CIS Controls CIS-4.5

Implement and manage a host-based firewall or port-filtering tool on end-user devices, with a default-deny rule that drops all traffic except those services and ports that are explicitly allowed.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021 Remote Services
Comments
A default-deny endpoint firewall directly restricts unsolicited remote-service connections and permits access only through explicitly approved services, ports, and management paths.
References
    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.001 Remote Desktop Protocol
    Comments
    Restricting TCP 3389 to approved management sources directly prevents unauthorized RDP connections and reduces RDP-based lateral movement.
    References
      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.002 SMB/Windows Admin Shares
      Comments
      Blocking or tightly restricting TCP 445 and 139 directly impedes access to administrative shares and other SMB-based lateral movement paths.
      References
        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.004 SSH
        Comments
        A default-deny firewall can block inbound SSH or restrict TCP 22 to approved management systems, directly limiting remote access to SSH-enabled end-user devices.
        References
          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.005 VNC
          Comments
          VNC requires an accessible listener, commonly on TCP 5900 and related ports. Blocking those ports unless specifically authorized directly prevents unauthorized VNC access.
          References
            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.006 Windows Remote Management
            Comments
            Restricting TCP 5985 and 5986 to approved systems directly limits adversary use of WinRM for remote administration and lateral movement.
            References
              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1210 Exploitation of Remote Services
              Comments
              Exploiting a remote service requires network reachability to that service. Default-deny endpoint rules remove unnecessary exposure and can restrict necessary services to trusted source systems.
              References
                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1571 Non-Standard Port
                Comments
                Default-deny rules directly block arbitrary and unexpected ports unless they have been explicitly approved, limiting adversary communications over non-standard ports.
                References
                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.003 Distributed Component Object Model
                  Comments
                  A firewall can restrict DCOM by controlling RPC endpoint mapper traffic and dynamic RPC ports. The relationship is direct, but implementation is more complex than filtering a single fixed port.
                  References
                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1048 Exfiltration Over Alternative Protocol
                    Comments
                    Restrictive outbound rules can prevent an endpoint from using unapproved protocols and ports for data exfiltration. The technique remains possible over protocols the organization must allow.
                    References
                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
                      Comments
                      The firewall can block unapproved encrypted protocols, ports, or destinations used for exfiltration. It generally cannot identify malicious content inside an allowed encrypted connection.
                      References
                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
                        Comments
                        Default-deny egress controls can prevent asymmetric encrypted sessions using unauthorized ports or services. Connections through an approved service may still succeed.
                        References
                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
                          Comments
                          Unapproved outbound services and ports used for cleartext exfiltration can be directly blocked. Effectiveness decreases when the adversary uses an operationally required protocol.
                          References
                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071 Application Layer Protocol
                            Comments
                            Endpoint firewalls can restrict which application protocols and services may communicate externally. The mapping is partial because common application protocols may need to remain available.
                            References
                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.002 File Transfer Protocols
                              Comments
                              FTP, SFTP, FTPS, and related file-transfer traffic can be denied or limited to approved destinations. File transfer over a generally permitted web protocol may remain possible.
                              References
                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.003 Mail Protocols
                                Comments
                                SMTP, IMAP, and POP traffic can be restricted to authorized mail infrastructure, reducing adversary use of attacker-controlled mail services for command and control.
                                References
                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.004 DNS
                                  Comments
                                  The firewall can force devices to use approved DNS resolvers and block direct DNS traffic to external systems. It does not by itself identify malicious data embedded in DNS traffic sent through an approved resolver.
                                  References
                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.005 Publish/Subscribe Protocols
                                    Comments
                                    Default-deny policies can block MQTT and other publish/subscribe services unless they are explicitly required. An approved publish/subscribe service could still be misused.
                                    References
                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1090.001 Internal Proxy
                                      Comments
                                      Restricting inbound listeners and lateral outbound connections makes it more difficult for a compromised endpoint to act as an unauthorized proxy for other systems.
                                      References
                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1095 Non-Application Layer Protocol
                                        Comments
                                        A host firewall can deny unnecessary ICMP, GRE, raw IP, and other non-application protocols that adversaries may use for command and control.
                                        References
                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1105 Ingress Tool Transfer
                                          Comments
                                          Default-deny egress policies can prevent compromised endpoints from retrieving payloads from unapproved systems, ports, or protocols. Transfers from an approved destination remain possible.
