CIS Controls Network Monitoring and Defense Capability Group

Operate processes and tooling to establish and maintain comprehensive network monitoring and defense against security threats across the enterprise’s network infrastructure and user base.

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1547.006 Kernel Modules and Extensions
Comments
Adversaries load malicious kernel modules or extensions for persistence or privilege escalation. Host-based security solutions can monitor module loading, detect known rootkits or unauthorized kernel modifications, and block or alert on suspicious kernel-extension activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.006 Python
Comments
Adversaries use Python interpreters and scripts to execute malicious commands and payloads. EDR/HIPS can monitor anomalous Python execution, unusual parent-child relationships, network activity, and other suspicious behaviors, and can block or quarantine malicious payloads.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.001 PowerShell
Comments
Adversaries use PowerShell to execute commands, scripts, and payloads. EDR/HIPS can monitor PowerShell process behavior, command lines, script activity, child processes, and suspicious follow-on actions, and can block or quarantine malicious activity
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1187 Forced Authentication
Comments
Adversaries coerce systems into authenticating to attacker-controlled SMB or WebDAV resources in order to capture credential material. This control requires traffic filtering between network segments, which can block or tightly restrict SMB and WebDAV communications to untrusted or unauthorized destinations, directly preventing the outbound authentication path required by the technique.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1659 Content Injection
Comments
Application-layer filtering can block uncommon, unauthorized, or malicious content and transferred file types at web proxies, application gateways, or similar inspection points before the content reaches protected systems.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1555.003 Credentials from Web Browsers
Comments
Web filtering and application-layer gateways can block malicious web content and destinations used to deliver browser-based credential theft or session-stealing content.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1189 Drive-by Compromise
Comments
Web proxies and application-layer gateways can prevent access to known malicious or unnecessary websites and block malicious web content used to compromise users through drive-by activity.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1568 Dynamic Resolution
Comments
DNS filtering and sinkholing can prevent systems from resolving domains associated with dynamically changing adversary command-and-control infrastructure.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1568.002 Domain Generation Algorithms
Comments
DNS filtering and sinkholing can block domains generated by known domain-generation algorithms when those domains or generation patterns can be identified.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1567 Exfiltration Over Web Service
Comments
Web proxies and application-layer gateways can restrict which external web services are permitted, reducing unauthorized use of web services for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1567.001 Exfiltration to Code Repository
Comments
Application-layer filtering can block or restrict access to unauthorized external code repositories, limiting their use as destinations for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1567.002 Exfiltration to Cloud Storage
Comments
Application-layer filtering can block or restrict access to unauthorized cloud-storage services, limiting their use as destinations for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1567.003 Exfiltration to Text Storage Sites
Comments
Application-layer filtering can block or restrict access to unauthorized text-storage and paste services, limiting their use as destinations for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1133 External Remote Services
Comments
Application-layer firewalls and proxies can restrict access to unauthorized remote-access services, anonymization services, and other external services used to access enterprise resources.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1566 Phishing
Comments
Application-layer filtering can block malicious websites, links, attachments, and other web or email content used in phishing activity before that content reaches users.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1566.001 Spearphishing Attachment
Comments
Mail and application-layer gateways can inspect and block dangerous attachment types, malicious archives, and other suspicious content delivered through spearphishing attachments.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1566.002 Spearphishing Link
Comments
Web proxies and application-layer gateways can block access to malicious or unnecessary websites reached through spearphishing links.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1566.003 Spearphishing via Service
Comments
Application-layer filtering can restrict access to personal webmail, social media, and other external services that may be abused to deliver spearphishing messages.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1539 Steal Web Session Cookie
Comments
Web filtering and application-layer gateways can block malicious content or destinations used to deliver browser-based session-cookie theft activity.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1218 System Binary Proxy Execution
Comments
Application-layer filtering can restrict malicious sites, downloads, attachments, and scripts that may deliver payloads later executed through trusted system binaries.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1218.001 Compiled HTML File
Comments
Application-layer filtering can block CHM and other uncommon or risky file types in transit, reducing delivery of content that may be executed through Compiled HTML Help.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1204 User Execution
Comments
Application-layer filtering can prevent malicious web or email content from reaching users, reducing opportunities for users to execute or interact with adversary-delivered content.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1204.001 Malicious Link
