CIS Controls CIS-9.4

Restrict, either through uninstalling or disabling, any unauthorized or unnecessary browser or email client plugins, extensions, and add-on applications.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions mitigates T1176.001 Browser Extensions
Comments
Browser extension allowlists, denylists, installation restrictions, and removal of unauthorized extensions directly prevent malicious browser extensions from establishing persistence or abusing inherited browser permissions.
References
    CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions mitigates T1137.006 Add-ins
    Comments
    Disabling unauthorized Outlook add-ins prevents those add-ins from automatically loading code when the email client starts. This directly reduces persistence through email-client add-on functionality.
    References
      CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions mitigates T1176 Software Extensions
      Comments
      This technique includes browser extensions, which are directly addressed by the safeguard.
      References
        CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions mitigates T1137 Office Application Startup
        Comments
        Restricting email-client add-ins mitigates the add-in portion of this parent technique.
        References
          CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions mitigates T1539 Steal Web Session Cookie
          Comments
          Malicious browser extensions may access browser cookies and session information. Restricting extensions removes one important cookie-theft path.
          References
            CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions mitigates T1555.003 Credentials from Web Browsers
            Comments
            Malicious extensions may access credentials stored in browsers. Extension restrictions reduce that attack surface, but malware already executing with access to the browser profile may still extract stored credentials.
            References
              CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions mitigates T1189 Drive-by Compromise
              Comments
              Removing unnecessary or vulnerable browser plug-ins reduces components that a malicious website can enumerate and exploit during a drive-by attack.
              References
                CIS-9.4 Restrict Unnecessary or Unauthorized Browser and Email Client Extensions mitigates T1203 Exploitation for Client Execution
                Comments
                Uninstalling unnecessary browser or email-client plug-ins removes potential client-side exploitation targets.
                References