Prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1027 | Obfuscated Files or Information |
Comments
Anti-malware software can detect and quarantine malicious files or commands that use encoding, packing, encryption, or other obfuscation techniques to evade detection.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1027 | Obfuscated Files or Information |
Comments
Behavior-based anti-malware can identify malicious activity after obfuscated content is decoded, unpacked, interpreted, or executed, allowing detection or blocking based on runtime behavior rather than relying solely on static signatures.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1211 | Exploitation for Stealth |
Comments
Security anti-exploitation tools and applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to help mitigate some exploitation behavior to evade detection.
References
|
| CIS-10.3 | Disable Autorun and Autoplay for Removable Media | mitigates | T1092 | Communication Through Removable Media |
Comments
Disable Autoruns if it is unnecessary to help prevent adversaries from performing command and control between compromised hosts on potentially disconnected networks by using removable media to transfer commands from system to system.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1059 | Command and Scripting Interpreter |
Comments
Behavioral anti-malware commonly monitors scripting engines and detects malicious script execution through behavioral indicators rather than signatures.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1059.006 | Python |
Comments
Products that explicitly monitor Python process behavior, command execution, child processes, and resulting system changes can detect or block malicious Python activity. Generic behavioral monitoring alone is insufficient.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1055 | Process Injection |
Comments
Some anti-malware products monitor cross-process memory writes, remote-thread creation, process hollowing, and similar injection behavior. Where these protections are enabled, the safeguard directly detects or blocks process injection.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1547.006 | Kernel Modules and Extensions |
Comments
Anti-malware products may detect malicious kernel drivers or unsigned modules during installation or loading. However, preventing unauthorized kernel module loading relies more heavily on platform integrity and driver enforcement controls (anti-malware product monitors and blocks malicious kernel modules, drivers, or extensions) than standard anti-malware alone.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1204.002 | Malicious File |
Comments
When a user executes a malicious file, behavior-based anti-malware can identify suspicious runtime activity and terminate or contain the process. This directly reduces the effectiveness of the malicious file after execution begins.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1055 | Process Injection |
Comments
Process injection produces observable behaviors such as cross-process memory writes, remote-thread creation, process hollowing, and abnormal memory execution. Behavior-based anti-malware can directly detect or block these actions.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1547.006 | Kernel Modules and Extensions |
Comments
Behavior-based products may monitor driver installation, kernel module loading, and suspicious kernel-level changes. Where these events are blocked or detected, the safeguard directly addresses malicious kernel persistence.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1027.002 | Software Packing |
Comments
Behavior-based anti-malware can identify packed malware after it unpacks in memory or begins performing malicious actions. This reduces the effectiveness of packing as a method for evading static detection.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1059.005 | Visual Basic |
Comments
Behavior-based anti-malware can identify suspicious Visual Basic and macro execution chains, such as an Office application spawning interpreters, downloading payloads, or modifying system settings.
References
|
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | mitigates | T1059.001 | PowerShell |
Comments
Behavior-based anti-malware can analyze PowerShell process ancestry, commands, script content, memory activity, and resulting system changes. This enables direct detection or blocking of malicious PowerShell execution.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1687 | Exploitation for Defense Impairment |
Comments
Adversaries may exploit anti-malware, EDR, logging, or other defensive components to disable or impair them. Anti-exploitation controls protecting those components directly restrict this behavior.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1212 | Exploitation for Credential Access |
Comments
Adversaries may exploit authentication, kernel, or security processes to access credentials. Anti-exploitation protections that cover the targeted component directly reduce the likelihood that the exploit succeeds.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1210 | Exploitation of Remote Services |
Comments
Remote-service exploitation targets vulnerabilities in network-accessible services or protocol handlers. Anti-exploitation protections applied to the targeted service can block the exploit or prevent successful payload execution.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Public-facing services frequently become initial access vectors through software vulnerabilities. Exploit mitigation technologies increase resistance to successful exploitation by preventing or disrupting exploit execution.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1189 | Drive-by Compromise |
Comments
Drive-by attacks commonly rely on browser or plugin exploitation. DEP, ASLR, CFG, and exploit guards are intended to prevent exploitation of these vulnerabilities before malicious code executes.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
Kernel, memory, driver, and control-flow protections can prevent exploitation of vulnerable components used to obtain elevated privileges. This is a direct technical restriction on privilege-escalation exploits.
References
|
| CIS-10.5 | Enable Anti-Exploitation Features | mitigates | T1203 | Exploitation for Client Execution |
Comments
Data execution prevention, control-flow protections, exploit guards, and similar mechanisms interfere directly with memory corruption and code execution in client applications. These features reduce the ability of an exploit to execute its payload.
References
|
| CIS-10.4 | Configure Automatic Anti-Malware Scanning of Removable Media | mitigates | T1204.002 | Malicious File |
Comments
Automatic scanning can detect and quarantine a malicious file on removable media before a user opens or executes it. This creates a direct preventive relationship when blocking or quarantine is enforced.
References
|
| CIS-10.4 | Configure Automatic Anti-Malware Scanning of Removable Media | mitigates | T1091 | Replication Through Removable Media |
Comments
Malware commonly uses removable media to move between systems. Automatic scanning can identify and quarantine malicious files when the media is connected, directly reducing the effectiveness of removable-media propagation.
References
|
| CIS-10.3 | Disable Autorun and Autoplay for Removable Media | mitigates | T1091 | Replication Through Removable Media |
Comments
Many removable-media malware families rely on Autorun/Autoplay to automatically execute malicious code after an infected USB device is inserted. Disabling these operating system features directly interrupts the automatic execution mechanism used to propagate malware through removable media, forcing an attacker to rely on manual execution or another execution vector.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1204.002 | Malicious File |
Comments
Anti-malware can scan a file when it is opened or executed and quarantine or block the file before the malicious payload runs. This directly reduces the effectiveness of malicious files that depend on user execution.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1027.002 | Software Packing |
Comments
Packed executables are a common malware delivery method. Modern anti-malware engines unpack or emulate packed binaries during scanning, making this a direct technical capability of the safeguard.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1059.005 | Visual Basic |
Comments
Malicious VBScript is routinely inspected by anti-malware through script scanning and behavioral analysis prior to execution.
References
|
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | mitigates | T1059.001 | PowerShell |
Comments
Anti-malware integrates with PowerShell logging and AMSI to inspect scripts and commands before execution, making PowerShell malware a primary detection target.
References
|
| Capability ID | Capability Name | Number of Mappings |
|---|---|---|
| CIS-10.3 | Disable Autorun and Autoplay for Removable Media | 2 |
| CIS-10.4 | Configure Automatic Anti-Malware Scanning of Removable Media | 2 |
| CIS-10.1 | Deploy and Maintain Anti-Malware Software | 7 |
| CIS-10.5 | Enable Anti-Exploitation Features | 8 |
| CIS-10.7 | Use Behavior-Based Anti-Malware Software | 9 |