and-control or data transfer. Deny-by-default inter-segment filtering permits only explicitly authorized protocols, directly blocking unauthorized non-application-layer communications across security boundaries.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1021.006 Windows Remote Management
Comments
Adversaries use WinRM to execute commands remotely and move laterally. Segmentation restricts WinRM connectivity to designated administrative zones and systems, directly preventing unauthorized remote WinRM sessions.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1021.003 Distributed Component Object Model
Comments
Adversaries use DCOM to remotely execute actions on accessible Windows systems. Network segmentation blocks DCOM traffic outside explicitly authorized relationships, directly restricting the network connectivity required for remote DCOM execution.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1021.001 Remote Desktop Protocol
Comments
Adversaries use RDP for remote access and lateral movement between systems. Segmentation and inter-zone ACLs permit RDP only across approved administrative paths, directly preventing unauthorized RDP connectivity between network zones.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1602.002 Network Device Configuration Dump
Comments
Adversaries retrieve network-device configurations to obtain topology, credentials, routing information, or security policy. Isolating management interfaces and permitting access only from approved administrative systems directly prevents unauthorized systems from reaching the configuration interface.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1602.001 SNMP (MIB Dump)
Comments
Adversaries query SNMP to obtain device, interface, routing, and network information. Restricting SNMP to an isolated management plane with ACLs permitting only authorized management systems directly prevents unauthorized hosts from issuing MIB queries.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1133 External Remote Services
Comments
Adversaries use externally accessible VPNs, gateways, and remote-access services to enter enterprise networks. The architecture forces external access through designated controlled gateways while denying direct connectivity to internal resources, directly restricting unauthorized remote entry paths.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1557.001 Name Resolution Poisoning and SMB Relay
Comments
Adversaries poison local name-resolution traffic and relay authentication attempts to reachable services. Layer-2/Layer-3 segmentation and SMB access restrictions constrain the poisoning domain and relay destinations, directly reducing viable poisoning and relay paths.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1040 Network Sniffing
Comments
Adversaries capture traffic visible from their network position to obtain credentials, sessions, or operational information. Segmentation reduces the broadcast domains, traffic flows, and network segments visible from a compromised system, directly limiting the traffic available for passive collection.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1046 Network Service Discovery
Comments
Adversaries probe remote systems to identify accessible hosts, ports, and services. Enforced segmentation limits probe reachability across security boundaries, directly reducing the systems and services that can be discovered.
References
CIS-12.2 Establish and Maintain a Secure Network Architecture mitigates T1210 Exploitation of Remote Services
Comments
Adversaries must reach a vulnerable remote service before exploiting it for lateral movement or execution. Network segmentation and least-privilege ACLs restrict which systems can communicate with those services, directly reducing exploitable network paths.
References
    CIS-12.1 Ensure Network Infrastructure is Up-to-Date mitigates T1601.002 Downgrade System Image
    Comments
    Adversaries downgrade network-device software to reintroduce vulnerable or weaker code. Enforced anti-rollback and approved-version controls prevent installation of older unauthorized images, directly blocking the downgrade behavior.
    References
    CIS-12.1 Ensure Network Infrastructure is Up-to-Date mitigates T1686.002 Network Device Firewall
    Comments
    Adversaries may exploit vulnerable network firewalls to gain the privileged access required to alter ACLs, zones, or firewall policy. Maintaining supported and patched firewall software removes known vulnerability-based access paths, directly reducing the adversary's ability to reach the configuration state required to modify the firewall.
    References
    CIS-12.1 Ensure Network Infrastructure is Up-to-Date mitigates T1210 Exploitation of Remote Services
    Comments
    Adversaries exploit vulnerabilities in remotely reachable services to execute code or move laterally. Updating network-device software removes known vulnerabilities from those services, directly preventing exploitation paths that depend on obsolete or vulnerable software.
    References
    CIS-12.1 Ensure Network Infrastructure is Up-to-Date mitigates T1190 Exploit Public-Facing Application
    Comments
    Adversaries exploit vulnerabilities in Internet-facing services or network-device management interfaces to gain initial access. Keeping network infrastructure on supported, current software removes known exploitable vulnerabilities, directly reducing the adversary's ability to successfully exploit those exposed services.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1561.002 Disk Structure Wipe
    Comments
    Disk structure wiping damages partitions, filesystems, or boot structures required to access a system. Recovery data stored on an isolated repository remains unaffected by those disk-level changes and can be used to rebuild the system.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1561.001 Disk Content Wipe
    Comments
    Disk content wiping destroys data on the affected storage device. An isolated recovery repository is not dependent on that disk and preserves the data needed to restore the wiped system.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1561 Disk Wipe
    Comments
    Adversaries erase disk data or structures to make systems unusable. Offline, cloud-separated, or off-site recovery copies remain outside the disk-wipe operation, directly preserving data required for restoration.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1491.002 External Defacement
    Comments
    External defacement modifies public-facing web or application content. Where an isolated recovery instance contains the affected content and configuration, known-good copies can be restored and the attacker-controlled state removed.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1491.001 Internal Defacement
    Comments
    Internal defacement changes internal application or web content visible to users. Where an isolated recovery instance preserves known-good versions of that content, the altered files or configuration can be replaced with trusted copies.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1491 Defacement
    Comments
    Adversaries alter operational or visible data to damage integrity. An isolated recovery copy preserves the trusted pre-defacement state, directly enabling restoration.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1490 Inhibit System Recovery
    Comments
    Recovery inhibition relies on eliminating backups, snapshots, or other recovery resources available to the victim. An isolated recovery instance remains outside the compromised recovery path, preventing the attacker from removing every usable recovery copy through the same access.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1486 Data Encrypted for Impact
    Comments
    Encryption for impact depends on the attacker being able to reach and modify usable data. An isolated recovery copy that is inaccessible through the compromised production path remains unencrypted and available for restoration.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1485.001 Lifecycle-Triggered Deletion
    Comments
    Lifecycle-triggered deletion relies on cloud policies automatically removing stored objects. Where the isolated recovery copy resides in a separate account, vault, or lifecycle boundary, those deletion rules do not affect the recovery copy.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1485 Data Destruction
    Comments
    Data destruction removes or overwrites production data to make it unrecoverable. An isolated recovery copy sits outside the same destructive access path, preserving data that can be restored after production copies are destroyed.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1565.001 Stored Data Manipulation
    Comments
    Stored data manipulation relies on altered data remaining authoritative or being used by downstream systems. Where the isolated recovery environment retains versioned or known-good data from before the manipulation, the modified production copy can be replaced with a trusted version.
    References
    CIS-11.4 Establish and Maintain an Isolated Instance of Recovery Data mitigates T1565 Data Manipulation
    Comments
    Adversaries manipulate data to affect operations or hide activity. An isolated recovery copy remains outside the compromised production write path, preserving a trusted version that can replace manipulated data.
    References
    CIS-11.3 Protect Recovery Data mitigates T1561.002 Disk Structure Wipe
    Comments
    Adversaries destroy file-system or partition structures to make data inaccessible. Recovery copies protected independently from the affected storage remain usable, directly enabling restoration despite destruction of the disk structure.
    References
    CIS-11.3 Protect Recovery Data mitigates T1561.001 Disk Content Wipe
    Comments
    Adversaries overwrite disk contents to eliminate stored information. Protected recovery copies remain unavailable to the local wiping operation, directly preserving recoverable versions of the destroyed data.
    References
    CIS-11.3 Protect Recovery Data mitigates T1561 Disk Wipe
    Comments
    Adversaries wipe disks to destroy data or render systems unusable. Recovery data protected on separate storage remains outside the affected disk's destructive operation, directly preserving the data required to rebuild the system.
    References
    CIS-11.3 Protect Recovery Data mitigates T1491.002 External Defacement
    Comments
    Adversaries modify externally visible content. Protected recovery copies preserve the legitimate content and enable replacement of the defaced version, directly reducing the duration and effectiveness of the attack
    References
    CIS-11.3 Protect Recovery Data mitigates T1491.001 Internal Defacement
    Comments
    Adversaries alter internally used content or systems. Protected backup copies maintain a trusted version outside the attacker's ordinary modification path, directly enabling restoration of internally defaced data
    References
    CIS-11.3 Protect Recovery Data mitigates T1491 Defacement
    Comments
    Adversaries alter content to disrupt operations or damage integrity. Protected recovery copies preserve trusted versions that remain available for restoration, directly limiting the persistence of the defacement.
    References
    CIS-11.3 Protect Recovery Data mitigates T1486 Data Encrypted for Impact
    Comments
    Encryption for impact depends on write access to the data the attacker wants to render unusable. Where recovery repositories are immutable, write-protected, or administered through separate credentials, ransomware cannot encrypt or overwrite the protected recovery copy.
    References
    CIS-11.3 Protect Recovery Data mitigates T1485.001 Lifecycle-Triggered Deletion
    Comments
    Adversaries manipulate cloud lifecycle policies or similar automation to cause stored data to be deleted. Immutable/versioned recovery storage and restricted lifecycle-policy modification preserve prior backup objects, directly preventing automated deletion from eliminating the recovery copy.
    References
    CIS-11.3 Protect Recovery Data mitigates T1485 Data Destruction
    Comments
    Data destruction depends on the attacker being able to delete or overwrite stored data. Where recovery data is held on immutable storage, deletion-protected repositories, or tightly restricted backup systems, those controls can prevent destruction of the protected copy.
    References
    CIS-11.3 Protect Recovery Data mitigates T1565.001 Stored Data Manipulation
    Comments
    Stored data manipulation changes data at rest so the altered state is trusted or used operationally. Where recovery repositories enforce immutability, integrity validation, or write restrictions, unauthorized changes to the recovery copy can be blocked or detected.
