CIS Controls Inventory and Control of Software Assets Capability Group

Actively manage (inventory, track, and correct) all software (operating systems and applications) on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-2.5 Allowlist Authorized Software mitigates T1059.011 Lua
Comments
Adversaries use Lua interpreters to execute Lua code. An application-control policy denying unauthorized Lua interpreters prevents those binaries from running, directly restricting Lua execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1059.006 Python
Comments
Adversaries use Python interpreters to execute malicious commands and payloads. An enforced allowlist denying Python prevents the interpreter from executing, directly removing the prerequisite for Python-based execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1176 Software Extensions
Comments
Adversaries install or use malicious browser or IDE extensions to obtain execution or persistence. The implementation to explicitly allowlists authorized extensions and blocks all others, unauthorized extensions cannot be installed or loaded, directly constraining the technique.
References
CIS-2.5 Allowlist Authorized Software mitigates T1564.003 Hidden Window
Comments
Adversaries may hide application windows while malicious programs execute. Where an unauthorized program is responsible for the hidden-window behavior, application allowlisting prevents that program from running and therefore prevents that implementation of the technique.
References
CIS-2.5 Allowlist Authorized Software mitigates T1548.004 Elevated Execution with Prompt
Comments
Adversaries may persuade users to approve elevated execution of malicious applications. If application control prevents the unapproved application from executing regardless of user approval, the malicious program cannot reach the elevation stage through this path.
References
CIS-2.5 Allowlist Authorized Software mitigates T1546.002 Screensaver
Comments
Adversaries can establish execution or persistence using malicious .scr screensaver files. Application-control rules can prevent unauthorized .scr files from executing, directly blocking the malicious executable used by the technique
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.014 MMC
Comments
Adversaries can abuse Microsoft Management Console to execute malicious content through a trusted system binary. Application allowlisting can block MMC on systems where its use is not authorized, directly preventing the executable from being used for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.013 Mavinject
Comments
Adversaries abuse mavinject.exe to inject malicious code into another process through a trusted Microsoft executable. Application allowlisting can deny execution of mavinject.exe where it is not authorized, directly preventing use of that binary for the technique.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.012 Verclsid
Comments
Adversaries abuse verclsid.exe to execute malicious COM objects through a trusted Windows binary. Application allowlisting can block verclsid.exe where it is unnecessary, directly preventing its use as the proxy executable.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.009 Regsvcs/Regasm
Comments
Adversaries use Regsvcs.exe or Regasm.exe to proxy execution of malicious .NET code. Application allowlisting can prevent these binaries from executing on systems where they are not authorized, directly preventing this execution path.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.008 Odbcconf
Comments
Adversaries abuse odbcconf.exe to execute malicious code through a trusted Windows utility. Application allowlisting can deny execution of odbcconf.exe where it is not required, directly preventing use of that proxy-execution mechanism.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.005 Mshta
Comments
Adversaries abuse mshta.exe to execute HTML application or script content through a trusted Windows binary. Application allowlisting can explicitly deny mshta.exe, preventing the executable from being used for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.004 InstallUtil
Comments
Adversaries use InstallUtil.exe to execute malicious .NET code while proxying execution through a trusted binary. Application allowlisting can block InstallUtil where it is not authorized, directly preventing use of the utility for this behavior.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.003 CMSTP
Comments
Adversaries abuse cmstp.exe to proxy execution of malicious code through a trusted Windows utility. Application allowlisting can prevent cmstp.exe from executing on systems where it is not required, directly removing the proxy-execution mechanism.
References
CIS-2.5 Allowlist Authorized Software mitigates T1218.001 Compiled HTML File
Comments
Adversaries abuse hh.exe to execute malicious compiled HTML content through a trusted Windows binary. Application allowlisting can block hh.exe where it is not authorized, preventing use of that binary for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1127.001 MSBuild
Comments
Adversaries abuse msbuild.exe to execute malicious code through a trusted Microsoft developer utility. Application allowlisting can deny execution of MSBuild on systems where it is not authorized, directly eliminating the binary used for proxy execution.
References
CIS-2.5 Allowlist Authorized Software mitigates T1059.010 AutoHotKey & AutoIT
Comments
Adversaries use AutoHotKey and AutoIT interpreters to execute automated commands and malicious scripts. Application allowlisting can block AutoHotkey.exe, AutoIt3.exe, and related unauthorized executables, directly preventing those interpreters from executing.
References
CIS-2.3 Address Unauthorized Software mitigates T1127.001 MSBuild
Comments
Adversaries abuse MSBuild to execute malicious code through a trusted developer utility. When MSBuild is unnecessary, explicitly classified as unauthorized, and removed under this safeguard, the executable required for this proxy-execution technique is eliminated.
