Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1211 | Exploitation for Stealth |
Comments
Security anti-exploitation tools and applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to help mitigate some exploitation behavior to evade detection.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1687 | Exploitation for Defense Impairment |
Comments
Adversaries may exploit anti-malware, EDR, logging, or other defensive components to disable or impair them. Anti-exploitation controls protecting those components directly restrict this behavior.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1212 | Exploitation for Credential Access |
Comments
Adversaries may exploit authentication, kernel, or security processes to access credentials. Anti-exploitation protections that cover the targeted component directly reduce the likelihood that the exploit succeeds.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1210 | Exploitation of Remote Services |
Comments
Remote-service exploitation targets vulnerabilities in network-accessible services or protocol handlers. Anti-exploitation protections applied to the targeted service can block the exploit or prevent successful payload execution.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Public-facing services frequently become initial access vectors through software vulnerabilities. Exploit mitigation technologies increase resistance to successful exploitation by preventing or disrupting exploit execution.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1189 | Drive-by Compromise |
Comments
Drive-by attacks commonly rely on browser or plugin exploitation. DEP, ASLR, CFG, and exploit guards are intended to prevent exploitation of these vulnerabilities before malicious code executes.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
Kernel, memory, driver, and control-flow protections can prevent exploitation of vulnerable components used to obtain elevated privileges. This is a direct technical restriction on privilege-escalation exploits.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1203 | Exploitation for Client Execution |
Comments
Data execution prevention, control-flow protections, exploit guards, and similar mechanisms interfere directly with memory corruption and code execution in client applications. These features reduce the ability of an exploit to execute its payload.
References
|