    References
    CIS-11.3 Protect Recovery Data mitigates T1565 Data Manipulation
    Comments
    Adversaries alter enterprise data to affect operations or hide activity. Integrity controls, access restrictions, and protected recovery copies preserve trusted versions that cannot be modified through ordinary production access, directly reducing the lasting effect of manipulation.
    References
    CIS-11.3 Protect Recovery Data mitigates T1490 Inhibit System Recovery
    Comments
    Recovery inhibition commonly relies on deleting, modifying, or disabling backup and recovery resources. Where recovery data is protected with immutability, write restrictions, separate credentials, or access isolation, those controls can prevent the compromised access path from removing or altering the recovery copy.
    References
    CIS-11.2 Perform Automated Backups mitigates T1565.001 Stored Data Manipulation
    Comments
    Adversaries alter data stored in files, databases, or other repositories. Automated backups preserve historical versions of the stored data, directly enabling recovery of the unmodified state.
    References
    CIS-11.2 Perform Automated Backups mitigates T1565 Data Manipulation
    Comments
    Adversaries alter data to affect decisions, processes, or system outcomes. Automated backups preserve earlier trusted versions of that data, directly enabling defenders to replace manipulated information with a known-good state.
    References
    CIS-11.2 Perform Automated Backups mitigates T1491.002 External Defacement
    Comments
    External defacement changes public-facing website or application content. Where the affected content and configuration are included in automated backups, known-good versions can be restored and the defaced state can be removed.
    References
    CIS-11.2 Perform Automated Backups mitigates T1491.001 Internal Defacement
    Comments
    Internal defacement modifies organizational web, application, or other internal content. Where that content is included in automated backups, known-good versions can replace the altered resources and shorten the duration of the defacement.
    References
    CIS-11.2 Perform Automated Backups mitigates T1491 Defacement
    Comments
    Automated backups preserve trusted versions of the modified data or content, directly enabling restoration of the pre-defacement state.
    References
    CIS-11.2 Perform Automated Backups mitigates T1485.001 Lifecycle-Triggered Deletion
    Comments
    Lifecycle-triggered deletion relies on cloud retention or lifecycle rules deleting stored objects. Where automated backups retain the same data outside the affected lifecycle policy or account, those copies survive the deletion and can be restored.
    References
    CIS-11.2 Perform Automated Backups mitigates T1561.002 Disk Structure Wipe
    Comments
    Disk structure wiping corrupts partitions, filesystems, or other structures needed to access stored data. Automated backups preserve recoverable copies independent of the damaged disk structure, directly supporting restoration.
    References
    CIS-11.2 Perform Automated Backups mitigates T1561.001 Disk Content Wipe
    Comments
    Disk content wiping destroys the data stored on an affected device. Automated backups preserve prior copies of the overwritten data, directly enabling restoration.
    References
      CIS-11.2 Perform Automated Backups mitigates T1561 Disk Wipe
      Comments
      Adversaries erase disk data or structures to render systems unusable. Automated backups preserve data outside the destroyed disk state, directly enabling restoration after the wipe.
      References
      CIS-11.2 Perform Automated Backups mitigates T1486 Data Encrypted for Impact
      Comments
      Ransomware and similar impact activity encrypt accessible production data to deny legitimate use. Automated backups preserve recoverable copies from before encryption, directly reducing the attacker's ability to make the encrypted data permanently unavailable.
      References
        CIS-11.2 Perform Automated Backups mitigates T1485 Data Destruction
        Comments
        Adversaries destroy data to impair operations or deny access to information. Automated backups preserve earlier copies of the affected data, directly enabling restoration and reducing the operational effectiveness of the destruction.
        References
        CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1565.001 Stored Data Manipulation
        Comments
        Adversaries modify stored data to affect outcomes or conceal activity. At-rest encryption may hinder offline manipulation where the adversary lacks the decryption key, but it does not prevent modification through an authorized application, database write access, or transparently decrypted storage
        References
        CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1565 Data Manipulation
        Comments
        Adversaries insert, delete, or manipulate data to influence outcomes or conceal activity. Encrypting sensitive data at rest can prevent an adversary who lacks the decryption capability from understanding the protected content sufficiently to perform targeted or meaningful modifications, reducing the effectiveness of the manipulation.
        References
        CIS-2.6 Allowlist Authorized Libraries mitigates T1553.003 SIP and Trust Provider Hijacking
        Comments
        Trust Provider Hijacking can replace or introduce malicious DLLs used by Windows trust-validation mechanisms. Where these libraries are governed, allowlisting approved trust-provider DLLs can directly prevent unauthorized components from loading.
        References
          CIS-2.6 Allowlist Authorized Libraries mitigates T1505.004 IIS Components
          Comments
          Malicious IIS components commonly use ISAPI extensions, filters, or modules implemented as DLLs loaded by IIS worker processes. Where library allowlisting governs IIS library loads, blocking unauthorized DLLs directly prevents those malicious components from loading.
          References
            CIS-2.6 Allowlist Authorized Libraries mitigates T1547.008 LSASS Driver
            Comments
            LSASS Driver persistence relies on malicious DLLs or LSA plug-ins being loaded into the LSASS process. Library allowlisting can prevent unauthorized libraries from loading into LSASS, directly disrupting this persistence mechanism.
            References
              CIS-2.6 Allowlist Authorized Libraries mitigates T1547.002 Authentication Package
              Comments
              Authentication Package persistence relies on a malicious authentication DLL being loaded by the Windows authentication subsystem. Where these DLLs are subject to allowlisting, unauthorized authentication packages can be blocked at load time.
              References
                CIS-2.6 Allowlist Authorized Libraries mitigates T1546.006 LC_LOAD_DYLIB Addition
                Comments
                LC_LOAD_DYLIB abuse causes a modified Mach-O binary to load an attacker-controlled dylib. Where macOS libraries are covered by the allowlist, blocking the unauthorized dylib directly limits this technique.
                References
                  CIS-2.6 Allowlist Authorized Libraries mitigates T1129 Shared Modules
                  Comments
                  Adversaries load DLLs, shared objects, and other modules into processes to execute malicious code. Library allowlisting directly restricts this behavior by permitting only approved modules to load.
                  References
                    CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1535 Unused/Unsupported Cloud Regions
                    Comments
                    Apply cloud configuration baselines that deactivate unused regions to reduce unmanaged cloud attack surface and help prevent adversaries from creating cloud instances in unused geographic service regions in order to evade detection.
                    References
                      CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1537 Transfer Data to Cloud Account
                      Comments
                      Apply cloud service configuration templates that restrict or disable external data sharing and limit sharing to authorized users or domains to help prevent adversaries from exfiltrating data by transferring the data.
                      References
                        CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1666 Modify Cloud Resource Hierarchy
                        Comments
                        Use standard cloud hardening templates to block unauthorized subscription transfers in Azure and prevent use of the AWS LeaveOrganization API through Service Control Policies to help prevent adversaries from modifying hierarchical structures in infrastructure-as-a-service (IaaS) environments.
                        References
                          CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1689 Downgrade Attack
                          Comments
                          Apply hardened web server templates that implement policies on internal web servers, such HTTP Strict Transport Security, that enforce the use of HTTPS/network traffic encryption to prevent insecure connections.
                          References
                            CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1677 Poisoned Pipeline Execution
                            Comments
                            Use standard hardening templates for continuous integration / continuous development (CI/CD) infrastructure that block unreviewed code execution, isolate untrusted builds, restrict secret access, and prohibit unsafe pipeline triggers to help prevent adversaries from manipulating CI/CD processes.
                            References
                              CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1685 Disable or Modify Tools
                              Comments
                              Apply controlled baseline configurations and change management for security-related forwarding mechanisms and firewall rules to help prevent disabling, degrading, or tampering with security tools or applications.
                              References
                                CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1590.002 DNS
                                Comments
                                Use standard hardening templates for DNS servers to implement zone transfer policies that permit zone transfers only to validated servers to help prevent adversaries from gathering DNS information.
                                References
                                  CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1213 Data from Information Repositories
                                  Comments
                                  Apply standard, industry-recommended hardening templates that enforce information repository data retention, archival, and deletion settings to limit accessible data.
                                  References
                                    CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1213.006 Databases
                                    Comments
                                    Apply standard, industry-recommended databases hardening templates that enforce information repository data retention, archival, and deletion settings to limit accessible data.
                                    References
                                      CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1213.004 Customer Relationship Management Software
                                      Comments
                                      Apply standard, industry-recommended customer relationship management software hardening templates that enforce data retention, archival, and deletion settings to limit accessible data.
                                      References
                                        CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1602.001 SNMP (MIB Dump)
                                        Comments
                                        Use standard hardening templates for application infrastructure components to allowlist MIB objects and implement SNMP views, restricting access to configuration information.
                                        References
                                          CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1543 Create or Modify System Process
                                          Comments
                                          Use standard hardening templates for application infrastructure components to allowlist MIB objects and implement SNMP views, restricting access to configuration information.
                                          References
                                            CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1602 Data from Configuration Repository
                                            CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1602.002 Network Device Configuration Dump
                                            Comments
                                            Use standard hardening templates to allowlist MIB objects, implement SNMP views, and disable Smart Install when it is not used, reducing exposure of network-device configuration data.
                                            References
                                              CIS-16.7 Use Standard Hardening Configuration Templates for Application Infrastructure mitigates T1543.005 Container Service
                                              Comments
                                              Using standard, industry-recommended hardening templates for cloud containers to enforce the use of container services in rootless mode can help mitigate the effects of adversaries creating or modifying system-level processes.
                                              References
                                                CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components mitigates T1195.001 Compromise Software Dependencies and Development Tools
                                                Comments
                                                Selecting and maintaining trusted software components helps prevent integration of malicious or compromised libraries, packages, and software.
