Operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats across the enterprise’s network infrastructure and user base.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1547.006 | Kernel Modules and Extensions |
Comments
Adversaries load malicious kernel modules or extensions for persistence or privilege escalation. Host-based security solutions can monitor module loading, detect known rootkits or unauthorized kernel modifications, and block or alert on suspicious kernel-extension activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059.006 | Python |
Comments
Adversaries use Python interpreters and scripts to execute malicious commands and payloads. EDR/HIPS can monitor anomalous Python execution, unusual parent-child relationships, network activity, and other suspicious behaviors, and can block or quarantine malicious payloads.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059.001 | PowerShell |
Comments
Adversaries use PowerShell to execute commands, scripts, and payloads. EDR/HIPS can monitor PowerShell process behavior, command lines, script activity, child processes, and suspicious follow-on actions, and can block or quarantine malicious activity
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1187 | Forced Authentication |
Comments
Adversaries coerce systems into authenticating to attacker-controlled SMB or WebDAV resources in order to capture credential material. This control requires traffic filtering between network segments, which can block or tightly restrict SMB and WebDAV communications to untrusted or unauthorized destinations, directly preventing the outbound authentication path required by the technique.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1659 | Content Injection |
Comments
Application-layer filtering can block uncommon, unauthorized, or malicious content and transferred file types at web proxies, application gateways, or similar inspection points before the content reaches protected systems.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Web filtering and application-layer gateways can block malicious web content and destinations used to deliver browser-based credential theft or session-stealing content.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1189 | Drive-by Compromise |
Comments
Web proxies and application-layer gateways can prevent access to known malicious or unnecessary websites and block malicious web content used to compromise users through drive-by activity.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1568 | Dynamic Resolution |
Comments
DNS filtering and sinkholing can prevent systems from resolving domains associated with dynamically changing adversary command-and-control infrastructure.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1568.002 | Domain Generation Algorithms |
Comments
DNS filtering and sinkholing can block domains generated by known domain-generation algorithms when those domains or generation patterns can be identified.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1567 | Exfiltration Over Web Service |
Comments
Web proxies and application-layer gateways can restrict which external web services are permitted, reducing unauthorized use of web services for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1567.001 | Exfiltration to Code Repository |
Comments
Application-layer filtering can block or restrict access to unauthorized external code repositories, limiting their use as destinations for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1567.002 | Exfiltration to Cloud Storage |
Comments
Application-layer filtering can block or restrict access to unauthorized cloud-storage services, limiting their use as destinations for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1567.003 | Exfiltration to Text Storage Sites |
Comments
Application-layer filtering can block or restrict access to unauthorized text-storage and paste services, limiting their use as destinations for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1133 | External Remote Services |
Comments
Application-layer firewalls and proxies can restrict access to unauthorized remote-access services, anonymization services, and other external services used to access enterprise resources.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1566 | Phishing |
Comments
Application-layer filtering can block malicious websites, links, attachments, and other web or email content used in phishing activity before that content reaches users.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1566.001 | Spearphishing Attachment |
Comments
Mail and application-layer gateways can inspect and block dangerous attachment types, malicious archives, and other suspicious content delivered through spearphishing attachments.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1566.002 | Spearphishing Link |
Comments
Web proxies and application-layer gateways can block access to malicious or unnecessary websites reached through spearphishing links.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1566.003 | Spearphishing via Service |
Comments
Application-layer filtering can restrict access to personal webmail, social media, and other external services that may be abused to deliver spearphishing messages.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1539 | Steal Web Session Cookie |
Comments
Web filtering and application-layer gateways can block malicious content or destinations used to deliver browser-based session-cookie theft activity.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1218 | System Binary Proxy Execution |
Comments
Application-layer filtering can restrict malicious sites, downloads, attachments, and scripts that may deliver payloads later executed through trusted system binaries.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1218.001 | Compiled HTML File |
Comments
Application-layer filtering can block CHM and other uncommon or risky file types in transit, reducing delivery of content that may be executed through Compiled HTML Help.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1204 | User Execution |
Comments
