CIS Controls Secure Configuration of Enterprise Assets and Software Capability Group

Establish and maintain the secure configuration of enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) and software (operating systems and applications).

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1005 Data from Local System
Comments
A successful remote wipe removes enterprise files, local databases, cached content, and other managed data before an adversary with possession of the device can collect it.
References
    CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1114.001 Local Email Collection
    Comments
    Wiping managed email applications and locally cached mailbox files can prevent collection of Outlook PST or OST files and other locally stored enterprise email.
    References
      CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1539 Steal Web Session Cookie
      Comments
      Wiping managed browsers and application data removes locally stored enterprise session cookies before they can be extracted from a lost or stolen device.
      References
        CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1552.001 Credentials In Files
        Comments
        Remote wipe can remove managed files containing passwords, API keys, connection strings, or other credential material. The mitigation is limited to files covered by the wipe and does not address credentials stored elsewhere.
        References
          CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1552.002 Credentials in Registry
          Comments
          A full Windows device wipe removes local Registry hives containing enterprise credential material before they can be searched or exported. A selective enterprise-data wipe may not remove operating-system Registry data.
          References
            CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1552.004 Private Keys
            Comments
            Wiping enterprise-managed key files, certificates, VPN profiles, and application containers can prevent private keys from being obtained from a lost device. Keys synchronized elsewhere or already exported remain exposed and should be revoked separately.
            References
              CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1555.001 Keychain
              Comments
              A full wipe of a managed macOS device removes locally stored Keychain databases and enterprise certificates. Items synchronized to other devices or already extracted are not revoked merely by wiping the device.
              References
                CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1555.003 Credentials from Web Browsers
                Comments
                Remote wipe of managed browser profiles can remove locally stored enterprise passwords and related authentication data. Browser-synchronized credentials and already extracted copies require separate account or server-side action.
                References
                  CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1555.004 Windows Credential Manager
                  Comments
                  A full Windows wipe removes local Credential Manager vault files and associated enterprise credentials. Selective wipe implementations may not remove credentials stored outside managed application containers.
                  References
                    CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1552.003 Shell History
                    Comments
                    A full device wipe removes local shell-history files that may contain passwords, tokens, or sensitive commands. Selective enterprise wipes may not remove operating-system shell histories.
                    References
                      CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices mitigates T1555.005 Password Managers
                      Comments
                      Remote wipe can remove a managed password-manager application, its local vault, and cached decrypted data. Cloud-hosted vault contents remain available and require account revocation, device removal, or token invalidation.
                      References
                        CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices mitigates T1110.004 Credential Stuffing
                        Comments
                        Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated breached username password attempts will succeed.
                        References
                          CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices mitigates T1110.003 Password Spraying
                          Comments
                          Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.
                          References
                            CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices mitigates T1110.001 Password Guessing
                            Comments
                            Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.
                            References
                              CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices mitigates T1110 Brute Force
                              Comments
                              Automatic device lockout limits the number of consecutive authentication attempts that can be made against a portable device, directly reducing the likelihood that repeated online password attempts will succeed.
                              References
                                CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1071.004 DNS
                                Comments
                                Directing DNS traffic through trusted enterprise resolvers can prevent systems from communicating directly with adversary-controlled DNS servers and can support blocking or sinkholing malicious DNS requests.
                                References
                                  CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1071 Application Layer Protocol
                                  Comments
                                  This is a partial mapping because DNS is one of the application-layer protocols covered by this technique. Configuring trusted DNS servers affects DNS-based command and control but does not mitigate web, mail, file-transfer, or publish-subscribe protocols.
                                  References
                                    CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1048 Exfiltration Over Alternative Protocol
                                    Comments
                                    Enforcing use of trusted DNS resolvers reduces the ability of enterprise assets to communicate directly with adversary-controlled DNS infrastructure for exfiltration. The mitigation applies only to implementations that use DNS or depend on unauthorized DNS servers.
                                    References
                                      CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
                                      Comments
                                      DNS can carry encoded exfiltrated data over an unencrypted non-command-and-control protocol. Routing requests through controlled resolvers provides an enforcement point for blocking unauthorized DNS servers, suspicious domains, or abnormal query activity.
