Deploy and maintain anti-malware software on all enterprise assets.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1027 | Obfuscated Files or Information |
Comments
Anti-malware software can detect and quarantine malicious files or commands that use encoding, packing, encryption, or other obfuscation techniques to evade detection.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1055 | Process Injection |
Comments
Some anti-malware products monitor cross-process memory writes, remote-thread creation, process hollowing, and similar injection behavior. Where these protections are enabled, the safeguard directly detects or blocks process injection.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1547.006 | Kernel Modules and Extensions |
Comments
Anti-malware products may detect malicious kernel drivers or unsigned modules during installation or loading. However, preventing unauthorized kernel module loading relies more heavily on platform integrity and driver enforcement controls (anti-malware product monitors and blocks malicious kernel modules, drivers, or extensions) than standard anti-malware alone.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1204.002 | Malicious File |
Comments
Anti-malware can scan a file when it is opened or executed and quarantine or block the file before the malicious payload runs. This directly reduces the effectiveness of malicious files that depend on user execution.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1027.002 | Software Packing |
Comments
Packed executables are a common malware delivery method. Modern anti-malware engines unpack or emulate packed binaries during scanning, making this a direct technical capability of the safeguard.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1059.005 | Visual Basic |
Comments
Malicious VBScript is routinely inspected by anti-malware through script scanning and behavioral analysis prior to execution.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1059.001 | PowerShell |
Comments
Anti-malware integrates with PowerShell logging and AMSI to inspect scripts and commands before execution, making PowerShell malware a primary detection target.
References
|