Comments
Web proxies and application-layer gateways can block requests to malicious links and prevent associated content from being downloaded.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1204.004 Malicious Copy and Paste
Comments
Application-layer filtering can block malicious web content or destinations used to provide commands, scripts, or other content that users are instructed to copy and execute.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1102 Web Service
Comments
Web proxies and application-layer gateways can restrict access to unauthorized external web services, limiting their use for adversary command and control.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1102.001 Dead Drop Resolver
Comments
Application-layer filtering can block access to unauthorized web services used as dead-drop resolvers for adversary command-and-control infrastructure.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1102.002 Bidirectional Communication
Comments
Application-layer filtering can block unauthorized web services used for bidirectional command-and-control communications.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1102.003 One-Way Communication
Comments
Application-layer filtering can block unauthorized web services used for one-way command-and-control communications.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071 Application Layer Protocol
Comments
Application-aware gateways can inspect and restrict unauthorized application-layer protocols, services, and destinations used for adversary command and control.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.001 Web Protocols
Comments
Web proxies and application-layer firewalls can inspect and restrict HTTP and HTTPS traffic to unauthorized or malicious destinations.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.002 File Transfer Protocols
Comments
Application-layer filtering can restrict FTP, SFTP, and related file-transfer protocol traffic to approved services and destinations.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.003 Mail Protocols
Comments
Application-layer filtering can restrict SMTP, IMAP, POP3, and related mail-protocol traffic to approved infrastructure and expected communication paths.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.004 DNS
Comments
DNS proxies and filtering services can block malicious domains and restrict systems to approved name-resolution services.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1071.005 Publish/Subscribe Protocols
Comments
Application-aware filtering can restrict publish/subscribe protocols to approved brokers, destinations, and expected service ports.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Application proxies and gateways can require use of approved protocol services and restrict unauthorized application-layer protocols or destinations used for data exfiltration.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Comments
Application-layer gateways can restrict symmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Comments
Application-layer gateways can restrict asymmetrically encrypted non-command-and-control protocol traffic to approved services and destinations where the traffic remains identifiable to the control.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Comments
Application-layer filtering can directly restrict unencrypted non-command-and-control protocols to approved services and destinations.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1190 Exploit Public-Facing Application
Comments
Web application firewalls and application-layer gateways can inspect inbound application requests and block known malicious request patterns or exploit payloads targeting public-facing applications.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1187 Forced Authentication
Comments
Application and protocol filtering can block outbound WebDAV and related requests that may be abused to force systems to authenticate to attacker-controlled resources.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1105 Ingress Tool Transfer
Comments
Web proxies and application-layer gateways can block unauthorized downloads, file-transfer services, and malicious content used to transfer adversary tools into the environment.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1572 Protocol Tunneling
Comments
Application-aware filtering can identify and restrict unauthorized tunneling through otherwise permitted application protocols and services.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1090 Proxy
Comments
Application-layer gateways can block known anonymization services, unauthorized proxy services, and other proxy destinations used to conceal adversary communications.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1090.003 Multi-hop Proxy
Comments
Application-layer gateways can restrict known anonymization and proxy services that may be chained together to form multi-hop proxy infrastructure.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1219 Remote Access Tools
Comments
Application firewalls and proxies can restrict access to websites, services, and destinations associated with unauthorized remote-access tools.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1219.002 Remote Desktop Software
Comments
Application-layer firewalls and proxies can restrict access to unauthorized remote-desktop services and destinations.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1552 Unsecured Credentials
Comments
Web application firewalls and application-layer controls can block server-side request forgery paths that would otherwise expose credential-bearing cloud metadata services.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1552.005 Cloud Instance Metadata API
Comments
A properly configured web application firewall can block external server-side request forgery attempts that target the cloud instance metadata API and expose temporary credentials.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1499.003 Application Exhaustion Flood
Comments
Application-layer firewalls and web application firewalls can inspect, rate-limit, or block abusive application requests that attempt to exhaust application resources.