Application-layer filtering can prevent malicious web or email content from reaching users, reducing opportunities for users to execute or interact with adversary-delivered content.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1204.001 | Malicious Link |
Comments
Web proxies and application-layer gateways can block requests to malicious links and prevent associated content from being downloaded.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1204.004 | Malicious Copy and Paste |
Comments
Application-layer filtering can block malicious web content or destinations used to provide commands, scripts, or other content that users are instructed to copy and execute.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1102 | Web Service |
Comments
Web proxies and application-layer gateways can restrict access to unauthorized external web services, limiting their use for adversary command and control.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1102.001 | Dead Drop Resolver |
Comments
Application-layer filtering can block access to unauthorized web services used as dead-drop resolvers for adversary command-and-control infrastructure.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1102.002 | Bidirectional Communication |
Comments
Application-layer filtering can block unauthorized web services used for bidirectional command-and-control communications.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1102.003 | One-Way Communication |
Comments
Application-layer filtering can block unauthorized web services used for one-way command-and-control communications.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071 | Application Layer Protocol |
Comments
Application-aware gateways can inspect and restrict unauthorized application-layer protocols, services, and destinations used for adversary command and control.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.001 | Web Protocols |
Comments
Web proxies and application-layer firewalls can inspect and restrict HTTP and HTTPS traffic to unauthorized or malicious destinations.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.002 | File Transfer Protocols |
Comments
Application-layer filtering can restrict FTP, SFTP, and related file-transfer protocol traffic to approved services and destinations.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.003 | Mail Protocols |
Comments
Application-layer filtering can restrict SMTP, IMAP, POP3, and related mail-protocol traffic to approved infrastructure and expected communication paths.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.004 | DNS |
Comments
DNS proxies and filtering services can block malicious domains and restrict systems to approved name-resolution services.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1071.005 | Publish/Subscribe Protocols |
Comments
Application-aware filtering can restrict publish/subscribe protocols to approved brokers, destinations, and expected service ports.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Application proxies and gateways can require use of approved protocol services and restrict unauthorized application-layer protocols or destinations used for data exfiltration.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
Application-layer gateways can restrict symmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Application-layer gateways can restrict asymmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
Application-layer filtering can directly restrict unencrypted non-command-and-control protocols to approved services and destinations.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Web application firewalls and application-layer gateways can inspect inbound application requests and block known malicious request patterns or exploit payloads targeting public-facing applications.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1187 | Forced Authentication |
Comments
Application and protocol filtering can block outbound WebDAV and related requests that may be abused to force systems to authenticate to attacker-controlled resources.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1105 | Ingress Tool Transfer |
Comments
Web proxies and application-layer gateways can block unauthorized downloads, file-transfer services, and malicious content used to transfer adversary tools into the environment.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1572 | Protocol Tunneling |
Comments
Application-aware filtering can identify and restrict unauthorized tunneling through otherwise permitted application protocols and services.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1090 | Proxy |
Comments
Application-layer gateways can block known anonymization services, unauthorized proxy services, and other proxy destinations used to conceal adversary communications.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1090.003 | Multi-hop Proxy |
Comments
Application-layer gateways can restrict known anonymization and proxy services that may be chained together to form multi-hop proxy infrastructure.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1219 | Remote Access Tools |
Comments
Application firewalls and proxies can restrict access to websites, services, and destinations associated with unauthorized remote-access tools.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1219.002 | Remote Desktop Software |
Comments
Application-layer firewalls and proxies can restrict access to unauthorized remote-desktop services and destinations.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1552 | Unsecured Credentials |
Comments
Web application firewalls and application-layer controls can block server-side request forgery paths that would otherwise expose credential-bearing cloud metadata services.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1552.005 | Cloud Instance Metadata API |
Comments
A properly configured web application firewall can block external server-side request forgery attempts that target the cloud instance metadata API and expose temporary credentials.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1499.003 | Application Exhaustion Flood |
Comments
Application-layer firewalls and web application firewalls can inspect, rate-limit, or block abusive application requests that attempt to exhaust application resources.
