CIS Controls CIS-10.5

Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-10.5 Enable Anti-Exploitation Features mitigates T1211 Exploitation for Stealth
Comments
Security anti-exploitation tools and applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to help mitigate some exploitation behavior to evade detection.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1687 Exploitation for Defense Impairment
Comments
Adversaries may exploit anti-malware, EDR, logging, or other defensive components to disable or impair them. Anti-exploitation controls protecting those components directly restrict this behavior.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1212 Exploitation for Credential Access
Comments
Adversaries may exploit authentication, kernel, or security processes to access credentials. Anti-exploitation protections that cover the targeted component directly reduce the likelihood that the exploit succeeds.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1210 Exploitation of Remote Services
Comments
Remote-service exploitation targets vulnerabilities in network-accessible services or protocol handlers. Anti-exploitation protections applied to the targeted service can block the exploit or prevent successful payload execution.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1190 Exploit Public-Facing Application
Comments
Public-facing services frequently become initial access vectors through software vulnerabilities. Exploit mitigation technologies increase resistance to successful exploitation by preventing or disrupting exploit execution.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1189 Drive-by Compromise
Comments
Drive-by attacks commonly rely on browser or plugin exploitation. DEP, ASLR, CFG, and exploit guards are intended to prevent exploitation of these vulnerabilities before malicious code executes.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1068 Exploitation for Privilege Escalation
Comments
Kernel, memory, driver, and control-flow protections can prevent exploitation of vulnerable components used to obtain elevated privileges. This is a direct technical restriction on privilege-escalation exploits.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1203 Exploitation for Client Execution
Comments
Data execution prevention, control-flow protections, exploit guards, and similar mechanisms interfere directly with memory corruption and code execution in client applications. These features reduce the ability of an exploit to execute its payload.
References