References
CIS-13.10 Perform Application Layer Filtering mitigates T1499.004 Application or System Exploitation
Comments
Application-layer firewalls and web application firewalls can inspect and block known malicious request patterns or exploit payloads intended to cause application or system resource exhaustion.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1021.004 SSH
Comments
Conditional access policies for remote enterprise assets can deny authentication attempts to the SSH service if external SSH access is reachable through a remote-access control plane that can evaluates device posture
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1110 Brute Force
Comments
Conditional access policies for remote enterprise assets can deny authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use brute-force activity from non-compliant remote endpoints.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1110.001 Password Guessing
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use guessed passwords from non-compliant remote endpoints.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1110.003 Password Spraying
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use password spraying from non-compliant remote endpoints.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1110.004 Credential Stuffing
Comments
Conditional access policies can deny remote authentication attempts from devices that do not satisfy enterprise security requirements, reducing the ability to use compromised credential pairs from non-compliant remote endpoints.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1621 Multi-Factor Authentication Request Generation
Comments
Conditional access policies can prevent authentication attempts from non-compliant remote devices from proceeding, thereby preventing associated multi-factor authentication requests from being generated.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1078 Valid Accounts
Comments
Access control policies for remote enterprise assets can evaluate device compliance before permitting access to enterprise resources. Requiring current anti-malware protection, secure configuration compliance, and current operating system and application versions can prevent valid credentials from being used from remote devices that do not meet enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1078.004 Cloud Accounts
Comments
Conditional access policies can evaluate device compliance before permitting cloud-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1078.002 Domain Accounts
Comments
Conditional access policies can evaluate device compliance before permitting domain-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1078.003 Local Accounts
Comments
Conditional access policies can evaluate device compliance before permitting local-account access, preventing valid cloud credentials from being used from remote devices that do not satisfy enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1133 External Remote Services
Comments
Centrally managed authorization systems can restrict access to enterprise remote services based on the security posture of the connecting asset, including anti-malware status, secure-configuration compliance, and operating system or application update status.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1021 Remote Services
Comments
Centrally managed remote-access controls can restrict access to enterprise remote services so remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1021.001 Remote Desktop Protocol
Comments
Remote Desktop access can be restricted through centrally managed authorization controls so that remote assets are permitted access only when they satisfy enterprise device-security and configuration requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1550 Use Alternate Authentication Material
Comments
Conditional access policies can evaluate the context and compliance state of a remote device when alternate authentication material is used, reducing the ability to use authentication material from devices that do not satisfy enterprise security requirements.
References
CIS-13.5 Manage Access Control for Remote Access mitigates T1550.001 Application Access Token
Comments
Conditional access policies can evaluate device compliance and expected access context when application access tokens are used, reducing the ability to use valid tokens from non-compliant remote endpoints or outside approved access conditions.