                                          References
                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1187 Forced Authentication
                                            Comments
                                            Blocking outbound SMB, NetBIOS, and unnecessary WebDAV traffic prevents many attempts to coerce an endpoint into authenticating to an attacker-controlled system. WebDAV over permitted web ports may require application-aware filtering.
                                            References
                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1205 Traffic Signaling
                                              Comments
                                              Stateful default-deny firewalls can block unsolicited signaling traffic and the resulting unauthorized connections for some implementations of this technique. Effectiveness depends on the signaling mechanism.
                                              References
                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1205.001 Port Knocking
                                                Comments
                                                A managed firewall can prevent unauthorized knock sequences from opening services and can preserve the default-deny state. The relationship becomes weaker if malware has already obtained privileges to modify firewall rules.
                                                References
                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1219 Remote Access Tools
                                                  Comments
                                                  Application-aware or destination-restricted firewall policies can block communications to unauthorized remote-access services. Tools communicating through generally permitted HTTPS may bypass basic port filtering.
                                                  References
                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1219.002 Remote Desktop Software
                                                    Comments
                                                    The firewall can block application traffic, service endpoints, or dedicated ports associated with unauthorized remote-desktop products. Effectiveness depends on whether the product uses an otherwise permitted web connection.
                                                    References
                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1557 Adversary-in-the-Middle
                                                      Comments
                                                      Blocking unnecessary local-link, legacy name-resolution, and file-sharing protocols reduces the network conditions available for several adversary-in-the-middle behaviors. Other sub-techniques require switch or network-infrastructure protections.
                                                      References
                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1557.001 Name Resolution Poisoning and SMB Relay
                                                        Comments
                                                        Blocking LLMNR, NBT-NS, mDNS, NetBIOS, and unnecessary SMB traffic reduces poisoning and relay opportunities involving end-user devices. Disabling the protocols and enforcing SMB signing remain stronger complementary mitigations.
                                                        References
                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1570 Lateral Tool Transfer
                                                          Comments
                                                          Restricting SMB, WinRM, SSH, VNC, and other peer-to-peer services impedes common channels used to transfer adversary tools between endpoints.
                                                          References
                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1572 Protocol Tunneling
                                                            Comments
                                                            Limiting approved ports, protocols, services, and destinations can prevent many unauthorized tunnels. Tunnels encapsulated within an approved HTTPS, DNS, or SSH connection may still succeed.
                                                            References
                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.001 Web Protocols
                                                              Comments
                                                              Destination-aware or application-aware firewall restrictions can disrupt web-based command and control, but basic port filtering cannot distinguish malicious traffic from legitimate browsing.
                                                              References
                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1090 Proxy
                                                                Comments
                                                                Blocking known proxy infrastructure and unauthorized listeners can disrupt some proxy usage. Proxies operating through approved web services or destinations may remain accessible.
                                                                References
                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1090.002 External Proxy
                                                                  Comments
                                                                  Firewall egress restrictions can block known or unauthorized external proxy destinations. External proxies commonly operate over permitted HTTP or HTTPS, limiting basic port-filtering effectiveness.
                                                                  References
                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1090.003 Multi-hop Proxy
                                                                    Comments
                                                                    Destination filtering may prevent access to identified anonymity or command-and-control infrastructure.
                                                                    References
                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1133 External Remote Services
                                                                      Comments
                                                                      Host firewall map help when an external remote service terminates directly on the end-user device. Many VPN, VDI, and access-gateway implementations terminate on centralized infrastructure outside the endpoint firewall's control.
                                                                      References
                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1197 BITS Jobs
                                                                        Comments
                                                                        Process-aware firewall rules may restrict BITS to approved destinations. The firewall does not prevent local creation or execution of a BITS job and may not distinguish BITS traffic over allowed web ports.
                                                                        References
                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1205.002 Socket Filters
                                                                          Comments
                                                                          Stateful firewall may block the triggering traffic or resulting connection. Socket filters may observe raw traffic or reuse an already permitted protocol, limiting the safeguard's effectiveness.
                                                                          References
                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1218.012 Verclsid
                                                                            Comments
                                                                            Process-aware host firewall can prevent verclsid.exe from making outbound connections which is part of the outcomes of this technique. But it does not prevent the local signed-binary proxy-execution behavior that defines the technique.
                                                                            References
                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1219.001 IDE Tunneling
                                                                              Comments
                                                                              Firewall policy can block unapproved IDE-tunneling services or destinations. Developer endpoints may legitimately require the same HTTPS or SSH channels, reducing the usefulness of simple port filtering.