References
|
| CIS-13.10 | Perform Application Layer Filtering | mitigates | T1499.004 | Application or System Exploitation |
Comments
Application-layer firewalls and web application firewalls can inspect and block known malicious request patterns or exploit payloads intended to cause application or system resource exhaustion.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1021.004 | SSH |
Comments
Conditional access policies for remote enterprise assets can deny authentication attempts to the SSH service if external SSH access is reachable through a remote-access control plane that can evaluates device posture
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1110 | Brute Force |
Comments
Conditional access policies for remote enterprise assets can deny authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use brute-force activity from non-compliant remote endpoints.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1110.001 | Password Guessing |
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use guessed passwords from non-compliant remote endpoints.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1110.003 | Password Spraying |
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use password spraying from non-compliant remote endpoints.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1110.004 | Credential Stuffing |
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use compromised credential pairs from non-compliant remote endpoints.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1621 | Multi-Factor Authentication Request Generation |
Comments
Conditional access policies can prevent authentication attempts from non-compliant remote devices from proceeding, thereby preventing associated multi-factor authentication requests from being generated.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1078 | Valid Accounts |
Comments
Access control policies for remote enterprise assets can evaluate device compliance before permitting access to enterprise resources. Requiring current anti-malware protection, secure configuration compliance, and current operating system and application versions can prevent valid credentials from being used from remote devices that do not meet enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1078.004 | Cloud Accounts |
Comments
Conditional access policies can evaluate device compliance before permitting cloud-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1078.002 | Domain Accounts |
Comments
Conditional access policies can evaluate device compliance before permitting domain-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1078.003 | Local Accounts |
Comments
Conditional access policies can evaluate device compliance before permitting local-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1133 | External Remote Services |
Comments
Centrally managed authorization systems can restrict access to enterprise remote services based on the security posture of the connecting asset, including anti-malware status, secure-configuration compliance, and operating system or application update status.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1021 | Remote Services |
Comments
Centrally managed remote-access controls can restrict access to enterprise remote services so remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1021.001 | Remote Desktop Protocol |
Comments
Remote Desktop access can be restricted through centrally managed authorization controls so that remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1550 | Use Alternate Authentication Material |
Comments
Conditional access policies can evaluate the context and compliance state of a remote device when alternate authentication material is used, reducing the ability to use authentication material from devices that do not satisfy enterprise security requirements.
References
|
| CIS-13.5 | Manage Access Control for Remote Access | mitigates | T1550.001 | Application Access Token |
Comments
Conditional access policies can evaluate device compliance and expected access context when application access tokens are used, reducing the ability to use valid tokens from non-compliant remote endpoints or outside approved access conditions.
References
|
| CIS-13.9 | Deploy Port-Level Access Control | mitigates | T1200 | Hardware Additions |
Comments
Port-level access control using 802.1X, device certificates, or similar network access control mechanisms can prevent unauthorized hardware from authenticating to and communicating on trusted enterprise networks.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059 | Command and Scripting Interpreter |
Comments
Host-based intrusion prevention capabilities can enforce behavioral controls such as Attack Surface Reduction rules to prevent Visual Basic and JavaScript from executing potentially malicious downloaded content.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059.005 | Visual Basic |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Visual Basic scripts from executing potentially malicious downloaded content.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1059.007 | JavaScript |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent JavaScript scripts from executing potentially malicious downloaded content.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1543 | Create or Modify System Process |
Comments
Host-based intrusion prevention capabilities can block applications from writing signed vulnerable drivers and can enforce vulnerable-driver blocklists to reduce abuse of system processes and services.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1543.003 | Windows Service |
Comments
Host-based intrusion prevention capabilities can block applications from writing signed vulnerable service drivers and can enforce vulnerable-driver blocklists to reduce abuse of Windows services.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1486 | Data Encrypted for Impact |
Comments
Host-based intrusion prevention capabilities can use cloud-delivered protection and behavioral rules to block execution of files that exhibit ransomware-like behavior.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1006 | Direct Volume Access |
Comments
Endpoint security solutions can block behaviors associated with direct volume or backup-related access, including suspicious command execution or API calls targeting backup services.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1546.003 | Windows Management Instrumentation Event Subscription |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent malware from abusing Windows Management Instrumentation to establish persistence.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1564.014 | Extended Attributes |
Comments
Host-based security controls can inspect extended attributes alongside file contents during artifact review, packaging, or deployment to identify hidden payloads, obfuscated data, or suspicious attribute keys.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1574 | Hijack Execution Flow |
