Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1059.011 | Lua |
Comments
Adversaries use Lua interpreters to execute Lua code. An application-control policy denying unauthorized Lua interpreters prevents those binaries from running, directly restricting Lua execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1059.006 | Python |
Comments
Adversaries use Python interpreters to execute malicious commands and payloads. An enforced allowlist denying Python prevents the interpreter from executing, directly removing the prerequisite for Python-based execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1176 | Software Extensions |
Comments
Adversaries install or use malicious browser or IDE extensions to obtain execution or persistence. The implementation to explicitly allowlists authorized extensions and blocks all others, unauthorized extensions cannot be installed or loaded, directly constraining the technique.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1564.003 | Hidden Window |
Comments
Adversaries may hide application windows while malicious programs execute. Where an unauthorized program is responsible for the hidden-window behavior, application allowlisting prevents that program from running and therefore prevents that implementation of the technique.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1548.004 | Elevated Execution with Prompt |
Comments
Adversaries may persuade users to approve elevated execution of malicious applications. If application control prevents the unapproved application from executing regardless of user approval, the malicious program cannot reach the elevation stage through this path.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1546.002 | Screensaver |
Comments
Adversaries can establish execution or persistence using malicious .scr screensaver files. Application-control rules can prevent unauthorized .scr files from executing, directly blocking the malicious executable used by the technique
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.014 | MMC |
Comments
Adversaries can abuse Microsoft Management Console to execute malicious content through a trusted system binary. Application allowlisting can block MMC on systems where its use is not authorized, directly preventing the executable from being used for proxy execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.013 | Mavinject |
Comments
Adversaries abuse mavinject.exe to inject malicious code into another process through a trusted Microsoft executable. Application allowlisting can deny execution of mavinject.exe where it is not authorized, directly preventing use of that binary for the technique.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.012 | Verclsid |
Comments
Adversaries abuse verclsid.exe to execute malicious COM objects through a trusted Windows binary. Application allowlisting can block verclsid.exe where it is unnecessary, directly preventing its use as the proxy executable.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.009 | Regsvcs/Regasm |
Comments
Adversaries use Regsvcs.exe or Regasm.exe to proxy execution of malicious .NET code. Application allowlisting can prevent these binaries from executing on systems where they are not authorized, directly preventing this execution path.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.008 | Odbcconf |
Comments
Adversaries abuse odbcconf.exe to execute malicious code through a trusted Windows utility. Application allowlisting can deny execution of odbcconf.exe where it is not required, directly preventing use of that proxy-execution mechanism.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.005 | Mshta |
Comments
Adversaries abuse mshta.exe to execute HTML application or script content through a trusted Windows binary. Application allowlisting can explicitly deny mshta.exe, preventing the executable from being used for proxy execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.004 | InstallUtil |
Comments
Adversaries use InstallUtil.exe to execute malicious .NET code while proxying execution through a trusted binary. Application allowlisting can block InstallUtil where it is not authorized, directly preventing use of the utility for this behavior.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.003 | CMSTP |
Comments
Adversaries abuse cmstp.exe to proxy execution of malicious code through a trusted Windows utility. Application allowlisting can prevent cmstp.exe from executing on systems where it is not required, directly removing the proxy-execution mechanism.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.001 | Compiled HTML File |
Comments
Adversaries abuse hh.exe to execute malicious compiled HTML content through a trusted Windows binary. Application allowlisting can block hh.exe where it is not authorized, preventing use of that binary for proxy execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1127.001 | MSBuild |
Comments
Adversaries abuse msbuild.exe to execute malicious code through a trusted Microsoft developer utility. Application allowlisting can deny execution of MSBuild on systems where it is not authorized, directly eliminating the binary used for proxy execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1059.010 | AutoHotKey & AutoIT |
Comments
Adversaries use AutoHotKey and AutoIT interpreters to execute automated commands and malicious scripts. Application allowlisting can block AutoHotkey.exe, AutoIt3.exe, and related unauthorized executables, directly preventing those interpreters from executing.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1105 | Ingress Tool Transfer |
Comments
Transferred malware payloads cannot execute if not explicitly authorized. Control reduces operational effectiveness post-transfer.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1543 | Create or Modify System Process |
Comments
Services relying on non-allowlisted binaries will fail to execute.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1219 | Remote Access Tools |
Comments
Application allowlisting prevents execution of unauthorized remote access tools (e.g., AnyDesk, TeamViewer, custom RATs). If not explicitly authorized, these binaries cannot execute, directly reducing adversary persistence and command-and-control capability.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218 | System Binary Proxy Execution |
Comments
If policy restricts execution to explicitly authorized binaries, unauthorized or abused proxy binaries may be prevented from executing.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1059 | Command and Scripting Interpreter |
Comments
If interpreters themselves are restricted or constrained by allowlisting, adversary-launched unauthorized interpreter binaries are blocked.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1204.002 | Malicious File |
Comments
Malicious binaries fail execution if not on the allowlist.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1204 | User Execution |
Comments
Non-allowlisted executables cannot run, directly preventing execution of malicious binaries delivered via user interaction.
References
|