Actively manage (inventory, track, and correct) all software (operating systems and applications) on the network so that only authorized software is installed and can execute, and that unauthorized and unmanaged software is found and prevented from installation or execution.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1059.011 | Lua |
Comments
Adversaries use Lua interpreters to execute Lua code. An application-control policy denying unauthorized Lua interpreters prevents those binaries from running, directly restricting Lua execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1059.006 | Python |
Comments
Adversaries use Python interpreters to execute malicious commands and payloads. An enforced allowlist denying Python prevents the interpreter from executing, directly removing the prerequisite for Python-based execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1176 | Software Extensions |
Comments
Adversaries install or use malicious browser or IDE extensions to obtain execution or persistence. The implementation to explicitly allowlists authorized extensions and blocks all others, unauthorized extensions cannot be installed or loaded, directly constraining the technique.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1564.003 | Hidden Window |
Comments
Adversaries may hide application windows while malicious programs execute. Where an unauthorized program is responsible for the hidden-window behavior, application allowlisting prevents that program from running and therefore prevents that implementation of the technique.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1548.004 | Elevated Execution with Prompt |
Comments
Adversaries may persuade users to approve elevated execution of malicious applications. If application control prevents the unapproved application from executing regardless of user approval, the malicious program cannot reach the elevation stage through this path.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1546.002 | Screensaver |
Comments
Adversaries can establish execution or persistence using malicious .scr screensaver files. Application-control rules can prevent unauthorized .scr files from executing, directly blocking the malicious executable used by the technique
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.014 | MMC |
Comments
Adversaries can abuse Microsoft Management Console to execute malicious content through a trusted system binary. Application allowlisting can block MMC on systems where its use is not authorized, directly preventing the executable from being used for proxy execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.013 | Mavinject |
Comments
Adversaries abuse mavinject.exe to inject malicious code into another process through a trusted Microsoft executable. Application allowlisting can deny execution of mavinject.exe where it is not authorized, directly preventing use of that binary for the technique.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.012 | Verclsid |
Comments
Adversaries abuse verclsid.exe to execute malicious COM objects through a trusted Windows binary. Application allowlisting can block verclsid.exe where it is unnecessary, directly preventing its use as the proxy executable.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.009 | Regsvcs/Regasm |
Comments
Adversaries use Regsvcs.exe or Regasm.exe to proxy execution of malicious .NET code. Application allowlisting can prevent these binaries from executing on systems where they are not authorized, directly preventing this execution path.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.008 | Odbcconf |
Comments
Adversaries abuse odbcconf.exe to execute malicious code through a trusted Windows utility. Application allowlisting can deny execution of odbcconf.exe where it is not required, directly preventing use of that proxy-execution mechanism.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.005 | Mshta |
Comments
Adversaries abuse mshta.exe to execute HTML application or script content through a trusted Windows binary. Application allowlisting can explicitly deny mshta.exe, preventing the executable from being used for proxy execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.004 | InstallUtil |
Comments
Adversaries use InstallUtil.exe to execute malicious .NET code while proxying execution through a trusted binary. Application allowlisting can block InstallUtil where it is not authorized, directly preventing use of the utility for this behavior.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.003 | CMSTP |
Comments
Adversaries abuse cmstp.exe to proxy execution of malicious code through a trusted Windows utility. Application allowlisting can prevent cmstp.exe from executing on systems where it is not required, directly removing the proxy-execution mechanism.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218.001 | Compiled HTML File |
Comments
Adversaries abuse hh.exe to execute malicious compiled HTML content through a trusted Windows binary. Application allowlisting can block hh.exe where it is not authorized, preventing use of that binary for proxy execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1127.001 | MSBuild |
Comments
Adversaries abuse msbuild.exe to execute malicious code through a trusted Microsoft developer utility. Application allowlisting can deny execution of MSBuild on systems where it is not authorized, directly eliminating the binary used for proxy execution.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1059.010 | AutoHotKey & AutoIT |
Comments
Adversaries use AutoHotKey and AutoIT interpreters to execute automated commands and malicious scripts. Application allowlisting can block AutoHotkey.exe, AutoIt3.exe, and related unauthorized executables, directly preventing those interpreters from executing.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1127.001 | MSBuild |
Comments
Adversaries abuse MSBuild to execute malicious code through a trusted developer utility. When MSBuild is unnecessary, explicitly classified as unauthorized, and removed under this safeguard, the executable required for this proxy-execution technique is eliminated.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1059.011 | Lua |
Comments
Adversaries can use a Lua interpreter to execute malicious Lua commands or scripts. When Lua is unauthorized on the asset and is removed through this safeguard, the interpreter required to execute Lua code is no longer available, directly restricting the technique.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1059.006 | Python |
Comments
Adversaries use installed Python interpreters to execute commands, scripts, and payloads. When Python is classified as unauthorized and removed under this safeguard, the local interpreter required for Python-based execution is eliminated, directly restricting this execution path.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1021.005 | VNC |
Comments
Adversaries use VNC server software to establish remote interactive access to systems. When VNC server software is classified as unauthorized, this safeguard requires it to be removed, eliminating the VNC server endpoint required to establish the remote session.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1553.003 | SIP and Trust Provider Hijacking |
Comments
Trust Provider Hijacking can replace or introduce malicious DLLs used by Windows trust-validation mechanisms. Where these libraries are governed, allowlisting approved trust-provider DLLs can directly prevent unauthorized components from loading.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1505.004 | IIS Components |
Comments
