Implement and manage a host-based firewall or port-filtering tool on end-user devices, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021 | Remote Services |
Comments
A default-deny endpoint firewall directly restricts unsolicited remote-service connections and permits access only through explicitly approved services, ports, and management paths.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Restricting TCP 3389 to approved management sources directly prevents unauthorized RDP connections and reduces RDP-based lateral movement.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021.002 | SMB/Windows Admin Shares |
Comments
Blocking or tightly restricting TCP 445 and 139 directly impedes access to administrative shares and other SMB-based lateral movement paths.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021.004 | SSH |
Comments
A default-deny firewall can block inbound SSH or restrict TCP 22 to approved management systems, directly limiting remote access to SSH-enabled end-user devices.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021.005 | VNC |
Comments
VNC requires an accessible listener, commonly on TCP 5900 and related ports. Blocking those ports unless specifically authorized directly prevents unauthorized VNC access.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021.006 | Windows Remote Management |
Comments
Restricting TCP 5985 and 5986 to approved systems directly limits adversary use of WinRM for remote administration and lateral movement.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1210 | Exploitation of Remote Services |
Comments
Exploiting a remote service requires network reachability to that service. Default-deny endpoint rules remove unnecessary exposure and can restrict necessary services to trusted source systems.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1571 | Non-Standard Port |
Comments
Default-deny rules directly block arbitrary and unexpected ports unless they have been explicitly approved, limiting adversary communications over non-standard ports.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021.003 | Distributed Component Object Model |
Comments
A firewall can restrict DCOM by controlling RPC endpoint mapper traffic and dynamic RPC ports. The relationship is direct, but implementation is more complex than filtering a single fixed port.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Restrictive outbound rules can prevent an endpoint from using unapproved protocols and ports for data exfiltration. The technique remains possible over protocols the organization must allow.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
The firewall can block unapproved encrypted protocols, ports, or destinations used for exfiltration. It generally cannot identify malicious content inside an allowed encrypted connection.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Default-deny egress controls can prevent asymmetric encrypted sessions using unauthorized ports or services. Connections through an approved service may still succeed.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
Unapproved outbound services and ports used for cleartext exfiltration can be directly blocked. Effectiveness decreases when the adversary uses an operationally required protocol.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1071 | Application Layer Protocol |
Comments
Endpoint firewalls can restrict which application protocols and services may communicate externally. The mapping is partial because common application protocols may need to remain available.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1071.002 | File Transfer Protocols |
Comments
FTP, SFTP, FTPS, and related file-transfer traffic can be denied or limited to approved destinations. File transfer over a generally permitted web protocol may remain possible.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1071.003 | Mail Protocols |
Comments
SMTP, IMAP, and POP traffic can be restricted to authorized mail infrastructure, reducing adversary use of attacker-controlled mail services for command and control.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1071.004 | DNS |
Comments
The firewall can force devices to use approved DNS resolvers and block direct DNS traffic to external systems. It does not by itself identify malicious data embedded in DNS traffic sent through an approved resolver.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1071.005 | Publish/Subscribe Protocols |
Comments
Default-deny policies can block MQTT and other publish/subscribe services unless they are explicitly required. An approved publish/subscribe service could still be misused.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1090.001 | Internal Proxy |
Comments
Restricting inbound listeners and lateral outbound connections makes it more difficult for a compromised endpoint to act as an unauthorized proxy for other systems.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1095 | Non-Application Layer Protocol |
Comments
A host firewall can deny unnecessary ICMP, GRE, raw IP, and other non-application protocols that adversaries may use for command and control.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1105 | Ingress Tool Transfer |
Comments
Default-deny egress policies can prevent compromised endpoints from retrieving payloads from unapproved systems, ports, or protocols. Transfers from an approved destination remain possible.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1187 | Forced Authentication |
Comments
Blocking outbound SMB, NetBIOS, and unnecessary WebDAV traffic prevents many attempts to coerce an endpoint into authenticating to an attacker-controlled system. WebDAV over permitted web ports may require application-aware filtering.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1205 | Traffic Signaling |
Comments
Stateful default-deny firewalls can block unsolicited signaling traffic and the resulting unauthorized connections for some implementations of this technique. Effectiveness depends on the signaling mechanism.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1205.001 | Port Knocking |
Comments
A managed firewall can prevent unauthorized knock sequences from opening services and can preserve the default-deny state. The relationship becomes weaker if malware has already obtained privileges to modify firewall rules.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1219 | Remote Access Tools |
Comments
Application-aware or destination-restricted firewall policies can block communications to unauthorized remote-access services. Tools communicating through generally permitted HTTPS may bypass basic port filtering.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1219.002 | Remote Desktop Software |
Comments
The firewall can block application traffic, service endpoints, or dedicated ports associated with unauthorized remote-desktop products. Effectiveness depends on whether the product uses an otherwise permitted web connection.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Blocking unnecessary local-link, legacy name-resolution, and file-sharing protocols reduces the network conditions available for several adversary-in-the-middle behaviors. Other sub-techniques require switch or network-infrastructure protections.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1557.001 | Name Resolution Poisoning and SMB Relay |
Comments
Blocking LLMNR, NBT-NS, mDNS, NetBIOS, and unnecessary SMB traffic reduces poisoning and relay opportunities involving end-user devices. Disabling the protocols and enforcing SMB signing remain stronger complementary mitigations.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1570 | Lateral Tool Transfer |