References
CIS-2.3 Address Unauthorized Software mitigates T1059.011 Lua
Comments
Adversaries can use a Lua interpreter to execute malicious Lua commands or scripts. When Lua is unauthorized on the asset and is removed through this safeguard, the interpreter required to execute Lua code is no longer available, directly restricting the technique.
References
CIS-2.3 Address Unauthorized Software mitigates T1059.006 Python
Comments
Adversaries use installed Python interpreters to execute commands, scripts, and payloads. When Python is classified as unauthorized and removed under this safeguard, the local interpreter required for Python-based execution is eliminated, directly restricting this execution path.
References
CIS-2.3 Address Unauthorized Software mitigates T1021.005 VNC
Comments
Adversaries use VNC server software to establish remote interactive access to systems. When VNC server software is classified as unauthorized, this safeguard requires it to be removed, eliminating the VNC server endpoint required to establish the remote session.
References
CIS-2.6 Allowlist Authorized Libraries mitigates T1553.003 SIP and Trust Provider Hijacking
Comments
Trust Provider Hijacking can replace or introduce malicious DLLs used by Windows trust-validation mechanisms. Where these libraries are governed, allowlisting approved trust-provider DLLs can directly prevent unauthorized components from loading.
References
    CIS-2.6 Allowlist Authorized Libraries mitigates T1505.004 IIS Components
    Comments
    Malicious IIS components commonly use ISAPI extensions, filters, or modules implemented as DLLs loaded by IIS worker processes. Where library allowlisting governs IIS library loads, blocking unauthorized DLLs directly prevents those malicious components from loading.
    References
      CIS-2.6 Allowlist Authorized Libraries mitigates T1547.008 LSASS Driver
      Comments
      LSASS Driver persistence relies on malicious DLLs or LSA plug-ins being loaded into the LSASS process. Library allowlisting can prevent unauthorized libraries from loading into LSASS, directly disrupting this persistence mechanism.
      References
        CIS-2.6 Allowlist Authorized Libraries mitigates T1547.002 Authentication Package
        Comments
        Authentication Package persistence relies on a malicious authentication DLL being loaded by the Windows authentication subsystem. Where these DLLs are subject to allowlisting, unauthorized authentication packages can be blocked at load time.
        References
          CIS-2.6 Allowlist Authorized Libraries mitigates T1546.006 LC_LOAD_DYLIB Addition
          Comments
          LC_LOAD_DYLIB abuse causes a modified Mach-O binary to load an attacker-controlled dylib. Where macOS libraries are covered by the allowlist, blocking the unauthorized dylib directly limits this technique.
          References
            CIS-2.6 Allowlist Authorized Libraries mitigates T1129 Shared Modules
            Comments
            Adversaries load DLLs, shared objects, and other modules into processes to execute malicious code. Library allowlisting directly restricts this behavior by permitting only approved modules to load.
            References
              CIS-2.7 Allowlist Authorized Scripts mitigates T1546.013 PowerShell Profile
              Comments
              PowerShell profile persistence relies on executing a script at interpreter startup. Script allowlisting prevents unauthorized profile scripts from executing.
              References
                CIS-2.7 Allowlist Authorized Scripts mitigates T1216 System Script Proxy Execution
                Comments
                If script payload execution is enforced regardless of invoking binary, proxy-based script execution is reduced.
                References
                CIS-2.7 Allowlist Authorized Scripts mitigates T1137.001 Office Template Macros
                Comments
                Macro scripts blocked if script enforcement applies to macro execution policies.
                References
                CIS-2.7 Allowlist Authorized Scripts mitigates T1037 Boot or Logon Initialization Scripts
                Comments
                Startup scripts not on the allowlist cannot execute, disrupting persistence.
                References
                CIS-2.7 Allowlist Authorized Scripts mitigates T1059.007 JavaScript
                Comments
                Script enforcement blocks execution of non-authorized JavaScript files invoked via host interpreters.
                References
                  CIS-2.7 Allowlist Authorized Scripts mitigates T1059.006 Python
                  Comments
                  Unauthorized Python scripts are blocked when interpreter policies enforce script validation.
                  References
                  CIS-2.7 Allowlist Authorized Scripts mitigates T1059.005 Visual Basic
                  Comments
                  Malicious VB scripts/macros are prevented if not allowlisted.
                  References
                  CIS-2.7 Allowlist Authorized Scripts mitigates T1059.004 Unix Shell
                  Comments
                  Unauthorized shell scripts fail execution when enforced through script hash/signature/path validation.
                  References
                    CIS-2.7 Allowlist Authorized Scripts mitigates T1059.003 Windows Command Shell
                    Comments
                    Non-authorized batch or shell scripts are blocked.
