Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021 | Remote Services |
Comments
Disabling unnecessary remote services eliminates the corresponding authentication and remote-access path, directly reducing lateral movement opportunities.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Disabling Remote Desktop Services where RDP is not operationally required prevents adversaries from connecting through that service.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021.002 | SMB/Windows Admin Shares |
Comments
Disabling unnecessary SMB file sharing and administrative shares directly removes common lateral movement, file-transfer, and remote-management paths.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021.003 | Distributed Component Object Model |
Comments
Disabling DCOM when it is not required removes a remote RPC-based execution and management interface that adversaries may abuse.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021.004 | SSH |
Comments
Disabling the SSH daemon or Remote Login on systems that do not require it eliminates an SSH-based remote-access path.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021.005 | VNC |
Comments
Uninstalling unnecessary VNC server software removes the listener and prevents remote control through that implementation.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021.006 | Windows Remote Management |
Comments
Disabling the WinRM service where it is unnecessary removes a remote command-execution and administration interface.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021.008 | Direct Cloud VM Connections |
Comments
Disabling unnecessary cloud-native VM connection types, serial consoles, or direct management services eliminates those remote-administration paths.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1080 | Taint Shared Content |
Comments
Removing unnecessary shared folders and file-sharing services prevents adversaries from placing malicious content in those shares for other users or systems to execute.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1133 | External Remote Services |
Comments
Uninstalling or disabling unnecessary externally accessible VPN, remote desktop, SSH, and management services directly reduces external entry points.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Removing unused public-facing applications, services, and web modules eliminates exploitable listeners and reduces the externally exposed attack surface.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1210 | Exploitation of Remote Services |
Comments
A remote service that has been disabled or uninstalled can no longer be reached and exploited through its network interface.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1219 | Remote Access Tools |
Comments
Removing unauthorized or unnecessary remote-access products and disabling embedded remote-support functionality directly eliminates those access channels.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1219.002 | Remote Desktop Software |
Comments
Uninstalling unnecessary remote desktop products prevents adversaries from abusing that specific software for persistent or interactive access.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1505 | Server Software Component |
Comments
Disabling unnecessary server extension mechanisms and components reduces the features adversaries can abuse to establish persistent server-side access.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1505.003 | Web Shell |
Comments
Disabling unnecessary web server functionality, scripting engines, and dangerous application functions can prevent particular web shell implementations from executing.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1505.004 | IIS Components |
Comments
Removing unused IIS modules, handlers, filters, and extensions directly reduces opportunities to install or abuse malicious IIS components.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1552.005 | Cloud Instance Metadata API |
Comments
Disabling unnecessary metadata services or insecure metadata-service versions directly prevents adversary access through those endpoints.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1602 | Data from Configuration Repository |
Comments
Removing unnecessary configuration-management protocols and repositories reduces the systems and services from which adversaries can collect configuration data.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Disabling SNMP where it is unnecessary removes the management service used to retrieve MIB and configuration information.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Removing unnecessary Telnet, HTTP management, TFTP, legacy SNMP, or similar configuration services reduces direct collection of network-device configurations.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1011 | Exfiltration Over Other Network Medium |
Comments
Disabling unnecessary Wi-Fi, cellular, modem, Bluetooth, or other secondary network services removes potential alternative exfiltration channels.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1011.001 | Exfiltration Over Bluetooth |
Comments
Disabling the Bluetooth service and adapter functionality where it is unnecessary prevents Bluetooth-based data transfer from that asset.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1021.007 | Cloud Services |
Comments
Disabling unnecessary cloud services, command-line integrations, and administrative applications reduces available cloud-management paths, although required web consoles may remain accessible.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1039 | Data from Network Shared Drive |
Comments
Removing unnecessary file-sharing services and shares reduces the network data repositories available for adversary collection.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1040 | Network Sniffing |
Comments
Removing unnecessary plaintext and broadcast-based services reduces sensitive service traffic available for interception, although it does not prevent sniffing of remaining traffic.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1047 | Windows Management Instrumentation |
Comments
Disabling unnecessary remote WMI and dependent management services reduces remote WMI execution, while local WMI functionality may remain available.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1059.008 | Network Device CLI |
Comments
Disabling unnecessary network-device command-line services, especially Telnet or direct CLI access, removes a command interface adversaries could abuse.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1072 | Software Deployment Tools |
Comments
Uninstalling unnecessary deployment agents and disabling unused remote-deployment functionality reduces the number of centralized execution mechanisms available to an adversary.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1090 | Proxy |
Comments
Removing unnecessary proxy, relay, port-forwarding, and tunneling services reduces the ability to turn an enterprise asset into a network intermediary.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1090.001 | Internal Proxy |
Comments
Disabling unnecessary internal proxy listeners, SSH forwarding, port proxies, and routing functions impedes the use of a compromised asset as an internal pivot.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1187 | Forced Authentication |
Comments
Disabling unnecessary SMB, WebClient, WebDAV, LLMNR, NBT-NS, and related services reduces mechanisms that can coerce outbound authentication.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1197 | BITS Jobs |
Comments
Disabling the Background Intelligent Transfer Service where it is genuinely unnecessary prevents adversary use of BITS for transfer, execution, or persistence.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1570 | Lateral Tool Transfer |
Comments
Removing unnecessary SMB, SSH, WinRM, file-sharing, and deployment services reduces common channels used to move tools between systems.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1505.001 | SQL Stored Procedures |
Comments
Disabling unnecessary extended stored procedures, scripting extensions, or database execution features reduces opportunities to establish persistence through the database server.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1505.002 | Transport Agent |
Comments
Removing unused mail transport agents and extension points reduces the components available for adversary persistence in messaging infrastructure.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1505.005 | Terminal Services DLL |
Comments
Disabling unnecessary Terminal Services functionality reduces opportunities to replace or abuse associated DLL components, although required RDP systems remain exposed.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1505.006 | vSphere Installation Bundles |
Comments
Removing unnecessary vSphere Installation Bundles and disabling unused ESXi extension functionality reduces the components available for hypervisor persistence.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1609 | Container Administration Command |
Comments
Removing unnecessary container-management utilities, exposed APIs, and administrative services reduces the mechanisms available for remote container commands.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1611 | Escape to Host |
Comments
Minimal container images and removal of unnecessary tools, shells, runtimes, and privileged services reduce some prerequisites and post-exploitation options for container escape.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1563 | Remote Service Session Hijacking |
Comments
Disabling unnecessary remote services prevents sessions from being established through those services and therefore removes sessions that could later be hijacked.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1563.001 | SSH Hijacking |
Comments
Disabling unnecessary SSH and agent-forwarding functions removes some SSH sessions and forwarding sockets that adversaries could hijack.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1563.002 | RDP Hijacking |
Comments
Disabling unnecessary RDP services prevents creation of RDP sessions on those assets, eliminating that session-hijacking opportunity.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1649 | Steal or Forge Authentication Certificates |
Comments
Disabling unnecessary Active Directory Certificate Services web enrollment, enrollment agents, legacy authentication protocols, and certificate-service roles reduces certificate abuse paths.
References
|
| CIS-4.8 | Uninstall or Disable Unnecessary Services on Enterprise Assets and Software | mitigates | T1671 | Cloud Application Integration |
Comments
Disabling unnecessary SaaS integrations, plug-ins, application consent features, and service connections reduces the number of integrations an adversary can authorize or abuse.
References
|