CIS Controls CIS-10.7

Use behavior-based anti-malware software.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1027 Obfuscated Files or Information
Comments
Behavior-based anti-malware can identify malicious activity after obfuscated content is decoded, unpacked, interpreted, or executed, allowing detection or blocking based on runtime behavior rather than relying solely on static signatures.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059 Command and Scripting Interpreter
Comments
Behavioral anti-malware commonly monitors scripting engines and detects malicious script execution through behavioral indicators rather than signatures.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059.006 Python
Comments
Products that explicitly monitor Python process behavior, command execution, child processes, and resulting system changes can detect or block malicious Python activity. Generic behavioral monitoring alone is insufficient.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1204.002 Malicious File
Comments
When a user executes a malicious file, behavior-based anti-malware can identify suspicious runtime activity and terminate or contain the process. This directly reduces the effectiveness of the malicious file after execution begins.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1055 Process Injection
Comments
Process injection produces observable behaviors such as cross-process memory writes, remote-thread creation, process hollowing, and abnormal memory execution. Behavior-based anti-malware can directly detect or block these actions.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1547.006 Kernel Modules and Extensions
Comments
Behavior-based products may monitor driver installation, kernel module loading, and suspicious kernel-level changes. Where these events are blocked or detected, the safeguard directly addresses malicious kernel persistence.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1027.002 Software Packing
Comments
Behavior-based anti-malware can identify packed malware after it unpacks in memory or begins performing malicious actions. This reduces the effectiveness of packing as a method for evading static detection.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059.005 Visual Basic
Comments
Behavior-based anti-malware can identify suspicious Visual Basic and macro execution chains, such as an Office application spawning interpreters, downloading payloads, or modifying system settings.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059.001 PowerShell
Comments
Behavior-based anti-malware can analyze PowerShell process ancestry, commands, script content, memory activity, and resulting system changes. This enables direct detection or blocking of malicious PowerShell execution.
References