CIS Controls CIS-9.7

Deploy and maintain email server anti-malware protections, such as attachment scanning and/or sandboxing.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1566.001 Spearphishing Attachment
Comments
Email-server attachment scanning and sandboxing can identify, quarantine, or remove malicious attachments before they reach the recipient.
References
    CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1204.002 Malicious File
    Comments
    Removing a malicious attachment before delivery prevents the user from opening the file and initiating its execution chain. The safeguard is limited to malicious files delivered through the protected email environment.
    References
      CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1203 Exploitation for Client Execution
      Comments
      Email sandboxing can detonate weaponized Office documents, PDFs, archives, and other attachments to identify exploit behavior before delivery.
      References
        CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1221 Template Injection
        Comments
        Email detonation chambers can open suspicious documents and observe attempts to retrieve or execute remote templates and payloads before the message reaches the recipient.
        References
          CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1027.012 LNK Icon Smuggling
          Comments
          Email scanning can identify suspicious LNK attachments and inspect icon-location or target fields that reference remote payloads.
          References
            CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1036.008 Masquerade File Type
            Comments
            Anti-malware scanners can compare file headers, MIME types, extensions, and content to detect attachments disguised as benign file formats.
            References
              CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1566 Phishing
              Comments
              Email-server anti-malware directly addresses malicious attachments.
              References
                CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1204 User Execution
                Comments
                Blocking malicious attachments prevents one major form of user execution.
                References
                  CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1027 Obfuscated Files or Information
                  Comments
                  Email anti-malware can use static, heuristic, and behavioral analysis to identify obfuscated files before delivery.
                  References
                    CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1027.002 Software Packing
                    Comments
                    Heuristic scanning and sandbox detonation can identify packed executables attached to messages, even when packing changes their static signature.
                    References
                      CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1027.006 HTML Smuggling
                      Comments
                      A sandbox capable of executing active HTML attachments may detect JavaScript that reconstructs and writes a malicious payload to disk.
                      References
                        CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1027.009 Embedded Payloads
                        Comments
                        Attachment scanners and sandboxes can identify malicious payloads hidden within documents, scripts, executables, or other carrier files.
                        References
                          CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1027.013 Encrypted/Encoded File
                          Comments
                          Anti-malware can identify encoded or high-entropy attachments and may block encrypted archives that cannot be inspected.
                          References
                            CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1027.015 Compression
                            Comments
                            Email anti-malware capable of recursively unpacking ZIP, RAR, 7z, self-extracting archives, and nested archives can identify malicious files before delivery.
                            References
                              CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1027.017 SVG Smuggling
                              Comments
                              A sandbox that renders SVG attachments and executes their embedded scripts may identify payload construction or malicious follow-on behavior.
                              References
                                CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1036 Masquerading
                                Comments
                                Anti-malware analysis can identify malicious attachments whose content, signature, or behavior conflicts with their apparent name or file type.
                                References
                                  CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1036.007 Double File Extension
                                  Comments
                                  Email gateways can inspect the complete filename and actual file type rather than relying on the first visible extension, allowing attachments such as invoice.pdf.exe or report.pdf.lnk to be blocked.
                                  References
                                    CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1059.005 Visual Basic
                                    Comments
                                    Email anti-malware and sandboxing can analyze Visual Basic scripts and macro-enabled attachments and quarantine files that exhibit malicious behavior. This does not prevent Visual Basic abuse originating outside email.
                                    References
                                      CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1059 Command and Scripting Interpreter
                                      Comments
                                      Email anti-malware can block suspicious script attachments before they reach an interpreter. Most command and scripting activity occurs after compromise or through channels unrelated to email.
                                      References
                                        CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1059.001 PowerShell
                                        Comments
                                        Email scanning or sandboxing may identify PowerShell script attachments or documents that launch PowerShell.
                                        References
                                          CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1059.006 Python
                                          Comments
                                          Email anti-malware may quarantine malicious Python scripts or packed Python payloads sent specifically as email attachments. Python activity originating from installed tools or post-compromise execution remains unaffected.
                                          References
                                            CIS-9.7 Deploy and Maintain Email Server Anti-Malware Protections mitigates T1059.007 JavaScript
                                            Comments
                                            A sandbox may execute JavaScript, JScript, HTA, HTML, or SVG attachments and identify malicious file creation or process execution. Depends on the email security product supporting active-content detonation.
                                            References