Ensure that unauthorized software is either removed from use on enterprise assets or receives a documented exception. Review monthly, or more frequently.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1127.001 | MSBuild |
Comments
Adversaries abuse MSBuild to execute malicious code through a trusted developer utility. When MSBuild is unnecessary, explicitly classified as unauthorized, and removed under this safeguard, the executable required for this proxy-execution technique is eliminated.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1059.011 | Lua |
Comments
Adversaries can use a Lua interpreter to execute malicious Lua commands or scripts. When Lua is unauthorized on the asset and is removed through this safeguard, the interpreter required to execute Lua code is no longer available, directly restricting the technique.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1059.006 | Python |
Comments
Adversaries use installed Python interpreters to execute commands, scripts, and payloads. When Python is classified as unauthorized and removed under this safeguard, the local interpreter required for Python-based execution is eliminated, directly restricting this execution path.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1021.005 | VNC |
Comments
Adversaries use VNC server software to establish remote interactive access to systems. When VNC server software is classified as unauthorized, this safeguard requires it to be removed, eliminating the VNC server endpoint required to establish the remote session.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1547 | Boot or Logon Autostart Execution |
Comments
If unauthorized startup software is identified and removed, persistence via installed startup components is disrupted.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1543.003 | Windows Service |
Comments
Removal of unauthorized service binaries prevents continued execution of adversary-installed services.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1543 | Create or Modify System Process |
Comments
Automated detection and removal of unauthorized installed services can directly disrupt adversary-created system services used for persistence. Enforcement reduces persistence reliability.
References
|