                                                                              References
                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1499 Endpoint Denial of Service
                                                                                Comments
                                                                                Host firewall can discard traffic targeting blocked ports, protocols, or identified hostile sources, reducing malicious traffic processed by the endpoint.
                                                                                References
                                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1499.001 OS Exhaustion Flood
                                                                                  Comments
                                                                                  Dropping unwanted inbound traffic through dynamic host based firewalls may reduce some operating-system resource floods.
                                                                                  References
                                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1499.002 Service Exhaustion Flood
                                                                                    Comments
                                                                                    The firewall can block floods against services that do not need to be exposed or restrict permitted sources.
                                                                                    References
                                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1499.003 Application Exhaustion Flood
                                                                                      Comments
                                                                                      Application-aware or source-restricted firewall rules may reduce hostile requests reaching an exposed endpoint application. Basic port filtering cannot distinguish an exhaustion attack from legitimate requests to an explicitly allowed application service.
                                                                                      References
                                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1537 Transfer Data to Cloud Account
                                                                                        Comments
                                                                                        Destination-aware egress rules may block connections to unauthorized cloud environments. Basic port filtering cannot determine which cloud account owns an HTTPS destination, and some transfers occur entirely within the cloud.
                                                                                        References
                                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1563 Remote Service Session Hijacking
                                                                                          Comments
                                                                                          Blocking unnecessary remote-service connectivity reduces the opportunity to reach a session that could be hijacked.
                                                                                          References
                                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1563.001 SSH Hijacking
                                                                                            Comments
                                                                                            Restricting SSH reachability reduces remote paths to SSH sessions.
                                                                                            References
                                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1563.002 RDP Hijacking
                                                                                              Comments
                                                                                              Restricting RDP to approved sources limits remote access to sessions.
                                                                                              References
                                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.007 Cloud Services
                                                                                                Comments
                                                                                                Destination-aware or application-aware endpoint firewall can restrict access to unauthorized cloud consoles, APIs, and command-line management endpoints.
                                                                                                References
                                                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.008 Direct Cloud VM Connections
                                                                                                  Comments
                                                                                                  Endpoint egress rules can prevent a compromised end-user device from reaching cloud-native VM connection services, APIs, or management endpoints. Cloud-native console access targets the cloud control plane and may not traverse the destination VM's host firewall.
                                                                                                  References
                                                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1102 Web Service
                                                                                                    Comments
                                                                                                    An application-aware or destination-restricted endpoint firewall can block unauthorized web, cloud, file-sharing, or social-media services used for command and control.
                                                                                                    References
                                                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1102.001 Dead Drop Resolver
                                                                                                      Comments
                                                                                                      A firewall that restricts outbound applications or destinations can prevent malware from contacting unauthorized web services used to retrieve secondary command-and-control addresses.
                                                                                                      References
                                                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1102.002 Bidirectional Communication
                                                                                                        Comments
                                                                                                        Blocking unauthorized web-service destinations or preventing unapproved processes from accessing the network can disrupt bidirectional command-and-control communications.
                                                                                                        References
                                                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1102.003 One-Way Communication
                                                                                                          Comments
                                                                                                          Endpoint firewall policy can prevent malware from sending data or retrieving instructions through unauthorized web services. One-way traffic to an approved and commonly used service may be difficult to distinguish from legitimate activity through basic port filtering.
                                                                                                          References
                                                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1498 Network Denial of Service
                                                                                                            Comments
                                                                                                            A host firewall can discard traffic targeting blocked ports, protocols, or identified hostile sources, reducing the amount of malicious traffic processed by the endpoint.
                                                                                                            References
                                                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1498.001 Direct Network Flood
                                                                                                              Comments
                                                                                                              A host firewall rules can block unnecessary protocols, targeted ports, or known attacking sources and may reduce endpoint resource consumption during smaller floods. High-volume floods normally require upstream filtering because traffic may saturate the connection before reaching the device.
                                                                                                              References
                                                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1498.002 Reflection Amplification
                                                                                                                Comments
                                                                                                                A host firewall can drop unsolicited reflected traffic and deny unnecessary UDP protocols used in amplification attacks. It cannot recover bandwidth already consumed by the reflected traffic, and spoofed or distributed sources reduce source-based filtering effectiveness.
                                                                                                                References