Restrict, either through uninstalling or disabling, any unauthorized or unnecessary browser or email client plugins, extensions, and add-on applications.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1176.001 | Browser Extensions |
Comments
Browser extension allowlists, denylists, installation restrictions, and removal of unauthorized extensions directly prevent malicious browser extensions from establishing persistence or abusing inherited browser permissions.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1137.006 | Add-ins |
Comments
Disabling unauthorized Outlook add-ins prevents those add-ins from automatically loading code when the email client starts. This directly reduces persistence through email-client add-on functionality.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1176 | Software Extensions |
Comments
This technique includes browser extensions, which are directly addressed by the safeguard.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1137 | Office Application Startup |
Comments
Restricting email-client add-ins mitigates the add-in portion of this parent technique.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1539 | Steal Web Session Cookie |
Comments
Malicious browser extensions may access browser cookies and session information. Restricting extensions removes one important cookie-theft path.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Malicious extensions may access credentials stored in browsers. Extension restrictions reduce that attack surface, but malware already executing with access to the browser profile may still extract stored credentials.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1189 | Drive-by Compromise |
Comments
Removing unnecessary or vulnerable browser plug-ins reduces components that a malicious website can enumerate and exploit during a drive-by attack.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1203 | Exploitation for Client Execution |
Comments
Uninstalling unnecessary browser or email-client plug-ins removes potential client-side exploitation targets.
References
|