Configure trusted DNS servers on network infrastructure. Example implementations include configuring network devices to use enterprise-controlled DNS servers and/or reputable externally accessible DNS servers.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-4.9 | Configure Trusted DNS Servers on Enterprise Assets | mitigates | T1071.004 | DNS |
Comments
Directing DNS traffic through trusted enterprise resolvers can prevent systems from communicating directly with adversary-controlled DNS servers and can support blocking or sinkholing malicious DNS requests.
References
|
| CIS-4.9 | Configure Trusted DNS Servers on Enterprise Assets | mitigates | T1071 | Application Layer Protocol |
Comments
This is a partial mapping because DNS is one of the application-layer protocols covered by this technique. Configuring trusted DNS servers affects DNS-based command and control but does not mitigate web, mail, file-transfer, or publish-subscribe protocols.
References
|
| CIS-4.9 | Configure Trusted DNS Servers on Enterprise Assets | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Enforcing use of trusted DNS resolvers reduces the ability of enterprise assets to communicate directly with adversary-controlled DNS infrastructure for exfiltration. The mitigation applies only to implementations that use DNS or depend on unauthorized DNS servers.
References
|
| CIS-4.9 | Configure Trusted DNS Servers on Enterprise Assets | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
DNS can carry encoded exfiltrated data over an unencrypted non-command-and-control protocol. Routing requests through controlled resolvers provides an enforcement point for blocking unauthorized DNS servers, suspicious domains, or abnormal query activity.
References
|
| CIS-4.9 | Configure Trusted DNS Servers on Enterprise Assets | mitigates | T1572 | Protocol Tunneling |
Comments
DNS can be used to tunnel command-and-control traffic or other protocols. Enforcing trusted resolvers and preventing direct DNS communication can disrupt conventional DNS tunneling,
References
|