Establish, implement, and actively manage (track, report, correct) network devices, in order to prevent attackers from exploiting vulnerable network services and access points.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1563.002 | RDP Hijacking |
Comments
Dedicated administrative workstations and segmented management networks reduce who can reach hosts carrying privileged RDP sessions and separate administrative activity from ordinary user networks. This does not prevent hijacking after the admin host itself is compromised, but it directly reduces network exposure of those sessions.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1563 | Remote Service Session Hijacking |
Comments
Adversaries hijack existing SSH, RDP, or other remote-management sessions. Keeping administrative sessions on dedicated, segmented resources reduces exposure of those sessions to compromised user endpoints and limits unnecessary network paths to privileged remote services.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Dedicated administrative resources are explicitly segmented from the primary enterprise network and denied Internet access. That separation reduces opportunities for adversaries on user or Internet-connected networks to position themselves between administrative systems and managed infrastructure, directly shrinking the attack surface for interception of privileged sessions.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1599.001 | Network Address Translation Traversal |
Comments
This sub-technique concerns traversing or bypassing network boundaries implemented through NAT and perimeter devices. Secure architecture using explicit trust zones, controlled routing, segmentation, and restricted inbound/outbound paths directly constrains the network reachability needed for NAT traversal.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1599 | Network Boundary Bridging |
Comments
This technique directly concerns adversaries compromising network devices to bypass segmentation and route prohibited traffic across trust boundaries. Because this control requires network segmentation and least privilege, designing and maintaining strong trust boundaries directly constrains the traffic paths the adversary is attempting to bridge. ATT&CK describes the technique specifically in terms of bypassing segmentation and boundary-device policy
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1557 | Adversary-in-the-Middle |
Comments
ATT&CK recommends network segmentation, traffic filtering, restricted access to network infrastructure, encryption, and network intrusion prevention for AiTM activity. Segmentation under this control reduces the network scope in which an adversary can position itself between communicating systems and restricts access to infrastructure capable of reshaping traffic
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1556.004 | Network Device Authentication |
Comments
This sub-technique specifically targets authentication on network devices. ATT&CK recommends MFA, privileged-account restriction, TACACS+/RADIUS, and vendor hardening; a secure network architecture that isolates the management plane and applies least-privilege administrative access directly constrains the access needed to modify network-device authentication.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1542.005 | TFTP Boot |
Comments
Adversaries can manipulate network-device boot configuration to load an unauthorized image from a malicious TFTP server. ATT&CK recommends limiting access to administrative interfaces, restricting insecure protocols, AAA/command authorization, and network-level filtering which are mechanisms that can be implemented as part of a secure management-plane architecture under this control.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1200 | Hardware Additions |
Comments
Adversaries may introduce unauthorized devices onto the network. ATT&CK recommends network access controls such as 802.1X, device certificates, and restricting DHCP to registered devices; these are architectural admission-control mechanisms that directly prevent unauthorized hardware from communicating with trusted systems.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1059.008 | Network Device CLI |
Comments
Adversaries use network-device CLIs to execute commands and modify device behavior. ATT&CK recommends AAA, least privilege, and command authorization such as TACACS+ to restrict which administrative commands users may execute. Because this control explicitly requires least privilege within the network architecture, this is a strong mapping when that architecture includes management-plane and command-access controls.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1021.002 | SMB/Windows Admin Shares |
Comments
Adversaries use SMB and administrative shares for remote access and lateral movement. A secure network architecture that enforces segmentation and least-privilege network access can restrict SMB connectivity to approved source/destination relationships, directly reducing the network reachability required for unauthorized lateral movement.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1071.001 | Web Protocols |
Comments
Adversaries use HTTP or HTTPS to communicate with command-and-control infrastructure. Default-deny Internet egress on dedicated administrative resources prevents direct connections to external HTTP/S C2 infrastructure, directly disrupting the communication channel.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1105 | Ingress Tool Transfer |
Comments
Adversaries transfer tools and payloads onto compromised systems from external infrastructure. Dedicated administrative resources have no direct Internet access and permit file transfer only through controlled internal mechanisms, directly preventing arbitrary external payload retrieval.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1021.006 | Windows Remote Management |
Comments
