CIS Controls Malware Defenses Capability Group

Prevent or control the installation, spread, and execution of malicious applications, code, or scripts on enterprise assets.

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1027 Obfuscated Files or Information
Comments
Anti-malware software can detect and quarantine malicious files or commands that use encoding, packing, encryption, or other obfuscation techniques to evade detection.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1027 Obfuscated Files or Information
Comments
Behavior-based anti-malware can identify malicious activity after obfuscated content is decoded, unpacked, interpreted, or executed, allowing detection or blocking based on runtime behavior rather than relying solely on static signatures.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1211 Exploitation for Stealth
Comments
Security anti-exploitation tools and applications that look for behavior used during exploitation such as Windows Defender Exploit Guard (WDEG) and the Enhanced Mitigation Experience Toolkit (EMET) can be used to help mitigate some exploitation behavior to evade detection.
References
CIS-10.3 Disable Autorun and Autoplay for Removable Media mitigates T1092 Communication Through Removable Media
Comments
Disable Autoruns if it is unnecessary to help prevent adversaries from performing command and control between compromised hosts on potentially disconnected networks by using removable media to transfer commands from system to system.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059 Command and Scripting Interpreter
Comments
Behavioral anti-malware commonly monitors scripting engines and detects malicious script execution through behavioral indicators rather than signatures.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059.006 Python
Comments
Products that explicitly monitor Python process behavior, command execution, child processes, and resulting system changes can detect or block malicious Python activity. Generic behavioral monitoring alone is insufficient.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1055 Process Injection
Comments
Some anti-malware products monitor cross-process memory writes, remote-thread creation, process hollowing, and similar injection behavior. Where these protections are enabled, the safeguard directly detects or blocks process injection.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1547.006 Kernel Modules and Extensions
Comments
Anti-malware products may detect malicious kernel drivers or unsigned modules during installation or loading. However, preventing unauthorized kernel module loading relies more heavily on platform integrity and driver enforcement controls (anti-malware product monitors and blocks malicious kernel modules, drivers, or extensions) than standard anti-malware alone.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1204.002 Malicious File
Comments
When a user executes a malicious file, behavior-based anti-malware can identify suspicious runtime activity and terminate or contain the process. This directly reduces the effectiveness of the malicious file after execution begins.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1055 Process Injection
Comments
Process injection produces observable behaviors such as cross-process memory writes, remote-thread creation, process hollowing, and abnormal memory execution. Behavior-based anti-malware can directly detect or block these actions.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1547.006 Kernel Modules and Extensions
Comments
Behavior-based products may monitor driver installation, kernel module loading, and suspicious kernel-level changes. Where these events are blocked or detected, the safeguard directly addresses malicious kernel persistence.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1027.002 Software Packing
Comments
Behavior-based anti-malware can identify packed malware after it unpacks in memory or begins performing malicious actions. This reduces the effectiveness of packing as a method for evading static detection.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059.005 Visual Basic
Comments
Behavior-based anti-malware can identify suspicious Visual Basic and macro execution chains, such as an Office application spawning interpreters, downloading payloads, or modifying system settings.
References
CIS-10.7 Use Behavior-Based Anti-Malware Software mitigates T1059.001 PowerShell
Comments
Behavior-based anti-malware can analyze PowerShell process ancestry, commands, script content, memory activity, and resulting system changes. This enables direct detection or blocking of malicious PowerShell execution.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1687 Exploitation for Defense Impairment
Comments
Adversaries may exploit anti-malware, EDR, logging, or other defensive components to disable or impair them. Anti-exploitation controls protecting those components directly restrict this behavior.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1212 Exploitation for Credential Access
Comments
Adversaries may exploit authentication, kernel, or security processes to access credentials. Anti-exploitation protections that cover the targeted component directly reduce the likelihood that the exploit succeeds.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1210 Exploitation of Remote Services
Comments
Remote-service exploitation targets vulnerabilities in network-accessible services or protocol handlers. Anti-exploitation protections applied to the targeted service can block the exploit or prevent successful payload execution.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1190 Exploit Public-Facing Application
Comments
Public-facing services frequently become initial access vectors through software vulnerabilities. Exploit mitigation technologies increase resistance to successful exploitation by preventing or disrupting exploit execution.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1189 Drive-by Compromise
Comments
Drive-by attacks commonly rely on browser or plugin exploitation. DEP, ASLR, CFG, and exploit guards are intended to prevent exploitation of these vulnerabilities before malicious code executes.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1068 Exploitation for Privilege Escalation
Comments
Kernel, memory, driver, and control-flow protections can prevent exploitation of vulnerable components used to obtain elevated privileges. This is a direct technical restriction on privilege-escalation exploits.
References
CIS-10.5 Enable Anti-Exploitation Features mitigates T1203 Exploitation for Client Execution
Comments
Data execution prevention, control-flow protections, exploit guards, and similar mechanisms interfere directly with memory corruption and code execution in client applications. These features reduce the ability of an exploit to execute its payload.
References
CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media mitigates T1204.002 Malicious File
Comments
Automatic scanning can detect and quarantine a malicious file on removable media before a user opens or executes it. This creates a direct preventive relationship when blocking or quarantine is enforced.
References
CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media mitigates T1091 Replication Through Removable Media
Comments
Malware commonly uses removable media to move between systems. Automatic scanning can identify and quarantine malicious files when the media is connected, directly reducing the effectiveness of removable-media propagation.
References
CIS-10.3 Disable Autorun and Autoplay for Removable Media mitigates T1091 Replication Through Removable Media
Comments
Many removable-media malware families rely on Autorun/Autoplay to automatically execute malicious code after an infected USB device is inserted. Disabling these operating system features directly interrupts the automatic execution mechanism used to propagate malware through removable media, forcing an attacker to rely on manual execution or another execution vector.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1204.002 Malicious File
Comments
Anti-malware can scan a file when it is opened or executed and quarantine or block the file before the malicious payload runs. This directly reduces the effectiveness of malicious files that depend on user execution.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1027.002 Software Packing
Comments
Packed executables are a common malware delivery method. Modern anti-malware engines unpack or emulate packed binaries during scanning, making this a direct technical capability of the safeguard.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1059.005 Visual Basic
Comments
Malicious VBScript is routinely inspected by anti-malware through script scanning and behavioral analysis prior to execution.
References
CIS-10.1 Deploy and Maintain Anti-Malware Software mitigates T1059.001 PowerShell
Comments
Anti-malware integrates with PowerShell logging and AMSI to inspect scripts and commands before execution, making PowerShell malware a primary detection target.
References

Capabilities

Capability ID Capability Name Number of Mappings
CIS-10.3 Disable Autorun and Autoplay for Removable Media 2
CIS-10.4 Configure Automatic Anti-Malware Scanning of Removable Media 2
CIS-10.1 Deploy and Maintain Anti-Malware Software 7
CIS-10.5 Enable Anti-Exploitation Features 8
CIS-10.7 Use Behavior-Based Anti-Malware Software 9