Use behavior-based anti-malware software.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1027 | Obfuscated Files or Information |
Comments
Behavior-based anti-malware can identify malicious activity after obfuscated content is decoded, unpacked, interpreted, or executed, allowing detection or blocking based on runtime behavior rather than relying solely on static signatures.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1059 | Command and Scripting Interpreter |
Comments
Behavioral anti-malware commonly monitors scripting engines and detects malicious script execution through behavioral indicators rather than signatures.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1059.006 | Python |
Comments
Products that explicitly monitor Python process behavior, command execution, child processes, and resulting system changes can detect or block malicious Python activity. Generic behavioral monitoring alone is insufficient.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1204.002 | Malicious File |
Comments
When a user executes a malicious file, behavior-based anti-malware can identify suspicious runtime activity and terminate or contain the process. This directly reduces the effectiveness of the malicious file after execution begins.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1055 | Process Injection |
Comments
Process injection produces observable behaviors such as cross-process memory writes, remote-thread creation, process hollowing, and abnormal memory execution. Behavior-based anti-malware can directly detect or block these actions.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1547.006 | Kernel Modules and Extensions |
Comments
Behavior-based products may monitor driver installation, kernel module loading, and suspicious kernel-level changes. Where these events are blocked or detected, the safeguard directly addresses malicious kernel persistence.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1027.002 | Software Packing |
Comments
Behavior-based anti-malware can identify packed malware after it unpacks in memory or begins performing malicious actions. This reduces the effectiveness of packing as a method for evading static detection.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1059.005 | Visual Basic |
Comments
Behavior-based anti-malware can identify suspicious Visual Basic and macro execution chains, such as an Office application spawning interpreters, downloading payloads, or modifying system settings.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1059.001 | PowerShell |
Comments
Behavior-based anti-malware can analyze PowerShell process ancestry, commands, script content, memory activity, and resulting system changes. This enables direct detection or blocking of malicious PowerShell execution.
References
|