                                      References
                                        CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets mitigates T1572 Protocol Tunneling
                                        Comments
                                        DNS can be used to tunnel command-and-control traffic or other protocols. Enforcing trusted resolvers and preventing direct DNS communication can disrupt conventional DNS tunneling,
                                        References
                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021 Remote Services
                                          Comments
                                          Disabling unnecessary remote services eliminates the corresponding authentication and remote-access path, directly reducing lateral movement opportunities.
                                          References
                                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.001 Remote Desktop Protocol
                                            Comments
                                            Disabling Remote Desktop Services where RDP is not operationally required prevents adversaries from connecting through that service.
                                            References
                                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.002 SMB/Windows Admin Shares
                                              Comments
                                              Disabling unnecessary SMB file sharing and administrative shares directly removes common lateral movement, file-transfer, and remote-management paths.
                                              References
                                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.003 Distributed Component Object Model
                                                Comments
                                                Disabling DCOM when it is not required removes a remote RPC-based execution and management interface that adversaries may abuse.
                                                References
                                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.004 SSH
                                                  Comments
                                                  Disabling the SSH daemon or Remote Login on systems that do not require it eliminates an SSH-based remote-access path.
                                                  References
                                                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.005 VNC
                                                    Comments
                                                    Uninstalling unnecessary VNC server software removes the listener and prevents remote control through that implementation.
                                                    References
                                                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.006 Windows Remote Management
                                                      Comments
                                                      Disabling the WinRM service where it is unnecessary removes a remote command-execution and administration interface.
                                                      References
                                                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.008 Direct Cloud VM Connections
                                                        Comments
                                                        Disabling unnecessary cloud-native VM connection types, serial consoles, or direct management services eliminates those remote-administration paths.
                                                        References
                                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1080 Taint Shared Content
                                                          Comments
                                                          Removing unnecessary shared folders and file-sharing services prevents adversaries from placing malicious content in those shares for other users or systems to execute.
                                                          References
                                                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1133 External Remote Services
                                                            Comments
                                                            Uninstalling or disabling unnecessary externally accessible VPN, remote desktop, SSH, and management services directly reduces external entry points.
                                                            References
                                                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1190 Exploit Public-Facing Application
                                                              Comments
                                                              Removing unused public-facing applications, services, and web modules eliminates exploitable listeners and reduces the externally exposed attack surface.
                                                              References
                                                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1210 Exploitation of Remote Services
                                                                Comments
                                                                A remote service that has been disabled or uninstalled can no longer be reached and exploited through its network interface.
                                                                References
                                                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1219 Remote Access Tools
                                                                  Comments
                                                                  Removing unauthorized or unnecessary remote-access products and disabling embedded remote-support functionality directly eliminates those access channels.
                                                                  References
                                                                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1219.002 Remote Desktop Software
                                                                    Comments
                                                                    Uninstalling unnecessary remote desktop products prevents adversaries from abusing that specific software for persistent or interactive access.
                                                                    References
                                                                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505 Server Software Component
                                                                      Comments
                                                                      Disabling unnecessary server extension mechanisms and components reduces the features adversaries can abuse to establish persistent server-side access.
                                                                      References
                                                                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.003 Web Shell
                                                                        Comments
                                                                        Disabling unnecessary web server functionality, scripting engines, and dangerous application functions can prevent particular web shell implementations from executing.
                                                                        References
                                                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.004 IIS Components
                                                                          Comments
                                                                          Removing unused IIS modules, handlers, filters, and extensions directly reduces opportunities to install or abuse malicious IIS components.
                                                                          References
                                                                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1552.005 Cloud Instance Metadata API
                                                                            Comments
                                                                            Disabling unnecessary metadata services or insecure metadata-service versions directly prevents adversary access through those endpoints.
                                                                            References
                                                                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1602 Data from Configuration Repository
                                                                              Comments
                                                                              Removing unnecessary configuration-management protocols and repositories reduces the systems and services from which adversaries can collect configuration data.