                    References
                    CIS-2.7 Allowlist Authorized Scripts mitigates T1059.002 AppleScript
                    Comments
                    Script allowlisting prevents execution of unauthorized AppleScript files under enforced script validation policies.
                    References
                      CIS-2.7 Allowlist Authorized Scripts mitigates T1059.001 PowerShell
                      Comments
                      Unauthorized PowerShell scripts fail execution under enforced script allowlisting.
                      References
                      CIS-2.6 Allowlist Authorized Libraries mitigates T1546.010 AppInit DLLs
                      Comments
                      Prevents unauthorized AppInit DLL persistence where load control is enforced.
                      References
                      CIS-2.6 Allowlist Authorized Libraries mitigates T1546.009 AppCert DLLs
                      Comments
                      Unauthorized persistence DLLs cannot load if restricted by library allowlisting.
                      References
                      CIS-2.6 Allowlist Authorized Libraries mitigates T1574.006 Dynamic Linker Hijacking
                      Comments
                      Enforced library validation prevents execution of malicious shared objects via linker abuse.
                      References
                      CIS-2.6 Allowlist Authorized Libraries mitigates T1574.012 COR_PROFILER
                      Comments
                      COR_PROFILER abuse requires loading a malicious profiling DLL. Library enforcement prevents unauthorized profiler DLLs from loading into .NET processes.
                      References
                        CIS-2.6 Allowlist Authorized Libraries mitigates T1547.005 Security Support Provider
                        Comments
                        SSP persistence requires loading a malicious authentication DLL. Load validation blocks unauthorized SSP modules from being loaded into LSASS.
                        References
                          CIS-2.6 Allowlist Authorized Libraries mitigates T1547.004 Winlogon Helper DLL
                          Comments
                          Winlogon helper persistence relies on loading an unauthorized DLL. Library allowlisting prevents loading of non-authorized modules, directly disrupting this persistence method.
                          References
                            CIS-2.6 Allowlist Authorized Libraries mitigates T1574.001 DLL
                            Comments
                            Unauthorized DLLs fail to load if not on the allowlist, directly mitigating search order hijacking. Side-loaded malicious libraries are blocked when load validation is enforced.
                            References
                            CIS-2.5 Allowlist Authorized Software mitigates T1105 Ingress Tool Transfer
                            Comments
                            Transferred malware payloads cannot execute if not explicitly authorized. Control reduces operational effectiveness post-transfer.
                            References
                            CIS-2.5 Allowlist Authorized Software mitigates T1543 Create or Modify System Process
                            Comments
                            Services relying on non-allowlisted binaries will fail to execute.
                            References
                            CIS-2.5 Allowlist Authorized Software mitigates T1219 Remote Access Tools
                            Comments
                            Application allowlisting prevents execution of unauthorized remote access tools (e.g., AnyDesk, TeamViewer, custom RATs). If not explicitly authorized, these binaries cannot execute, directly reducing adversary persistence and command-and-control capability.
                            References
                              CIS-2.5 Allowlist Authorized Software mitigates T1218 System Binary Proxy Execution
                              Comments
                              If policy restricts execution to explicitly authorized binaries, unauthorized or abused proxy binaries may be prevented from executing.
                              References
                              CIS-2.5 Allowlist Authorized Software mitigates T1059 Command and Scripting Interpreter
                              Comments
                              If interpreters themselves are restricted or constrained by allowlisting, adversary-launched unauthorized interpreter binaries are blocked.
                              References
                              CIS-2.5 Allowlist Authorized Software mitigates T1204.002 Malicious File
                              Comments
                              Malicious binaries fail execution if not on the allowlist.
                              References
                              CIS-2.5 Allowlist Authorized Software mitigates T1204 User Execution
                              Comments
                              Non-allowlisted executables cannot run, directly preventing execution of malicious binaries delivered via user interaction.
                              References
                              CIS-2.3 Address Unauthorized Software mitigates T1547 Boot or Logon Autostart Execution
                              Comments
                              If unauthorized startup software is identified and removed, persistence via installed startup components is disrupted.
                              References
                              CIS-2.3 Address Unauthorized Software mitigates T1543.003 Windows Service
                              Comments
                              Removal of unauthorized service binaries prevents continued execution of adversary-installed services.
                              References
                              CIS-2.3 Address Unauthorized Software mitigates T1543 Create or Modify System Process
                              Comments
                              Automated detection and removal of unauthorized installed services can directly disrupt adversary-created system services used for persistence. Enforcement reduces persistence reliability.
                              References

                              Capabilities

                              Capability ID Capability Name Number of Mappings
                              CIS-2.5 Allowlist Authorized Software 24
                              CIS-2.3 Address Unauthorized Software 7
                              CIS-2.7 Allowlist Authorized Scripts 11
                              CIS-2.6 Allowlist Authorized Libraries 13