Perform traffic filtering between network segments, where appropriate.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1187 | Forced Authentication |
Comments
Adversaries coerce systems into authenticating to attacker-controlled SMB or WebDAV resources in order to capture credential material. This control requires traffic filtering between network segments, which can block or tightly restrict SMB and WebDAV communications to untrusted or unauthorized destinations, directly preventing the outbound authentication path required by the technique.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Filtering unnecessary and legacy network traffic between network segments reduces opportunities for adversaries to establish adversary-in-the-middle conditions.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071 | Application Layer Protocol |
Comments
Use network filtering between segments to permit only required application-layer protocols and authorized communications, limiting adversary use of application protocols for command and control.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.001 | Web Protocols |
Comments
Restrict HTTP and HTTPS traffic crossing network-segment boundaries from critical systems to approved destinations, reducing unauthorized outbound web communications used for command and control or payload transfer.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.002 | File Transfer Protocols |
Comments
Filter FTP and SFTP traffic between network segments so sensitive systems can transfer files only to trusted internal systems or other explicitly approved destinations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.003 | Mail Protocols |
Comments
Restrict SMTP, IMAP, and POP3 traffic between segments so servers and critical systems communicate only with trusted mail infrastructure, reducing unauthorized mail-based command, control, or exfiltration paths.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.004 | DNS |
Comments
Restrict DNS traffic between segments to approved resolvers and filter requests to unknown, untrusted, or known malicious resources, reducing adversary use of DNS for command and control or concealed data transfer.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.005 | Publish/Subscribe Protocols |
Comments
Filter publish/subscribe protocol traffic crossing segment boundaries to approved brokers, destinations, and expected ports, reducing use of untrusted resources or irregular ports for command and control.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1602 | Data from Configuration Repository |
Comments
Apply network access-control rules between trusted and untrusted segments to block unauthorized management protocols used to reach configuration repositories and managed network devices.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Apply network access-control rules to restrict SNMP traffic across segment boundaries to authorized management systems, preventing unauthorized retrieval of Management Information Base data.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Apply network access-control rules to restrict management protocols used to retrieve network-device configurations to approved management segments and authorized systems.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Enforce network segmentation, proxies, and dedicated protocol services so only approved systems can communicate over protocols such as DNS, reducing opportunities to exfiltrate data through alternative protocols.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
Enforce proxies or dedicated services and restrict encrypted non-command-and-control protocol traffic between segments to systems with a legitimate requirement to use those protocols.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Enforce proxies or dedicated services and restrict asymmetric encrypted non-command-and-control protocol traffic between segments to approved systems and destinations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
Restrict unencrypted alternative-protocol traffic between network segments and allow those protocols only where required for approved business communications.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Restrict outbound traffic from public-facing or DMZ network segments to approved internal and external destinations, limiting post-exploitation communication from a compromised public-facing server.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1570 | Lateral Tool Transfer |
Comments
Restrict file-sharing communications such as SMB between network segments to systems with a legitimate requirement, reducing adversary opportunities to transfer tools laterally.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1599 | Network Boundary Bridging |
Comments
Use unaffected firewalls or routers to block unauthorized traffic that attempts to bridge established network-segment boundaries and continue monitoring to ensure the filtering remains effective.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1599.001 | Network Address Translation Traversal |
Comments
Use unaffected network filtering devices to block unauthorized traffic attempting to traverse network boundaries through NAT or related boundary-bridging mechanisms.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1095 | Non-Application Layer Protocol |
Comments
Filter traffic at network-segment boundaries to prevent use of non-application-layer protocols that are not required for business operations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1572 | Protocol Tunneling |
Comments
Filter network traffic between segments to untrusted, unauthorized, or known malicious destinations and restrict protocols that can be abused to tunnel communications across network boundaries.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1219 | Remote Access Tools |
Comments
Configure network firewalls and proxies at segment boundaries to restrict outgoing traffic to sites and services associated with unauthorized remote-access software.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1219.002 | Remote Desktop Software |
Comments
Restrict remote-desktop software traffic between network segments to authorized systems, destinations, and management paths using firewalls and proxy controls.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1021.002 | SMB/Windows Admin Shares |
Comments
Restrict SMB and Windows administrative-share communications between network segments to explicitly authorized systems and management paths.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1021.005 | VNC |
Comments
Filter or block VNC traffic across network-segment boundaries, including commonly used VNC ports, except where the communication is explicitly required.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1205 | Traffic Signaling |
Comments
Use stateful filtering at network-segment boundaries to block traffic patterns used by traffic-signaling mechanisms when the signaling implementation can be identified and constrained.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1205.001 | Port Knocking |
Comments
Use stateful filtering at network-segment boundaries to prevent port-knocking sequences from reaching protected systems where the signaling pattern can be constrained.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1205.002 | Socket Filters |
Comments
Use stateful filtering at network-segment boundaries to block crafted traffic used to trigger socket-filter-based communication when the signaling implementation can be identified.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1537 | Transfer Data to Cloud Account |
Comments
Implement network-based filtering restrictions between trusted and untrusted VPCs or equivalent network segments to prohibit unauthorized data transfers to external cloud accounts.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1197 | BITS Jobs |
Comments
Configure network filtering controls so only legitimate BITS traffic is permitted across network boundaries, restricting unauthorized BITS communications used for background transfer or execution activity.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1530 | Data from Cloud Storage |
Comments
Use network-based source restrictions and expected IP ranges when accessing cloud resources so data access is limited to authorized network locations in addition to valid user accounts.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1090 | Proxy |
Comments
Use network allow and block lists to prevent traffic between network segments and known anonymity networks or command-and-control infrastructure that may be used as proxy destinations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1090.003 | Multi-hop Proxy |
Comments
Use network allow and block lists to restrict traffic to known anonymity networks and command-and-control infrastructure that may be chained together as multi-hop proxy destinations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1218 | System Binary Proxy Execution |
Comments
Use network appliances at segment boundaries to filter ingress and egress traffic and restrict unnecessary protocols or destinations that trusted system binaries could otherwise use for malicious communications.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1218.012 | Verclsid |
Comments
Restrict unnecessary outbound traffic from systems that do not require external communications through Verclsid, using network filtering controls where the relevant traffic crosses a managed segment boundary.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1552 | Unsecured Credentials |
Comments
Restrict network access paths to cloud instance metadata services and use filtering controls to reduce exposure of metadata interfaces that may contain temporary credentials or other authentication material.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1552.005 | Cloud Instance Metadata API |
Comments
Restrict network access to the Cloud Instance Metadata API so only workloads with a legitimate requirement can reach the service, reducing adversary access to credentials and metadata through unintended network paths.
References
|