                                                                              References
                                                                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1602.001 SNMP (MIB Dump)
                                                                                Comments
                                                                                Disabling SNMP where it is unnecessary removes the management service used to retrieve MIB and configuration information.
                                                                                References
                                                                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1602.002 Network Device Configuration Dump
                                                                                  Comments
                                                                                  Removing unnecessary Telnet, HTTP management, TFTP, legacy SNMP, or similar configuration services reduces direct collection of network-device configurations.
                                                                                  References
                                                                                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1011 Exfiltration Over Other Network Medium
                                                                                    Comments
                                                                                    Disabling unnecessary Wi-Fi, cellular, modem, Bluetooth, or other secondary network services removes potential alternative exfiltration channels.
                                                                                    References
                                                                                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1011.001 Exfiltration Over Bluetooth
                                                                                      Comments
                                                                                      Disabling the Bluetooth service and adapter functionality where it is unnecessary prevents Bluetooth-based data transfer from that asset.
                                                                                      References
                                                                                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1021.007 Cloud Services
                                                                                        Comments
                                                                                        Disabling unnecessary cloud services, command-line integrations, and administrative applications reduces available cloud-management paths, although required web consoles may remain accessible.
                                                                                        References
                                                                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1039 Data from Network Shared Drive
                                                                                          Comments
                                                                                          Removing unnecessary file-sharing services and shares reduces the network data repositories available for adversary collection.
                                                                                          References
                                                                                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1040 Network Sniffing
                                                                                            Comments
                                                                                            Removing unnecessary plaintext and broadcast-based services reduces sensitive service traffic available for interception, although it does not prevent sniffing of remaining traffic.
                                                                                            References
                                                                                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1047 Windows Management Instrumentation
                                                                                              Comments
                                                                                              Disabling unnecessary remote WMI and dependent management services reduces remote WMI execution, while local WMI functionality may remain available.
                                                                                              References
                                                                                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1059.008 Network Device CLI
                                                                                                Comments
                                                                                                Disabling unnecessary network-device command-line services, especially Telnet or direct CLI access, removes a command interface adversaries could abuse.
                                                                                                References
                                                                                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1072 Software Deployment Tools
                                                                                                  Comments
                                                                                                  Uninstalling unnecessary deployment agents and disabling unused remote-deployment functionality reduces the number of centralized execution mechanisms available to an adversary.
                                                                                                  References
                                                                                                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1090 Proxy
                                                                                                    Comments
                                                                                                    Removing unnecessary proxy, relay, port-forwarding, and tunneling services reduces the ability to turn an enterprise asset into a network intermediary.
                                                                                                    References
                                                                                                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1090.001 Internal Proxy
                                                                                                      Comments
                                                                                                      Disabling unnecessary internal proxy listeners, SSH forwarding, port proxies, and routing functions impedes the use of a compromised asset as an internal pivot.
                                                                                                      References
                                                                                                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1187 Forced Authentication
                                                                                                        Comments
                                                                                                        Disabling unnecessary SMB, WebClient, WebDAV, LLMNR, NBT-NS, and related services reduces mechanisms that can coerce outbound authentication.
                                                                                                        References
                                                                                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1197 BITS Jobs
                                                                                                          Comments
                                                                                                          Disabling the Background Intelligent Transfer Service where it is genuinely unnecessary prevents adversary use of BITS for transfer, execution, or persistence.
                                                                                                          References
                                                                                                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1570 Lateral Tool Transfer
                                                                                                            Comments
                                                                                                            Removing unnecessary SMB, SSH, WinRM, file-sharing, and deployment services reduces common channels used to move tools between systems.
                                                                                                            References
                                                                                                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.001 SQL Stored Procedures
                                                                                                              Comments
                                                                                                              Disabling unnecessary extended stored procedures, scripting extensions, or database execution features reduces opportunities to establish persistence through the database server.
                                                                                                              References
                                                                                                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.002 Transport Agent
                                                                                                                Comments
                                                                                                                Removing unused mail transport agents and extension points reduces the components available for adversary persistence in messaging infrastructure.