Adversaries use WinRM to execute commands remotely and move laterally. Administrative network controls permit WinRM only over approved management paths, directly denying unauthorized WinRM connectivity.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Adversaries use RDP for lateral movement into privileged systems. Administrative enclave ACLs restrict RDP to explicitly authorized source and destination relationships, directly preventing arbitrary RDP access into or through the enclave.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Adversaries use alternate network protocols to transfer data outside the environment. Protocol-aware egress filtering and destination restrictions in the administrative enclave directly block unauthorized alternate-protocol exfiltration channels.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1571 | Non-Standard Port |
Comments
Adversaries use unexpected ports for command-and-control to evade standard network restrictions. The administrative enclave permits only explicitly approved ports and denies all others, directly preventing outbound communication over unauthorized ports.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1095 | Non-Application Layer Protocol |
Comments
Adversaries use non-application-layer protocols for command-and-control or data transfer. The administrative enclave enforces default-deny egress with explicit protocol allowlisting, directly blocking unauthorized low-level communications.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1133 | External Remote Services |
Comments
Adversaries use externally accessible remote services to reach internal or privileged resources. Dedicated administrative systems are not externally reachable and accept access only through controlled administrative paths, directly preventing external remote-service access to the enclave.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1567 | Exfiltration Over Web Service |
Comments
Adversaries transfer stolen data to external Web services. Dedicated administrative resources have no Internet egress, directly preventing connections to the external Web destinations required by the technique.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1102 | Web Service |
Comments
Adversaries use external Web services as command-and-control infrastructure. Dedicated administrative systems have no direct Internet access, directly preventing them from establishing command-and-control sessions with external Web services.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1557.001 | Name Resolution Poisoning and SMB Relay |
Comments
Adversaries manipulate local name-resolution traffic and relay authentication to reachable services. Separating administrative systems from general-user broadcast domains and restricting SMB paths directly reduces poisoning opportunities and viable privileged relay targets.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1040 | Network Sniffing |
Comments
Adversaries capture traffic visible from a compromised privileged system to collect credentials or operational information. Isolating administrative resources from the primary network reduces the traffic and broadcast domains visible to those systems, directly limiting passive collection opportunities.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1046 | Network Service Discovery |
Comments
Adversaries probe network systems to identify accessible services and hosts. Administrative enclave segmentation restricts network visibility and reachability across the enclave boundary, directly reducing the systems and services available for discovery.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1210 | Exploitation of Remote Services |
Comments
Adversaries exploit vulnerable remote services on reachable systems to move laterally. Segmentation of administrative resources restricts the remote services reachable into and out of the privileged enclave, directly reducing lateral exploitation opportunities.
References
|
| CIS-12.8 | Establish and Maintain Dedicated Computing Resources for All Administrative Work | mitigates | T1189 | Drive-by Compromise |
Comments
Adversaries compromise systems when users access malicious or compromised Internet content. Dedicated administrative resources are prohibited from general Internet access, directly removing ordinary Web browsing as an initial-access path to privileged systems.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1021.006 | Windows Remote Management |
Comments
Adversaries may use WinRM for remote command execution and lateral movement. WinRM is not externally reachable and can only be accessed through authenticated enterprise VPN connectivity, directly restricting unauthorized remote WinRM sessions.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Adversaries use RDP for remote access or lateral movement into enterprise systems. RDP is inaccessible directly from external networks and reachable remotely only after authenticated VPN access through approved paths, directly preventing unauthenticated external RDP connectivity.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1659 | Content Injection |
Comments
Adversaries can inject malicious content into network traffic through a compromised or hostile upstream communication path. VPN integrity protection prevents unauthorized modification of enterprise-bound tunneled traffic, directly blocking injected content from becoming part of the protected session.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Adversaries positioned along the remote user's network path attempt to intercept or modify enterprise communications. An authenticated VPN tunnel provides confidentiality and integrity protection, directly preventing useful interception or alteration of tunneled traffic.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1040 | Network Sniffing |
Comments
Adversaries capture traffic traversing untrusted remote networks to obtain sensitive enterprise information. The enterprise VPN encrypts traffic between the endpoint and enterprise gateway, directly preventing passive observers from recovering protected traffic.