References
CIS-13.9 Deploy Port-Level Access Control mitigates T1200 Hardware Additions
Comments
Port-level access control using 802.1X, device certificates, or similar network access control mechanisms can prevent unauthorized hardware from authenticating to and communicating on trusted enterprise networks.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059 Command and Scripting Interpreter
Comments
Host-based intrusion prevention capabilities can enforce behavioral controls such as Attack Surface Reduction rules to prevent Visual Basic and JavaScript from executing potentially malicious downloaded content.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.005 Visual Basic
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Visual Basic scripts from executing potentially malicious downloaded content.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1059.007 JavaScript
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent JavaScript scripts from executing potentially malicious downloaded content.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1543 Create or Modify System Process
Comments
Host-based intrusion prevention capabilities can block applications from writing signed vulnerable drivers and can enforce vulnerable-driver blocklists to reduce abuse of system processes and services.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1543.003 Windows Service
Comments
Host-based intrusion prevention capabilities can block applications from writing signed vulnerable service drivers and can enforce vulnerable-driver blocklists to reduce abuse of Windows services.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1486 Data Encrypted for Impact
Comments
Host-based intrusion prevention capabilities can use cloud-delivered protection and behavioral rules to block execution of files that exhibit ransomware-like behavior.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1006 Direct Volume Access
Comments
Endpoint security solutions can block behaviors associated with direct volume or backup-related access, including suspicious command execution or API calls targeting backup services.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1546.003 Windows Management Instrumentation Event Subscription
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent malware from abusing Windows Management Instrumentation to establish persistence.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1564.014 Extended Attributes
Comments
Host-based security controls can inspect extended attributes alongside file contents during artifact review, packaging, or deployment to identify hidden payloads, obfuscated data, or suspicious attribute keys.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1574 Hijack Execution Flow
Comments
Endpoint security solutions can block behaviors associated with process injection or memory tampering based on common sequences of indicators such as suspicious API usage.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1574.013 KernelCallbackTable
Comments
Endpoint security solutions can block behaviors associated with KernelCallbackTable abuse and related memory-tampering activity based on common sequences of indicators and suspicious API usage.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1559 Inter-Process Communication
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1559.002 Dynamic Data Exchange
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules to prevent Dynamic Data Exchange attacks and block Office applications from spawning suspicious child processes.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1036 Masquerading
Comments
Host intrusion prevention systems can identify and prevent execution of potentially malicious files, including files whose signatures do not match their apparent file type.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1036.008 Masquerade File Type
Comments
Host intrusion prevention systems can identify and prevent execution of files whose signatures do not match their apparent file type.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1106 Native API
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office VBA macros from calling Win32 APIs.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027 Obfuscated Files or Information
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.009 Embedded Payloads
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts containing embedded payloads.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.010 Command Obfuscation
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block execution of potentially obfuscated scripts or commands.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.012 LNK Icon Smuggling
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated scripts or payloads delivered through LNK-based techniques.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.013 Encrypted/Encoded File
Comments
Host-based intrusion prevention capabilities can block execution of potentially obfuscated scripts and analyze file-encoding properties for anomalies that deviate from expected encoding practices.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1027.014 Polymorphic Code
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that prevent execution of potentially obfuscated or polymorphic payloads.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137 Office Application Startup
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.001 Office Template Macros
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.002 Office Test
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.003 Outlook Forms
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.004 Outlook Home Page
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.005 Outlook Rules
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1137.006 Add-ins
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that prevent Office applications from creating child processes or writing potentially malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1003 OS Credential Dumping
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent credential-stealing activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1003.001 LSASS Memory
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that secure LSASS and prevent attempts to steal credentials from LSASS memory.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055 Process Injection
Comments
Endpoint security solutions can block process-injection behavior based on common sequences of activity, including suspicious API use and code injection from applications such as Microsoft Office.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.001 Dynamic-link Library Injection
Comments
Endpoint security solutions can block dynamic-link library injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.002 Portable Executable Injection
Comments
Endpoint security solutions can block portable executable injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.003 Thread Execution Hijacking
Comments
Endpoint security solutions can block thread execution hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.004 Asynchronous Procedure Call
Comments
Endpoint security solutions can block process injection using asynchronous procedure calls based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.005 Thread Local Storage
Comments
Endpoint security solutions can block process injection using thread local storage based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.008 Ptrace System Calls
Comments
Endpoint security solutions can block process injection using ptrace system calls based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.009 Proc Memory
Comments
Endpoint security solutions can block process injection through proc memory based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.011 Extra Window Memory Injection
Comments
Endpoint security solutions can block extra window memory injection based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.012 Process Hollowing
Comments
Endpoint security solutions can block process hollowing based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.013 Process Doppelgänging
Comments
Endpoint security solutions can block process doppelgänging based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.014 VDSO Hijacking
Comments
Endpoint security solutions can block VDSO hijacking based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1055.015 ListPlanting
Comments
Endpoint security solutions can block ListPlanting based on common behavioral sequences and suspicious memory-manipulation activity.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1091 Replication Through Removable Media
Comments
Host-based intrusion prevention capabilities can block unsigned or untrusted executable files from running from removable media such as USB drives.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1216.001 PubPrn
Comments
Host-based intrusion prevention capabilities can enforce application-control policies that block older or vulnerable versions of PubPrn from executing.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1569 System Services
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1569.002 Service Execution
Comments
Host-based intrusion prevention capabilities can enforce behavioral rules that block processes created by PsExec from running.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1204 User Execution
Comments
Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running based on prevalence, age, trust, or behavioral criteria and can block Office applications from writing malicious executable content to disk.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1204.002 Malicious File
Comments
Host-based intrusion prevention capabilities can prevent potentially malicious executable files from running when they are downloaded or launched by Office applications, scripting interpreters, email clients, or fail prevalence, age, or trust criteria.
