Deploy a network intrusion prevention solution, where appropriate. Example implementations include the use of a Network Intrusion Prevention System (NIPS) or equivalent CSP service.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Network intrusion prevention solutions can identify traffic patterns associated with adversary-in-the-middle activity and block the activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557.001 | Name Resolution Poisoning and SMB Relay |
Comments
Network intrusion prevention solutions can identify traffic patterns associated with name-resolution poisoning and SMB relay activity and block the activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557.002 | ARP Cache Poisoning |
Comments
Network intrusion prevention solutions can identify traffic patterns associated with ARP cache poisoning and block the activity where the relevant network traffic is monitored.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557.003 | DHCP Spoofing |
Comments
Network intrusion prevention solutions can identify traffic patterns associated with DHCP spoofing and block the activity where the relevant network traffic is monitored.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557.004 | Evil Twin |
Comments
Wireless intrusion prevention capabilities can identify rogue access points and traffic patterns associated with evil-twin activity and block or contain the unauthorized wireless connection.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071 | Application Layer Protocol |
Comments
Network intrusion prevention solutions can use signatures for known malicious application-layer traffic to block adversary command-and-control communications at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.001 | Web Protocols |
Comments
Network intrusion prevention solutions can use signatures for malicious HTTP or HTTPS traffic associated with specific adversary tools to block command-and-control activity at the network boundary.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.002 | File Transfer Protocols |
Comments
Network intrusion prevention solutions can use signatures for malicious file-transfer protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.003 | Mail Protocols |
Comments
Network intrusion prevention solutions can use signatures for malicious mail-protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.004 | DNS |
Comments
Network intrusion prevention solutions can use signatures for malicious DNS traffic associated with specific adversary tools to block command-and-control activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.005 | Publish/Subscribe Protocols |
Comments
Network intrusion prevention solutions can use signatures for malicious publish/subscribe protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1132 | Data Encoding |
Comments
Network intrusion prevention solutions can use protocol and malware-specific signatures to identify encoded command-and-control traffic and block matching activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1132.001 | Standard Encoding |
Comments
Network intrusion prevention solutions can use signatures for known protocol indicators and standard encoding patterns used by adversary tools to block matching network activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1132.002 | Non-Standard Encoding |
Comments
Network intrusion prevention solutions can use signatures for known protocol indicators and non-standard encoding patterns used by adversary tools to block matching network activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1602 | Data from Configuration Repository |
Comments
Configure network intrusion prevention solutions to identify and block unauthorized management queries and commands used to access network-device configuration repositories.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Configure network intrusion prevention solutions to identify and block SNMP queries and commands originating from unauthorized sources.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Configure network intrusion prevention solutions to identify and block unauthorized SNMP activity and unexpected Smart Install usage directed at network devices.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1001 | Data Obfuscation |
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block obfuscated command-and-control activity that remains identifiable at the network level.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1001.001 | Junk Data |
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control communications that use junk data for obfuscation.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1001.002 | Steganography |
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block network activity that uses identifiable steganographic methods.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1001.003 | Protocol or Service Impersonation |
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control activity that impersonates legitimate protocols or services.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1030 | Data Transfer Size Limits |
Comments
Network intrusion prevention solutions can use signatures associated with known adversary infrastructure and malware to block command-and-control traffic that varies transfer size to evade controls.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1568 | Dynamic Resolution |
Comments
Network intrusion prevention solutions can use signatures and known indicators associated with dynamically resolved adversary infrastructure to block matching command-and-control traffic.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1568.002 | Domain Generation Algorithms |
Comments
Network intrusion prevention solutions can block traffic to domains or patterns associated with known domain-generation algorithms when those indicators can be identified in advance or during network activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1573 | Encrypted Channel |
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block encrypted command-and-control traffic at monitored boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1573.001 | Symmetric Cryptography |
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with symmetric cryptography.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1573.002 | Asymmetric Cryptography |
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with asymmetric cryptography.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over alternative protocols.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over symmetrically encrypted non-command-and-control protocols.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over asymmetrically encrypted non-command-and-control protocols.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over unencrypted non-command-and-control protocols.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1041 | Exfiltration Over C2 Channel |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable exfiltration occurring over command-and-control channels.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1008 | Fallback Channels |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable fallback command-and-control channels at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1105 | Ingress Tool Transfer |
Comments
Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over protocols such as FTP and block the associated tool-transfer activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1570 | Lateral Tool Transfer |
Comments
Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over common tools and protocols and block lateral tool-transfer activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1104 | Multi-Stage Channels |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic associated with multi-stage command-and-control channels.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1046 | Network Service Discovery |
Comments
Network intrusion prevention solutions can identify and block remote service scanning that crosses monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1095 | Non-Application Layer Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block malicious use of non-application-layer protocols at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1571 | Non-Standard Port |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block malicious traffic using non-standard ports at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1566 | Phishing |
Comments
Network intrusion prevention solutions and network-based content controls can block malicious email links or attachments before they reach or execute on enterprise assets.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1566.001 | Spearphishing Attachment |
Comments
Network intrusion prevention solutions and network-based content controls can block malicious email attachments before they reach or execute on enterprise assets.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1542.004 | ROMMONkit |
Comments
Network intrusion prevention solutions can use signatures for protocols such as TFTP to block identifiable network activity associated with unauthorized modification of network-device boot components.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1542.005 | TFTP Boot |
Comments
Network intrusion prevention solutions can use signatures for protocols such as TFTP to block unauthorized TFTP traffic associated with network-device boot activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1572 | Protocol Tunneling |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware and tunneling traffic to block identifiable protocol-tunneling activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1090 | Proxy |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable proxy communications used for adversary command and control.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1090.001 | Internal Proxy |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable internal proxy communications used for adversary command and control.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1090.002 | External Proxy |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable external proxy communications used for adversary command and control.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1219 | Remote Access Tools |
Comments
Network intrusion prevention solutions can use network signatures to block traffic associated with unauthorized remote-access services.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1029 | Scheduled Transfer |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure and malware to block identifiable scheduled command-and-control or data-transfer activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1221 | Template Injection |
Comments
Network intrusion prevention solutions can block network activity that attempts to fetch or execute malicious payloads through externally referenced document templates.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204 | User Execution |
Comments
When user execution depends on visiting a malicious link or retrieving malicious content, network intrusion prevention solutions can block the associated network request or download.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204.001 | Malicious Link |
Comments
Network intrusion prevention solutions can block requests to malicious links and prevent associated content from being downloaded across monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204.003 | Malicious Image |
Comments
Network intrusion prevention solutions can block malicious image downloads when the content or associated network activity matches known malicious indicators.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204.004 | Malicious Copy and Paste |
Comments
Network intrusion prevention solutions can block network requests for malicious content used in copy-and-paste execution workflows when the destination or traffic matches known malicious indicators.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204.005 | Malicious Library |
Comments
Network intrusion prevention solutions can block malicious library downloads when the content or associated network activity matches known malicious indicators.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1102 | Web Service |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable command-and-control traffic using web services.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1102.001 | Dead Drop Resolver |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic to web services used as dead-drop resolvers.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1102.002 | Bidirectional Communication |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable bidirectional command-and-control traffic using web services.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1102.003 | One-Way Communication |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable one-way command-and-control traffic using web services.
References
|