Use technical controls to ensure that only authorized software libraries, such as specific .dll, .ocx, and .so files, are allowed to load into a system process. Block unauthorized libraries from loading into a system process. Reassess bi-annually, or more frequently.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1553.003 | SIP and Trust Provider Hijacking |
Comments
Trust Provider Hijacking can replace or introduce malicious DLLs used by Windows trust-validation mechanisms. Where these libraries are governed, allowlisting approved trust-provider DLLs can directly prevent unauthorized components from loading.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1505.004 | IIS Components |
Comments
Malicious IIS components commonly use ISAPI extensions, filters, or modules implemented as DLLs loaded by IIS worker processes. Where library allowlisting governs IIS library loads, blocking unauthorized DLLs directly prevents those malicious components from loading.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1547.008 | LSASS Driver |
Comments
LSASS Driver persistence relies on malicious DLLs or LSA plug-ins being loaded into the LSASS process. Library allowlisting can prevent unauthorized libraries from loading into LSASS, directly disrupting this persistence mechanism.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1547.002 | Authentication Package |
Comments
Authentication Package persistence relies on a malicious authentication DLL being loaded by the Windows authentication subsystem. Where these DLLs are subject to allowlisting, unauthorized authentication packages can be blocked at load time.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1546.006 | LC_LOAD_DYLIB Addition |
Comments
LC_LOAD_DYLIB abuse causes a modified Mach-O binary to load an attacker-controlled dylib. Where macOS libraries are covered by the allowlist, blocking the unauthorized dylib directly limits this technique.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1129 | Shared Modules |
Comments
Adversaries load DLLs, shared objects, and other modules into processes to execute malicious code. Library allowlisting directly restricts this behavior by permitting only approved modules to load.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1546.010 | AppInit DLLs |
Comments
Prevents unauthorized AppInit DLL persistence where load control is enforced.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1546.009 | AppCert DLLs |
Comments
Unauthorized persistence DLLs cannot load if restricted by library allowlisting.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1574.006 | Dynamic Linker Hijacking |
Comments
Enforced library validation prevents execution of malicious shared objects via linker abuse.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1574.012 | COR_PROFILER |
Comments
COR_PROFILER abuse requires loading a malicious profiling DLL. Library enforcement prevents unauthorized profiler DLLs from loading into .NET processes.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1547.005 | Security Support Provider |
Comments
SSP persistence requires loading a malicious authentication DLL. Load validation blocks unauthorized SSP modules from being loaded into LSASS.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1547.004 | Winlogon Helper DLL |
Comments
Winlogon helper persistence relies on loading an unauthorized DLL. Library allowlisting prevents loading of non-authorized modules, directly disrupting this persistence method.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1574.001 | DLL |
Comments
Unauthorized DLLs fail to load if not on the allowlist, directly mitigating search order hijacking. Side-loaded malicious libraries are blocked when load validation is enforced.
References
|