References
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution mitigates T1047 Windows Management Instrumentation
Comments
Host-based intrusion prevention capabilities can enforce Attack Surface Reduction rules that block processes created by Windows Management Instrumentation commands from running.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557 Adversary-in-the-Middle
Comments
Network intrusion prevention solutions can identify traffic patterns associated with adversary-in-the-middle activity and block the activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.001 Name Resolution Poisoning and SMB Relay
Comments
Network intrusion prevention solutions can identify traffic patterns associated with name-resolution poisoning and SMB relay activity and block the activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.002 ARP Cache Poisoning
Comments
Network intrusion prevention solutions can identify traffic patterns associated with ARP cache poisoning and block the activity where the relevant network traffic is monitored.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.003 DHCP Spoofing
Comments
Network intrusion prevention solutions can identify traffic patterns associated with DHCP spoofing and block the activity where the relevant network traffic is monitored.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1557.004 Evil Twin
Comments
Wireless intrusion prevention capabilities can identify rogue access points and traffic patterns associated with evil-twin activity and block or contain the unauthorized wireless connection.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071 Application Layer Protocol
Comments
Network intrusion prevention solutions can use signatures for known malicious application-layer traffic to block adversary command-and-control communications at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.001 Web Protocols
Comments
Network intrusion prevention solutions can use signatures for malicious HTTP or HTTPS traffic associated with specific adversary tools to block command-and-control activity at the network boundary.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.002 File Transfer Protocols
Comments
Network intrusion prevention solutions can use signatures for malicious file-transfer protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.003 Mail Protocols
Comments
Network intrusion prevention solutions can use signatures for malicious mail-protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.004 DNS
Comments
Network intrusion prevention solutions can use signatures for malicious DNS traffic associated with specific adversary tools to block command-and-control activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1071.005 Publish/Subscribe Protocols
Comments
Network intrusion prevention solutions can use signatures for malicious publish/subscribe protocol traffic associated with specific adversary tools to block activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1132 Data Encoding
Comments
Network intrusion prevention solutions can use protocol and malware-specific signatures to identify encoded command-and-control traffic and block matching activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1132.001 Standard Encoding
Comments
Network intrusion prevention solutions can use signatures for known protocol indicators and standard encoding patterns used by adversary tools to block matching network activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1132.002 Non-Standard Encoding
Comments
Network intrusion prevention solutions can use signatures for known protocol indicators and non-standard encoding patterns used by adversary tools to block matching network activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1602 Data from Configuration Repository
Comments
Configure network intrusion prevention solutions to identify and block unauthorized management queries and commands used to access network-device configuration repositories.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1602.001 SNMP (MIB Dump)
Comments
Configure network intrusion prevention solutions to identify and block SNMP queries and commands originating from unauthorized sources.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1602.002 Network Device Configuration Dump
Comments
Configure network intrusion prevention solutions to identify and block unauthorized SNMP activity and unexpected Smart Install usage directed at network devices.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001 Data Obfuscation
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block obfuscated command-and-control activity that remains identifiable at the network level.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001.001 Junk Data
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control communications that use junk data for obfuscation.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001.002 Steganography
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block network activity that uses identifiable steganographic methods.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1001.003 Protocol or Service Impersonation
Comments
Network intrusion prevention solutions can use signatures for known adversary traffic patterns to block command-and-control activity that impersonates legitimate protocols or services.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1030 Data Transfer Size Limits
Comments
Network intrusion prevention solutions can use signatures associated with known adversary infrastructure and malware to block command-and-control traffic that varies transfer size to evade controls.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1568 Dynamic Resolution
Comments
Network intrusion prevention solutions can use signatures and known indicators associated with dynamically resolved adversary infrastructure to block matching command-and-control traffic.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1568.002 Domain Generation Algorithms
Comments
Network intrusion prevention solutions can block traffic to domains or patterns associated with known domain-generation algorithms when those indicators can be identified in advance or during network activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1573 Encrypted Channel
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block encrypted command-and-control traffic at monitored boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1573.001 Symmetric Cryptography
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with symmetric cryptography.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1573.002 Asymmetric Cryptography
Comments