Malicious IIS components commonly use ISAPI extensions, filters, or modules implemented as DLLs loaded by IIS worker processes. Where library allowlisting governs IIS library loads, blocking unauthorized DLLs directly prevents those malicious components from loading.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1547.008 | LSASS Driver |
Comments
LSASS Driver persistence relies on malicious DLLs or LSA plug-ins being loaded into the LSASS process. Library allowlisting can prevent unauthorized libraries from loading into LSASS, directly disrupting this persistence mechanism.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1547.002 | Authentication Package |
Comments
Authentication Package persistence relies on a malicious authentication DLL being loaded by the Windows authentication subsystem. Where these DLLs are subject to allowlisting, unauthorized authentication packages can be blocked at load time.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1546.006 | LC_LOAD_DYLIB Addition |
Comments
LC_LOAD_DYLIB abuse causes a modified Mach-O binary to load an attacker-controlled dylib. Where macOS libraries are covered by the allowlist, blocking the unauthorized dylib directly limits this technique.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1129 | Shared Modules |
Comments
Adversaries load DLLs, shared objects, and other modules into processes to execute malicious code. Library allowlisting directly restricts this behavior by permitting only approved modules to load.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1546.013 | PowerShell Profile |
Comments
PowerShell profile persistence relies on executing a script at interpreter startup. Script allowlisting prevents unauthorized profile scripts from executing.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1216 | System Script Proxy Execution |
Comments
If script payload execution is enforced regardless of invoking binary, proxy-based script execution is reduced.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1137.001 | Office Template Macros |
Comments
Macro scripts blocked if script enforcement applies to macro execution policies.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1037 | Boot or Logon Initialization Scripts |
Comments
Startup scripts not on the allowlist cannot execute, disrupting persistence.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1059.007 | JavaScript |
Comments
Script enforcement blocks execution of non-authorized JavaScript files invoked via host interpreters.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1059.006 | Python |
Comments
Unauthorized Python scripts are blocked when interpreter policies enforce script validation.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1059.005 | Visual Basic |
Comments
Malicious VB scripts/macros are prevented if not allowlisted.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1059.004 | Unix Shell |
Comments
Unauthorized shell scripts fail execution when enforced through script hash/signature/path validation.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1059.003 | Windows Command Shell |
Comments
Non-authorized batch or shell scripts are blocked.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1059.002 | AppleScript |
Comments
Script allowlisting prevents execution of unauthorized AppleScript files under enforced script validation policies.
References
|
| CIS-2.7 | Allowlist Authorized Scripts | mitigates | T1059.001 | PowerShell |
Comments
Unauthorized PowerShell scripts fail execution under enforced script allowlisting.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1546.010 | AppInit DLLs |
Comments
Prevents unauthorized AppInit DLL persistence where load control is enforced.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1546.009 | AppCert DLLs |
Comments
Unauthorized persistence DLLs cannot load if restricted by library allowlisting.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1574.006 | Dynamic Linker Hijacking |
Comments
Enforced library validation prevents execution of malicious shared objects via linker abuse.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1574.012 | COR_PROFILER |
Comments
COR_PROFILER abuse requires loading a malicious profiling DLL. Library enforcement prevents unauthorized profiler DLLs from loading into .NET processes.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1547.005 | Security Support Provider |
Comments
SSP persistence requires loading a malicious authentication DLL. Load validation blocks unauthorized SSP modules from being loaded into LSASS.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1547.004 | Winlogon Helper DLL |
Comments
Winlogon helper persistence relies on loading an unauthorized DLL. Library allowlisting prevents loading of non-authorized modules, directly disrupting this persistence method.
References
|
| CIS-2.6 | Allowlist Authorized Libraries | mitigates | T1574.001 | DLL |
Comments
Unauthorized DLLs fail to load if not on the allowlist, directly mitigating search order hijacking. Side-loaded malicious libraries are blocked when load validation is enforced.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1105 | Ingress Tool Transfer |
Comments
Transferred malware payloads cannot execute if not explicitly authorized. Control reduces operational effectiveness post-transfer.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1543 | Create or Modify System Process |
Comments
Services relying on non-allowlisted binaries will fail to execute.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1219 | Remote Access Tools |
Comments
Application allowlisting prevents execution of unauthorized remote access tools (e.g., AnyDesk, TeamViewer, custom RATs). If not explicitly authorized, these binaries cannot execute, directly reducing adversary persistence and command-and-control capability.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1218 | System Binary Proxy Execution |
Comments
If policy restricts execution to explicitly authorized binaries, unauthorized or abused proxy binaries may be prevented from executing.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1059 | Command and Scripting Interpreter |
Comments
If interpreters themselves are restricted or constrained by allowlisting, adversary-launched unauthorized interpreter binaries are blocked.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1204.002 | Malicious File |
Comments
Malicious binaries fail execution if not on the allowlist.
References
|
| CIS-2.5 | Allowlist Authorized Software | mitigates | T1204 | User Execution |
Comments
Non-allowlisted executables cannot run, directly preventing execution of malicious binaries delivered via user interaction.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1547 | Boot or Logon Autostart Execution |
Comments
If unauthorized startup software is identified and removed, persistence via installed startup components is disrupted.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1543.003 | Windows Service |
Comments
Removal of unauthorized service binaries prevents continued execution of adversary-installed services.
References
|
| CIS-2.3 | Address Unauthorized Software | mitigates | T1543 | Create or Modify System Process |
Comments
Automated detection and removal of unauthorized installed services can directly disrupt adversary-created system services used for persistence. Enforcement reduces persistence reliability.
References
|
| Capability ID | Capability Name | Number of Mappings |
|---|---|---|
| CIS-2.5 | Allowlist Authorized Software | 24 |
| CIS-2.3 | Address Unauthorized Software | 7 |
| CIS-2.7 | Allowlist Authorized Scripts | 11 |
| CIS-2.6 | Allowlist Authorized Libraries | 13 |