                                                References
                                                  CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components mitigates T1195 Supply Chain Compromise
                                                  Comments
                                                  Selecting and maintaining trusted software components helps prevent integration of malicious or compromised libraries, packages, and software.
                                                  References
                                                    CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components mitigates T1195.002 Compromise Software Supply Chain
                                                    Comments
                                                    Selecting and maintaining trusted software components helps prevent integration of malicious or compromised libraries, packages, and software.
                                                    References
                                                      CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities mitigates T1212 Exploitation for Credential Access
                                                      Comments
                                                      Application developers can use root-cause analysis to identify and remediate recurring authentication-validation weaknesses, such as missing replay protections, weak session controls, or flawed request validation. This reduces opportunities for adversaries to replay authentication messages, impersonate authorized parties, and conduct exploitation for credential access.
                                                      References
                                                        CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities mitigates T1195.001 Compromise Software Dependencies and Development Tools
                                                        Comments
                                                        Application developers should exercise caution when selecting and integrating third-party libraries, using root-cause analysis of identified vulnerabilities to strengthen dependency-selection and management practices. This helps prevent supply-chain compromise through vulnerable or malicious software dependencies and development tools.
                                                        References
                                                          CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities mitigates T1195 Supply Chain Compromise
                                                          Comments
                                                          Application developers should exercise caution when selecting and integrating third-party libraries, using root-cause analysis of identified vulnerabilities to strengthen dependency-selection and management practices. This helps prevent supply chain compromise through vulnerable or malicious software dependencies and development tools.
                                                          References
                                                            CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities mitigates T1078 Valid Accounts
                                                            Comments
                                                            Application developers can use root cause analysis to address code or build process practices that expose credentials to ensure that applications do not store sensitive data or credentials insecurely.
                                                            References
                                                              CIS-15.7 Securely Decommission Service Providers mitigates T1072 Software Deployment Tools
                                                              Comments
                                                              Securely decommissioning service providers with service accounts or other access to software deployment, endpoint management, or configuration management platforms prevents residual provider access from being abused through these centralized software suites.
                                                              References
                                                                CIS-15.7 Securely Decommission Service Providers mitigates T1199 Trusted Relationship
                                                                Comments
                                                                Remove accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party and if the party is compromised by an adversary.
                                                                References
                                                                  CIS-15.7 Securely Decommission Service Providers mitigates T1078 Valid Accounts
                                                                  Comments
                                                                  Disabling provider user and service accounts and revoking associated credentials, tokens, and access permissions prevents residual provider identities from being abused by adversaries to access enterprise resources.
                                                                  References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1659 Content Injection
                                                                    Comments
                                                                    Application-layer filtering can block uncommon, unauthorized, or malicious content and transferred file types at web proxies, application gateways, or similar inspection points before the content reaches protected systems.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1555.003 Credentials from Web Browsers
                                                                    Comments
                                                                    Web filtering and application-layer gateways can block malicious web content and destinations used to deliver browser-based credential theft or session-stealing content.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1189 Drive-by Compromise
                                                                    Comments
                                                                    Web proxies and application-layer gateways can prevent access to known malicious or unnecessary websites and block malicious web content used to compromise users through drive-by activity.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1568 Dynamic Resolution
                                                                    Comments
                                                                    DNS filtering and sinkholing can prevent systems from resolving domains associated with dynamically changing adversary command-and-control infrastructure.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1568.002 Domain Generation Algorithms
                                                                    Comments
                                                                    DNS filtering and sinkholing can block domains generated by known domain-generation algorithms when those domains or generation patterns can be identified.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1567 Exfiltration Over Web Service
                                                                    Comments
                                                                    Web proxies and application-layer gateways can restrict which external web services are permitted, reducing unauthorized use of web services for data exfiltration.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1567.001 Exfiltration to Code Repository
                                                                    Comments
                                                                    Application-layer filtering can block or restrict access to unauthorized external code repositories, limiting their use as destinations for data exfiltration.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1567.002 Exfiltration to Cloud Storage
                                                                    Comments
                                                                    Application-layer filtering can block or restrict access to unauthorized cloud-storage services, limiting their use as destinations for data exfiltration.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1567.003 Exfiltration to Text Storage Sites
                                                                    Comments
                                                                    Application-layer filtering can block or restrict access to unauthorized text-storage and paste services, limiting their use as destinations for data exfiltration.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1133 External Remote Services
                                                                    Comments
                                                                    Application-layer firewalls and proxies can restrict access to unauthorized remote-access services, anonymization services, and other external services used to access enterprise resources.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1566 Phishing
                                                                    Comments
                                                                    Application-layer filtering can block malicious websites, links, attachments, and other web or email content used in phishing activity before that content reaches users.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1566.001 Spearphishing Attachment
                                                                    Comments
                                                                    Mail and application-layer gateways can inspect and block dangerous attachment types, malicious archives, and other suspicious content delivered through spearphishing attachments.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1566.002 Spearphishing Link
                                                                    Comments
                                                                    Web proxies and application-layer gateways can block access to malicious or unnecessary websites reached through spearphishing links.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1566.003 Spearphishing via Service
                                                                    Comments
                                                                    Application-layer filtering can restrict access to personal webmail, social media, and other external services that may be abused to deliver spearphishing messages.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1539 Steal Web Session Cookie
                                                                    Comments
                                                                    Web filtering and application-layer gateways can block malicious content or destinations used to deliver browser-based session-cookie theft activity.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1218 System Binary Proxy Execution
                                                                    Comments
                                                                    Application-layer filtering can restrict malicious sites, downloads, attachments, and scripts that may deliver payloads later executed through trusted system binaries.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1218.001 Compiled HTML File
                                                                    Comments
                                                                    Application-layer filtering can block CHM and other uncommon or risky file types in transit, reducing delivery of content that may be executed through Compiled HTML Help.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1204 User Execution
                                                                    Comments
                                                                    Application-layer filtering can prevent malicious web or email content from reaching users, reducing opportunities for users to execute or interact with adversary-delivered content.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1204.001 Malicious Link
                                                                    Comments
                                                                    Web proxies and application-layer gateways can block requests to malicious links and prevent associated content from being downloaded.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1204.004 Malicious Copy and Paste
                                                                    Comments
                                                                    Application-layer filtering can block malicious web content or destinations used to provide commands, scripts, or other content that users are instructed to copy and execute.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1102 Web Service
                                                                    Comments
                                                                    Web proxies and application-layer gateways can restrict access to unauthorized external web services, limiting their use for adversary command and control.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1102.001 Dead Drop Resolver
                                                                    Comments
                                                                    Application-layer filtering can block access to unauthorized web services used as dead-drop resolvers for adversary command-and-control infrastructure.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1102.002 Bidirectional Communication
                                                                    Comments
                                                                    Application-layer filtering can block unauthorized web services used for bidirectional command-and-control communications.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1102.003 One-Way Communication
                                                                    Comments
                                                                    Application-layer filtering can block unauthorized web services used for one-way command-and-control communications.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1071 Application Layer Protocol
                                                                    Comments
                                                                    Application-aware gateways can inspect and restrict unauthorized application-layer protocols, services, and destinations used for adversary command and control.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1071.001 Web Protocols
                                                                    Comments
                                                                    Web proxies and application-layer firewalls can inspect and restrict HTTP and HTTPS traffic to unauthorized or malicious destinations.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1071.002 File Transfer Protocols
                                                                    Comments
                                                                    Application-layer filtering can restrict FTP, SFTP, and related file-transfer protocol traffic to approved services and destinations.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1071.003 Mail Protocols
                                                                    Comments
                                                                    Application-layer filtering can restrict SMTP, IMAP, POP3, and related mail-protocol traffic to approved infrastructure and expected communication paths.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1071.004 DNS
                                                                    Comments
                                                                    DNS proxies and filtering services can block malicious domains and restrict systems to approved name-resolution services.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1071.005 Publish/Subscribe Protocols
                                                                    Comments
                                                                    Application-aware filtering can restrict publish/subscribe protocols to approved brokers, destinations, and expected service ports.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1048 Exfiltration Over Alternative Protocol
                                                                    Comments
                                                                    Application proxies and gateways can require use of approved protocol services and restrict unauthorized application-layer protocols or destinations used for data exfiltration.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
                                                                    Comments
                                                                    Application-layer gateways can restrict symmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
                                                                    Comments
                                                                    Application-layer gateways can restrict asymmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
                                                                    Comments
                                                                    Application-layer filtering can directly restrict unencrypted non-command-and-control protocols to approved services and destinations.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1190 Exploit Public-Facing Application
                                                                    Comments
                                                                    Web application firewalls and application-layer gateways can inspect inbound application requests and block known malicious request patterns or exploit payloads targeting public-facing applications.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1187 Forced Authentication
                                                                    Comments
                                                                    Application and protocol filtering can block outbound WebDAV and related requests that may be abused to force systems to authenticate to attacker-controlled resources.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1105 Ingress Tool Transfer
                                                                    Comments
                                                                    Web proxies and application-layer gateways can block unauthorized downloads, file-transfer services, and malicious content used to transfer adversary tools into the environment.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1572 Protocol Tunneling
                                                                    Comments
                                                                    Application-aware filtering can identify and restrict unauthorized tunneling through otherwise permitted application protocols and services.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1090 Proxy
                                                                    Comments
                                                                    Application-layer gateways can block known anonymization services, unauthorized proxy services, and other proxy destinations used to conceal adversary communications.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1090.003 Multi-hop Proxy
                                                                    Comments
                                                                    Application-layer gateways can restrict known anonymization and proxy services that may be chained together to form multi-hop proxy infrastructure.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1219 Remote Access Tools
                                                                    Comments
                                                                    Application firewalls and proxies can restrict access to websites, services, and destinations associated with unauthorized remote-access tools.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1219.002 Remote Desktop Software
                                                                    Comments
                                                                    Application-layer firewalls and proxies can restrict access to unauthorized remote-desktop services and destinations.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1552 Unsecured Credentials
                                                                    Comments
                                                                    Web application firewalls and application-layer controls can block server-side request forgery paths that would otherwise expose credential-bearing cloud metadata services.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1552.005 Cloud Instance Metadata API
                                                                    Comments
                                                                    A properly configured web application firewall can block external server-side request forgery attempts that target the cloud instance metadata API and expose temporary credentials.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1499.003 Application Exhaustion Flood
                                                                    Comments
                                                                    Application-layer firewalls and web application firewalls can inspect, rate-limit, or block abusive application requests that attempt to exhaust application resources.
