CIS Controls CIS-9.6

Block unnecessary file types attempting to enter the enterprise’s email gateway.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-9.6 Block Unnecessary File Types mitigates T1553.005 Mark-of-the-Web Bypass
Comments
Adversaries may abuse container files such as compressed/archive (.arj, .gzip) and/or disk image (.iso, .vhd) file formats to deliver malicious payloads. The execution prevention mitigation mentions the use of blocking container file types at web and/or email gateways which could apply to the implementation of this safeguard.
References
    CIS-9.6 Block Unnecessary File Types mitigates T1059.005 Visual Basic
    Comments
    Adversaries may use VB payloads to execute malicious commands. Common malicious usage includes automating execution of behaviors with VBScript or embedding VBA content into spearphishing Attachment payloads. If .VB objects are blocked at the email boundary then it can mitigate the spearphishing delivery of this technique.
    References
      CIS-9.6 Block Unnecessary File Types mitigates T1218.001 Compiled HTML File
      Comments
      A custom CHM file containing embedded payloads could be delivered to a victim through email then triggered by User Execution If those custom CHM files are blocked at the email boundary, then it can mitigate the delivery of this technique.
      References
        CIS-9.6 Block Unnecessary File Types mitigates T1137.006 Add-ins
        Comments
        dversaries often weaponize Office add-ins (e.g., Excel .xll files or Outlook .wll / .ecf extensions) by sending them via phishing campaigns. Blocking these file types at the email boundary prevents the initial execution and subsequent installation of malicious persistence mechanisms.
        References
          CIS-9.6 Block Unnecessary File Types mitigates T1027.009 Embedded Payloads
          Comments
          File blocking mitigates embedded payloads by completely stripping high-risk file types at the perimeter, denying attackers the ability to deliver the initial malicious file or its nested, obfuscated components. Attackers frequently embed malicious scripts (e.g., .js, .vbs) inside legitimate document formats (e.g., PDFs, Word docs). By blocking macro-enabled or script-based file types, gateways prevent these malicious combinations from ever reaching the user's inbox
          References
            CIS-9.6 Block Unnecessary File Types mitigates T1027.012 LNK Icon Smuggling
            Comments
            LNK files are used as phishing payloads and when a user invokes them they can download or execute additional payloads. If .lnk objects are blocked at the email boundary then it can mitigate the delivery of this technique.
            References
              CIS-9.6 Block Unnecessary File Types mitigates T1027.006 HTML Smuggling
              Comments
              For this technique, adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files. If the implementation for 9.3 can mitigate this technique if it disallows .html, .htm, .hta, and similar active content files as email attachments on the block list.
              References
                CIS-9.6 Block Unnecessary File Types mitigates T1027.015 Compression
                Comments
                9.6 can prevent this type of technique if it blocks RAR, 7z, and other known unauthorized self-extracting archive types from specific machines.
                References
                  CIS-9.6 Block Unnecessary File Types mitigates T1204.002 Malicious File
                  Comments
                  9.6 enforcement can reduce user exposure by removing risky files upstream at the point of email delivery.
                  References
                    CIS-9.6 Block Unnecessary File Types mitigates T1204 User Execution
                    Comments
                    9.6 enforcement can reduce user exposure by removing risky files upstream at the point of email delivery.
                    References
                      CIS-9.6 Block Unnecessary File Types mitigates T1566.001 Spearphishing Attachment
                      Comments
                      9.6 is a preventive email-gateway control that blocks disallowed attachment types before delivery.
                      References
                        CIS-9.6 Block Unnecessary File Types mitigates T1566 Phishing
                        Comments
                        9.6 is a preventive email-gateway control that blocks disallowed attachment types before delivery.
                        References