Use DNS filtering services on all end-user devices, including remote and on-premises assets, to block access to known malicious domains.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1071.004 | DNS |
Comments
DNS filtering can prevent resolution of known malicious domains used for DNS-based command and control and can sinkhole requests before an endpoint reaches adversary infrastructure.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1189 | Drive-by Compromise |
Comments
Blocking known malicious or compromised domains prevents browsers from reaching websites used to exploit users or deliver malicious content.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1566.002 | Spearphishing Link |
Comments
DNS filtering can block the destination of a malicious link delivered through email before the user reaches a credential-harvesting page, exploit site, or malware download. Newly registered, compromised, or uncategorized domains may initially evade filtering.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1204.001 | Malicious Link |
Comments
Even when a user clicks a malicious link, DNS filtering can prevent successful navigation when the destination domain is known to be malicious.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1071 | Application Layer Protocol |
Comments
DNS filtering directly affects DNS and can also prevent connections to malicious domains used for web-based application-layer command and control.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1071.001 | Web Protocols |
Comments
DNS filtering can prevent HTTP, HTTPS, and WebSocket command-and-control connections when the destination domain has been classified as malicious.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
DNS and other domain-based destinations may be used as alternative exfiltration channels. DNS filtering only impedes implementations that depend on resolving a known malicious domain.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
DNS can carry encoded exfiltrated data over an unencrypted non-command-and-control protocol. Blocking resolution of an adversary-controlled domain can interrupt DNS-based exfiltration, although newly registered or uncategorized domains may initially be allowed.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1105 | Ingress Tool Transfer |
Comments
DNS filtering can prevent a compromised endpoint from resolving known malicious domains used to host tools or secondary payloads. Transfers over direct IP addresses, approved cloud services, compromised legitimate domains, or uncategorized domains may still succeed.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1566 | Phishing |
Comments
DNS filtering materially mitigates phishing that directs users to malicious domains. It does not mitigate phishing attachments, voice phishing, or messages that do not require visiting a domain.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1572 | Protocol Tunneling |
Comments
DNS filtering can block tunnels that depend on resolving known malicious domains, including some DNS and web-based tunnels. Tunnels using direct IP addresses, trusted domains, or infrastructure not yet classified as malicious may still succeed.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1568 | Dynamic Resolution |
Comments
DNS sinkholing and reputation-based filtering can prevent resolution of identified dynamic-DNS and generated domains used to reestablish command and control.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1568.002 | Domain Generation Algorithms |
Comments
DNS filtering services may block or sinkhole known and predicted algorithmically generated domains, for example those that have high entropy in the name.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
DNS filtering can block resolution of a known malicious exfiltration destination regardless of whether the transmitted data is encrypted.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Blocking a known malicious destination domain may interrupt an asymmetric encrypted exfiltration channel.
References
|