CIS Controls CIS-9.2

Use DNS filtering services on all end-user devices, including remote and on-premises assets, to block access to known malicious domains.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-9.2 Use DNS Filtering Services mitigates T1071.004 DNS
Comments
DNS filtering can prevent resolution of known malicious domains used for DNS-based command and control and can sinkhole requests before an endpoint reaches adversary infrastructure.
References
    CIS-9.2 Use DNS Filtering Services mitigates T1189 Drive-by Compromise
    Comments
    Blocking known malicious or compromised domains prevents browsers from reaching websites used to exploit users or deliver malicious content.
    References
      CIS-9.2 Use DNS Filtering Services mitigates T1566.002 Spearphishing Link
      Comments
      DNS filtering can block the destination of a malicious link delivered through email before the user reaches a credential-harvesting page, exploit site, or malware download. Newly registered, compromised, or uncategorized domains may initially evade filtering.
      References
        CIS-9.2 Use DNS Filtering Services mitigates T1204.001 Malicious Link
        Comments
        Even when a user clicks a malicious link, DNS filtering can prevent successful navigation when the destination domain is known to be malicious.
        References
          CIS-9.2 Use DNS Filtering Services mitigates T1071 Application Layer Protocol
          Comments
          DNS filtering directly affects DNS and can also prevent connections to malicious domains used for web-based application-layer command and control.
          References
            CIS-9.2 Use DNS Filtering Services mitigates T1071.001 Web Protocols
            Comments
            DNS filtering can prevent HTTP, HTTPS, and WebSocket command-and-control connections when the destination domain has been classified as malicious.
            References
              CIS-9.2 Use DNS Filtering Services mitigates T1048 Exfiltration Over Alternative Protocol
              Comments
              DNS and other domain-based destinations may be used as alternative exfiltration channels. DNS filtering only impedes implementations that depend on resolving a known malicious domain.
              References
                CIS-9.2 Use DNS Filtering Services mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
                Comments
                DNS can carry encoded exfiltrated data over an unencrypted non-command-and-control protocol. Blocking resolution of an adversary-controlled domain can interrupt DNS-based exfiltration, although newly registered or uncategorized domains may initially be allowed.
                References
                  CIS-9.2 Use DNS Filtering Services mitigates T1105 Ingress Tool Transfer
                  Comments
                  DNS filtering can prevent a compromised endpoint from resolving known malicious domains used to host tools or secondary payloads. Transfers over direct IP addresses, approved cloud services, compromised legitimate domains, or uncategorized domains may still succeed.
                  References
                    CIS-9.2 Use DNS Filtering Services mitigates T1566 Phishing
                    Comments
                    DNS filtering materially mitigates phishing that directs users to malicious domains. It does not mitigate phishing attachments, voice phishing, or messages that do not require visiting a domain.
                    References
                      CIS-9.2 Use DNS Filtering Services mitigates T1572 Protocol Tunneling
                      Comments
                      DNS filtering can block tunnels that depend on resolving known malicious domains, including some DNS and web-based tunnels. Tunnels using direct IP addresses, trusted domains, or infrastructure not yet classified as malicious may still succeed.
                      References
                        CIS-9.2 Use DNS Filtering Services mitigates T1568 Dynamic Resolution
                        Comments
                        DNS sinkholing and reputation-based filtering can prevent resolution of identified dynamic-DNS and generated domains used to reestablish command and control.
                        References
                          CIS-9.2 Use DNS Filtering Services mitigates T1568.002 Domain Generation Algorithms
                          Comments
                          DNS filtering services may block or sinkhole known and predicted algorithmically generated domains, for example those that have high entropy in the name.
                          References
                            CIS-9.2 Use DNS Filtering Services mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
                            Comments
                            DNS filtering can block resolution of a known malicious exfiltration destination regardless of whether the transmitted data is encrypted.
                            References
                              CIS-9.2 Use DNS Filtering Services mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
                              Comments
                              Blocking a known malicious destination domain may interrupt an asymmetric encrypted exfiltration channel.
                              References