Deploy and maintain email server anti-malware protections, such as attachment scanning and/or sandboxing.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1566.001 | Spearphishing Attachment |
Comments
Email-server attachment scanning and sandboxing can identify, quarantine, or remove malicious attachments before they reach the recipient.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1204.002 | Malicious File |
Comments
Removing a malicious attachment before delivery prevents the user from opening the file and initiating its execution chain. The safeguard is limited to malicious files delivered through the protected email environment.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1203 | Exploitation for Client Execution |
Comments
Email sandboxing can detonate weaponized Office documents, PDFs, archives, and other attachments to identify exploit behavior before delivery.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1221 | Template Injection |
Comments
Email detonation chambers can open suspicious documents and observe attempts to retrieve or execute remote templates and payloads before the message reaches the recipient.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.012 | LNK Icon Smuggling |
Comments
Email scanning can identify suspicious LNK attachments and inspect icon-location or target fields that reference remote payloads.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1036.008 | Masquerade File Type |
Comments
Anti-malware scanners can compare file headers, MIME types, extensions, and content to detect attachments disguised as benign file formats.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1566 | Phishing |
Comments
Email-server anti-malware directly addresses malicious attachments.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1204 | User Execution |
Comments
Blocking malicious attachments prevents one major form of user execution.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027 | Obfuscated Files or Information |
Comments
Email anti-malware can use static, heuristic, and behavioral analysis to identify obfuscated files before delivery.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.002 | Software Packing |
Comments
Heuristic scanning and sandbox detonation can identify packed executables attached to messages, even when packing changes their static signature.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.006 | HTML Smuggling |
Comments
A sandbox capable of executing active HTML attachments may detect JavaScript that reconstructs and writes a malicious payload to disk.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.009 | Embedded Payloads |
Comments
Attachment scanners and sandboxes can identify malicious payloads hidden within documents, scripts, executables, or other carrier files.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.013 | Encrypted/Encoded File |
Comments
Anti-malware can identify encoded or high-entropy attachments and may block encrypted archives that cannot be inspected.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.015 | Compression |
Comments
Email anti-malware capable of recursively unpacking ZIP, RAR, 7z, self-extracting archives, and nested archives can identify malicious files before delivery.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.017 | SVG Smuggling |
Comments
A sandbox that renders SVG attachments and executes their embedded scripts may identify payload construction or malicious follow-on behavior.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1036 | Masquerading |
Comments
Anti-malware analysis can identify malicious attachments whose content, signature, or behavior conflicts with their apparent name or file type.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1036.007 | Double File Extension |
Comments
Email gateways can inspect the complete filename and actual file type rather than relying on the first visible extension, allowing attachments such as invoice.pdf.exe or report.pdf.lnk to be blocked.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059.005 | Visual Basic |
Comments
Email anti-malware and sandboxing can analyze Visual Basic scripts and macro-enabled attachments and quarantine files that exhibit malicious behavior. This does not prevent Visual Basic abuse originating outside email.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059 | Command and Scripting Interpreter |
Comments
Email anti-malware can block suspicious script attachments before they reach an interpreter. Most command and scripting activity occurs after compromise or through channels unrelated to email.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059.001 | PowerShell |
Comments
Email scanning or sandboxing may identify PowerShell script attachments or documents that launch PowerShell.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059.006 | Python |
Comments
Email anti-malware may quarantine malicious Python scripts or packed Python payloads sent specifically as email attachments. Python activity originating from installed tools or post-compromise execution remains unaffected.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059.007 | JavaScript |
Comments
A sandbox may execute JavaScript, JScript, HTA, HTML, or SVG attachments and identify malicious file creation or process execution. Depends on the email security product supporting active-content detonation.
References
|