                                                                    References
                                                                    CIS-13.10 Perform Application Layer Filtering mitigates T1499.004 Application or System Exploitation
                                                                    Comments
                                                                    Application-layer firewalls and web application firewalls can inspect and block known malicious request patterns or exploit payloads intended to cause application or system resource exhaustion.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1021.004 SSH
                                                                    Comments
                                                                    Conditional access policies for remote enterprise assets can deny authentication attempts to the SSH service if external SSH access is reachable through a remote-access control plane that can evaluates device posture
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1110 Brute Force
                                                                    Comments
                                                                    Conditional access policies for remote enterprise assets can deny authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use brute-force activity from non-compliant remote endpoints.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1110.001 Password Guessing
                                                                    Comments
                                                                    Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use guessed passwords from non-compliant remote endpoints.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1110.003 Password Spraying
                                                                    Comments
                                                                    Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use password spraying from non-compliant remote endpoints.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1110.004 Credential Stuffing
                                                                    Comments
                                                                    Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use compromised credential pairs from non-compliant remote endpoints.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1621 Multi-Factor Authentication Request Generation
                                                                    Comments
                                                                    Conditional access policies can prevent authentication attempts from non-compliant remote devices from proceeding, thereby preventing associated multi-factor authentication requests from being generated.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1078 Valid Accounts
                                                                    Comments
                                                                    Access control policies for remote enterprise assets can evaluate device compliance before permitting access to enterprise resources. Requiring current anti-malware protection, secure configuration compliance, and current operating system and application versions can prevent valid credentials from being used from remote devices that do not meet enterprise security requirements.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1078.004 Cloud Accounts
                                                                    Comments
                                                                    Conditional access policies can evaluate device compliance before permitting cloud-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1078.002 Domain Accounts
                                                                    Comments
                                                                    Conditional access policies can evaluate device compliance before permitting domain-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1078.003 Local Accounts
                                                                    Comments
                                                                    Conditional access policies can evaluate device compliance before permitting local-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1133 External Remote Services
                                                                    Comments
                                                                    Centrally managed authorization systems can restrict access to enterprise remote services based on the security posture of the connecting asset, including anti-malware status, secure-configuration compliance, and operating system or application update status.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1021 Remote Services
                                                                    Comments
                                                                    Centrally managed remote-access controls can restrict access to enterprise remote services so remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1021.001 Remote Desktop Protocol
                                                                    Comments
                                                                    Remote Desktop access can be restricted through centrally managed authorization controls so that remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1550 Use Alternate Authentication Material
                                                                    Comments
                                                                    Conditional access policies can evaluate the context and compliance state of a remote device when alternate authentication material is used, reducing the ability to use authentication material from devices that do not satisfy enterprise security requirements.
                                                                    References
                                                                    CIS-13.5 Manage Access Control for Remote Access mitigates T1550.001 Application Access Token
                                                                    Comments
                                                                    Conditional access policies can evaluate device compliance and expected access context when application access tokens are used, reducing the ability to use valid tokens from non-compliant remote endpoints or outside approved access conditions.
                                                                    References
                                                                    CIS-13.9 Deploy Port-Level Access Control mitigates T1200 Hardware Additions
                                                                    Comments
                                                                    Port-level access control using 802.1X, device certificates, or similar network access control mechanisms can prevent unauthorized hardware from authenticating to and communicating on trusted enterprise networks.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059 Command and Scripting Interpreter
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral controls such as Attack Surface Reduction rules to prevent Visual Basic and JavaScript from executing potentially malicious downloaded content.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.005 Visual Basic
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Visual Basic scripts from executing potentially malicious downloaded content.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.007 JavaScript
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent JavaScript scripts from executing potentially malicious downloaded content.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1543 Create or Modify System Process
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can block applications from writing signed vulnerable drivers and can enforce vulnerable-driver blocklists to reduce abuse of system processes and services.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1543.003 Windows Service
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can block applications from writing signed vulnerable service drivers and can enforce vulnerable-driver blocklists to reduce abuse of Windows services.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1486 Data Encrypted for Impact
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can use cloud-delivered protection and behavioral rules to block execution of files that exhibit ransomware-like behavior.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1006 Direct Volume Access
                                                                    Comments
                                                                    Endpoint security solutions can block behaviors associated with direct volume or backup-related access, including suspicious command execution or API calls targeting backup services.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1546.003 Windows Management Instrumentation Event Subscription
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that prevent malware from abusing Windows Management Instrumentation to establish persistence.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1564.014 Extended Attributes
                                                                    Comments
                                                                    Host-based security controls can inspect extended attributes alongside file contents during artifact review, packaging, or deployment to identify hidden payloads, obfuscated data, or suspicious attribute keys.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1574 Hijack Execution Flow
                                                                    Comments
                                                                    Endpoint security solutions can block behaviors associated with process injection or memory tampering based on common sequences of indicators such as suspicious API usage.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1574.013 KernelCallbackTable
                                                                    Comments
                                                                    Endpoint security solutions can block behaviors associated with KernelCallbackTable abuse and related memory-tampering activity based on common sequences of indicators and suspicious API usage.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1559 Inter-Process Communication
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1559.002 Dynamic Data Exchange
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1036 Masquerading
                                                                    Comments
                                                                    Host intrusion prevention systems can identify and prevent execution of potentially malicious files, including files whose signatures do not match their apparent file type.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1036.008 Masquerade File Type
                                                                    Comments
                                                                    Host intrusion prevention systems can identify and prevent execution of files whose signatures do not match their apparent file type.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1106 Native API
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office VBA macros from calling Win32 APIs.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027 Obfuscated Files or Information
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.009 Embedded Payloads
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts containing embedded payloads.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.010 Command Obfuscation
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that block execution of potentially obfuscated scripts or commands.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.012 LNK Icon Smuggling
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads delivered through LNK-based techniques.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.013 Encrypted/Encoded File
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can block execution of potentially obfuscated scripts and analyze file-encoding properties for anomalies that deviate from expected encoding practices.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.014 Polymorphic Code
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated or polymorphic payloads.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137 Office Application Startup
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.001 Office Template Macros
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.002 Office Test
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.003 Outlook Forms
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.004 Outlook Home Page
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.005 Outlook Rules
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.006 Add-ins
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1003 OS Credential Dumping
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent credential-stealing activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1003.001 LSASS Memory
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent attempts to steal credentials from LSASS memory.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055 Process Injection
                                                                    Comments
                                                                    Endpoint security solutions can block process-injection behavior based on common sequences of activity, including suspicious API use and code injection from applications such as Microsoft Office.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.001 Dynamic-link Library Injection
                                                                    Comments
                                                                    Endpoint security solutions can block dynamic-link library injection based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.002 Portable Executable Injection
                                                                    Comments
                                                                    Endpoint security solutions can block portable executable injection based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.003 Thread Execution Hijacking
                                                                    Comments
                                                                    Endpoint security solutions can block thread execution hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.004 Asynchronous Procedure Call
                                                                    Comments
                                                                    Endpoint security solutions can block process injection using asynchronous procedure calls based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.005 Thread Local Storage
                                                                    Comments
                                                                    Endpoint security solutions can block process injection using thread local storage based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.008 Ptrace System Calls
                                                                    Comments
                                                                    Endpoint security solutions can block process injection using ptrace system calls based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.009 Proc Memory
                                                                    Comments
                                                                    Endpoint security solutions can block process injection through proc memory based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.011 Extra Window Memory Injection
                                                                    Comments
                                                                    Endpoint security solutions can block extra window memory injection based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.012 Process Hollowing
                                                                    Comments
                                                                    Endpoint security solutions can block process hollowing based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.013 Process Doppelgänging
                                                                    Comments
                                                                    Endpoint security solutions can block process doppelgänging based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.014 VDSO Hijacking
                                                                    Comments
                                                                    Endpoint security solutions can block VDSO hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.015 ListPlanting
                                                                    Comments
                                                                    Endpoint security solutions can block ListPlanting based on common behavioral sequences and suspicious memory-manipulation activity.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1091 Replication Through Removable Media
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can block unsigned or untrusted executable files from running from removable media such as USB drives.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1216.001 PubPrn
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce application-control policies that block older or vulnerable versions of PubPrn from executing.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1569 System Services
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1569.002 Service Execution
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1204 User Execution
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running based on prevalence, age, trust, or behavioral criteria and can block Office applications from writing malicious executable content to disk.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1204.002 Malicious File
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running when they are downloaded or launched by Office applications, scripting interpreters, email clients, or fail prevalence, age, or trust criteria.