Comments
Endpoint security solutions can block behaviors associated with process injection or memory tampering based on common sequences of indicators such as suspicious API usage.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1574.013 | KernelCallbackTable |
Comments
Endpoint security solutions can block behaviors associated with KernelCallbackTable abuse and related memory-tampering activity based on common sequences of indicators and suspicious API usage.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1559 | Inter-Process Communication |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1559.002 | Dynamic Data Exchange |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1036 | Masquerading |
Comments
Host intrusion prevention systems can identify and prevent execution of potentially malicious files, including files whose signatures do not match their apparent file type.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1036.008 | Masquerade File Type |
Comments
Host intrusion prevention systems can identify and prevent execution of files whose signatures do not match their apparent file type.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1106 | Native API |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office VBA macros from calling Win32 APIs.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027 | Obfuscated Files or Information |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.009 | Embedded Payloads |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts containing embedded payloads.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.010 | Command Obfuscation |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block execution of potentially obfuscated scripts or commands.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.012 | LNK Icon Smuggling |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads delivered through LNK-based techniques.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.013 | Encrypted/Encoded File |
Comments
Host-based intrusion prevention capabilities can block execution of potentially obfuscated scripts and analyze file-encoding properties for anomalies that deviate from expected encoding practices.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1027.014 | Polymorphic Code |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated or polymorphic payloads.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137 | Office Application Startup |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.001 | Office Template Macros |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.002 | Office Test |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.003 | Outlook Forms |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.004 | Outlook Home Page |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.005 | Outlook Rules |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1137.006 | Add-ins |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1003 | OS Credential Dumping |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent credential-stealing activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1003.001 | LSASS Memory |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent attempts to steal credentials from LSASS memory.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055 | Process Injection |
Comments
Endpoint security solutions can block process-injection behavior based on common sequences of activity, including suspicious API use and code injection from applications such as Microsoft Office.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.001 | Dynamic-link Library Injection |
Comments
Endpoint security solutions can block dynamic-link library injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.002 | Portable Executable Injection |
Comments
Endpoint security solutions can block portable executable injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.003 | Thread Execution Hijacking |
Comments
Endpoint security solutions can block thread execution hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.004 | Asynchronous Procedure Call |
Comments
Endpoint security solutions can block process injection using asynchronous procedure calls based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.005 | Thread Local Storage |
Comments
Endpoint security solutions can block process injection using thread local storage based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.008 | Ptrace System Calls |
Comments
Endpoint security solutions can block process injection using ptrace system calls based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.009 | Proc Memory |
Comments
Endpoint security solutions can block process injection through proc memory based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.011 | Extra Window Memory Injection |
Comments
Endpoint security solutions can block extra window memory injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.012 | Process Hollowing |
Comments
Endpoint security solutions can block process hollowing based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.013 | Process Doppelgänging |
Comments
Endpoint security solutions can block process doppelgänging based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.014 | VDSO Hijacking |
Comments
Endpoint security solutions can block VDSO hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1055.015 | ListPlanting |
Comments
Endpoint security solutions can block ListPlanting based on common behavioral sequences and suspicious memory-manipulation activity.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1091 | Replication Through Removable Media |
Comments
Host-based intrusion prevention capabilities can block unsigned or untrusted executable files from running from removable media such as USB drives.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1216.001 | PubPrn |
Comments
Host-based intrusion prevention capabilities can enforce application-control policies that block older or vulnerable versions of PubPrn from executing.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1569 | System Services |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1569.002 | Service Execution |
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1204 | User Execution |
Comments
Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running based on prevalence, age, trust, or behavioral criteria and can block Office applications from writing malicious executable content to disk.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1204.002 | Malicious File |
Comments
Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running when they are downloaded or launched by Office applications, scripting interpreters, email clients, or fail prevalence, age, or trust criteria.
