Implement and manage a firewall on servers, where supported. Example implementations include a virtual firewall, operating system firewall, or a third-party firewall agent.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1021.002 | SMB/Windows Admin Shares |
Comments
Blocking inbound SMB (TCP 445/139) is a primary server firewall function and directly reduces lateral movement via administrative shares.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Restricting TCP 3389 to authorized management hosts directly limits unauthorized RDP access to servers.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1021 | Remote Services |
Comments
A default-deny host firewall directly restricts inbound remote service access to servers, reducing opportunities for remote administration and lateral movement.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1021.003 | Distributed Component Object Model |
Comments
DCOM relies on RPC communications that can be restricted through host firewall rules, limiting remote DCOM access to authorized systems. Dynamic RPC ports make the effectiveness dependent on careful firewall configuration.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1021.004 | SSH |
Comments
A default-deny server firewall can directly restrict inbound SSH, normally TCP 22, to approved management systems. This reduces unauthorized remote administration and lateral movement against Linux, macOS, and other SSH-enabled servers.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1021.005 | VNC |
Comments
A server firewall prevents unauthorized inbound VNC connections unless the relevant service and source systems are explicitly permitted.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1021.006 | Windows Remote Management |
Comments
Restricting WinRM ports, commonly TCP 5985 and 5986, to approved administrative systems directly limits unauthorized remote management of servers.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
When outbound filtering is configured, a server firewall can block unauthorized protocols used to exfiltrate data. Effectiveness depends on whether egress rules are enforced rather than allowing unrestricted outbound traffic.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
Outbound firewall restrictions can block unapproved encrypted non-C2 protocols or destinations used for exfiltration. The control is less effective when the traffic uses an explicitly permitted protocol and destination.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
A managed egress policy can prevent servers from establishing unapproved asymmetric encrypted connections used to transfer data. This mitigation depends on restrictive outbound rules and destination controls.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
A host firewall can block unauthorized outbound protocols and ports used for unencrypted data exfiltration. Exfiltration over an explicitly permitted service may remain possible.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1071 | Application Layer Protocol |
Comments
Application-aware or restrictive outbound firewall rules can limit unauthorized HTTP, HTTPS, DNS, SMTP, and other application-layer communications used for command and control. A basic port-only policy provides limited protection when adversaries use permitted protocols.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1090 | Proxy |
Comments
Restricting outbound server connections can prevent malware from reaching unauthorized proxy infrastructure or accepting proxy traffic on unapproved ports. Proxy activity over approved channels may still succeed.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1095 | Non-Application Layer Protocol |
Comments
Host firewalls can restrict raw IP, ICMP, GRE, and other non-application-layer protocols used for command and control. The mitigation depends on denying protocols that the server does not explicitly require.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1105 | Ingress Tool Transfer |
Comments
Restrictive outbound firewall rules can prevent a compromised server from downloading tools or payloads from unapproved external systems. The mapping is partial because transfers over approved destinations and protocols may still be possible.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1133 | External Remote Services |
Comments
A default-deny host firewall reduces the exposure of externally accessible remote services by permitting only explicitly authorized ports, protocols, and source systems.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1190 | Exploit Public-Facing Application |
Comments
A host firewall cannot remove vulnerabilities in a public-facing application, but it can ensure that only intended application ports are reachable and restrict access by source where operationally feasible. This reduces unnecessary exposure and possible exploitation paths.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1205.001 | Port Knocking |
Comments
Port knocking relies on specific traffic patterns that cause a firewall or related mechanism to expose a service port. Managed default-deny rules and monitoring of unauthorized firewall changes can restrict the trigger traffic and prevent unapproved ports from being opened.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1210 | Exploitation of Remote Services |
Comments
Exploitation of a remote service requires network reachability to the vulnerable service. A default-deny server firewall reduces the number of reachable services and limits access to authorized source systems.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1219 | Remote Access Tools |
Comments
Host firewall rules can block inbound or outbound communications associated with unauthorized remote access software. The firewall does not prevent the software from being installed or executed when it communicates over an allowed channel.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1537 | Transfer Data to Cloud Account |
Comments
Egress filtering can restrict server connections to unauthorized cloud services or accounts, making cloud-based data transfer more difficult. The mitigation depends on destination-aware outbound controls.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1557.001 | Name Resolution Poisoning and SMB Relay |