Comments
Restricting SMB, WinRM, SSH, VNC, and other peer-to-peer services impedes common channels used to transfer adversary tools between endpoints.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1572 | Protocol Tunneling |
Comments
Limiting approved ports, protocols, services, and destinations can prevent many unauthorized tunnels. Tunnels encapsulated within an approved HTTPS, DNS, or SSH connection may still succeed.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1071.001 | Web Protocols |
Comments
Destination-aware or application-aware firewall restrictions can disrupt web-based command and control, but basic port filtering cannot distinguish malicious traffic from legitimate browsing.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1090 | Proxy |
Comments
Blocking known proxy infrastructure and unauthorized listeners can disrupt some proxy usage. Proxies operating through approved web services or destinations may remain accessible.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1090.002 | External Proxy |
Comments
Firewall egress restrictions can block known or unauthorized external proxy destinations. External proxies commonly operate over permitted HTTP or HTTPS, limiting basic port-filtering effectiveness.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1090.003 | Multi-hop Proxy |
Comments
Destination filtering may prevent access to identified anonymity or command-and-control infrastructure.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1133 | External Remote Services |
Comments
Host firewall map help when an external remote service terminates directly on the end-user device. Many VPN, VDI, and access-gateway implementations terminate on centralized infrastructure outside the endpoint firewall's control.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1197 | BITS Jobs |
Comments
Process-aware firewall rules may restrict BITS to approved destinations. The firewall does not prevent local creation or execution of a BITS job and may not distinguish BITS traffic over allowed web ports.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1205.002 | Socket Filters |
Comments
Stateful firewall may block the triggering traffic or resulting connection. Socket filters may observe raw traffic or reuse an already permitted protocol, limiting the safeguard's effectiveness.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1218.012 | Verclsid |
Comments
Process-aware host firewall can prevent verclsid.exe from making outbound connections which is part of the outcomes of this technique. But it does not prevent the local signed-binary proxy-execution behavior that defines the technique.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1219.001 | IDE Tunneling |
Comments
Firewall policy can block unapproved IDE-tunneling services or destinations. Developer endpoints may legitimately require the same HTTPS or SSH channels, reducing the usefulness of simple port filtering.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1499 | Endpoint Denial of Service |
Comments
Host firewall can discard traffic targeting blocked ports, protocols, or identified hostile sources, reducing malicious traffic processed by the endpoint.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1499.001 | OS Exhaustion Flood |
Comments
Dropping unwanted inbound traffic through dynamic host based firewalls may reduce some operating-system resource floods.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1499.002 | Service Exhaustion Flood |
Comments
The firewall can block floods against services that do not need to be exposed or restrict permitted sources.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1499.003 | Application Exhaustion Flood |
Comments
Application-aware or source-restricted firewall rules may reduce hostile requests reaching an exposed endpoint application. Basic port filtering cannot distinguish an exhaustion attack from legitimate requests to an explicitly allowed application service.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1537 | Transfer Data to Cloud Account |
Comments
Destination-aware egress rules may block connections to unauthorized cloud environments. Basic port filtering cannot determine which cloud account owns an HTTPS destination, and some transfers occur entirely within the cloud.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1563 | Remote Service Session Hijacking |
Comments
Blocking unnecessary remote-service connectivity reduces the opportunity to reach a session that could be hijacked.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1563.001 | SSH Hijacking |
Comments
Restricting SSH reachability reduces remote paths to SSH sessions.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1563.002 | RDP Hijacking |
Comments
Restricting RDP to approved sources limits remote access to sessions.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021.007 | Cloud Services |
Comments
Destination-aware or application-aware endpoint firewall can restrict access to unauthorized cloud consoles, APIs, and command-line management endpoints.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1021.008 | Direct Cloud VM Connections |
Comments
Endpoint egress rules can prevent a compromised end-user device from reaching cloud-native VM connection services, APIs, or management endpoints. Cloud-native console access targets the cloud control plane and may not traverse the destination VM's host firewall.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1102 | Web Service |
Comments
An application-aware or destination-restricted endpoint firewall can block unauthorized web, cloud, file-sharing, or social-media services used for command and control.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1102.001 | Dead Drop Resolver |
Comments
A firewall that restricts outbound applications or destinations can prevent malware from contacting unauthorized web services used to retrieve secondary command-and-control addresses.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1102.002 | Bidirectional Communication |
Comments
Blocking unauthorized web-service destinations or preventing unapproved processes from accessing the network can disrupt bidirectional command-and-control communications.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1102.003 | One-Way Communication |
Comments
Endpoint firewall policy can prevent malware from sending data or retrieving instructions through unauthorized web services. One-way traffic to an approved and commonly used service may be difficult to distinguish from legitimate activity through basic port filtering.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1498 | Network Denial of Service |
Comments
A host firewall can discard traffic targeting blocked ports, protocols, or identified hostile sources, reducing the amount of malicious traffic processed by the endpoint.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1498.001 | Direct Network Flood |
Comments
A host firewall rules can block unnecessary protocols, targeted ports, or known attacking sources and may reduce endpoint resource consumption during smaller floods. High-volume floods normally require upstream filtering because traffic may saturate the connection before reaching the device.
References
|
| CIS-4.5 | Implement and Manage a Firewall on End-User Devices | mitigates | T1498.002 | Reflection Amplification |
Comments
A host firewall can drop unsolicited reflected traffic and deny unnecessary UDP protocols used in amplification attacks. It cannot recover bandwidth already consumed by the reflected traffic, and spoofed or distributed sources reduce source-based filtering effectiveness.
References
|