Remotely wipe enterprise data from enterprise-owned portable end-user devices when deemed appropriate such as lost or stolen devices, or when an individual no longer supports the enterprise.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1005 | Data from Local System |
Comments
A successful remote wipe removes enterprise files, local databases, cached content, and other managed data before an adversary with possession of the device can collect it.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1114.001 | Local Email Collection |
Comments
Wiping managed email applications and locally cached mailbox files can prevent collection of Outlook PST or OST files and other locally stored enterprise email.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1539 | Steal Web Session Cookie |
Comments
Wiping managed browsers and application data removes locally stored enterprise session cookies before they can be extracted from a lost or stolen device.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1552.001 | Credentials In Files |
Comments
Remote wipe can remove managed files containing passwords, API keys, connection strings, or other credential material. The mitigation is limited to files covered by the wipe and does not address credentials stored elsewhere.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1552.002 | Credentials in Registry |
Comments
A full Windows device wipe removes local Registry hives containing enterprise credential material before they can be searched or exported. A selective enterprise-data wipe may not remove operating-system Registry data.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1552.004 | Private Keys |
Comments
Wiping enterprise-managed key files, certificates, VPN profiles, and application containers can prevent private keys from being obtained from a lost device. Keys synchronized elsewhere or already exported remain exposed and should be revoked separately.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1555.001 | Keychain |
Comments
A full wipe of a managed macOS device removes locally stored Keychain databases and enterprise certificates. Items synchronized to other devices or already extracted are not revoked merely by wiping the device.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Remote wipe of managed browser profiles can remove locally stored enterprise passwords and related authentication data. Browser-synchronized credentials and already extracted copies require separate account or server-side action.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1555.004 | Windows Credential Manager |
Comments
A full Windows wipe removes local Credential Manager vault files and associated enterprise credentials. Selective wipe implementations may not remove credentials stored outside managed application containers.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1552.003 | Shell History |
Comments
A full device wipe removes local shell-history files that may contain passwords, tokens, or sensitive commands. Selective enterprise wipes may not remove operating-system shell histories.
References
|
| CIS-4.11 | Enforce Remote Wipe Capability on Portable End-User Devices | mitigates | T1555.005 | Password Managers |
Comments
Remote wipe can remove a managed password-manager application, its local vault, and cached decrypted data. Cloud-hosted vault contents remain available and require account revocation, device removal, or token invalidation.
References
|