CIS Controls CIS-4.8

Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021 Remote Services
Comments
Disabling unnecessary remote services eliminates the corresponding authentication and remote-access path, directly reducing lateral movement opportunities.
References
    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.001 Remote Desktop Protocol
    Comments
    Disabling Remote Desktop Services where RDP is not operationally required prevents adversaries from connecting through that service.
    References
      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.002 SMB/Windows Admin Shares
      Comments
      Disabling unnecessary SMB file sharing and administrative shares directly removes common lateral movement, file-transfer, and remote-management paths.
      References
        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.003 Distributed Component Object Model
        Comments
        Disabling DCOM when it is not required removes a remote RPC-based execution and management interface that adversaries may abuse.
        References
          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.004 SSH
          Comments
          Disabling the SSH daemon or Remote Login on systems that do not require it eliminates an SSH-based remote-access path.
          References
            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.005 VNC
            Comments
            Uninstalling unnecessary VNC server software removes the listener and prevents remote control through that implementation.
            References
              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.006 Windows Remote Management
              Comments
              Disabling the WinRM service where it is unnecessary removes a remote command-execution and administration interface.
              References
                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.008 Direct Cloud VM Connections
                Comments
                Disabling unnecessary cloud-native VM connection types, serial consoles, or direct management services eliminates those remote-administration paths.
                References
                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1080 Taint Shared Content
                  Comments
                  Removing unnecessary shared folders and file-sharing services prevents adversaries from placing malicious content in those shares for other users or systems to execute.
                  References
                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1133 External Remote Services
                    Comments
                    Uninstalling or disabling unnecessary externally accessible VPN, remote desktop, SSH, and management services directly reduces external entry points.
                    References
                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1190 Exploit Public-Facing Application
                      Comments
                      Removing unused public-facing applications, services, and web modules eliminates exploitable listeners and reduces the externally exposed attack surface.
                      References
                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1210 Exploitation of Remote Services
                        Comments
                        A remote service that has been disabled or uninstalled can no longer be reached and exploited through its network interface.
                        References
                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1219 Remote Access Tools
                          Comments
                          Removing unauthorized or unnecessary remote-access products and disabling embedded remote-support functionality directly eliminates those access channels.
                          References
                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1219.002 Remote Desktop Software
                            Comments
                            Uninstalling unnecessary remote desktop products prevents adversaries from abusing that specific software for persistent or interactive access.
                            References
                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505 Server Software Component
                              Comments
                              Disabling unnecessary server extension mechanisms and components reduces the features adversaries can abuse to establish persistent server-side access.
                              References
                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.003 Web Shell
                                Comments
                                Disabling unnecessary web server functionality, scripting engines, and dangerous application functions can prevent particular web shell implementations from executing.
                                References
                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.004 IIS Components
                                  Comments
                                  Removing unused IIS modules, handlers, filters, and extensions directly reduces opportunities to install or abuse malicious IIS components.
                                  References
                                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1552.005 Cloud Instance Metadata API
                                    Comments
                                    Disabling unnecessary metadata services or insecure metadata-service versions directly prevents adversary access through those endpoints.
                                    References
                                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1602 Data from Configuration Repository
                                      Comments
                                      Removing unnecessary configuration-management protocols and repositories reduces the systems and services from which adversaries can collect configuration data.
                                      References
                                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1602.001 SNMP (MIB Dump)
                                        Comments
                                        Disabling SNMP where it is unnecessary removes the management service used to retrieve MIB and configuration information.
                                        References
                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1602.002 Network Device Configuration Dump
                                          Comments
                                          Removing unnecessary Telnet, HTTP management, TFTP, legacy SNMP, or similar configuration services reduces direct collection of network-device configurations.
                                          References
                                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1011 Exfiltration Over Other Network Medium
                                            Comments
                                            Disabling unnecessary Wi-Fi, cellular, modem, Bluetooth, or other secondary network services removes potential alternative exfiltration channels.
                                            References
                                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1011.001 Exfiltration Over Bluetooth
                                              Comments
                                              Disabling the Bluetooth service and adapter functionality where it is unnecessary prevents Bluetooth-based data transfer from that asset.
                                              References
                                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.007 Cloud Services
                                                Comments
                                                Disabling unnecessary cloud services, command-line integrations, and administrative applications reduces available cloud-management paths, although required web consoles may remain accessible.
                                                References
                                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1039 Data from Network Shared Drive
                                                  Comments
                                                  Removing unnecessary file-sharing services and shares reduces the network data repositories available for adversary collection.