References
|
| CIS-12.7 | Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise's AAA Infrastructure | mitigates | T1133 | External Remote Services |
Comments
Adversaries can use externally accessible remote-access services to enter enterprise networks. Requiring remote devices to authenticate through an enterprise-managed VPN and centralized AAA confines remote access to a controlled gateway, directly eliminating unmanaged direct access paths.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1542.005 | TFTP Boot |
Comments
Adversaries can abuse unauthenticated network-boot mechanisms to load malicious or unauthorized system images. Disabling insecure TFTP/PXE boot or restricting it to authenticated management infrastructure directly prevents unauthorized network boot operations.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Adversaries can query SNMP to collect network-device and topology information. Enforced SNMPv3 authentication, encryption, and management-source restrictions directly prevent unauthorized systems from successfully issuing or reading management queries.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1557.004 | Evil Twin |
Comments
Adversaries can deploy a rogue access point impersonating the legitimate enterprise WLAN to capture credentials or intercept communications. Managed 802.1X supplicants validate the trusted RADIUS/EAP server certificate and approved wireless profile, directly preventing endpoints from authenticating to the rogue infrastructure.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Adversaries can intercept or manipulate communications between wireless clients and enterprise infrastructure. Enterprise authentication and encrypted wireless communications provide confidentiality and integrity protections that directly constrain interception and modification.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1040 | Network Sniffing |
Comments
Adversaries can capture wireless network traffic to recover credentials or sensitive information. WPA2 Enterprise or stronger encryption protects wireless frames from passive observers, directly preventing useful plaintext recovery from captured traffic.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1669 | Wi-Fi Networks |
Comments
Adversaries can gain initial access by associating with the target organization's wireless network. Secure network management protocols like 802.1X and enterprise wireless authentication require authorized credentials or device identity before admission, directly preventing unauthorized wireless access.
References
|
| CIS-12.6 | Use of Secure Network Management and Communication Protocols | mitigates | T1200 | Hardware Additions |
Comments
Adversaries can attach rogue computers, appliances, or networking hardware to obtain enterprise network connectivity. Secure network management protocols like 802.1X requires successful user or device authentication before network admission, directly denying unauthorized hardware access.
References
|
| CIS-12.5 | Centralize Network Authentication, Authorization, and Auditing network AAA | mitigates | T1601.002 | Downgrade System Image |
Comments
Adversaries may install an older network-device image to restore vulnerable functionality or bypass newer protections. AAA authorization restricts downgrade and image-installation commands to approved roles, directly preventing unauthorized rollback operations.
References
|
| CIS-12.5 | Centralize Network Authentication, Authorization, and Auditing network AAA | mitigates | T1601.001 | Patch System Image |
Comments
Adversaries may install malicious or unauthorized network-device images to modify device operation. AAA command authorization restricts image upload and installation functions to approved administrative roles, directly preventing unauthorized system-image replacement.
References
|
| CIS-12.5 | Centralize Network Authentication, Authorization, and Auditing network AAA | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Adversaries may retrieve network-device configurations to collect topology, credentials, routes, and security policy. AAA command authorization denies configuration-display and export operations to identities without explicit permission, directly restricting configuration collection.
References
|
| CIS-12.5 | Centralize Network Authentication, Authorization, and Auditing network AAA | mitigates | T1686.002 | Network Device Firewall |
Comments
Adversaries may change firewall rules, ACLs, or security zones to weaken network restrictions. Centralized AAA authorization limits those configuration commands to approved roles, directly preventing unauthorized identities from modifying firewall policy.