                                                                    References
                                                                    CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1047 Windows Management Instrumentation
                                                                    Comments
                                                                    Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that block processes created by Windows Management Instrumentation commands from running.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557 Adversary-in-the-Middle
                                                                    Comments
                                                                    Network intrusion prevention solutions can identify traffic patterns associated with adversary-in-the-middle activity and block the activity at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.001 Name Resolution Poisoning and SMB Relay
                                                                    Comments
                                                                    Network intrusion prevention solutions can identify traffic patterns associated with name-resolution poisoning and SMB relay activity and block the activity at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.002 ARP Cache Poisoning
                                                                    Comments
                                                                    Network intrusion prevention solutions can identify traffic patterns associated with ARP cache poisoning and block the activity where the relevant network traffic is monitored.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.003 DHCP Spoofing
                                                                    Comments
                                                                    Network intrusion prevention solutions can identify traffic patterns associated with DHCP spoofing and block the activity where the relevant network traffic is monitored.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.004 Evil Twin
                                                                    Comments
                                                                    Wireless intrusion prevention capabilities can identify rogue access points and traffic patterns associated with evil-twin activity and block or contain the unauthorized wireless connection.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071 Application Layer Protocol
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known malicious application-layer traffic to block adversary command-and-control communications at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.001 Web Protocols
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for malicious HTTP or HTTPS traffic associated with specific adversary tools to block command-and-control activity at the network boundary.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.002 File Transfer Protocols
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for malicious file-transfer protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.003 Mail Protocols
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for malicious mail-protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.004 DNS
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for malicious DNS traffic associated with specific adversary tools to block command-and-control activity at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.005 Publish/Subscribe Protocols
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for malicious publish/subscribe protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1132 Data Encoding
                                                                    Comments
                                                                    Network intrusion prevention solutions can use protocol and malware-specific signatures to identify encoded command-and-control traffic and block matching activity at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1132.001 Standard Encoding
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known protocol indicators and standard encoding patterns used by adversary tools to block matching network activity.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1132.002 Non-Standard Encoding
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known protocol indicators and non-standard encoding patterns used by adversary tools to block matching network activity.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1602 Data from Configuration Repository
                                                                    Comments
                                                                    Configure network intrusion prevention solutions to identify and block unauthorized management queries and commands used to access network-device configuration repositories.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1602.001 SNMP (MIB Dump)
                                                                    Comments
                                                                    Configure network intrusion prevention solutions to identify and block SNMP queries and commands originating from unauthorized sources.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1602.002 Network Device Configuration Dump
                                                                    Comments
                                                                    Configure network intrusion prevention solutions to identify and block unauthorized SNMP activity and unexpected Smart Install usage directed at network devices.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001 Data Obfuscation
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block obfuscated command-and-control activity that remains identifiable at the network level.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001.001 Junk Data
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control communications that use junk data for obfuscation.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001.002 Steganography
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block network activity that uses identifiable steganographic methods.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001.003 Protocol or Service Impersonation
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control activity that impersonates legitimate protocols or services.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1030 Data Transfer Size Limits
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures associated with known adversary infrastructure and malware to block command-and-control traffic that varies transfer size to evade controls.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1568 Dynamic Resolution
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures and known indicators associated with dynamically resolved adversary infrastructure to block matching command-and-control traffic.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1568.002 Domain Generation Algorithms
                                                                    Comments
                                                                    Network intrusion prevention solutions can block traffic to domains or patterns associated with known domain-generation algorithms when those indicators can be identified in advance or during network activity.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1573 Encrypted Channel
                                                                    Comments
                                                                    Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block encrypted command-and-control traffic at monitored boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1573.001 Symmetric Cryptography
                                                                    Comments
                                                                    Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with symmetric cryptography.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1573.002 Asymmetric Cryptography
                                                                    Comments
                                                                    Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with asymmetric cryptography.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048 Exfiltration Over Alternative Protocol
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over alternative protocols.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over symmetrically encrypted non-command-and-control protocols.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over asymmetrically encrypted non-command-and-control protocols.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over unencrypted non-command-and-control protocols.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1041 Exfiltration Over C2 Channel
                                                                    Comments
                                                                    Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable exfiltration occurring over command-and-control channels.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1008 Fallback Channels
                                                                    Comments
                                                                    Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable fallback command-and-control channels at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1105 Ingress Tool Transfer
                                                                    Comments
                                                                    Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over protocols such as FTP and block the associated tool-transfer activity.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1570 Lateral Tool Transfer
                                                                    Comments
                                                                    Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over common tools and protocols and block lateral tool-transfer activity.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1104 Multi-Stage Channels
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic associated with multi-stage command-and-control channels.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1046 Network Service Discovery
                                                                    Comments
                                                                    Network intrusion prevention solutions can identify and block remote service scanning that crosses monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1095 Non-Application Layer Protocol
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary malware to block malicious use of non-application-layer protocols at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1571 Non-Standard Port
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary malware to block malicious traffic using non-standard ports at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1566 Phishing
                                                                    Comments
                                                                    Network intrusion prevention solutions and network-based content controls can block malicious email links or attachments before they reach or execute on enterprise assets.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1566.001 Spearphishing Attachment
                                                                    Comments
                                                                    Network intrusion prevention solutions and network-based content controls can block malicious email attachments before they reach or execute on enterprise assets.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1542.004 ROMMONkit
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for protocols such as TFTP to block identifiable network activity associated with unauthorized modification of network-device boot components.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1542.005 TFTP Boot
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for protocols such as TFTP to block unauthorized TFTP traffic associated with network-device boot activity.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1572 Protocol Tunneling
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary malware and tunneling traffic to block identifiable protocol-tunneling activity at monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1090 Proxy
                                                                    Comments
                                                                    Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable proxy communications used for adversary command and control.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1090.001 Internal Proxy
                                                                    Comments
                                                                    Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable internal proxy communications used for adversary command and control.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1090.002 External Proxy
                                                                    Comments
                                                                    Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable external proxy communications used for adversary command and control.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1219 Remote Access Tools
                                                                    Comments
                                                                    Network intrusion prevention solutions can use network signatures to block traffic associated with unauthorized remote-access services.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1029 Scheduled Transfer
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary infrastructure and malware to block identifiable scheduled command-and-control or data-transfer activity.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1221 Template Injection
                                                                    Comments
                                                                    Network intrusion prevention solutions can block network activity that attempts to fetch or execute malicious payloads through externally referenced document templates.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204 User Execution
                                                                    Comments
                                                                    When user execution depends on visiting a malicious link or retrieving malicious content, network intrusion prevention solutions can block the associated network request or download.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.001 Malicious Link
                                                                    Comments
                                                                    Network intrusion prevention solutions can block requests to malicious links and prevent associated content from being downloaded across monitored network boundaries.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.003 Malicious Image
                                                                    Comments
                                                                    Network intrusion prevention solutions can block malicious image downloads when the content or associated network activity matches known malicious indicators.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.004 Malicious Copy and Paste
                                                                    Comments
                                                                    Network intrusion prevention solutions can block network requests for malicious content used in copy-and-paste execution workflows when the destination or traffic matches known malicious indicators.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.005 Malicious Library
                                                                    Comments
                                                                    Network intrusion prevention solutions can block malicious library downloads when the content or associated network activity matches known malicious indicators.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102 Web Service
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable command-and-control traffic using web services.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.001 Dead Drop Resolver
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic to web services used as dead-drop resolvers.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.002 Bidirectional Communication
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable bidirectional command-and-control traffic using web services.