                                                                                                                References
                                                                                                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.005 Terminal Services DLL
                                                                                                                  Comments
                                                                                                                  Disabling unnecessary Terminal Services functionality reduces opportunities to replace or abuse associated DLL components, although required RDP systems remain exposed.
                                                                                                                  References
                                                                                                                    CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1505.006 vSphere Installation Bundles
                                                                                                                    Comments
                                                                                                                    Removing unnecessary vSphere Installation Bundles and disabling unused ESXi extension functionality reduces the components available for hypervisor persistence.
                                                                                                                    References
                                                                                                                      CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1609 Container Administration Command
                                                                                                                      Comments
                                                                                                                      Removing unnecessary container-management utilities, exposed APIs, and administrative services reduces the mechanisms available for remote container commands.
                                                                                                                      References
                                                                                                                        CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1611 Escape to Host
                                                                                                                        Comments
                                                                                                                        Minimal container images and removal of unnecessary tools, shells, runtimes, and privileged services reduce some prerequisites and post-exploitation options for container escape.
                                                                                                                        References
                                                                                                                          CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1563 Remote Service Session Hijacking
                                                                                                                          Comments
                                                                                                                          Disabling unnecessary remote services prevents sessions from being established through those services and therefore removes sessions that could later be hijacked.
                                                                                                                          References
                                                                                                                            CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1563.001 SSH Hijacking
                                                                                                                            Comments
                                                                                                                            Disabling unnecessary SSH and agent-forwarding functions removes some SSH sessions and forwarding sockets that adversaries could hijack.
                                                                                                                            References
                                                                                                                              CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1563.002 RDP Hijacking
                                                                                                                              Comments
                                                                                                                              Disabling unnecessary RDP services prevents creation of RDP sessions on those assets, eliminating that session-hijacking opportunity.
                                                                                                                              References
                                                                                                                                CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1649 Steal or Forge Authentication Certificates
                                                                                                                                Comments
                                                                                                                                Disabling unnecessary Active Directory Certificate Services web enrollment, enrollment agents, legacy authentication protocols, and certificate-service roles reduces certificate abuse paths.
                                                                                                                                References
                                                                                                                                  CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software mitigates T1671 Cloud Application Integration
                                                                                                                                  Comments
                                                                                                                                  Disabling unnecessary SaaS integrations, plug-ins, application consent features, and service connections reduces the number of integrations an adversary can authorize or abuse.
                                                                                                                                  References
                                                                                                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1040 Network Sniffing
                                                                                                                                    Comments
                                                                                                                                    Replacing plaintext administrative protocols such as Telnet and HTTP with SSH and HTTPS prevents captured management traffic from directly exposing credentials, commands, and configuration data. Encryption does not prevent packet capture, but it materially reduces the value of the captured traffic.
                                                                                                                                    References
                                                                                                                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1072 Software Deployment Tools
                                                                                                                                      Comments
                                                                                                                                      Safeguard 4.6 directly concerns securely managing software and configuration-management platforms, including tools integrated with CI/CD systems. Restricting administrative access and managing deployment configuration through controlled, versioned mechanisms reduces unauthorized use of these platforms for execution and lateral movement.
                                                                                                                                      References
                                                                                                                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1210 Exploitation of Remote Services
                                                                                                                                        Comments
                                                                                                                                        Disabling obsolete management protocols and securely configuring required administrative services reduces the number of remotely reachable and vulnerable services. The safeguard does not patch vulnerabilities, but it directly removes insecure management paths that could be exploited.
                                                                                                                                        References
                                                                                                                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1552.007 Container API
                                                                                                                                          Comments
                                                                                                                                          Disabling unauthenticated Docker and Kubernetes API access and requiring secured channels such as SSH or TLS directly reduces unauthorized access to container-management interfaces. This closely matches the safeguard's requirement to access administrative interfaces through secure protocols.
                                                                                                                                          References
                                                                                                                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1557 Adversary-in-the-Middle
                                                                                                                                            Comments
                                                                                                                                            Authenticated encryption through SSH, HTTPS, and TLS limits an adversary's ability to read or alter administrative traffic even after obtaining a network interception position. Certificate and SSH host-key validation remain essential to the effectiveness of the mitigation.