References
|
| CIS-12.5 | Centralize Network Authentication, Authorization, and Auditing network AAA | mitigates | T1059.008 | Network Device CLI |
Comments
Adversaries may use network-device CLIs to execute privileged administrative commands. Centralized AAA with command-level authorization restricts which commands each identity may execute, directly preventing unauthorized CLI operations.
References
|
| CIS-12.3 | Securely Manage Network Infrastructure | mitigates | T1686.002 | Network Device Firewall |
Comments
Adversaries can alter ACLs, firewall rules, or network security zones to create unauthorized access paths. Enforced IaC/GitOps configuration management validates approved firewall state and rejects or automatically reverses unauthorized policy changes, directly disrupting the modification.
References
|
| CIS-12.3 | Securely Manage Network Infrastructure | mitigates | T1059.008 | Network Device CLI |
Comments
Adversaries can use network-device command-line interfaces to make malicious configuration changes. Enforced version-controlled Infrastructure-as-Code with direct configuration disabled or automatically reconciled prevents unauthorized CLI changes from becoming persistent device state.
References
|
| CIS-12.3 | Securely Manage Network Infrastructure | mitigates | T1659 | Content Injection |
Comments
Adversaries can inject malicious content into network communications while positioned along the traffic path. Integrity-protected SSH or HTTPS management sessions reject unauthorized modifications, directly preventing injected content from becoming part of the protected administrative session.
References
|
| CIS-12.3 | Securely Manage Network Infrastructure | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Adversaries can position themselves between communicating systems to intercept or alter network traffic. Authenticated and encrypted management sessions provide confidentiality, peer authentication, and integrity protection, directly preventing useful interception or modification of administrative communications.
References
|
| CIS-12.3 | Securely Manage Network Infrastructure | mitigates | T1040 | Network Sniffing |
Comments
Adversaries can passively capture management traffic to obtain credentials, commands, or configuration information. SSH, HTTPS, and equivalent encrypted management protocols make captured administrative traffic unreadable, directly reducing the value of network sniffing.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1669 | Wi-Fi Networks |
Comments
Adversaries obtain initial access by connecting to an organization's wireless network. Separating wireless access networks from sensitive enterprise segments with enforced routing and firewall controls directly limits what an attacker can reach after establishing wireless connectivity.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1199 | Trusted Relationship |
Comments
Adversaries abuse connectivity granted to trusted third parties or external organizations to reach enterprise resources. Segmented third-party access restricts those connections to explicitly authorized services and network zones, directly preventing movement beyond the intended trust boundary.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1072 | Software Deployment Tools |
Comments
Adversaries abuse centralized deployment or management systems to execute software or move laterally. Placing those systems in a restricted management segment and allowing access only from approved administrative hosts directly limits unauthorized interaction with the deployment infrastructure.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
Adversaries use unencrypted alternate protocols to transfer stolen data. Inter-zone and egress filtering blocks unauthorized protocols and destinations, directly disrupting the exfiltration channel.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Adversaries use asymmetrically encrypted non-C2 protocols to move data outside the environment. Network controls restrict permitted protocols and destinations, directly blocking unauthorized encrypted exfiltration channels.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
Adversaries exfiltrate data through encrypted non-C2 protocols that use symmetric encryption. Enforced protocol and destination allowlists deny unauthorized encrypted outbound channels, directly preventing the required network transfer.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Adversaries exfiltrate data using protocols other than their primary command-and-control channel. Protocol-aware egress and inter-zone controls restrict communications to approved protocols and destinations, directly blocking unauthorized alternate-protocol exfiltration paths.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1571 | Non-Standard Port |
Comments
Adversaries communicate over unusual ports to evade expected network controls. Explicit port allowlists and default-deny inter-zone filtering block unapproved ports, directly preventing those communications from traversing protected network boundaries.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1095 | Non-Application Layer Protocol |
Comments
