CIS Controls CIS-13.10

Perform application layer filtering. Example implementations include a filtering proxy, application layer firewall, or gateway.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-13.10 Perform Application Layer Filtering mitigates T1659 Content Injection
Comments
Application-layer filtering can block uncommon, unauthorized, or malicious content and transferred file types at web proxies, application gateways, or similar inspection points before the content reaches protected systems.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1555.003 Credentials from Web Browsers
Comments
Web filtering and application-layer gateways can block malicious web content and destinations used to deliver browser-based credential theft or session-stealing content.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1189 Drive-by Compromise
Comments
Web proxies and application-layer gateways can prevent access to known malicious or unnecessary websites and block malicious web content used to compromise users through drive-by activity.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1568 Dynamic Resolution
Comments
DNS filtering and sinkholing can prevent systems from resolving domains associated with dynamically changing adversary command-and-control infrastructure.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1568.002 Domain Generation Algorithms
Comments
DNS filtering and sinkholing can block domains generated by known domain-generation algorithms when those domains or generation patterns can be identified.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1567 Exfiltration Over Web Service
Comments
Web proxies and application-layer gateways can restrict which external web services are permitted, reducing unauthorized use of web services for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1567.001 Exfiltration to Code Repository
Comments
Application-layer filtering can block or restrict access to unauthorized external code repositories, limiting their use as destinations for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1567.002 Exfiltration to Cloud Storage
Comments
Application-layer filtering can block or restrict access to unauthorized cloud-storage services, limiting their use as destinations for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1567.003 Exfiltration to Text Storage Sites
Comments
Application-layer filtering can block or restrict access to unauthorized text-storage and paste services, limiting their use as destinations for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1133 External Remote Services
Comments
Application-layer firewalls and proxies can restrict access to unauthorized remote-access services, anonymization services, and other external services used to access enterprise resources.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1566 Phishing
Comments
Application-layer filtering can block malicious websites, links, attachments, and other web or email content used in phishing activity before that content reaches users.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1566.001 Spearphishing Attachment
Comments
Mail and application-layer gateways can inspect and block dangerous attachment types, malicious archives, and other suspicious content delivered through spearphishing attachments.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1566.002 Spearphishing Link
Comments
Web proxies and application-layer gateways can block access to malicious or unnecessary websites reached through spearphishing links.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1566.003 Spearphishing via Service
Comments
Application-layer filtering can restrict access to personal webmail, social media, and other external services that may be abused to deliver spearphishing messages.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1539 Steal Web Session Cookie
Comments
Web filtering and application-layer gateways can block malicious content or destinations used to deliver browser-based session-cookie theft activity.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1218 System Binary Proxy Execution
Comments
Application-layer filtering can restrict malicious sites, downloads, attachments, and scripts that may deliver payloads later executed through trusted system binaries.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1218.001 Compiled HTML File
Comments
Application-layer filtering can block CHM and other uncommon or risky file types in transit, reducing delivery of content that may be executed through Compiled HTML Help.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1204 User Execution
Comments
Application-layer filtering can prevent malicious web or email content from reaching users, reducing opportunities for users to execute or interact with adversary-delivered content.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1204.001 Malicious Link
Comments
Web proxies and application-layer gateways can block requests to malicious links and prevent associated content from being downloaded.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1204.004 Malicious Copy and Paste
Comments
Application-layer filtering can block malicious web content or destinations used to provide commands, scripts, or other content that users are instructed to copy and execute.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1102 Web Service
Comments
Web proxies and application-layer gateways can restrict access to unauthorized external web services, limiting their use for adversary command and control.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1102.001 Dead Drop Resolver
Comments
Application-layer filtering can block access to unauthorized web services used as dead-drop resolvers for adversary command-and-control infrastructure.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1102.002 Bidirectional Communication
Comments
Application-layer filtering can block unauthorized web services used for bidirectional command-and-control communications.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1102.003 One-Way Communication
Comments
Application-layer filtering can block unauthorized web services used for one-way command-and-control communications.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071 Application Layer Protocol
Comments
Application-aware gateways can inspect and restrict unauthorized application-layer protocols, services, and destinations used for adversary command and control.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.001 Web Protocols
Comments
Web proxies and application-layer firewalls can inspect and restrict HTTP and HTTPS traffic to unauthorized or malicious destinations.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.002 File Transfer Protocols
Comments
Application-layer filtering can restrict FTP, SFTP, and related file-transfer protocol traffic to approved services and destinations.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.003 Mail Protocols
Comments
Application-layer filtering can restrict SMTP, IMAP, POP3, and related mail-protocol traffic to approved infrastructure and expected communication paths.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.004 DNS
Comments
DNS proxies and filtering services can block malicious domains and restrict systems to approved name-resolution services.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.005 Publish/Subscribe Protocols
Comments
Application-aware filtering can restrict publish/subscribe protocols to approved brokers, destinations, and expected service ports.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Application proxies and gateways can require use of approved protocol services and restrict unauthorized application-layer protocols or destinations used for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Comments
Application-layer gateways can restrict symmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Comments
Application-layer gateways can restrict asymmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Comments
Application-layer filtering can directly restrict unencrypted non-command-and-control protocols to approved services and destinations.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1190 Exploit Public-Facing Application
Comments
Web application firewalls and application-layer gateways can inspect inbound application requests and block known malicious request patterns or exploit payloads targeting public-facing applications.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1187 Forced Authentication
Comments
Application and protocol filtering can block outbound WebDAV and related requests that may be abused to force systems to authenticate to attacker-controlled resources.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1105 Ingress Tool Transfer
Comments
Web proxies and application-layer gateways can block unauthorized downloads, file-transfer services, and malicious content used to transfer adversary tools into the environment.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1572 Protocol Tunneling
Comments
Application-aware filtering can identify and restrict unauthorized tunneling through otherwise permitted application protocols and services.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1090 Proxy
Comments
Application-layer gateways can block known anonymization services, unauthorized proxy services, and other proxy destinations used to conceal adversary communications.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1090.003 Multi-hop Proxy
Comments
Application-layer gateways can restrict known anonymization and proxy services that may be chained together to form multi-hop proxy infrastructure.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1219 Remote Access Tools
Comments
Application firewalls and proxies can restrict access to websites, services, and destinations associated with unauthorized remote-access tools.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1219.002 Remote Desktop Software
Comments
Application-layer firewalls and proxies can restrict access to unauthorized remote-desktop services and destinations.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1552 Unsecured Credentials
Comments
Web application firewalls and application-layer controls can block server-side request forgery paths that would otherwise expose credential-bearing cloud metadata services.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1552.005 Cloud Instance Metadata API
Comments
A properly configured web application firewall can block external server-side request forgery attempts that target the cloud instance metadata API and expose temporary credentials.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1499.003 Application Exhaustion Flood
Comments
Application-layer firewalls and web application firewalls can inspect, rate-limit, or block abusive application requests that attempt to exhaust application resources.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1499.004 Application or System Exploitation
Comments
Application-layer firewalls and web application firewalls can inspect and block known malicious request patterns or exploit payloads intended to cause application or system resource exhaustion.
References