Block unnecessary file types attempting to enter the enterprise’s email gateway.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1553.005 | Mark-of-the-Web Bypass |
Comments
Adversaries may abuse container files such as compressed/archive (.arj, .gzip) and/or disk image (.iso, .vhd) file formats to deliver malicious payloads. The execution prevention mitigation mentions the use of blocking container file types at web and/or email gateways which could apply to the implementation of this safeguard.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1059.005 | Visual Basic |
Comments
Adversaries may use VB payloads to execute malicious commands. Common malicious usage includes automating execution of behaviors with VBScript or embedding VBA content into spearphishing Attachment payloads. If .VB objects are blocked at the email boundary then it can mitigate the spearphishing delivery of this technique.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1218.001 | Compiled HTML File |
Comments
A custom CHM file containing embedded payloads could be delivered to a victim through email then triggered by User Execution If those custom CHM files are blocked at the email boundary, then it can mitigate the delivery of this technique.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1137.006 | Add-ins |
Comments
dversaries often weaponize Office add-ins (e.g., Excel .xll files or Outlook .wll / .ecf extensions) by sending them via phishing campaigns. Blocking these file types at the email boundary prevents the initial execution and subsequent installation of malicious persistence mechanisms.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1027.009 | Embedded Payloads |
Comments
File blocking mitigates embedded payloads by completely stripping high-risk file types at the perimeter, denying attackers the ability to deliver the initial malicious file or its nested, obfuscated components. Attackers frequently embed malicious scripts (e.g., .js, .vbs) inside legitimate document formats (e.g., PDFs, Word docs). By blocking macro-enabled or script-based file types, gateways prevent these malicious combinations from ever reaching the user's inbox
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1027.012 | LNK Icon Smuggling |
Comments
LNK files are used as phishing payloads and when a user invokes them they can download or execute additional payloads. If .lnk objects are blocked at the email boundary then it can mitigate the delivery of this technique.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1027.006 | HTML Smuggling |
Comments
For this technique, adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files. If the implementation for 9.3 can mitigate this technique if it disallows .html, .htm, .hta, and similar active content files as email attachments on the block list.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1027.015 | Compression |
Comments
9.6 can prevent this type of technique if it blocks RAR, 7z, and other known unauthorized self-extracting archive types from specific machines.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1204.002 | Malicious File |
Comments
9.6 enforcement can reduce user exposure by removing risky files upstream at the point of email delivery.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1204 | User Execution |
Comments
9.6 enforcement can reduce user exposure by removing risky files upstream at the point of email delivery.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1566.001 | Spearphishing Attachment |
Comments
9.6 is a preventive email-gateway control that blocks disallowed attachment types before delivery.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1566 | Phishing |
Comments
9.6 is a preventive email-gateway control that blocks disallowed attachment types before delivery.
References
|