Adversaries use lower-layer protocols for command-and-control or data transfer. Deny-by-default inter-segment filtering permits only explicitly authorized protocols, directly blocking unauthorized non-application-layer communications across security boundaries.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1021.006 | Windows Remote Management |
Comments
Adversaries use WinRM to execute commands remotely and move laterally. Segmentation restricts WinRM connectivity to designated administrative zones and systems, directly preventing unauthorized remote WinRM sessions.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1021.003 | Distributed Component Object Model |
Comments
Adversaries use DCOM to remotely execute actions on accessible Windows systems. Network segmentation blocks DCOM traffic outside explicitly authorized relationships, directly restricting the network connectivity required for remote DCOM execution.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Adversaries use RDP for remote access and lateral movement between systems. Segmentation and inter-zone ACLs permit RDP only across approved administrative paths, directly preventing unauthorized RDP connectivity between network zones.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Adversaries retrieve network-device configurations to obtain topology, credentials, routing information, or security policy. Isolating management interfaces and permitting access only from approved administrative systems directly prevents unauthorized systems from reaching the configuration interface.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Adversaries query SNMP to obtain device, interface, routing, and network information. Restricting SNMP to an isolated management plane with ACLs permitting only authorized management systems directly prevents unauthorized hosts from issuing MIB queries.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1133 | External Remote Services |
Comments
Adversaries use externally accessible VPNs, gateways, and remote-access services to enter enterprise networks. The architecture forces external access through designated controlled gateways while denying direct connectivity to internal resources, directly restricting unauthorized remote entry paths.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1557.001 | Name Resolution Poisoning and SMB Relay |
Comments
Adversaries poison local name-resolution traffic and relay authentication attempts to reachable services. Layer-2/Layer-3 segmentation and SMB access restrictions constrain the poisoning domain and relay destinations, directly reducing viable poisoning and relay paths.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1040 | Network Sniffing |
Comments
Adversaries capture traffic visible from their network position to obtain credentials, sessions, or operational information. Segmentation reduces the broadcast domains, traffic flows, and network segments visible from a compromised system, directly limiting the traffic available for passive collection.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1046 | Network Service Discovery |
Comments
Adversaries probe remote systems to identify accessible hosts, ports, and services. Enforced segmentation limits probe reachability across security boundaries, directly reducing the systems and services that can be discovered.
References
|
| CIS-12.2 | Establish and Maintain a Secure Network Architecture | mitigates | T1210 | Exploitation of Remote Services |
Comments
Adversaries must reach a vulnerable remote service before exploiting it for lateral movement or execution. Network segmentation and least-privilege ACLs restrict which systems can communicate with those services, directly reducing exploitable network paths.
References
|
| CIS-12.1 | Ensure Network Infrastructure is Up-to-Date | mitigates | T1601.002 | Downgrade System Image |
Comments
Adversaries downgrade network-device software to reintroduce vulnerable or weaker code. Enforced anti-rollback and approved-version controls prevent installation of older unauthorized images, directly blocking the downgrade behavior.
References
|
| CIS-12.1 | Ensure Network Infrastructure is Up-to-Date | mitigates | T1686.002 | Network Device Firewall |
Comments
Adversaries may exploit vulnerable network firewalls to gain the privileged access required to alter ACLs, zones, or firewall policy. Maintaining supported and patched firewall software removes known vulnerability-based access paths, directly reducing the adversary's ability to reach the configuration state required to modify the firewall.
References
|
| CIS-12.1 | Ensure Network Infrastructure is Up-to-Date | mitigates | T1210 | Exploitation of Remote Services |
Comments
Adversaries exploit vulnerabilities in remotely reachable services to execute code or move laterally. Updating network-device software removes known vulnerabilities from those services, directly preventing exploitation paths that depend on obsolete or vulnerable software.
References
|
| CIS-12.1 | Ensure Network Infrastructure is Up-to-Date | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Adversaries exploit vulnerabilities in Internet-facing services or network-device management interfaces to gain initial access. Keeping network infrastructure on supported, current software removes known exploitable vulnerabilities, directly reducing the adversary's ability to successfully exploit those exposed services.
References
|