                                                  References
                                                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1040 Network Sniffing
                                                    Comments
                                                    Removing unnecessary plaintext and broadcast-based services reduces sensitive service traffic available for interception, although it does not prevent sniffing of remaining traffic.
                                                    References
                                                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1047 Windows Management Instrumentation
                                                      Comments
                                                      Disabling unnecessary remote WMI and dependent management services reduces remote WMI execution, while local WMI functionality may remain available.
                                                      References
                                                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1059.008 Network Device CLI
                                                        Comments
                                                        Disabling unnecessary network-device command-line services, especially Telnet or direct CLI access, removes a command interface adversaries could abuse.
                                                        References
                                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1072 Software Deployment Tools
                                                          Comments
                                                          Uninstalling unnecessary deployment agents and disabling unused remote-deployment functionality reduces the number of centralized execution mechanisms available to an adversary.
                                                          References
                                                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1090 Proxy
                                                            Comments
                                                            Removing unnecessary proxy, relay, port-forwarding, and tunneling services reduces the ability to turn an enterprise asset into a network intermediary.
                                                            References
                                                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1090.001 Internal Proxy
                                                              Comments
                                                              Disabling unnecessary internal proxy listeners, SSH forwarding, port proxies, and routing functions impedes the use of a compromised asset as an internal pivot.
                                                              References
                                                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1187 Forced Authentication
                                                                Comments
                                                                Disabling unnecessary SMB, WebClient, WebDAV, LLMNR, NBT-NS, and related services reduces mechanisms that can coerce outbound authentication.
                                                                References
                                                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1197 BITS Jobs
                                                                  Comments
                                                                  Disabling the Background Intelligent Transfer Service where it is genuinely unnecessary prevents adversary use of BITS for transfer, execution, or persistence.
                                                                  References
                                                                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1570 Lateral Tool Transfer
                                                                    Comments
                                                                    Removing unnecessary SMB, SSH, WinRM, file-sharing, and deployment services reduces common channels used to move tools between systems.
                                                                    References
                                                                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.001 SQL Stored Procedures
                                                                      Comments
                                                                      Disabling unnecessary extended stored procedures, scripting extensions, or database execution features reduces opportunities to establish persistence through the database server.
                                                                      References
                                                                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.002 Transport Agent
                                                                        Comments
                                                                        Removing unused mail transport agents and extension points reduces the components available for adversary persistence in messaging infrastructure.
                                                                        References
                                                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.005 Terminal Services DLL
                                                                          Comments
                                                                          Disabling unnecessary Terminal Services functionality reduces opportunities to replace or abuse associated DLL components, although required RDP systems remain exposed.
                                                                          References
                                                                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.006 vSphere Installation Bundles
                                                                            Comments
                                                                            Removing unnecessary vSphere Installation Bundles and disabling unused ESXi extension functionality reduces the components available for hypervisor persistence.
                                                                            References
                                                                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1609 Container Administration Command
                                                                              Comments
                                                                              Removing unnecessary container-management utilities, exposed APIs, and administrative services reduces the mechanisms available for remote container commands.
                                                                              References
                                                                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1611 Escape to Host
                                                                                Comments
                                                                                Minimal container images and removal of unnecessary tools, shells, runtimes, and privileged services reduce some prerequisites and post-exploitation options for container escape.
                                                                                References
                                                                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1563 Remote Service Session Hijacking
                                                                                  Comments
                                                                                  Disabling unnecessary remote services prevents sessions from being established through those services and therefore removes sessions that could later be hijacked.
                                                                                  References
                                                                                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1563.001 SSH Hijacking
                                                                                    Comments
                                                                                    Disabling unnecessary SSH and agent-forwarding functions removes some SSH sessions and forwarding sockets that adversaries could hijack.
                                                                                    References
                                                                                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1563.002 RDP Hijacking
                                                                                      Comments
                                                                                      Disabling unnecessary RDP services prevents creation of RDP sessions on those assets, eliminating that session-hijacking opportunity.
                                                                                      References
                                                                                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1649 Steal or Forge Authentication Certificates
                                                                                        Comments
                                                                                        Disabling unnecessary Active Directory Certificate Services web enrollment, enrollment agents, legacy authentication protocols, and certificate-service roles reduces certificate abuse paths.
                                                                                        References
                                                                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1671 Cloud Application Integration
                                                                                          Comments
                                                                                          Disabling unnecessary SaaS integrations, plug-ins, application consent features, and service connections reduces the number of integrations an adversary can authorize or abuse.
                                                                                          References