Remediate penetration test findings based on the enterprise’s documented vulnerability remediation process. This should include determining a timeline and level of effort based on the impact and prioritization of each identified finding.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1550.004 | Web Session Cookie |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and the remediation configures applications and browsers to reduce persistent sessions, shorten cookie validity, require reauthentication, and invalidate session material more aggressively.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1543 | Create or Modify System Process |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and the remediation restricts insecure service/process behavior.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1606 | Forge Web Credentials |
Comments
Application and browser configuration can reduce persistent or weakly protected web credential artifacts such as cookies that were found/forged during penetration testing.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1543.005 | Container Service |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and the remediation is related to configuring container services to run rootless or otherwise reduce unnecessary service privileges, directly constraining persistence or privilege abuse through the container service. The mapping does not apply when the finding requires patching or architectural changes rather than configuration correction.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1555.005 | Password Managers |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and the remediation deals with enforcing password-manager locking, timeout, vault-access, and related security settings that reduce exposure of stored or decrypted credentials.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1685 | Disable or Modify Tools |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation relates to hardening security, logging, and monitoring tools so they are harder to disable or reconfigure, including by enforcing permissions, persistence settings, and service configuration.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1667 | Email Bombing |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens mail service configuration, sender authentication policy, filtering, throttling, and related controls that reduce abusive high-volume email delivery.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1546.013 | PowerShell Profile |
Comments
This relationship applies when penetration testing identifies the described software-configuration weakness and remediation of the finding removes unnecessary PowerShell profiles, restrict profile modification, or configure PowerShell execution so untrusted profile content is not loaded.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1606.001 | Web Cookies |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the applications and browsers to minimize persistent cookies, shorten cookie lifetime, and apply secure cookie settings that reduce reusable credential material.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1590.002 | DNS |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the DNS zone transfers to explicitly authorized servers and correct other DNS service settings that expose internal naming information.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1559.002 | Dynamic Data Exchange |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding restricts the unnecessary DDE and embedded-content functionality in affected applications, directly reducing an execution path that relies on permissive application configuration.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1566.001 | Spearphishing Attachment |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthen mail system sender-authentication, attachment-handling, and filtering policies that reduce delivery of malicious attachments.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1566.002 | Spearphishing Link |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens mail authentication, URL-handling, and browser or mail-client policy to reduce delivery or successful use of malicious links.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1598.002 | Spearphishing Attachment |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding strengthens sender-authentication and attachment-filtering configuration to reduce spoofed or malicious messages used to solicit sensitive information.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1677 | Poisoned Pipeline Execution |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding hardens CI/CD pipeline settings by restricting unreviewed code execution, isolating runners, reducing secrets exposure, constraining triggers, and preventing user-controlled input from being implicitly trusted.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1688 | Safe Mode Boot |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding configure system settings so defensive services remain active or recover correctly when Windows is booted into Safe Mode.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1684.002 | Email Spoofing |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes and enforces SPF, DKIM, DMARC, and related mail-domain protections to reduce successful sender impersonation.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1539 | Steal Web Session Cookie |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes by configuring secure cookie attributes, shorter lifetimes, session invalidation, and reduced persistence in affected applications or browsers.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1537 | Transfer Data to Cloud Account |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes the cloud applications and services to restrict external sharing, cross account transfers, and unapproved destinations, directly constraining data movement to adversary controlled cloud accounts.
References
|
| CIS-18.3 | Remediate Penetration Test Findings | mitigates | T1535 | Unused/Unsupported Cloud Regions |
Comments
This relationship applies when penetration testing identifies the described software configuration weakness and remediation of the finding changes disables or restricts unused cloud regions and services so adversaries cannot create or operate resources in locations outside the organization's intended monitoring and governance scope.
References
|