Comments
Blocking unnecessary LLMNR, NBT-NS, mDNS, NetBIOS, and SMB traffic can reduce name-resolution poisoning and relay opportunities involving servers. Disabling the protocols and enforcing SMB signing remain stronger primary mitigations.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1557.002 | ARP Cache Poisoning |
Comments
A host firewall may restrict follow-on connections created through ARP poisoning, but it has limited ability to prevent manipulation of Layer 2 address resolution itself. This is therefore a weak and environment-dependent mitigation.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1557.003 | DHCP Spoofing |
Comments
A host firewall may limit some follow-on communications after a malicious DHCP configuration is accepted, but it does not directly prevent DHCP spoofing. Network access controls and DHCP protections are the primary mitigations.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1570 | Lateral Tool Transfer |
Comments
Lateral tool transfers often rely on SMB, WinRM, SSH, or other network services that are directly governed by server firewall rules. Restricting those services to approved systems impedes common transfer channels.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1571 | Non-Standard Port |
Comments
A default-deny firewall blocks communication over arbitrary or non-standard ports unless they are explicitly permitted, directly limiting adversary use of unexpected ports.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1572 | Protocol Tunneling |
Comments
Restricting permitted ports, protocols, and destinations can impede protocol tunneling from compromised servers. Tunnels carried inside an explicitly allowed protocol may still bypass simple port-based filtering.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Blocking unnecessary SNMP traffic and restricting authorized SNMP sources reduces the ability to query management information from servers or server-hosted management services. The applicability depends on whether the server exposes SNMP.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1686 | Disable or Modify System Firewall |
Comments
Adversaries may disable or alter host firewall configurations to expose services or enable unrestricted network communication, directly undermining the safeguard. Implementing and actively managing the firewall establishes the required configuration and supports identifying or correcting unauthorized changes.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1686.001 | Cloud Firewall |
Comments
This sub-technique concerns changes to cloud firewall rules or security groups rather than a host-based firewall installed on a server. The relationship to Safeguard 4.4 is therefore indirect and primarily relevant where server firewall management also encompasses associated cloud firewall controls.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1686.002 | Network Device Firewall |
Comments
This sub-technique targets firewalls implemented on network infrastructure rather than host-based firewalls on servers. Its relationship to Safeguard 4.4 is weak and applies only where the server firewall management process also governs supporting network firewall policy.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1686.003 | Windows Host Firewall |
Comments
This sub-technique explicitly covers disabling or modifying the Windows host firewall, including changing profiles or rules to expose services or permit command-and-control traffic. Implementing and managing the required firewall configuration helps identify, prevent, or reverse unauthorized changes.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1041 | Exfiltration Over C2 Channel |
Comments
This technique may be mitigated depending on where ingress and egress is tightly controlled. For example, the use network signatures such as IP addresses or domain names to identify traffic for specific adversary malware can be used to mitigate activity at the network level.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1205.002 | Socket Filters |
Comments
ATT&CK mentions that the mitigation of some variants of this technique could be achieved through the use of stateful firewalls, depending upon how it is implemented.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1552.005 | Cloud Instance Metadata API |
Comments
ATT&CK mentions to limit access to the Instance Metadata API using a host-based firewall such as iptables. A properly configured Web Application Firewall (WAF) may help prevent external adversaries from exploiting Server-side Request Forgery (SSRF) attacks that allow access to the Cloud Instance Metadata API.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1218.012 | Verclsid |
Comments
Consider modifying host firewall rules to prevent egress traffic from verclsid.exe.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1090.003 | Multi-hop Proxy |
Comments
This technique may be lessened or mitigated though the use of firewall policy that constrains relay and redirect paths.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1197 | BITS Jobs |
Comments
Modify network and/or host firewall rules, as well as other network controls, to only allow legitimate BITS traffic.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1205 | Traffic Signaling |
Comments
ATT&CK mentions that the mitigation of some variants of this technique could be achieved through the use of stateful firewalls, depending upon how it is implemented.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1071.001 | Web Protocols |
Comments
Adversaries use web protocols to blend with normal traffic. A server firewall can partially restrict which destinations, ports, and web services a server may contact, though it will not stop all HTTP/S abuse.
References
|
| CIS-4.4 | Implement and Manage a Firewall on Servers | mitigates | T1563.002 | RDP Hijacking |
Comments
Adversaries leverage RDP if it is reachable. Firewall rules are among the most direct ways to prevent unauthorized RDP reachability to servers.
References
|