Disable autorun and autoplay auto-execute functionality for removable media.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-10.3 | Disable Autorun and Autoplay for Removable Media | mitigates | T1092 | Communication Through Removable Media |
Comments
Disable Autoruns if it is unnecessary to help prevent adversaries from performing command and control between compromised hosts on potentially disconnected networks by using removable media to transfer commands from system to system.
References
|
| CIS-10.3 | Disable Autorun and Autoplay for Removable Media | mitigates | T1091 | Replication Through Removable Media |
Comments
Many removable-media malware families rely on Autorun/Autoplay to automatically execute malicious code after an infected USB device is inserted. Disabling these operating system features directly interrupts the automatic execution mechanism used to propagate malware through removable media, forcing an attacker to rely on manual execution or another execution vector.
References
|