Perform operating system updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1495 | Firmware Corruption |
Comments
Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1542 | Pre-OS Boot |
Comments
This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1542.001 | System Firmware |
Comments
Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1542.002 | Component Firmware |
Comments
Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1176.002 | IDE Extensions |
Comments
ATT&CK mentions ensuring operating systems and software are using the most current version.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1176.001 | Browser Extensions |
Comments
ATT&CK mentions ensuring operating systems and software are using the most current version.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1176 | Software Extensions |
Comments
ATT&CK mentions ensuring operating systems and software are using the most current version.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1072 | Software Deployment Tools |
Comments
ATT&CK mentions having a patch deployment systems regularly to prevent potential remote access through Exploitation for Privilege Escalation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1195.002 | Compromise Software Supply Chain |
Comments
ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1195.001 | Compromise Software Dependencies and Development Tools |
Comments
ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1195 | Supply Chain Compromise |
Comments
ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1546 | Event Triggered Execution |
Comments
OS patches that address specific Windows event-triggered execution mechanisms, particularly Application Shimming.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1552 | Unsecured Credentials |
Comments
ATT&CK specifically recommends applying patch KB2962486 which prevents credentials from being stored in GPPs.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1686.002 | Network Device Firewall |
Comments
ATT&CK specifically recommends maintaining network firewalls with current security patches. Include this where network firewall appliances and their operating systems are considered enterprise assets covered by the automated an OS-patching process.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1548 | Abuse Elevation Control Mechanism |
Comments
OS updates can close vulnerabilities and implementation weaknesses used to bypass native elevation mechanisms, especially UAC, but they do not prevent abuse of sudo permissions, temporary cloud elevation, or other correctly functioning mechanisms.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1211 | Exploitation for Stealth |
Comments
OS updates can correct vulnerabilities in kernels, logging components, security tools, and system services that could be exploited to conceal activity. Application-specific exploitation remains outside 7.3.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1210 | Exploitation of Remote Services |
Comments
OS patching directly addresses vulnerabilities in operating-system services such as SMB, RDP, RPC, SSH components, and other built-in remote services. The technique also includes independently installed applications that would fall under application patch management instead.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1550.002 | Pass the Hash |
Comments
ATT&CK identifies Windows 7 and higher system patch KB2871997 as limiting default access available to local administrator accounts, reducing some pass-the-hash lateral movement.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1552.006 | Group Policy Preferences |
Comments
ATT&CK identifies Windows patch KB2962486, which prevents credentials from being stored in Group Policy Preferences. This is a direct OS-patch implementation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1546.011 | Application Shimming |
Comments
ATT&CK identifies a specific Windows patch, KB3045645, that removes an auto-elevation behavior used to abuse application shims. Automated OS patch deployment directly applies this type of mitigation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1548.002 | Bypass User Account Control |
Comments
Windows updates include changes that close known UAC-bypass methods and improve elevation protections. ATT&CK directly recommends maintaining the latest Windows version and patch level.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1611 | Escape to Host |
Comments
Container and VM escapes may exploit vulnerabilities in the host kernel, hypervisor, or operating-system components. ATT&CK explicitly recommends keeping hosts current with security patches.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
OS and kernel vulnerabilities are a primary means of escalating from user privileges to SYSTEM or root. Automated OS patching directly removes known vulnerable code paths. ATT&CK specifically recommends patch management for internal endpoints and servers.
References
|