CIS Controls CIS-13.8

Deploy a network intrusion prevention solution, where appropriate. Example implementations include the use of a Network Intrusion Prevention System (NIPS) or equivalent CSP service.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557 Adversary-in-the-Middle
Comments
Network intrusion prevention solutions can identify traffic patterns associated with adversary-in-the-middle activity and block the activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.001 Name Resolution Poisoning and SMB Relay
Comments
Network intrusion prevention solutions can identify traffic patterns associated with name-resolution poisoning and SMB relay activity and block the activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.002 ARP Cache Poisoning
Comments
Network intrusion prevention solutions can identify traffic patterns associated with ARP cache poisoning and block the activity where the relevant network traffic is monitored.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.003 DHCP Spoofing
Comments
Network intrusion prevention solutions can identify traffic patterns associated with DHCP spoofing and block the activity where the relevant network traffic is monitored.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.004 Evil Twin
Comments
Wireless intrusion prevention capabilities can identify rogue access points and traffic patterns associated with evil-twin activity and block or contain the unauthorized wireless connection.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071 Application Layer Protocol
Comments
Network intrusion prevention solutions can use signatures for known malicious application-layer traffic to block adversary command-and-control communications at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.001 Web Protocols
Comments
Network intrusion prevention solutions can use signatures for malicious HTTP or HTTPS traffic associated with specific adversary tools to block command-and-control activity at the network boundary.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.002 File Transfer Protocols
Comments
Network intrusion prevention solutions can use signatures for malicious file-transfer protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.003 Mail Protocols
Comments
Network intrusion prevention solutions can use signatures for malicious mail-protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.004 DNS
Comments
Network intrusion prevention solutions can use signatures for malicious DNS traffic associated with specific adversary tools to block command-and-control activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.005 Publish/Subscribe Protocols
Comments
Network intrusion prevention solutions can use signatures for malicious publish/subscribe protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1132 Data Encoding
Comments
Network intrusion prevention solutions can use protocol and malware-specific signatures to identify encoded command-and-control traffic and block matching activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1132.001 Standard Encoding
Comments
Network intrusion prevention solutions can use signatures for known protocol indicators and standard encoding patterns used by adversary tools to block matching network activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1132.002 Non-Standard Encoding
Comments
Network intrusion prevention solutions can use signatures for known protocol indicators and non-standard encoding patterns used by adversary tools to block matching network activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1602 Data from Configuration Repository
Comments
Configure network intrusion prevention solutions to identify and block unauthorized management queries and commands used to access network-device configuration repositories.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1602.001 SNMP (MIB Dump)
Comments
Configure network intrusion prevention solutions to identify and block SNMP queries and commands originating from unauthorized sources.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1602.002 Network Device Configuration Dump
Comments
Configure network intrusion prevention solutions to identify and block unauthorized SNMP activity and unexpected Smart Install usage directed at network devices.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001 Data Obfuscation
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block obfuscated command-and-control activity that remains identifiable at the network level.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001.001 Junk Data
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control communications that use junk data for obfuscation.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001.002 Steganography
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block network activity that uses identifiable steganographic methods.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001.003 Protocol or Service Impersonation
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control activity that impersonates legitimate protocols or services.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1030 Data Transfer Size Limits
Comments
Network intrusion prevention solutions can use signatures associated with known adversary infrastructure and malware to block command-and-control traffic that varies transfer size to evade controls.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1568 Dynamic Resolution
Comments
Network intrusion prevention solutions can use signatures and known indicators associated with dynamically resolved adversary infrastructure to block matching command-and-control traffic.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1568.002 Domain Generation Algorithms
Comments
Network intrusion prevention solutions can block traffic to domains or patterns associated with known domain-generation algorithms when those indicators can be identified in advance or during network activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1573 Encrypted Channel
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block encrypted command-and-control traffic at monitored boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1573.001 Symmetric Cryptography
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with symmetric cryptography.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1573.002 Asymmetric Cryptography
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with asymmetric cryptography.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over alternative protocols.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over symmetrically encrypted non-command-and-control protocols.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over asymmetrically encrypted non-command-and-control protocols.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over unencrypted non-command-and-control protocols.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1041 Exfiltration Over C2 Channel
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable exfiltration occurring over command-and-control channels.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1008 Fallback Channels
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable fallback command-and-control channels at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1105 Ingress Tool Transfer
Comments
Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over protocols such as FTP and block the associated tool-transfer activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1570 Lateral Tool Transfer
Comments
Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over common tools and protocols and block lateral tool-transfer activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1104 Multi-Stage Channels
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic associated with multi-stage command-and-control channels.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1046 Network Service Discovery
Comments
Network intrusion prevention solutions can identify and block remote service scanning that crosses monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1095 Non-Application Layer Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block malicious use of non-application-layer protocols at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1571 Non-Standard Port
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block malicious traffic using non-standard ports at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1566 Phishing
Comments
Network intrusion prevention solutions and network-based content controls can block malicious email links or attachments before they reach or execute on enterprise assets.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1566.001 Spearphishing Attachment
Comments
Network intrusion prevention solutions and network-based content controls can block malicious email attachments before they reach or execute on enterprise assets.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1542.004 ROMMONkit
Comments
Network intrusion prevention solutions can use signatures for protocols such as TFTP to block identifiable network activity associated with unauthorized modification of network-device boot components.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1542.005 TFTP Boot
Comments
Network intrusion prevention solutions can use signatures for protocols such as TFTP to block unauthorized TFTP traffic associated with network-device boot activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1572 Protocol Tunneling
Comments
Network intrusion prevention solutions can use signatures for known adversary malware and tunneling traffic to block identifiable protocol-tunneling activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1090 Proxy
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable proxy communications used for adversary command and control.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1090.001 Internal Proxy
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable internal proxy communications used for adversary command and control.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1090.002 External Proxy
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable external proxy communications used for adversary command and control.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1219 Remote Access Tools
Comments
Network intrusion prevention solutions can use network signatures to block traffic associated with unauthorized remote-access services.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1029 Scheduled Transfer
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure and malware to block identifiable scheduled command-and-control or data-transfer activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1221 Template Injection
Comments
Network intrusion prevention solutions can block network activity that attempts to fetch or execute malicious payloads through externally referenced document templates.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204 User Execution
Comments
When user execution depends on visiting a malicious link or retrieving malicious content, network intrusion prevention solutions can block the associated network request or download.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.001 Malicious Link
Comments
Network intrusion prevention solutions can block requests to malicious links and prevent associated content from being downloaded across monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.003 Malicious Image
Comments
Network intrusion prevention solutions can block malicious image downloads when the content or associated network activity matches known malicious indicators.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.004 Malicious Copy and Paste
Comments
Network intrusion prevention solutions can block network requests for malicious content used in copy-and-paste execution workflows when the destination or traffic matches known malicious indicators.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.005 Malicious Library
Comments
Network intrusion prevention solutions can block malicious library downloads when the content or associated network activity matches known malicious indicators.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102 Web Service
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable command-and-control traffic using web services.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.001 Dead Drop Resolver
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic to web services used as dead-drop resolvers.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.002 Bidirectional Communication
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable bidirectional command-and-control traffic using web services.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.003 One-Way Communication
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable one-way command-and-control traffic using web services.
References