Perform application layer filtering. Example implementations include a filtering proxy, application layer firewall, or gateway.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1659 | Content Injection |
Comments
Application-layer filtering can block uncommon, unauthorized, or malicious content and transferred file types at web proxies, application gateways, or similar inspection points before the content reaches protected systems.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Web filtering and application-layer gateways can block malicious web content and destinations used to deliver browser-based credential theft or session-stealing content.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1189 | Drive-by Compromise |
Comments
Web proxies and application-layer gateways can prevent access to known malicious or unnecessary websites and block malicious web content used to compromise users through drive-by activity.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1568 | Dynamic Resolution |
Comments
DNS filtering and sinkholing can prevent systems from resolving domains associated with dynamically changing adversary command-and-control infrastructure.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1568.002 | Domain Generation Algorithms |
Comments
DNS filtering and sinkholing can block domains generated by known domain-generation algorithms when those domains or generation patterns can be identified.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1567 | Exfiltration Over Web Service |
Comments
Web proxies and application-layer gateways can restrict which external web services are permitted, reducing unauthorized use of web services for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1567.001 | Exfiltration to Code Repository |
Comments
Application-layer filtering can block or restrict access to unauthorized external code repositories, limiting their use as destinations for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1567.002 | Exfiltration to Cloud Storage |
Comments
Application-layer filtering can block or restrict access to unauthorized cloud-storage services, limiting their use as destinations for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1567.003 | Exfiltration to Text Storage Sites |
Comments
Application-layer filtering can block or restrict access to unauthorized text-storage and paste services, limiting their use as destinations for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1133 | External Remote Services |
Comments
Application-layer firewalls and proxies can restrict access to unauthorized remote-access services, anonymization services, and other external services used to access enterprise resources.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1566 | Phishing |
Comments
Application-layer filtering can block malicious websites, links, attachments, and other web or email content used in phishing activity before that content reaches users.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1566.001 | Spearphishing Attachment |
Comments
Mail and application-layer gateways can inspect and block dangerous attachment types, malicious archives, and other suspicious content delivered through spearphishing attachments.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1566.002 | Spearphishing Link |
Comments
Web proxies and application-layer gateways can block access to malicious or unnecessary websites reached through spearphishing links.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1566.003 | Spearphishing via Service |
Comments
Application-layer filtering can restrict access to personal webmail, social media, and other external services that may be abused to deliver spearphishing messages.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1539 | Steal Web Session Cookie |
Comments
Web filtering and application-layer gateways can block malicious content or destinations used to deliver browser-based session-cookie theft activity.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1218 | System Binary Proxy Execution |
Comments
Application-layer filtering can restrict malicious sites, downloads, attachments, and scripts that may deliver payloads later executed through trusted system binaries.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1218.001 | Compiled HTML File |
Comments
Application-layer filtering can block CHM and other uncommon or risky file types in transit, reducing delivery of content that may be executed through Compiled HTML Help.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1204 | User Execution |
Comments
Application-layer filtering can prevent malicious web or email content from reaching users, reducing opportunities for users to execute or interact with adversary-delivered content.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1204.001 | Malicious Link |
Comments
Web proxies and application-layer gateways can block requests to malicious links and prevent associated content from being downloaded.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1204.004 | Malicious Copy and Paste |
Comments
Application-layer filtering can block malicious web content or destinations used to provide commands, scripts, or other content that users are instructed to copy and execute.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1102 | Web Service |
Comments
Web proxies and application-layer gateways can restrict access to unauthorized external web services, limiting their use for adversary command and control.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1102.001 | Dead Drop Resolver |
Comments
Application-layer filtering can block access to unauthorized web services used as dead-drop resolvers for adversary command-and-control infrastructure.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1102.002 | Bidirectional Communication |
Comments
Application-layer filtering can block unauthorized web services used for bidirectional command-and-control communications.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1102.003 | One-Way Communication |
Comments
Application-layer filtering can block unauthorized web services used for one-way command-and-control communications.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071 | Application Layer Protocol |
Comments
Application-aware gateways can inspect and restrict unauthorized application-layer protocols, services, and destinations used for adversary command and control.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.001 | Web Protocols |
Comments
Web proxies and application-layer firewalls can inspect and restrict HTTP and HTTPS traffic to unauthorized or malicious destinations.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.002 | File Transfer Protocols |
Comments
Application-layer filtering can restrict FTP, SFTP, and related file-transfer protocol traffic to approved services and destinations.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.003 | Mail Protocols |
Comments
Application-layer filtering can restrict SMTP, IMAP, POP3, and related mail-protocol traffic to approved infrastructure and expected communication paths.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.004 | DNS |
Comments
DNS proxies and filtering services can block malicious domains and restrict systems to approved name-resolution services.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.005 | Publish/Subscribe Protocols |
Comments
Application-aware filtering can restrict publish/subscribe protocols to approved brokers, destinations, and expected service ports.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Application proxies and gateways can require use of approved protocol services and restrict unauthorized application-layer protocols or destinations used for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
Application-layer gateways can restrict symmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Application-layer gateways can restrict asymmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
Application-layer filtering can directly restrict unencrypted non-command-and-control protocols to approved services and destinations.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Web application firewalls and application-layer gateways can inspect inbound application requests and block known malicious request patterns or exploit payloads targeting public-facing applications.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1187 | Forced Authentication |
Comments
Application and protocol filtering can block outbound WebDAV and related requests that may be abused to force systems to authenticate to attacker-controlled resources.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1105 | Ingress Tool Transfer |
Comments
Web proxies and application-layer gateways can block unauthorized downloads, file-transfer services, and malicious content used to transfer adversary tools into the environment.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1572 | Protocol Tunneling |
Comments
Application-aware filtering can identify and restrict unauthorized tunneling through otherwise permitted application protocols and services.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1090 | Proxy |
Comments
Application-layer gateways can block known anonymization services, unauthorized proxy services, and other proxy destinations used to conceal adversary communications.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1090.003 | Multi-hop Proxy |
Comments
Application-layer gateways can restrict known anonymization and proxy services that may be chained together to form multi-hop proxy infrastructure.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1219 | Remote Access Tools |
Comments
Application firewalls and proxies can restrict access to websites, services, and destinations associated with unauthorized remote-access tools.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1219.002 | Remote Desktop Software |
Comments
Application-layer firewalls and proxies can restrict access to unauthorized remote-desktop services and destinations.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1552 | Unsecured Credentials |
Comments
Web application firewalls and application-layer controls can block server-side request forgery paths that would otherwise expose credential-bearing cloud metadata services.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1552.005 | Cloud Instance Metadata API |
Comments
A properly configured web application firewall can block external server-side request forgery attempts that target the cloud instance metadata API and expose temporary credentials.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1499.003 | Application Exhaustion Flood |
Comments
Application-layer firewalls and web application firewalls can inspect, rate-limit, or block abusive application requests that attempt to exhaust application resources.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1499.004 | Application or System Exploitation |
Comments
Application-layer firewalls and web application firewalls can inspect and block known malicious request patterns or exploit payloads intended to cause application or system resource exhaustion.
References
|