CIS Controls CIS-13.4

Perform traffic filtering between network segments, where appropriate.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1187 Forced Authentication
Comments
Adversaries coerce systems into authenticating to attacker-controlled SMB or WebDAV resources in order to capture credential material. This control requires traffic filtering between network segments, which can block or tightly restrict SMB and WebDAV communications to untrusted or unauthorized destinations, directly preventing the outbound authentication path required by the technique.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1557 Adversary-in-the-Middle
Comments
Filtering unnecessary and legacy network traffic between network segments reduces opportunities for adversaries to establish adversary-in-the-middle conditions.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071 Application Layer Protocol
Comments
Use network filtering between segments to permit only required application-layer protocols and authorized communications, limiting adversary use of application protocols for command and control.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.001 Web Protocols
Comments
Restrict HTTP and HTTPS traffic crossing network-segment boundaries from critical systems to approved destinations, reducing unauthorized outbound web communications used for command and control or payload transfer.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.002 File Transfer Protocols
Comments
Filter FTP and SFTP traffic between network segments so sensitive systems can transfer files only to trusted internal systems or other explicitly approved destinations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.003 Mail Protocols
Comments
Restrict SMTP, IMAP, and POP3 traffic between segments so servers and critical systems communicate only with trusted mail infrastructure, reducing unauthorized mail-based command, control, or exfiltration paths.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.004 DNS
Comments
Restrict DNS traffic between segments to approved resolvers and filter requests to unknown, untrusted, or known malicious resources, reducing adversary use of DNS for command and control or concealed data transfer.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.005 Publish/Subscribe Protocols
Comments
Filter publish/subscribe protocol traffic crossing segment boundaries to approved brokers, destinations, and expected ports, reducing use of untrusted resources or irregular ports for command and control.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1602 Data from Configuration Repository
Comments
Apply network access-control rules between trusted and untrusted segments to block unauthorized management protocols used to reach configuration repositories and managed network devices.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1602.001 SNMP (MIB Dump)
Comments
Apply network access-control rules to restrict SNMP traffic across segment boundaries to authorized management systems, preventing unauthorized retrieval of Management Information Base data.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1602.002 Network Device Configuration Dump
Comments
Apply network access-control rules to restrict management protocols used to retrieve network-device configurations to approved management segments and authorized systems.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Enforce network segmentation, proxies, and dedicated protocol services so only approved systems can communicate over protocols such as DNS, reducing opportunities to exfiltrate data through alternative protocols.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Comments
Enforce proxies or dedicated services and restrict encrypted non-command-and-control protocol traffic between segments to systems with a legitimate requirement to use those protocols.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Comments
Enforce proxies or dedicated services and restrict asymmetric encrypted non-command-and-control protocol traffic between segments to approved systems and destinations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Comments
Restrict unencrypted alternative-protocol traffic between network segments and allow those protocols only where required for approved business communications.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1190 Exploit Public-Facing Application
Comments
Restrict outbound traffic from public-facing or DMZ network segments to approved internal and external destinations, limiting post-exploitation communication from a compromised public-facing server.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1570 Lateral Tool Transfer
Comments
Restrict file-sharing communications such as SMB between network segments to systems with a legitimate requirement, reducing adversary opportunities to transfer tools laterally.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1599 Network Boundary Bridging
Comments
Use unaffected firewalls or routers to block unauthorized traffic that attempts to bridge established network-segment boundaries and continue monitoring to ensure the filtering remains effective.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1599.001 Network Address Translation Traversal
Comments
Use unaffected network filtering devices to block unauthorized traffic attempting to traverse network boundaries through NAT or related boundary-bridging mechanisms.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1095 Non-Application Layer Protocol
Comments
Filter traffic at network-segment boundaries to prevent use of non-application-layer protocols that are not required for business operations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1572 Protocol Tunneling
Comments
Filter network traffic between segments to untrusted, unauthorized, or known malicious destinations and restrict protocols that can be abused to tunnel communications across network boundaries.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1219 Remote Access Tools
Comments
Configure network firewalls and proxies at segment boundaries to restrict outgoing traffic to sites and services associated with unauthorized remote-access software.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1219.002 Remote Desktop Software
Comments
Restrict remote-desktop software traffic between network segments to authorized systems, destinations, and management paths using firewalls and proxy controls.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1021.002 SMB/Windows Admin Shares
Comments
Restrict SMB and Windows administrative-share communications between network segments to explicitly authorized systems and management paths.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1021.005 VNC
Comments
Filter or block VNC traffic across network-segment boundaries, including commonly used VNC ports, except where the communication is explicitly required.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1205 Traffic Signaling
Comments
Use stateful filtering at network-segment boundaries to block traffic patterns used by traffic-signaling mechanisms when the signaling implementation can be identified and constrained.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1205.001 Port Knocking
Comments
Use stateful filtering at network-segment boundaries to prevent port-knocking sequences from reaching protected systems where the signaling pattern can be constrained.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1205.002 Socket Filters
Comments
Use stateful filtering at network-segment boundaries to block crafted traffic used to trigger socket-filter-based communication when the signaling implementation can be identified.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1537 Transfer Data to Cloud Account
Comments
Implement network-based filtering restrictions between trusted and untrusted VPCs or equivalent network segments to prohibit unauthorized data transfers to external cloud accounts.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1197 BITS Jobs
Comments
Configure network filtering controls so only legitimate BITS traffic is permitted across network boundaries, restricting unauthorized BITS communications used for background transfer or execution activity.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1530 Data from Cloud Storage
Comments
Use network-based source restrictions and expected IP ranges when accessing cloud resources so data access is limited to authorized network locations in addition to valid user accounts.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1090 Proxy
Comments
Use network allow and block lists to prevent traffic between network segments and known anonymity networks or command-and-control infrastructure that may be used as proxy destinations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1090.003 Multi-hop Proxy
Comments
Use network allow and block lists to restrict traffic to known anonymity networks and command-and-control infrastructure that may be chained together as multi-hop proxy destinations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1218 System Binary Proxy Execution
Comments
Use network appliances at segment boundaries to filter ingress and egress traffic and restrict unnecessary protocols or destinations that trusted system binaries could otherwise use for malicious communications.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1218.012 Verclsid
Comments
Restrict unnecessary outbound traffic from systems that do not require external communications through Verclsid, using network filtering controls where the relevant traffic crosses a managed segment boundary.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1552 Unsecured Credentials
Comments
Restrict network access paths to cloud instance metadata services and use filtering controls to reduce exposure of metadata interfaces that may contain temporary credentials or other authentication material.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1552.005 Cloud Instance Metadata API
Comments
Restrict network access to the Cloud Instance Metadata API so only workloads with a legitimate requirement can reach the service, reducing adversary access to credentials and metadata through unintended network paths.
References