CIS Controls CIS-2.6

Use technical controls to ensure that only authorized software libraries, such as specific .dll, .ocx, and .so files, are allowed to load into a system process. Block unauthorized libraries from loading into a system process. Reassess bi-annually, or more frequently.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-2.6 Allowlist Authorized Libraries mitigates T1553.003 SIP and Trust Provider Hijacking
Comments
Trust Provider Hijacking can replace or introduce malicious DLLs used by Windows trust-validation mechanisms. Where these libraries are governed, allowlisting approved trust-provider DLLs can directly prevent unauthorized components from loading.
References
    CIS-2.6 Allowlist Authorized Libraries mitigates T1505.004 IIS Components
    Comments
    Malicious IIS components commonly use ISAPI extensions, filters, or modules implemented as DLLs loaded by IIS worker processes. Where library allowlisting governs IIS library loads, blocking unauthorized DLLs directly prevents those malicious components from loading.
    References
      CIS-2.6 Allowlist Authorized Libraries mitigates T1547.008 LSASS Driver
      Comments
      LSASS Driver persistence relies on malicious DLLs or LSA plug-ins being loaded into the LSASS process. Library allowlisting can prevent unauthorized libraries from loading into LSASS, directly disrupting this persistence mechanism.
      References
        CIS-2.6 Allowlist Authorized Libraries mitigates T1547.002 Authentication Package
        Comments
        Authentication Package persistence relies on a malicious authentication DLL being loaded by the Windows authentication subsystem. Where these DLLs are subject to allowlisting, unauthorized authentication packages can be blocked at load time.
        References
          CIS-2.6 Allowlist Authorized Libraries mitigates T1546.006 LC_LOAD_DYLIB Addition
          Comments
          LC_LOAD_DYLIB abuse causes a modified Mach-O binary to load an attacker-controlled dylib. Where macOS libraries are covered by the allowlist, blocking the unauthorized dylib directly limits this technique.
          References
            CIS-2.6 Allowlist Authorized Libraries mitigates T1129 Shared Modules
            Comments
            Adversaries load DLLs, shared objects, and other modules into processes to execute malicious code. Library allowlisting directly restricts this behavior by permitting only approved modules to load.
            References
              CIS-2.6 Allowlist Authorized Libraries mitigates T1546.010 AppInit DLLs
              Comments
              Prevents unauthorized AppInit DLL persistence where load control is enforced.
              References
              CIS-2.6 Allowlist Authorized Libraries mitigates T1546.009 AppCert DLLs
              Comments
              Unauthorized persistence DLLs cannot load if restricted by library allowlisting.
              References
              CIS-2.6 Allowlist Authorized Libraries mitigates T1574.006 Dynamic Linker Hijacking
              Comments
              Enforced library validation prevents execution of malicious shared objects via linker abuse.
              References
              CIS-2.6 Allowlist Authorized Libraries mitigates T1574.012 COR_PROFILER
              Comments
              COR_PROFILER abuse requires loading a malicious profiling DLL. Library enforcement prevents unauthorized profiler DLLs from loading into .NET processes.
              References
                CIS-2.6 Allowlist Authorized Libraries mitigates T1547.005 Security Support Provider
                Comments
                SSP persistence requires loading a malicious authentication DLL. Load validation blocks unauthorized SSP modules from being loaded into LSASS.
                References
                  CIS-2.6 Allowlist Authorized Libraries mitigates T1547.004 Winlogon Helper DLL
                  Comments
                  Winlogon helper persistence relies on loading an unauthorized DLL. Library allowlisting prevents loading of non-authorized modules, directly disrupting this persistence method.
                  References
                    CIS-2.6 Allowlist Authorized Libraries mitigates T1574.001 DLL
                    Comments
                    Unauthorized DLLs fail to load if not on the allowlist, directly mitigating search order hijacking. Side-loaded malicious libraries are blocked when load validation is enforced.
                    References