                                                                    References
                                                                    CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.003 One-Way Communication
                                                                    Comments
                                                                    Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable one-way command-and-control traffic using web services.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1557 Adversary-in-the-Middle
                                                                    Comments
                                                                    Filtering unnecessary and legacy network traffic between network segments reduces opportunities for adversaries to establish adversary-in-the-middle conditions.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071 Application Layer Protocol
                                                                    Comments
                                                                    Use network filtering between segments to permit only required application-layer protocols and authorized communications, limiting adversary use of application protocols for command and control.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.001 Web Protocols
                                                                    Comments
                                                                    Restrict HTTP and HTTPS traffic crossing network-segment boundaries from critical systems to approved destinations, reducing unauthorized outbound web communications used for command and control or payload transfer.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.002 File Transfer Protocols
                                                                    Comments
                                                                    Filter FTP and SFTP traffic between network segments so sensitive systems can transfer files only to trusted internal systems or other explicitly approved destinations.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.003 Mail Protocols
                                                                    Comments
                                                                    Restrict SMTP, IMAP, and POP3 traffic between segments so servers and critical systems communicate only with trusted mail infrastructure, reducing unauthorized mail-based command, control, or exfiltration paths.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.004 DNS
                                                                    Comments
                                                                    Restrict DNS traffic between segments to approved resolvers and filter requests to unknown, untrusted, or known malicious resources, reducing adversary use of DNS for command and control or concealed data transfer.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.005 Publish/Subscribe Protocols
                                                                    Comments
                                                                    Filter publish/subscribe protocol traffic crossing segment boundaries to approved brokers, destinations, and expected ports, reducing use of untrusted resources or irregular ports for command and control.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1602 Data from Configuration Repository
                                                                    Comments
                                                                    Apply network access-control rules between trusted and untrusted segments to block unauthorized management protocols used to reach configuration repositories and managed network devices.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1602.001 SNMP (MIB Dump)
                                                                    Comments
                                                                    Apply network access-control rules to restrict SNMP traffic across segment boundaries to authorized management systems, preventing unauthorized retrieval of Management Information Base data.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1602.002 Network Device Configuration Dump
                                                                    Comments
                                                                    Apply network access-control rules to restrict management protocols used to retrieve network-device configurations to approved management segments and authorized systems.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048 Exfiltration Over Alternative Protocol
                                                                    Comments
                                                                    Enforce network segmentation, proxies, and dedicated protocol services so only approved systems can communicate over protocols such as DNS, reducing opportunities to exfiltrate data through alternative protocols.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
                                                                    Comments
                                                                    Enforce proxies or dedicated services and restrict encrypted non-command-and-control protocol traffic between segments to systems with a legitimate requirement to use those protocols.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
                                                                    Comments
                                                                    Enforce proxies or dedicated services and restrict asymmetric encrypted non-command-and-control protocol traffic between segments to approved systems and destinations.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
                                                                    Comments
                                                                    Restrict unencrypted alternative-protocol traffic between network segments and allow those protocols only where required for approved business communications.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1190 Exploit Public-Facing Application
                                                                    Comments
                                                                    Restrict outbound traffic from public-facing or DMZ network segments to approved internal and external destinations, limiting post-exploitation communication from a compromised public-facing server.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1570 Lateral Tool Transfer
                                                                    Comments
                                                                    Restrict file-sharing communications such as SMB between network segments to systems with a legitimate requirement, reducing adversary opportunities to transfer tools laterally.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1599 Network Boundary Bridging
                                                                    Comments
                                                                    Use unaffected firewalls or routers to block unauthorized traffic that attempts to bridge established network-segment boundaries and continue monitoring to ensure the filtering remains effective.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1599.001 Network Address Translation Traversal
                                                                    Comments
                                                                    Use unaffected network filtering devices to block unauthorized traffic attempting to traverse network boundaries through NAT or related boundary-bridging mechanisms.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1095 Non-Application Layer Protocol
                                                                    Comments
                                                                    Filter traffic at network-segment boundaries to prevent use of non-application-layer protocols that are not required for business operations.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1572 Protocol Tunneling
                                                                    Comments
                                                                    Filter network traffic between segments to untrusted, unauthorized, or known malicious destinations and restrict protocols that can be abused to tunnel communications across network boundaries.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1219 Remote Access Tools
                                                                    Comments
                                                                    Configure network firewalls and proxies at segment boundaries to restrict outgoing traffic to sites and services associated with unauthorized remote-access software.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1219.002 Remote Desktop Software
                                                                    Comments
                                                                    Restrict remote-desktop software traffic between network segments to authorized systems, destinations, and management paths using firewalls and proxy controls.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1021.002 SMB/Windows Admin Shares
                                                                    Comments
                                                                    Restrict SMB and Windows administrative-share communications between network segments to explicitly authorized systems and management paths.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1021.005 VNC
                                                                    Comments
                                                                    Filter or block VNC traffic across network-segment boundaries, including commonly used VNC ports, except where the communication is explicitly required.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1205 Traffic Signaling
                                                                    Comments
                                                                    Use stateful filtering at network-segment boundaries to block traffic patterns used by traffic-signaling mechanisms when the signaling implementation can be identified and constrained.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1205.001 Port Knocking
                                                                    Comments
                                                                    Use stateful filtering at network-segment boundaries to prevent port-knocking sequences from reaching protected systems where the signaling pattern can be constrained.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1205.002 Socket Filters
                                                                    Comments
                                                                    Use stateful filtering at network-segment boundaries to block crafted traffic used to trigger socket-filter-based communication when the signaling implementation can be identified.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1537 Transfer Data to Cloud Account
                                                                    Comments
                                                                    Implement network-based filtering restrictions between trusted and untrusted VPCs or equivalent network segments to prohibit unauthorized data transfers to external cloud accounts.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1197 BITS Jobs
                                                                    Comments
                                                                    Configure network filtering controls so only legitimate BITS traffic is permitted across network boundaries, restricting unauthorized BITS communications used for background transfer or execution activity.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1530 Data from Cloud Storage
                                                                    Comments
                                                                    Use network-based source restrictions and expected IP ranges when accessing cloud resources so data access is limited to authorized network locations in addition to valid user accounts.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1090 Proxy
                                                                    Comments
                                                                    Use network allow and block lists to prevent traffic between network segments and known anonymity networks or command-and-control infrastructure that may be used as proxy destinations.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1090.003 Multi-hop Proxy
                                                                    Comments
                                                                    Use network allow and block lists to restrict traffic to known anonymity networks and command-and-control infrastructure that may be chained together as multi-hop proxy destinations.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1218 System Binary Proxy Execution
                                                                    Comments
                                                                    Use network appliances at segment boundaries to filter ingress and egress traffic and restrict unnecessary protocols or destinations that trusted system binaries could otherwise use for malicious communications.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1218.012 Verclsid
                                                                    Comments
                                                                    Restrict unnecessary outbound traffic from systems that do not require external communications through Verclsid, using network filtering controls where the relevant traffic crosses a managed segment boundary.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1552 Unsecured Credentials
                                                                    Comments
                                                                    Restrict network access paths to cloud instance metadata services and use filtering controls to reduce exposure of metadata interfaces that may contain temporary credentials or other authentication material.
                                                                    References
                                                                    CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1552.005 Cloud Instance Metadata API
                                                                    Comments
                                                                    Restrict network access to the Cloud Instance Metadata API so only workloads with a legitimate requirement can reach the service, reducing adversary access to credentials and metadata through unintended network paths.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1550.004 Web Session Cookie
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and the remediation configures applications and browsers to reduce persistent sessions, shorten cookie validity, require reauthentication, and invalidate session material more aggressively.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1543 Create or Modify System Process
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and the remediation restricts insecure service/process behavior.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1606 Forge Web Credentials
                                                                    Comments
                                                                    Application and browser configuration can reduce persistent or weakly protected web credential artifacts such as cookies that were found/forged during penetration testing.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1543.005 Container Service
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and the remediation is related to configuring container services to run rootless or otherwise reduce unnecessary service privileges, directly constraining persistence or privilege abuse through the container service. The mapping does not apply when the finding requires patching or architectural changes rather than configuration correction.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1555.005 Password Managers
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and the remediation deals with enforcing password-manager locking, timeout, vault-access, and related security settings that reduce exposure of stored or decrypted credentials.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1685 Disable or Modify Tools
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation relates to hardening security, logging, and monitoring tools so they are harder to disable or reconfigure, including by enforcing permissions, persistence settings, and service configuration.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1667 Email Bombing
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens mail service configuration, sender authentication policy, filtering, throttling, and related controls that reduce abusive high-volume email delivery.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1546.013 PowerShell Profile
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software-configuration weakness and remediation of the finding removes unnecessary PowerShell profiles, restrict profile modification, or configure PowerShell execution so untrusted profile content is not loaded.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1606.001 Web Cookies
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the applications and browsers to minimize persistent cookies, shorten cookie lifetime, and apply secure cookie settings that reduce reusable credential material.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1590.002 DNS
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the DNS zone transfers to explicitly authorized servers and correct other DNS service settings that expose internal naming information.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1559.002 Dynamic Data Exchange
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding restricts the unnecessary DDE and embedded-content functionality in affected applications, directly reducing an execution path that relies on permissive application configuration.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1566.001 Spearphishing Attachment
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthen mail system sender-authentication, attachment-handling, and filtering policies that reduce delivery of malicious attachments.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1566.002 Spearphishing Link
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens mail authentication, URL-handling, and browser or mail-client policy to reduce delivery or successful use of malicious links.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1598.002 Spearphishing Attachment
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens sender-authentication and attachment-filtering configuration to reduce spoofed or malicious messages used to solicit sensitive information.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1677 Poisoned Pipeline Execution
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding hardens CI/CD pipeline settings by restricting unreviewed code execution, isolating runners, reducing secrets exposure, constraining triggers, and preventing user-controlled input from being implicitly trusted.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1688 Safe Mode Boot
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding configure system settings so defensive services remain active or recover correctly when Windows is booted into Safe Mode.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1684.002 Email Spoofing
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes and enforces SPF, DKIM, DMARC, and related mail-domain protections to reduce successful sender impersonation.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1539 Steal Web Session Cookie
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes by configuring secure cookie attributes, shorter lifetimes, session invalidation, and reduced persistence in affected applications or browsers.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1537 Transfer Data to Cloud Account
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the cloud applications and services to restrict external sharing, cross account transfers, and unapproved destinations, directly constraining data movement to adversary controlled cloud accounts.