References
|
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | mitigates | T1047 | Windows Management Instrumentation |
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that block processes created by Windows Management Instrumentation commands from running.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Network intrusion prevention solutions can identify traffic patterns associated with adversary-in-the-middle activity and block the activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557.001 | Name Resolution Poisoning and SMB Relay |
Comments
Network intrusion prevention solutions can identify traffic patterns associated with name-resolution poisoning and SMB relay activity and block the activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557.002 | ARP Cache Poisoning |
Comments
Network intrusion prevention solutions can identify traffic patterns associated with ARP cache poisoning and block the activity where the relevant network traffic is monitored.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557.003 | DHCP Spoofing |
Comments
Network intrusion prevention solutions can identify traffic patterns associated with DHCP spoofing and block the activity where the relevant network traffic is monitored.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1557.004 | Evil Twin |
Comments
Wireless intrusion prevention capabilities can identify rogue access points and traffic patterns associated with evil-twin activity and block or contain the unauthorized wireless connection.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071 | Application Layer Protocol |
Comments
Network intrusion prevention solutions can use signatures for known malicious application-layer traffic to block adversary command-and-control communications at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.001 | Web Protocols |
Comments
Network intrusion prevention solutions can use signatures for malicious HTTP or HTTPS traffic associated with specific adversary tools to block command-and-control activity at the network boundary.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.002 | File Transfer Protocols |
Comments
Network intrusion prevention solutions can use signatures for malicious file-transfer protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.003 | Mail Protocols |
Comments
Network intrusion prevention solutions can use signatures for malicious mail-protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.004 | DNS |
Comments
Network intrusion prevention solutions can use signatures for malicious DNS traffic associated with specific adversary tools to block command-and-control activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1071.005 | Publish/Subscribe Protocols |
Comments
Network intrusion prevention solutions can use signatures for malicious publish/subscribe protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1132 | Data Encoding |
Comments
Network intrusion prevention solutions can use protocol and malware-specific signatures to identify encoded command-and-control traffic and block matching activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1132.001 | Standard Encoding |
Comments
Network intrusion prevention solutions can use signatures for known protocol indicators and standard encoding patterns used by adversary tools to block matching network activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1132.002 | Non-Standard Encoding |
Comments
Network intrusion prevention solutions can use signatures for known protocol indicators and non-standard encoding patterns used by adversary tools to block matching network activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1602 | Data from Configuration Repository |
Comments
Configure network intrusion prevention solutions to identify and block unauthorized management queries and commands used to access network-device configuration repositories.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Configure network intrusion prevention solutions to identify and block SNMP queries and commands originating from unauthorized sources.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Configure network intrusion prevention solutions to identify and block unauthorized SNMP activity and unexpected Smart Install usage directed at network devices.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1001 | Data Obfuscation |
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block obfuscated command-and-control activity that remains identifiable at the network level.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1001.001 | Junk Data |
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control communications that use junk data for obfuscation.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1001.002 | Steganography |
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block network activity that uses identifiable steganographic methods.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1001.003 | Protocol or Service Impersonation |
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control activity that impersonates legitimate protocols or services.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1030 | Data Transfer Size Limits |
Comments
Network intrusion prevention solutions can use signatures associated with known adversary infrastructure and malware to block command-and-control traffic that varies transfer size to evade controls.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1568 | Dynamic Resolution |
Comments
Network intrusion prevention solutions can use signatures and known indicators associated with dynamically resolved adversary infrastructure to block matching command-and-control traffic.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1568.002 | Domain Generation Algorithms |
Comments
Network intrusion prevention solutions can block traffic to domains or patterns associated with known domain-generation algorithms when those indicators can be identified in advance or during network activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1573 | Encrypted Channel |
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block encrypted command-and-control traffic at monitored boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1573.001 | Symmetric Cryptography |
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with symmetric cryptography.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1573.002 | Asymmetric Cryptography |
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with asymmetric cryptography.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over alternative protocols.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over symmetrically encrypted non-command-and-control protocols.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over asymmetrically encrypted non-command-and-control protocols.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over unencrypted non-command-and-control protocols.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1041 | Exfiltration Over C2 Channel |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable exfiltration occurring over command-and-control channels.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1008 | Fallback Channels |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable fallback command-and-control channels at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1105 | Ingress Tool Transfer |
Comments
Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over protocols such as FTP and block the associated tool-transfer activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1570 | Lateral Tool Transfer |
Comments
Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over common tools and protocols and block lateral tool-transfer activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1104 | Multi-Stage Channels |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic associated with multi-stage command-and-control channels.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1046 | Network Service Discovery |
Comments
Network intrusion prevention solutions can identify and block remote service scanning that crosses monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1095 | Non-Application Layer Protocol |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block malicious use of non-application-layer protocols at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1571 | Non-Standard Port |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block malicious traffic using non-standard ports at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1566 | Phishing |
Comments
Network intrusion prevention solutions and network-based content controls can block malicious email links or attachments before they reach or execute on enterprise assets.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1566.001 | Spearphishing Attachment |
Comments
Network intrusion prevention solutions and network-based content controls can block malicious email attachments before they reach or execute on enterprise assets.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1542.004 | ROMMONkit |
Comments
Network intrusion prevention solutions can use signatures for protocols such as TFTP to block identifiable network activity associated with unauthorized modification of network-device boot components.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1542.005 | TFTP Boot |
Comments
Network intrusion prevention solutions can use signatures for protocols such as TFTP to block unauthorized TFTP traffic associated with network-device boot activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1572 | Protocol Tunneling |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware and tunneling traffic to block identifiable protocol-tunneling activity at monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1090 | Proxy |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable proxy communications used for adversary command and control.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1090.001 | Internal Proxy |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable internal proxy communications used for adversary command and control.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1090.002 | External Proxy |
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable external proxy communications used for adversary command and control.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1219 | Remote Access Tools |
Comments
Network intrusion prevention solutions can use network signatures to block traffic associated with unauthorized remote-access services.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1029 | Scheduled Transfer |
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure and malware to block identifiable scheduled command-and-control or data-transfer activity.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1221 | Template Injection |
Comments
Network intrusion prevention solutions can block network activity that attempts to fetch or execute malicious payloads through externally referenced document templates.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204 | User Execution |
Comments
When user execution depends on visiting a malicious link or retrieving malicious content, network intrusion prevention solutions can block the associated network request or download.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204.001 | Malicious Link |
Comments
Network intrusion prevention solutions can block requests to malicious links and prevent associated content from being downloaded across monitored network boundaries.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204.003 | Malicious Image |
Comments
Network intrusion prevention solutions can block malicious image downloads when the content or associated network activity matches known malicious indicators.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204.004 | Malicious Copy and Paste |
Comments
Network intrusion prevention solutions can block network requests for malicious content used in copy-and-paste execution workflows when the destination or traffic matches known malicious indicators.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1204.005 | Malicious Library |
Comments
Network intrusion prevention solutions can block malicious library downloads when the content or associated network activity matches known malicious indicators.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1102 | Web Service |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable command-and-control traffic using web services.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1102.001 | Dead Drop Resolver |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic to web services used as dead-drop resolvers.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1102.002 | Bidirectional Communication |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable bidirectional command-and-control traffic using web services.
References
|
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | mitigates | T1102.003 | One-Way Communication |
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable one-way command-and-control traffic using web services.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1557 | Adversary-in-the-Middle |
Comments
Filtering unnecessary and legacy network traffic between network segments reduces opportunities for adversaries to establish adversary-in-the-middle conditions.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071 | Application Layer Protocol |
Comments
Use network filtering between segments to permit only required application-layer protocols and authorized communications, limiting adversary use of application protocols for command and control.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.001 | Web Protocols |
Comments
Restrict HTTP and HTTPS traffic crossing network-segment boundaries from critical systems to approved destinations, reducing unauthorized outbound web communications used for command and control or payload transfer.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.002 | File Transfer Protocols |
Comments
Filter FTP and SFTP traffic between network segments so sensitive systems can transfer files only to trusted internal systems or other explicitly approved destinations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.003 | Mail Protocols |
Comments
Restrict SMTP, IMAP, and POP3 traffic between segments so servers and critical systems communicate only with trusted mail infrastructure, reducing unauthorized mail-based command, control, or exfiltration paths.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.004 | DNS |
Comments
Restrict DNS traffic between segments to approved resolvers and filter requests to unknown, untrusted, or known malicious resources, reducing adversary use of DNS for command and control or concealed data transfer.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1071.005 | Publish/Subscribe Protocols |
Comments
Filter publish/subscribe protocol traffic crossing segment boundaries to approved brokers, destinations, and expected ports, reducing use of untrusted resources or irregular ports for command and control.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1602 | Data from Configuration Repository |
Comments
Apply network access-control rules between trusted and untrusted segments to block unauthorized management protocols used to reach configuration repositories and managed network devices.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
