CIS Controls CIS-13.7

Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1547.006 Kernel Modules and Extensions
Comments
Adversaries load malicious kernel modules or extensions for persistence or privilege escalation. Host-based security solutions can monitor module loading, detect known rootkits or unauthorized kernel modifications, and block or alert on suspicious kernel-extension activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.006 Python
Comments
Adversaries use Python interpreters and scripts to execute malicious commands and payloads. EDR/HIPS can monitor anomalous Python execution, unusual parent-child relationships, network activity, and other suspicious behaviors, and can block or quarantine malicious payloads.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.001 PowerShell
Comments
Adversaries use PowerShell to execute commands, scripts, and payloads. EDR/HIPS can monitor PowerShell process behavior, command lines, script activity, child processes, and suspicious follow-on actions, and can block or quarantine malicious activity
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059 Command and Scripting Interpreter
Comments
Host-based intrusion prevention capabilities can enforce behavioral controls such as Attack Surface Reduction rules to prevent Visual Basic and JavaScript from executing potentially malicious downloaded content.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.005 Visual Basic
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Visual Basic scripts from executing potentially malicious downloaded content.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.007 JavaScript
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent JavaScript scripts from executing potentially malicious downloaded content.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1543 Create or Modify System Process
Comments
Host-based intrusion prevention capabilities can block applications from writing signed vulnerable drivers and can enforce vulnerable-driver blocklists to reduce abuse of system processes and services.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1543.003 Windows Service
Comments
Host-based intrusion prevention capabilities can block applications from writing signed vulnerable service drivers and can enforce vulnerable-driver blocklists to reduce abuse of Windows services.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1486 Data Encrypted for Impact
Comments
Host-based intrusion prevention capabilities can use cloud-delivered protection and behavioral rules to block execution of files that exhibit ransomware-like behavior.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1006 Direct Volume Access
Comments
Endpoint security solutions can block behaviors associated with direct volume or backup-related access, including suspicious command execution or API calls targeting backup services.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1546.003 Windows Management Instrumentation Event Subscription
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent malware from abusing Windows Management Instrumentation to establish persistence.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1564.014 Extended Attributes
Comments
Host-based security controls can inspect extended attributes alongside file contents during artifact review, packaging, or deployment to identify hidden payloads, obfuscated data, or suspicious attribute keys.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1574 Hijack Execution Flow
Comments
Endpoint security solutions can block behaviors associated with process injection or memory tampering based on common sequences of indicators such as suspicious API usage.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1574.013 KernelCallbackTable
Comments
Endpoint security solutions can block behaviors associated with KernelCallbackTable abuse and related memory-tampering activity based on common sequences of indicators and suspicious API usage.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1559 Inter-Process Communication
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1559.002 Dynamic Data Exchange
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1036 Masquerading
Comments
Host intrusion prevention systems can identify and prevent execution of potentially malicious files, including files whose signatures do not match their apparent file type.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1036.008 Masquerade File Type
Comments
Host intrusion prevention systems can identify and prevent execution of files whose signatures do not match their apparent file type.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1106 Native API
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office VBA macros from calling Win32 APIs.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027 Obfuscated Files or Information
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.009 Embedded Payloads
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts containing embedded payloads.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.010 Command Obfuscation
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block execution of potentially obfuscated scripts or commands.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.012 LNK Icon Smuggling
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads delivered through LNK-based techniques.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.013 Encrypted/Encoded File
Comments
Host-based intrusion prevention capabilities can block execution of potentially obfuscated scripts and analyze file-encoding properties for anomalies that deviate from expected encoding practices.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.014 Polymorphic Code
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated or polymorphic payloads.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137 Office Application Startup
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.001 Office Template Macros
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.002 Office Test
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.003 Outlook Forms
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.004 Outlook Home Page
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.005 Outlook Rules
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.006 Add-ins
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1003 OS Credential Dumping
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent credential-stealing activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1003.001 LSASS Memory
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent attempts to steal credentials from LSASS memory.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055 Process Injection
Comments
Endpoint security solutions can block process-injection behavior based on common sequences of activity, including suspicious API use and code injection from applications such as Microsoft Office.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.001 Dynamic-link Library Injection
Comments
Endpoint security solutions can block dynamic-link library injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.002 Portable Executable Injection
Comments
Endpoint security solutions can block portable executable injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.003 Thread Execution Hijacking
Comments
Endpoint security solutions can block thread execution hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.004 Asynchronous Procedure Call
Comments
Endpoint security solutions can block process injection using asynchronous procedure calls based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.005 Thread Local Storage
Comments
Endpoint security solutions can block process injection using thread local storage based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.008 Ptrace System Calls
Comments
Endpoint security solutions can block process injection using ptrace system calls based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.009 Proc Memory
Comments
Endpoint security solutions can block process injection through proc memory based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.011 Extra Window Memory Injection
Comments
Endpoint security solutions can block extra window memory injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.012 Process Hollowing
Comments
Endpoint security solutions can block process hollowing based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.013 Process Doppelgänging
Comments
Endpoint security solutions can block process doppelgänging based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.014 VDSO Hijacking
Comments
Endpoint security solutions can block VDSO hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.015 ListPlanting
Comments
Endpoint security solutions can block ListPlanting based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1091 Replication Through Removable Media
Comments
Host-based intrusion prevention capabilities can block unsigned or untrusted executable files from running from removable media such as USB drives.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1216.001 PubPrn
Comments
Host-based intrusion prevention capabilities can enforce application-control policies that block older or vulnerable versions of PubPrn from executing.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1569 System Services
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1569.002 Service Execution
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1204 User Execution
Comments
Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running based on prevalence, age, trust, or behavioral criteria and can block Office applications from writing malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1204.002 Malicious File
Comments
Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running when they are downloaded or launched by Office applications, scripting interpreters, email clients, or fail prevalence, age, or trust criteria.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1047 Windows Management Instrumentation
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that block processes created by Windows Management Instrumentation commands from running.
References