CIS Controls CIS-10.1

Deploy and maintain anti-malware software on all enterprise assets.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1027 Obfuscated Files or Information
Comments
Anti-malware software can detect and quarantine malicious files or commands that use encoding, packing, encryption, or other obfuscation techniques to evade detection.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1055 Process Injection
Comments
Some anti-malware products monitor cross-process memory writes, remote-thread creation, process hollowing, and similar injection behavior. Where these protections are enabled, the safeguard directly detects or blocks process injection.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1547.006 Kernel Modules and Extensions
Comments
Anti-malware products may detect malicious kernel drivers or unsigned modules during installation or loading. However, preventing unauthorized kernel module loading relies more heavily on platform integrity and driver enforcement controls (anti-malware product monitors and blocks malicious kernel modules, drivers, or extensions) than standard anti-malware alone.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1204.002 Malicious File
Comments
Anti-malware can scan a file when it is opened or executed and quarantine or block the file before the malicious payload runs. This directly reduces the effectiveness of malicious files that depend on user execution.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1027.002 Software Packing
Comments
Packed executables are a common malware delivery method. Modern anti-malware engines unpack or emulate packed binaries during scanning, making this a direct technical capability of the safeguard.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1059.005 Visual Basic
Comments
Malicious VBScript is routinely inspected by anti-malware through script scanning and behavioral analysis prior to execution.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1059.001 PowerShell
Comments
Anti-malware integrates with PowerShell logging and AMSI to inspect scripts and commands before execution, making PowerShell malware a primary detection target.
References