                                                                    References
                                                                    CIS-18.3 Remediate Penetration Test Findings mitigates T1535 Unused/Unsupported Cloud Regions
                                                                    Comments
                                                                    This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes disables or restricts unused cloud regions and services so adversaries cannot create or operate resources in locations outside the organization's intended monitoring and governance scope.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1550.003 Pass the Ticket
                                                                    Comments
                                                                    Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries’ ability to reuse Kerberos tickets for lateral movement.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1550.002 Pass the Hash
                                                                    Comments
                                                                    Using role-based access control (RBAC) to prevent domain users from being local administrators on multiple systems can help limit adversaries’ ability to reuse NTLM hashes for lateral movement.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1550 Use Alternate Authentication Material
                                                                    Comments
                                                                    Using role-based access control (RBAC) to enforce least privilege and prevent domain users from holding local-administrator rights across multiple systems can help limit an adversary’s ability to use alternate authentication material for lateral movement.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1552.007 Container API
                                                                    Comments
                                                                    Enforce authentication and role-based access control (RBAC) on the container API to restrict users to the least privileges required to help prevent adversaries from gathering credentials via APIs within a containers environment.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1537 Transfer Data to Cloud Account
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit user-account and identity access management (IAM) permissions to the least privileges required can help prevent adversaries from transferring organizational data to cloud accounts they control.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1199 Trusted Relationship
                                                                    Comments
                                                                    Implement role-based access control (RBAC) to manage accounts and permissions used by parties in trusted relationships to minimize potential abuse by the party or if the party is compromised by an adversary.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1569.003 Systemctl
                                                                    Comments
                                                                    Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing systemctl to execute commands or programs.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1569.001 Launchctl
                                                                    Comments
                                                                    Implement role-based access control (RBAC) to ensure lower-privileged users cannot create or interact with higher-privileged system services to help prevent adversaries from abusing launchctl to execute commands or programs.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1047 Windows Management Instrumentation
                                                                    Comments
                                                                    Using role-based access control (RBAC) to restrict remote WMI access to authorized administrative roles can help prevent adversaries from abusing Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1195 Supply Chain Compromise
                                                                    Comments
                                                                    Implement role-based access control (RBAC) to ensure software and development tools run with the lowest necessary privileges to help limit an adversary’s ability to propagate or perform unauthorized actions in the event of a supply chain compromise.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1528 Steal Application Access Token
                                                                    Comments
                                                                    Enforce role-based access control (RBAC) to limit accounts to the least privileges they require to help prevent adversaries from obtaining or abusing application access tokens.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1489 Service Stop
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit user accounts and groups so that only authorized administrators can interact with service changes and service configurations can help prevent adversaries from stopping or disabling services.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1648 Serverless Execution
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create, modify, or run serverless resources only to users that explicitly require them can help prevent adversaries from abusing serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1505.003 Web Shell
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to upload, create, or modify content in web-server application directories to users with a legitimate need can help prevent adversaries from backdooring web servers with web shells.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1505 Server Software Component
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to add or modify server software components to users with a legitimate need can help prevent adversaries from abusing legitimate extensible development features of servers.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.001 Remote Desktop Protocol
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit Remote Desktop Users group membership and Remote Desktop Protocol (RDP) permissions to users with a legitimate need can help prevent adversaries from using RDP for lateral movement.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.006 Systemd Timers
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via system utilities to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.003 Cron
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the cron utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053 Scheduled Task/Job
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks and jobs on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.002 At
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via the at utility to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.005 Scheduled Task
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks on remote systems to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.004 SSH
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit SSH access and permitted commands to users with a legitimate need can help prevent adversaries from using SSH for lateral movement.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1053.007 Container Orchestration Job
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create or modify scheduled tasks via container orchestration tools to authorized administrator roles to help prevent adversaries from abusing task scheduling functionality.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1072 Software Deployment Tools
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit access to and use of centralized software suites to a limited number of authorized administrators with a verified business need can help prevent adversaries from accessing and abusing software deployment tools.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021 Remote Services
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit which accounts can use remote services and restrict the commands or resources available to those accounts to help prevent adversaries from using remote services for lateral movement.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1563.001 SSH Hijacking
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1563.002 RDP Hijacking
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1563 Remote Service Session Hijacking
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit remote user permissions to necessary users to help prevent adversaries from commandeering these sessions.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1677 Poisoned Pipeline Execution
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit write access to internal repositories and CI/CD pipeline permissions to users and services with a legitimate need can help prevent adversaries from modifying pipelines to execute malicious code.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1566.003 Spearphishing via Service
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit third-party messaging and collaboration-service account privileges to users with a legitimate need can help prevent adversaries from abusing compromised service accounts for spearphishing.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1566.002 Spearphishing Link
                                                                    Comments
                                                                    Using role-based access control (RBAC) to apply limitations on which roles can grant consent to third-party applications can help prevent users from granting consent to unfamiliar or unverified third-party applications through spearphishing links.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1566.001 Spearphishing Attachment
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit file-opening and execution permissions to only the accounts that require them can help reduce the impact of malicious email attachments by preventing unauthorized execution or spread of malware.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1040 Network Sniffing
                                                                    Comments
                                                                    In cloud environments, using role-based access control (RBAC) to ensure that users are not granted permissions to create or modify traffic mirrors unless explicitly required can help prevent adversaries from capturing network traffic.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1666 Modify Cloud Resource Hierarchy
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to add, delete, or modify cloud resource groups and hierarchy structures to authorized roles can help prevent adversaries from evading organizational guardrails and cloud security policies.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.005 Modify Cloud Compute Configurations
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to modify cloud compute settings, quotas, and tenant-level configurations to authorized roles can help prevent adversaries from altering infrastructure resources or bypassing restrictions.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.003 Delete Cloud Instance
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to delete cloud instances to authorized roles can help prevent adversaries from removing instances to destroy evidence of malicious activity.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.002 Create Cloud Instance
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create cloud instances to authorized roles can help prevent adversaries from deploying new instances to evade defenses or conduct unauthorized activity.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578.001 Create Snapshot
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create cloud snapshots and backups to authorized roles can help prevent adversaries from creating copies of cloud resources for unauthorized access or data collection.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1578 Modify Cloud Compute Infrastructure
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to create, delete, and modify cloud compute infrastructure to authorized roles can help prevent adversaries from altering cloud resources to evade defenses or gain unauthorized access.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1021.008 Direct Cloud VM Connections
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit direct cloud-native VM connection permissions to users with a legitimate need can help prevent adversaries from accessing cloud compute infrastructure for lateral movement.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556.006 Multi-Factor Authentication
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to enroll, disable, or modify multi-factor authentication (MFA) methods and policies to authorized administrative roles can help prevent adversaries from weakening MFA protections on compromised accounts.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556 Modify Authentication Process
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to modify authentication processes and identity-provider settings to authorized administrative roles can help prevent adversaries from altering authentication controls to gain unauthorized access.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1654 Log Enumeration
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to access and export sensitive system and service logs to privileged roles can help prevent adversaries from enumerating logs for valuable information.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1490 Inhibit System Recovery
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to backups to only required users with a legitimate need can help prevent adversaries from deleting or removing built-in data and turning off services designed to aid in the recovery of a corrupted system.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574.012 COR_PROFILER
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to modify COR_PROFILER environment variables and related .NET configuration settings to users with a legitimate need can help prevent adversaries from loading malicious DLLs into .NET processes.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574.010 Services File Permissions Weakness
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to modify service executables and their file paths to users with a legitimate need can help prevent adversaries from replacing service binaries with malicious payloads.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574.005 Executable Installer File Permissions Weakness
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to modify installer executables and their file paths to users with a legitimate need can help prevent adversaries from replacing installer binaries with malicious payloads.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1574 Hijack Execution Flow
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to modify service configurations, registry settings, and protected file paths to users with a legitimate need can help prevent adversaries from hijacking execution flow.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1530 Data from Cloud Storage
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage to only users with a legitimate need can help prevent adversaries from accessing and collecting data from cloud storage solutions.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1606 Forge Web Credentials
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge credential materials.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1657 Financial Theft
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit sensitive financial transactions and approval privileges to narrowly scoped roles can mitigate use of a compromised account to initiate or authorize unauthorized payments.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1556.009 Conditional Access Policies
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit permissions to modify conditional access policies to authorized administrative roles can help prevent adversaries from removing multi-factor authentication (MFA) requirements or adding exclusions that enable persistent access.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1606.002 SAML Tokens
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit access to identity infrastructure and token-issuance permissions to narrowly scoped privileged roles reduces opportunities to forge SAML tokens.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1048 Exfiltration Over Alternative Protocol
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit user groups and roles for access to cloud storage systems and objects to only users with a legitimate need can help prevent adversaries from exfiltrating data from cloud storage.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1484.001 Group Policy Modification
                                                                    Comments
                                                                    Role-based access control (RBAC) can be used to limit which users and computers can access Group Policy Objects (GPOs), helping to prevent adversaries from modifying GPOs.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1484 Domain or Tenant Policy Modification
                                                                    Comments
                                                                    Role-based access control (RBAC) can be used to limit which users and computers can access domain and identity tenant settings, helping to prevent adversaries from modifying their configuration settings.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1610 Deploy Container
                                                                    Comments
                                                                    Enforcing role-based access control (RBAC) to limit container dashboard access to only necessary users can prevent adversaries from deploying a container into an environment.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.006 Databases
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit database access to only authorized users helps prevent adversaries from leveraging these databases to mine valuable information.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.001 Confluence
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit Confluence repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1484.002 Trust Modification
                                                                    Comments
                                                                    In cloud environments, role-based access control (RBAC) can be used to limit permissions to create new identity providers to only those accounts that require them. This can prevent adversaries from adding new domain trusts, modifying the properties of existing domain trusts, or otherwise changing the configuration of trust relationships between domains and tenants.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.004 Customer Relationship Management Software
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit Customer Relationship Management (CRM) software access to only authorized users helps prevent adversaries from leveraging CRM software to mine valuable information.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.003 Code Repositories
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit code repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213 Data from Information Repositories
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit information repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543 Create or Modify System Process
                                                                    Comments
                                                                    Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with system-level process changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1485.001 Lifecycle-Triggered Deletion
                                                                    Comments
                                                                    In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying all objects stored within buckets.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1485 Data Destruction
                                                                    Comments
                                                                    In cloud environments, using role-based access control (RBAC) to limit user permissions to modify cloud bucket lifecycle policies to only users with a legitimate need can help prevent adversaries from destroying data and files.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.005 Container Service