                                                                                                                                            References
                                                                                                                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1565.002 Transmitted Data Manipulation
                                                                                                                                              Comments
                                                                                                                                              SSH and HTTPS provide confidentiality and integrity protection for management commands and configuration data in transit. This makes undetected modification of administrative traffic substantially more difficult.
                                                                                                                                              References
                                                                                                                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1602 Data from Configuration Repository
                                                                                                                                                Comments
                                                                                                                                                Secure management protocols, authenticated access, and controlled configuration repositories directly reduce unauthorized collection of device and infrastructure configuration. Version-controlled Infrastructure-as-Code can also reduce the need to retrieve configurations through insecure management interfaces.
                                                                                                                                                References
                                                                                                                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1602.001 SNMP (MIB Dump)
                                                                                                                                                  Comments
                                                                                                                                                  Migrating from insecure SNMP versions to SNMPv3 with authentication and privacy protection directly reduces unauthorized MIB collection. Restricting management access to approved systems further limits successful enumeration.
                                                                                                                                                  References
                                                                                                                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1602.002 Network Device Configuration Dump
                                                                                                                                                    Comments
                                                                                                                                                    Using SSH, HTTPS, SNMPv3, and securely managed configuration repositories reduces exposure of network-device configurations and embedded credentials. Insecure services such as Telnet, HTTP, TFTP, or legacy management protocols create substantially greater collection risk.
                                                                                                                                                    References
                                                                                                                                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1609 Container Administration Command
                                                                                                                                                      Comments
                                                                                                                                                      Restricting Docker and Kubernetes administration to authenticated TLS, SSH, local sockets, or other secured management channels directly reduces unauthorized remote container commands. Version-controlled manifests and Infrastructure-as-Code also reduce unreviewed administrative changes.
                                                                                                                                                      References
                                                                                                                                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1659 Content Injection
                                                                                                                                                        Comments
                                                                                                                                                        HTTPS and other authenticated encrypted protocols make it more difficult for an adversary positioned in the network path to inject malicious content into management downloads or administrative sessions. This is a direct benefit of prohibiting plaintext HTTP management.
                                                                                                                                                        References
                                                                                                                                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1689 Downgrade Attack
                                                                                                                                                          Comments
                                                                                                                                                          This safeguard explicitly prohibits fallback to insecure protocols such as HTTP and Telnet. Enforcing HTTPS, modern TLS, SSH, and policies such as HSTS directly limits attempts to downgrade management communications to weaker or plaintext alternatives.
                                                                                                                                                          References
                                                                                                                                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021 Remote Services
                                                                                                                                                            Comments
                                                                                                                                                            Securely managing which remote services are permitted and requiring authenticated encrypted protocols reduces exposed administrative paths. The safeguard does not independently prevent adversaries from using valid credentials through an approved service.
                                                                                                                                                            References
                                                                                                                                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.001 Remote Desktop Protocol
                                                                                                                                                              Comments
                                                                                                                                                              Secure RDP configuration, gateways, TLS, and restricted administrative access reduce interception and direct exposure. RDP remains usable by an adversary who possesses authorized credentials or an active session.
                                                                                                                                                              References
                                                                                                                                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.002 SMB/Windows Admin Shares
                                                                                                                                                                Comments
                                                                                                                                                                Secure management can disable unnecessary administrative shares and require modern SMB signing or encryption where remote administration is needed. It does not fully prevent abuse of an authorized SMB management path.
                                                                                                                                                                References
                                                                                                                                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.003 Distributed Component Object Model
                                                                                                                                                                  Comments
                                                                                                                                                                  Securely managing DCOM availability and restricting it to approved administrative workflows reduces remote abuse. DCOM does not have a simple SSH or HTTPS replacement, so effectiveness depends on disabling or tightly constraining it.
                                                                                                                                                                  References
                                                                                                                                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.004 SSH
                                                                                                                                                                    Comments
                                                                                                                                                                    SSH protects administrative credentials and commands from plaintext interception and should replace Telnet. It does not prevent an adversary with valid credentials or an unauthorized SSH key from using the service.