Network intrusion prevention solutions can use observable network signatures associated with known adversary malware to block command-and-control traffic protected with asymmetric cryptography.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over alternative protocols.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over symmetrically encrypted non-command-and-control protocols.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over asymmetrically encrypted non-command-and-control protocols.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure, malware, and unusual protocol activity to block exfiltration over unencrypted non-command-and-control protocols.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1041 Exfiltration Over C2 Channel
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable exfiltration occurring over command-and-control channels.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1008 Fallback Channels
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable fallback command-and-control channels at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1105 Ingress Tool Transfer
Comments
Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over protocols such as FTP and block the associated tool-transfer activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1570 Lateral Tool Transfer
Comments
Network intrusion prevention solutions can identify known malicious transfer patterns or unusual transfers over common tools and protocols and block lateral tool-transfer activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1104 Multi-Stage Channels
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic associated with multi-stage command-and-control channels.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1046 Network Service Discovery
Comments
Network intrusion prevention solutions can identify and block remote service scanning that crosses monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1095 Non-Application Layer Protocol
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block malicious use of non-application-layer protocols at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1571 Non-Standard Port
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block malicious traffic using non-standard ports at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1566 Phishing
Comments
Network intrusion prevention solutions and network-based content controls can block malicious email links or attachments before they reach or execute on enterprise assets.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1566.001 Spearphishing Attachment
Comments
Network intrusion prevention solutions and network-based content controls can block malicious email attachments before they reach or execute on enterprise assets.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1542.004 ROMMONkit
Comments
Network intrusion prevention solutions can use signatures for protocols such as TFTP to block identifiable network activity associated with unauthorized modification of network-device boot components.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1542.005 TFTP Boot
Comments
Network intrusion prevention solutions can use signatures for protocols such as TFTP to block unauthorized TFTP traffic associated with network-device boot activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1572 Protocol Tunneling
Comments
Network intrusion prevention solutions can use signatures for known adversary malware and tunneling traffic to block identifiable protocol-tunneling activity at monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1090 Proxy
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable proxy communications used for adversary command and control.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1090.001 Internal Proxy
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable internal proxy communications used for adversary command and control.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1090.002 External Proxy
Comments
Network intrusion prevention solutions can use malware- and protocol-specific signatures to block identifiable external proxy communications used for adversary command and control.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1219 Remote Access Tools
Comments
Network intrusion prevention solutions can use network signatures to block traffic associated with unauthorized remote-access services.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1029 Scheduled Transfer
Comments
Network intrusion prevention solutions can use signatures for known adversary infrastructure and malware to block identifiable scheduled command-and-control or data-transfer activity.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1221 Template Injection
Comments
Network intrusion prevention solutions can block network activity that attempts to fetch or execute malicious payloads through externally referenced document templates.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204 User Execution
Comments
When user execution depends on visiting a malicious link or retrieving malicious content, network intrusion prevention solutions can block the associated network request or download.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.001 Malicious Link
Comments
Network intrusion prevention solutions can block requests to malicious links and prevent associated content from being downloaded across monitored network boundaries.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.003 Malicious Image
Comments
Network intrusion prevention solutions can block malicious image downloads when the content or associated network activity matches known malicious indicators.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.004 Malicious Copy and Paste
Comments
Network intrusion prevention solutions can block network requests for malicious content used in copy-and-paste execution workflows when the destination or traffic matches known malicious indicators.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1204.005 Malicious Library
Comments
Network intrusion prevention solutions can block malicious library downloads when the content or associated network activity matches known malicious indicators.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102 Web Service
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable command-and-control traffic using web services.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.001 Dead Drop Resolver
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable traffic to web services used as dead-drop resolvers.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.002 Bidirectional Communication
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable bidirectional command-and-control traffic using web services.