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit user access to utilities such as docker to only users with a legitimate need helps prevent adversaries from creating or modifying container or cluster management tools to establish persistence or escalate privileges.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.004 Launch Daemon
                                                                    Comments
                                                                    Using role-based access control (RBAC) to ensure only authorized administrator roles can create new Launch Daemons helps prevent adversaries from creating or modifying Launch Daemons to establish persistence or escalate privileges.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.003 Windows Service
                                                                    Comments
                                                                    Using role-based access control (RBAC) to ensure only authorized administrator roles can interact with service changes and service configurations helps prevent adversaries from leveraging this functionality to establish persistence or escalate privileges.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1543.002 Systemd Service
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit user access to system utilities to only users with a legitimate need helps prevent adversaries from creating or modifying systemd services to establish persistence or escalate privileges.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1213.002 Sharepoint
                                                                    Comments
                                                                    Using role-based access control (RBAC) to limit SharePoint repository access to only authorized users helps prevent adversaries from leveraging these repositories to mine valuable information.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134.002 Create Process with Token
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create new processes with tokens and limiting privileges to a small set of tightly controlled roles.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1609 Container Administration Command
                                                                    Comments
                                                                    Enforcing authentication and role-based access control (RBAC) on the container administration service to restrict users to the least privileges required can help prevent adversaries from abusing the service to execute commands within the container.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1059.008 Network Device CLI
                                                                    Comments
                                                                    Role-based access control (RBAC) helps mitigate this technique by enforcing least privilege and command authorization on network device CLI access, limiting which roles can run perform authorization changes.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1619 Cloud Storage Object Discovery
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate discovery of cloud storage objects by limiting cloud storage list permissions to narrowly scoped roles, reducing who can enumerate storage objects for discovery.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1580 Cloud Infrastructure Discovery
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate discovery of cloud infrastructure and resources by limiting which roles can access, manage, or query cloud infrastructure metadata and enforcing who can see and do what in cloud service dashboards.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1185 Browser Session Hijacking
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate browser session hijacking techniques by enforcing least privilege so that hijacked browser sessions are associated with minimally scoped roles, limiting what an adversary can do with a captured session.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.012 Print Processors
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or unload device drivers by disabling SeLoadDriverPrivilege.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1613 Container and Resource Discovery
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate this technique by tightly controlling which roles can view or query container APIs and dashboards and restricting discovery of cluster resources to narrowly scoped roles.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.009 Shortcut Modification
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate this technique by limiting shortcut creation and modification to narrowly scoped roles.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.006 Kernel Modules and Extensions
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate this technique by limiting which roles can load or configure kernel modules and extensions to tightly controlled admin roles.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.004 Winlogon Helper DLL
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate this technique by restricting Winlogon configuration changes to a small set of tightly controlled admin roles.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1547.013 XDG Autostart Entries
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate this technique by limiting which roles can can create and modify XDG autostart entries to narrowly scoped privileged roles.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.004 SSH Authorized Keys
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles in cloud environments are allowed to modify SSH authorized_keys files and ensuring that only users who explicitly require the permissions to update instance metadata or configurations can do so.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1197 BITS Jobs
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate abuse of BITS jobs by limiting access to the BITS interface to specific user roles or groups.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.003 Additional Cloud Roles
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add permissions to accounts or update IAM policies.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.001 Additional Cloud Credentials
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to add access keys to accounts.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098 Account Manipulation
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to create or modify accounts and ensuring that low-privileged users do not have permissions to modify accounts or account-related policies.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1087.004 Cloud Account
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1087 Account Discovery
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate account discovery by limiting what each role can see or query.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1098.006 Additional Container Cluster Roles
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate account manipulation by limiting which roles are allowed to add additional roles or permissions and ensuring that low-privileged accounts do not have permissions to add permissions to accounts or to update container cluster roles.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1546.003 Windows Management Instrumentation Event Subscription
                                                                    Comments
                                                                    Using role-based access control (RBAC) to restrict or disallow user groups allowed to connect to WMI can help prevent adversaries from maliciously using WMI event subscription capabilities.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134.001 Token Impersonation/Theft
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or impersonate tokens and limiting privileges to a small set of tightly controlled roles.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134 Access Token Manipulation
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create or modify tokens and limiting privileges to a small set of tightly controlled roles.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548.005 Temporary Elevated Cloud Access
                                                                    Comments
                                                                    Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1548 Abuse Elevation Control Mechanism
                                                                    Comments
                                                                    Role-based access control (RBAC), implemented under least privilege and access enforcement controls, helps mitigate this technique by limiting which identities can use elevation mechanisms and what they can elevate to.
                                                                    References
                                                                    CIS-6.8 Define and Maintain Role-Based Access Control mitigates T1134.003 Make and Impersonate Token
                                                                    Comments
                                                                    Role-based access control (RBAC) can help mitigate access token manipulation by restricting which roles are allowed to create and impersonate tokens and limiting privileges to a small set of tightly controlled roles.
                                                                    References
                                                                    CIS-3.11 Encrypt Sensitive Data At Rest mitigates T1003 OS Credential Dumping
                                                                    Comments
                                                                    Encrypting sensitive data at rest prevents dumping credentials from OS caches, memory, or credential structures to obtain hashes or plaintext passwords on domain controller backups.
                                                                    References
                                                                    CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059 Command and Scripting Interpreter
                                                                    Comments
                                                                    Behavioral anti-malware commonly monitors scripting engines and detects malicious script execution through behavioral indicators rather than signatures.
                                                                    References
                                                                    CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059.006 Python
                                                                    Comments
                                                                    Products that explicitly monitor Python process behavior, command execution, child processes, and resulting system changes can detect or block malicious Python activity. Generic behavioral monitoring alone is insufficient.
                                                                    References
                                                                    CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1055 Process Injection
                                                                    Comments
                                                                    Some anti-malware products monitor cross-process memory writes, remote-thread creation, process hollowing, and similar injection behavior. Where these protections are enabled, the safeguard directly detects or blocks process injection.
                                                                    References
                                                                    CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1547.006 Kernel Modules and Extensions
                                                                    Comments
                                                                    Anti-malware products may detect malicious kernel drivers or unsigned modules during installation or loading. However, preventing unauthorized kernel module loading relies more heavily on platform integrity and driver enforcement controls (anti-malware product monitors and blocks malicious kernel modules, drivers, or extensions) than standard anti-malware alone.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1068 Exploitation for Privilege Escalation
                                                                    Comments
                                                                    Remediating known vulnerabilities in kernels, drivers, services, and privileged applications directly removes exploit paths that adversaries could use to obtain elevated privileges. This does not prevent exploitation of unknown vulnerabilities or weaknesses that remain outside the remediation scope.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1189 Drive-by Compromise
                                                                    Comments
                                                                    Remediating detected vulnerabilities in browsers, plug-ins, and other client software reduces successful exploitation when users visit malicious or compromised websites. This does not prevent drive-by activity that relies on zero-day vulnerabilities, social engineering, or malicious content that does not require exploitation.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1190 Exploit Public-Facing Application
                                                                    Comments
                                                                    Correcting identified vulnerabilities in internet-facing applications, services, and appliances directly removes known initial-access paths. Remediation may include patching, upgrading, replacing, disabling, or isolating the vulnerable component.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1203 Exploitation for Client Execution
                                                                    Comments
                                                                    Remediating known vulnerabilities in browsers, Office products, PDF readers, and other client applications reduces successful exploit-based code execution. This does not prevent exploitation of unknown vulnerabilities or unremediated unsupported software.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1210 Exploitation of Remote Services
                                                                    Comments
                                                                    Patching or otherwise correcting vulnerabilities in remotely reachable services removes known lateral-movement and remote-execution paths.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1211 Exploitation for Stealth
                                                                    Comments
                                                                    Remediation can remove vulnerabilities in operating systems, applications, security tools, and logging components that adversaries could exploit to conceal activity or impair visibility. This relationship applies only when the stealth behavior depends on an identified vulnerability.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1212 Exploitation for Credential Access
                                                                    Comments
                                                                    Correcting vulnerabilities in authentication systems, credential-handling software, kernels, and related components prevents exploit-based access to credentials.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1611 Escape to Host
                                                                    Comments
                                                                    Remediating vulnerabilities in host kernels, hypervisors, and container runtimes reduces successful container or virtual-machine escape. This does not prevent escapes caused solely by unsafe configuration, privileged containers, or exposed management sockets.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1495 Firmware Corruption
                                                                    Comments
                                                                    Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1542 Pre-OS Boot
                                                                    Comments
                                                                    This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1542.001 System Firmware
                                                                    Comments
                                                                    Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1542.002 Component Firmware
                                                                    Comments
                                                                    Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1548 Abuse Elevation Control Mechanism
                                                                    Comments
                                                                    This is a partial parent mapping because remediation can remove known vulnerabilities and implementation weaknesses used to bypass elevation controls.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1548.002 Bypass User Account Control
                                                                    Comments
                                                                    Applying current Windows security updates and supported platform upgrades removes known UAC-bypass and auto-elevation weaknesses. This does not prevent every UAC bypass or activity performed by an account that already has administrative privileges.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1546 Event Triggered Execution
                                                                    Comments
                                                                    Remediation can remove specific vulnerable event-triggered execution mechanisms, including known AppInit DLL and Application Shimming behaviors. Most event-triggered persistence also depends on configuration and permissions.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1546.010 AppInit DLLs
                                                                    Comments
                                                                    Upgrading or patching affected Windows platforms removes older AppInit DLL behaviors and weaknesses that adversaries could abuse for persistence or execution. Configuration controls remain necessary where the feature is still supported.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1546.011 Application Shimming
                                                                    Comments
                                                                    Applying the relevant Windows security updates removes known auto-elevation behavior associated with application-shim installation. Remediation does not prevent all shim abuse by an adversary that already has sufficient privileges.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1552 Unsecured Credentials
                                                                    Comments
                                                                    Remediation can correct specific software weaknesses that store credentials insecurely, including the Group Policy Preferences implementation. Most unsecured credential exposures require separate configuration, access-control, or secret-management controls.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1552.006 Group Policy Preferences
                                                                    Comments
                                                                    Applying the applicable Microsoft security update prevents newly configured Group Policy Preferences from storing credentials in a recoverable form. Previously stored credentials may still require separate identification, removal, and rotation.
                                                                    References
                                                                    CIS-7.7 Remediate Detected Vulnerabilities mitigates T1550.002 Pass the Hash
                                                                    Comments
                                                                    Applying relevant Windows security updates can restrict default remote access available to local administrator accounts and reduce some pass-the-hash activity. Remediation does not eliminate hash theft, NTLM use, or pass-the-hash through accounts that retain applicable privileges.
                                                                    References