Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise assets.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1189 | Drive-by Compromise |
Comments
CIS 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1105 | Ingress Tool Transfer |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists.
In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 implementation blocks outbound traffic from machines to unapproved external destinations. Restricting access to known, trusted IP addresses and protocols can prevent attackers from downloading malicious tools or payloads onto compromised servers after gaining initial access.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1567.003 | Exfiltration to Text Storage Sites |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. Adversaries may exfiltrate data to text storage sites instead of their primary command and control channel. If 9.3 implementation blocks unauthorized text storage sites, the technique is defensible.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1567.002 | Exfiltration to Cloud Storage |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved sites. If 9.3 implementation blocks the URLs of unauthorized cloud storage services that are not approved by the organization then this technique is defensible.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1593.003 | Code Repositories |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content. If 9.3 implementation blocks unapproved code repositories and repository APIs, this is applicable.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1102.002 | Bidirectional Communication |
Comments
If 9.3 implementation includes outbound web-service use broadly enough to block unauthorized services and risky websites, then this technique is applicable. ATT&CK describes two-way C2 via legitimate web services and again points to web proxies and blocking unauthorized external services as mitigation.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1102.003 | One-Way Communication |
Comments
Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise.
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content. If 9.3 implementation includes outbound web-services used broadly enough to block unauthorized services and restrict access to unsafe websites, then this technique is defensible.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1102.001 | Dead Drop Resolver |
Comments
CIS 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content. If 9.3 implementation blocks unapproved social media, code repositories, paste sites, and similar web services across enterprise HTTP/S traffic, this becomes defensible. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1102 | Web Service |
Comments
CIS 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 implementation includes certain risky or suspicious web-services used broadly enough to block unauthorized services, then this technique is applicable.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1204 | User Execution |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 is implemented as a secure web gateway or proxy that can stop the post-click fetch/download, then this technique is applicable.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1204.001 | Malicious Link |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 is implemented as a secure web gateway or proxy that can stop the post-click fetch/download, then this technique is applicable.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1566.002 | Spearphishing Link |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1566 | Phishing |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery.
References
|