References
CIS-13.8 Deploy a Network Intrusion Prevention Solution mitigates T1102.003 One-Way Communication
Comments
Network intrusion prevention solutions can use signatures for known adversary malware to block identifiable one-way command-and-control traffic using web services.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1557 Adversary-in-the-Middle
Comments
Filtering unnecessary and legacy network traffic between network segments reduces opportunities for adversaries to establish adversary-in-the-middle conditions.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071 Application Layer Protocol
Comments
Use network filtering between segments to permit only required application-layer protocols and authorized communications, limiting adversary use of application protocols for command and control.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.001 Web Protocols
Comments
Restrict HTTP and HTTPS traffic crossing network-segment boundaries from critical systems to approved destinations, reducing unauthorized outbound web communications used for command and control or payload transfer.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.002 File Transfer Protocols
Comments
Filter FTP and SFTP traffic between network segments so sensitive systems can transfer files only to trusted internal systems or other explicitly approved destinations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.003 Mail Protocols
Comments
Restrict SMTP, IMAP, and POP3 traffic between segments so servers and critical systems communicate only with trusted mail infrastructure, reducing unauthorized mail-based command, control, or exfiltration paths.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.004 DNS
Comments
Restrict DNS traffic between segments to approved resolvers and filter requests to unknown, untrusted, or known malicious resources, reducing adversary use of DNS for command and control or concealed data transfer.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1071.005 Publish/Subscribe Protocols
Comments
Filter publish/subscribe protocol traffic crossing segment boundaries to approved brokers, destinations, and expected ports, reducing use of untrusted resources or irregular ports for command and control.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1602 Data from Configuration Repository
Comments
Apply network access-control rules between trusted and untrusted segments to block unauthorized management protocols used to reach configuration repositories and managed network devices.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1602.001 SNMP (MIB Dump)
Comments
Apply network access-control rules to restrict SNMP traffic across segment boundaries to authorized management systems, preventing unauthorized retrieval of Management Information Base data.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1602.002 Network Device Configuration Dump
Comments
Apply network access-control rules to restrict management protocols used to retrieve network-device configurations to approved management segments and authorized systems.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048 Exfiltration Over Alternative Protocol
Comments
Enforce network segmentation, proxies, and dedicated protocol services so only approved systems can communicate over protocols such as DNS, reducing opportunities to exfiltrate data through alternative protocols.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Comments
Enforce proxies or dedicated services and restrict encrypted non-command-and-control protocol traffic between segments to systems with a legitimate requirement to use those protocols.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Comments
Enforce proxies or dedicated services and restrict asymmetric encrypted non-command-and-control protocol traffic between segments to approved systems and destinations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
Comments
Restrict unencrypted alternative-protocol traffic between network segments and allow those protocols only where required for approved business communications.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1190 Exploit Public-Facing Application
Comments
Restrict outbound traffic from public-facing or DMZ network segments to approved internal and external destinations, limiting post-exploitation communication from a compromised public-facing server.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1570 Lateral Tool Transfer
Comments
Restrict file-sharing communications such as SMB between network segments to systems with a legitimate requirement, reducing adversary opportunities to transfer tools laterally.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1599 Network Boundary Bridging
Comments
Use unaffected firewalls or routers to block unauthorized traffic that attempts to bridge established network-segment boundaries and continue monitoring to ensure the filtering remains effective.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1599.001 Network Address Translation Traversal
Comments
Use unaffected network filtering devices to block unauthorized traffic attempting to traverse network boundaries through NAT or related boundary-bridging mechanisms.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1095 Non-Application Layer Protocol
