Deploy a host-based intrusion prevention solution on enterprise assets, where appropriate and/or supported. Example implementations include use of an Endpoint Detection and Response (EDR) client or host-based IPS agent.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1547.006 | Kernel Modules and Extensions |
Comments
Adversaries load malicious kernel modules or extensions for persistence or privilege escalation. Host-based security solutions can monitor module loading, detect known rootkits or unauthorized kernel modifications, and block or alert on suspicious kernel-extension activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059.006 | Python |
Comments
Adversaries use Python interpreters and scripts to execute malicious commands and payloads. EDR/HIPS can monitor anomalous Python execution, unusual parent-child relationships, network activity, and other suspicious behaviors, and can block or quarantine malicious payloads.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059.001 | PowerShell |
Comments
Adversaries use PowerShell to execute commands, scripts, and payloads. EDR/HIPS can monitor PowerShell process behavior, command lines, script activity, child processes, and suspicious follow-on actions, and can block or quarantine malicious activity
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059 | Command and Scripting Interpreter |
Comments
Host-based intrusion prevention capabilities can enforce behavioral controls such as Attack Surface Reduction rules to prevent Visual Basic and JavaScript from executing potentially malicious downloaded content.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059.005 | Visual Basic |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Visual Basic scripts from executing potentially malicious downloaded content.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059.007 | JavaScript |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent JavaScript scripts from executing potentially malicious downloaded content.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1543 | Create or Modify System Process |
Comments
Host-based intrusion prevention capabilities can block applications from writing signed vulnerable drivers and can enforce vulnerable-driver blocklists to reduce abuse of system processes and services.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1543.003 | Windows Service |
Comments
Host-based intrusion prevention capabilities can block applications from writing signed vulnerable service drivers and can enforce vulnerable-driver blocklists to reduce abuse of Windows services.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1486 | Data Encrypted for Impact |
Comments
Host-based intrusion prevention capabilities can use cloud-delivered protection and behavioral rules to block execution of files that exhibit ransomware-like behavior.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1006 | Direct Volume Access |
Comments
Endpoint security solutions can block behaviors associated with direct volume or backup-related access, including suspicious command execution or API calls targeting backup services.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1546.003 | Windows Management Instrumentation Event Subscription |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent malware from abusing Windows Management Instrumentation to establish persistence.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1564.014 | Extended Attributes |
Comments
Host-based security controls can inspect extended attributes alongside file contents during artifact review, packaging, or deployment to identify hidden payloads, obfuscated data, or suspicious attribute keys.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1574 | Hijack Execution Flow |
Comments
Endpoint security solutions can block behaviors associated with process injection or memory tampering based on common sequences of indicators such as suspicious API usage.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1574.013 | KernelCallbackTable |
Comments
Endpoint security solutions can block behaviors associated with KernelCallbackTable abuse and related memory-tampering activity based on common sequences of indicators and suspicious API usage.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1559 | Inter-Process Communication |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1559.002 | Dynamic Data Exchange |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1036 | Masquerading |
Comments
Host intrusion prevention systems can identify and prevent execution of potentially malicious files, including files whose signatures do not match their apparent file type.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1036.008 | Masquerade File Type |
Comments
Host intrusion prevention systems can identify and prevent execution of files whose signatures do not match their apparent file type.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1106 | Native API |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office VBA macros from calling Win32 APIs.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027 | Obfuscated Files or Information |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.009 | Embedded Payloads |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts containing embedded payloads.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.010 | Command Obfuscation |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block execution of potentially obfuscated scripts or commands.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.012 | LNK Icon Smuggling |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads delivered through LNK-based techniques.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.013 | Encrypted/Encoded File |
Comments
Host-based intrusion prevention capabilities can block execution of potentially obfuscated scripts and analyze file-encoding properties for anomalies that deviate from expected encoding practices.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.014 | Polymorphic Code |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated or polymorphic payloads.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137 | Office Application Startup |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.001 | Office Template Macros |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.002 | Office Test |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.003 | Outlook Forms |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.004 | Outlook Home Page |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.005 | Outlook Rules |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.006 | Add-ins |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1003 | OS Credential Dumping |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent credential-stealing activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1003.001 | LSASS Memory |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent attempts to steal credentials from LSASS memory.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055 | Process Injection |
Comments
Endpoint security solutions can block process-injection behavior based on common sequences of activity, including suspicious API use and code injection from applications such as Microsoft Office.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.001 | Dynamic-link Library Injection |
Comments
Endpoint security solutions can block dynamic-link library injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.002 | Portable Executable Injection |
Comments
Endpoint security solutions can block portable executable injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.003 | Thread Execution Hijacking |
Comments
Endpoint security solutions can block thread execution hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.004 | Asynchronous Procedure Call |
Comments
Endpoint security solutions can block process injection using asynchronous procedure calls based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.005 | Thread Local Storage |
Comments
Endpoint security solutions can block process injection using thread local storage based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.008 | Ptrace System Calls |
Comments
Endpoint security solutions can block process injection using ptrace system calls based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.009 | Proc Memory |
Comments
Endpoint security solutions can block process injection through proc memory based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.011 | Extra Window Memory Injection |
Comments
Endpoint security solutions can block extra window memory injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.012 | Process Hollowing |
Comments
Endpoint security solutions can block process hollowing based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.013 | Process Doppelgänging |
Comments
Endpoint security solutions can block process doppelgänging based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.014 | VDSO Hijacking |
Comments
Endpoint security solutions can block VDSO hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.015 | ListPlanting |
Comments
Endpoint security solutions can block ListPlanting based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1091 | Replication Through Removable Media |
Comments
Host-based intrusion prevention capabilities can block unsigned or untrusted executable files from running from removable media such as USB drives.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1216.001 | PubPrn |
Comments
Host-based intrusion prevention capabilities can enforce application-control policies that block older or vulnerable versions of PubPrn from executing.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1569 | System Services |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1569.002 | Service Execution |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1204 | User Execution |
Comments
Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running based on prevalence, age, trust, or behavioral criteria and can block Office applications from writing malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1204.002 | Malicious File |
Comments
Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running when they are downloaded or launched by Office applications, scripting interpreters, email clients, or fail prevalence, age, or trust criteria.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1047 | Windows Management Instrumentation |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that block processes created by Windows Management Instrumentation commands from running.
References
|