CIS Controls CIS-2.5

Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. Reassess bi-annually, or more frequently.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-2.5 Allowlist Authorized Software mitigates T1059.011 Lua
Comments
Adversaries use Lua interpreters to execute Lua code. An application-control policy denying unauthorized Lua interpreters prevents those binaries from running, directly restricting Lua execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1059.006 Python
Comments
Adversaries use Python interpreters to execute malicious commands and payloads. An enforced allowlist denying Python prevents the interpreter from executing, directly removing the prerequisite for Python-based execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1176 Software Extensions
Comments
Adversaries install or use malicious browser or IDE extensions to obtain execution or persistence. The implementation to explicitly allowlists authorized extensions and blocks all others, unauthorized extensions cannot be installed or loaded, directly constraining the technique.
References
CIS-2.5 Allowlist Authorized Software mitigates T1564.003 Hidden Window
Comments
Adversaries may hide application windows while malicious programs execute. Where an unauthorized program is responsible for the hidden-window behavior, application allowlisting prevents that program from running and therefore prevents that implementation of the technique.
References
CIS-2.5 Allowlist Authorized Software mitigates T1548.004 Elevated Execution with Prompt
Comments
Adversaries may persuade users to approve elevated execution of malicious applications. If application control prevents the unapproved application from executing regardless of user approval, the malicious program cannot reach the elevation stage through this path.
References
CIS-2.5 Allowlist Authorized Software mitigates T1546.002 Screensaver
Comments
Adversaries can establish execution or persistence using malicious .scr screensaver files. Application-control rules can prevent unauthorized .scr files from executing, directly blocking the malicious executable used by the technique
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.014 MMC
Comments
Adversaries can abuse Microsoft Management Console to execute malicious content through a trusted system binary. Application allowlisting can block MMC on systems where its use is not authorized, directly preventing the executable from being used for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.013 Mavinject
Comments
Adversaries abuse mavinject.exe to inject malicious code into another process through a trusted Microsoft executable. Application allowlisting can deny execution of mavinject.exe where it is not authorized, directly preventing use of that binary for the technique.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.012 Verclsid
Comments
Adversaries abuse verclsid.exe to execute malicious COM objects through a trusted Windows binary. Application allowlisting can block verclsid.exe where it is unnecessary, directly preventing its use as the proxy executable.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.009 Regsvcs/Regasm
Comments
Adversaries use Regsvcs.exe or Regasm.exe to proxy execution of malicious .NET code. Application allowlisting can prevent these binaries from executing on systems where they are not authorized, directly preventing this execution path.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.008 Odbcconf
Comments
Adversaries abuse odbcconf.exe to execute malicious code through a trusted Windows utility. Application allowlisting can deny execution of odbcconf.exe where it is not required, directly preventing use of that proxy-execution mechanism.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.005 Mshta
Comments
Adversaries abuse mshta.exe to execute HTML application or script content through a trusted Windows binary. Application allowlisting can explicitly deny mshta.exe, preventing the executable from being used for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.004 InstallUtil
Comments
Adversaries use InstallUtil.exe to execute malicious .NET code while proxying execution through a trusted binary. Application allowlisting can block InstallUtil where it is not authorized, directly preventing use of the utility for this behavior.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.003 CMSTP
Comments
Adversaries abuse cmstp.exe to proxy execution of malicious code through a trusted Windows utility. Application allowlisting can prevent cmstp.exe from executing on systems where it is not required, directly removing the proxy-execution mechanism.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.001 Compiled HTML File
Comments
Adversaries abuse hh.exe to execute malicious compiled HTML content through a trusted Windows binary. Application allowlisting can block hh.exe where it is not authorized, preventing use of that binary for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1127.001 MSBuild
Comments
Adversaries abuse msbuild.exe to execute malicious code through a trusted Microsoft developer utility. Application allowlisting can deny execution of MSBuild on systems where it is not authorized, directly eliminating the binary used for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1059.010 AutoHotKey & AutoIT
Comments
Adversaries use AutoHotKey and AutoIT interpreters to execute automated commands and malicious scripts. Application allowlisting can block AutoHotkey.exe, AutoIt3.exe, and related unauthorized executables, directly preventing those interpreters from executing.
References
CIS-2.5 Allowlist Authorized Software mitigates T1105 Ingress Tool Transfer
Comments
Transferred malware payloads cannot execute if not explicitly authorized. Control reduces operational effectiveness post-transfer.
References
CIS-2.5 Allowlist Authorized Software mitigates T1543 Create or Modify System Process
Comments
Services relying on non-allowlisted binaries will fail to execute.
References
CIS-2.5 Allowlist Authorized Software mitigates T1219 Remote Access Tools
Comments
Application allowlisting prevents execution of unauthorized remote access tools (e.g., AnyDesk, TeamViewer, custom RATs). If not explicitly authorized, these binaries cannot execute, directly reducing adversary persistence and command-and-control capability.
References
    CIS-2.5 Allowlist Authorized Software mitigates T1218 System Binary Proxy Execution
    Comments
    If policy restricts execution to explicitly authorized binaries, unauthorized or abused proxy binaries may be prevented from executing.
    References
    CIS-2.5 Allowlist Authorized Software mitigates T1059 Command and Scripting Interpreter
    Comments
    If interpreters themselves are restricted or constrained by allowlisting, adversary-launched unauthorized interpreter binaries are blocked.
    References
    CIS-2.5 Allowlist Authorized Software mitigates T1204.002 Malicious File
    Comments
    Malicious binaries fail execution if not on the allowlist.
    References
    CIS-2.5 Allowlist Authorized Software mitigates T1204 User Execution
    Comments
    Non-allowlisted executables cannot run, directly preventing execution of malicious binaries delivered via user interaction.
    References