Apply network access-control rules to restrict SNMP traffic across segment boundaries to authorized management systems, preventing unauthorized retrieval of Management Information Base data.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
Apply network access-control rules to restrict management protocols used to retrieve network-device configurations to approved management segments and authorized systems.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
Enforce network segmentation, proxies, and dedicated protocol services so only approved systems can communicate over protocols such as DNS, reducing opportunities to exfiltrate data through alternative protocols.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
Enforce proxies or dedicated services and restrict encrypted non-command-and-control protocol traffic between segments to systems with a legitimate requirement to use those protocols.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Enforce proxies or dedicated services and restrict asymmetric encrypted non-command-and-control protocol traffic between segments to approved systems and destinations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
Restrict unencrypted alternative-protocol traffic between network segments and allow those protocols only where required for approved business communications.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Restrict outbound traffic from public-facing or DMZ network segments to approved internal and external destinations, limiting post-exploitation communication from a compromised public-facing server.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1570 | Lateral Tool Transfer |
Comments
Restrict file-sharing communications such as SMB between network segments to systems with a legitimate requirement, reducing adversary opportunities to transfer tools laterally.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1599 | Network Boundary Bridging |
Comments
Use unaffected firewalls or routers to block unauthorized traffic that attempts to bridge established network-segment boundaries and continue monitoring to ensure the filtering remains effective.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1599.001 | Network Address Translation Traversal |
Comments
Use unaffected network filtering devices to block unauthorized traffic attempting to traverse network boundaries through NAT or related boundary-bridging mechanisms.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1095 | Non-Application Layer Protocol |
Comments
Filter traffic at network-segment boundaries to prevent use of non-application-layer protocols that are not required for business operations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1572 | Protocol Tunneling |
Comments
Filter network traffic between segments to untrusted, unauthorized, or known malicious destinations and restrict protocols that can be abused to tunnel communications across network boundaries.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1219 | Remote Access Tools |
Comments
Configure network firewalls and proxies at segment boundaries to restrict outgoing traffic to sites and services associated with unauthorized remote-access software.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1219.002 | Remote Desktop Software |
Comments
Restrict remote-desktop software traffic between network segments to authorized systems, destinations, and management paths using firewalls and proxy controls.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1021.002 | SMB/Windows Admin Shares |
Comments
Restrict SMB and Windows administrative-share communications between network segments to explicitly authorized systems and management paths.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1021.005 | VNC |
Comments
Filter or block VNC traffic across network-segment boundaries, including commonly used VNC ports, except where the communication is explicitly required.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1205 | Traffic Signaling |
Comments
Use stateful filtering at network-segment boundaries to block traffic patterns used by traffic-signaling mechanisms when the signaling implementation can be identified and constrained.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1205.001 | Port Knocking |
Comments
Use stateful filtering at network-segment boundaries to prevent port-knocking sequences from reaching protected systems where the signaling pattern can be constrained.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1205.002 | Socket Filters |
Comments
Use stateful filtering at network-segment boundaries to block crafted traffic used to trigger socket-filter-based communication when the signaling implementation can be identified.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1537 | Transfer Data to Cloud Account |
Comments
Implement network-based filtering restrictions between trusted and untrusted VPCs or equivalent network segments to prohibit unauthorized data transfers to external cloud accounts.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1197 | BITS Jobs |
Comments
Configure network filtering controls so only legitimate BITS traffic is permitted across network boundaries, restricting unauthorized BITS communications used for background transfer or execution activity.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1530 | Data from Cloud Storage |
Comments
Use network-based source restrictions and expected IP ranges when accessing cloud resources so data access is limited to authorized network locations in addition to valid user accounts.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1090 | Proxy |
Comments
Use network allow and block lists to prevent traffic between network segments and known anonymity networks or command-and-control infrastructure that may be used as proxy destinations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1090.003 | Multi-hop Proxy |
Comments
Use network allow and block lists to restrict traffic to known anonymity networks and command-and-control infrastructure that may be chained together as multi-hop proxy destinations.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1218 | System Binary Proxy Execution |
Comments
Use network appliances at segment boundaries to filter ingress and egress traffic and restrict unnecessary protocols or destinations that trusted system binaries could otherwise use for malicious communications.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1218.012 | Verclsid |
Comments
Restrict unnecessary outbound traffic from systems that do not require external communications through Verclsid, using network filtering controls where the relevant traffic crosses a managed segment boundary.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1552 | Unsecured Credentials |
Comments
Restrict network access paths to cloud instance metadata services and use filtering controls to reduce exposure of metadata interfaces that may contain temporary credentials or other authentication material.
References
|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | mitigates | T1552.005 | Cloud Instance Metadata API |
Comments
Restrict network access to the Cloud Instance Metadata API so only workloads with a legitimate requirement can reach the service, reducing adversary access to credentials and metadata through unintended network paths.
References
|
| Capability ID | Capability Name | Number of Mappings |
|---|---|---|
| CIS-13.4 | Perform Traffic Filtering Between Network Segments | 37 |
| CIS-13.10 | Perform Application Layer Filtering | 46 |
| CIS-13.5 | Manage Access Control for Remote Access | 15 |
| CIS-13.8 | Deploy a Network Intrusion Prevention Solution | 59 |
| CIS-13.7 | Deploy a Host-Based Intrusion Prevention Solution | 54 |
| CIS-13.9 | Deploy Port-Level Access Control | 1 |