Comments
Filter traffic at network-segment boundaries to prevent use of non-application-layer protocols that are not required for business operations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1572 Protocol Tunneling
Comments
Filter network traffic between segments to untrusted, unauthorized, or known malicious destinations and restrict protocols that can be abused to tunnel communications across network boundaries.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1219 Remote Access Tools
Comments
Configure network firewalls and proxies at segment boundaries to restrict outgoing traffic to sites and services associated with unauthorized remote-access software.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1219.002 Remote Desktop Software
Comments
Restrict remote-desktop software traffic between network segments to authorized systems, destinations, and management paths using firewalls and proxy controls.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1021.002 SMB/Windows Admin Shares
Comments
Restrict SMB and Windows administrative-share communications between network segments to explicitly authorized systems and management paths.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1021.005 VNC
Comments
Filter or block VNC traffic across network-segment boundaries, including commonly used VNC ports, except where the communication is explicitly required.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1205 Traffic Signaling
Comments
Use stateful filtering at network-segment boundaries to block traffic patterns used by traffic-signaling mechanisms when the signaling implementation can be identified and constrained.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1205.001 Port Knocking
Comments
Use stateful filtering at network-segment boundaries to prevent port-knocking sequences from reaching protected systems where the signaling pattern can be constrained.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1205.002 Socket Filters
Comments
Use stateful filtering at network-segment boundaries to block crafted traffic used to trigger socket-filter-based communication when the signaling implementation can be identified.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1537 Transfer Data to Cloud Account
Comments
Implement network-based filtering restrictions between trusted and untrusted VPCs or equivalent network segments to prohibit unauthorized data transfers to external cloud accounts.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1197 BITS Jobs
Comments
Configure network filtering controls so only legitimate BITS traffic is permitted across network boundaries, restricting unauthorized BITS communications used for background transfer or execution activity.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1530 Data from Cloud Storage
Comments
Use network-based source restrictions and expected IP ranges when accessing cloud resources so data access is limited to authorized network locations in addition to valid user accounts.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1090 Proxy
Comments
Use network allow and block lists to prevent traffic between network segments and known anonymity networks or command-and-control infrastructure that may be used as proxy destinations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1090.003 Multi-hop Proxy
Comments
Use network allow and block lists to restrict traffic to known anonymity networks and command-and-control infrastructure that may be chained together as multi-hop proxy destinations.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1218 System Binary Proxy Execution
Comments
Use network appliances at segment boundaries to filter ingress and egress traffic and restrict unnecessary protocols or destinations that trusted system binaries could otherwise use for malicious communications.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1218.012 Verclsid
Comments
Restrict unnecessary outbound traffic from systems that do not require external communications through Verclsid, using network filtering controls where the relevant traffic crosses a managed segment boundary.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1552 Unsecured Credentials
Comments
Restrict network access paths to cloud instance metadata services and use filtering controls to reduce exposure of metadata interfaces that may contain temporary credentials or other authentication material.
References
CIS-13.4 Perform Traffic Filtering Between Network Segments mitigates T1552.005 Cloud Instance Metadata API
Comments
Restrict network access to the Cloud Instance Metadata API so only workloads with a legitimate requirement can reach the service, reducing adversary access to credentials and metadata through unintended network paths.
References

Capabilities

Capability ID Capability Name Number of Mappings
CIS-13.4 Perform Traffic Filtering Between Network Segments 37
CIS-13.10 Perform Application Layer Filtering 46
CIS-13.5 Manage Access Control for Remote Access 15
CIS-13.8 Deploy a Network Intrusion Prevention Solution 59
CIS-13.7 Deploy a Host-Based Intrusion Prevention Solution 54
CIS-13.9 Deploy Port-Level Access Control 1