                                                                                                                                                                    References
                                                                                                                                                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.005 VNC
                                                                                                                                                                      Comments
                                                                                                                                                                      Secure management can prohibit unencrypted VNC deployments or require encrypted tunnels and approved administrative tooling. The relationship is partial because some VNC implementations or tunnels remain accessible with valid credentials.
                                                                                                                                                                      References
                                                                                                                                                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.006 Windows Remote Management
                                                                                                                                                                        Comments
                                                                                                                                                                        Requiring WinRM over HTTPS rather than unencrypted HTTP protects management credentials and commands in transit. Authorized-account abuse remains possible through the secured channel.
                                                                                                                                                                        References
                                                                                                                                                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.007 Cloud Services
                                                                                                                                                                          Comments
                                                                                                                                                                          Securing cloud administrative consoles and APIs, using controlled automation, and managing resources through version-controlled Infrastructure-as-Code reduces ad hoc and insecure administration. It does not prevent malicious activity performed through a compromised authorized cloud account.
                                                                                                                                                                          References
                                                                                                                                                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1021.008 Direct Cloud VM Connections
                                                                                                                                                                            Comments
                                                                                                                                                                            Approved and securely configured cloud-native VM connection methods reduce exposure from direct or insecure management services. Cloud control-plane access may bypass the guest operating system's network controls, so identity and cloud policy protections are also required.
                                                                                                                                                                            References
                                                                                                                                                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1059.008 Network Device CLI
                                                                                                                                                                              Comments
                                                                                                                                                                              Requiring SSH rather than Telnet protects command-line interface credentials and commands in transit and reduces interception or manipulation. Once an adversary has authorized administrative access, the encrypted CLI still permits malicious commands.
                                                                                                                                                                              References
                                                                                                                                                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1133 External Remote Services
                                                                                                                                                                                Comments
                                                                                                                                                                                Requiring secure protocols and centrally managed administrative access reduces risk from externally accessible management services. Additional protections such as multi-factor authentication, gateways, and network restrictions remain necessary.
                                                                                                                                                                                References
                                                                                                                                                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1190 Exploit Public-Facing Application
                                                                                                                                                                                  Comments
                                                                                                                                                                                  Administrative web interfaces should use HTTPS and should not be exposed through unnecessary plaintext or legacy services. HTTPS does not remediate an application vulnerability, so this mitigation primarily reduces unnecessary exposure and traffic manipulation.
                                                                                                                                                                                  References
                                                                                                                                                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1098.004 SSH Authorized Keys
                                                                                                                                                                                    Comments
                                                                                                                                                                                    Version-controlled SSH configuration and managed deployment of approved keys can prevent or identify unauthorized additions to authorized_keys. File permissions and privileged access controls are still needed to prevent local modification.
                                                                                                                                                                                    References
                                                                                                                                                                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1213.003 Code Repositories
                                                                                                                                                                                      Comments
                                                                                                                                                                                      Infrastructure-as-Code repositories may reveal infrastructure topology, administrative endpoints, configuration, and embedded credentials. Secure repository administration and keeping secrets outside version control reduce the value and accessibility of these repositories.
                                                                                                                                                                                      References
                                                                                                                                                                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1219 Remote Access Tools
                                                                                                                                                                                        Comments
                                                                                                                                                                                        Secure software management can limit administration to approved and securely configured remote-access products. The safeguard does not prevent an approved tool or account from being abused by an adversary.
                                                                                                                                                                                        References
                                                                                                                                                                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1219.001 IDE Tunneling
                                                                                                                                                                                          Comments
                                                                                                                                                                                          Securely managing development tools can disable unnecessary tunneling functions and restrict approved remote-development services. Legitimate HTTPS or SSH development channels may still be abused.
                                                                                                                                                                                          References
                                                                                                                                                                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1219.002 Remote Desktop Software
                                                                                                                                                                                            Comments
                                                                                                                                                                                            Organizations can centrally approve, configure, and secure remote-support software while removing unauthorized products. An adversary may still misuse an approved product or compromised support account.
                                                                                                                                                                                            References
                                                                                                                                                                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1552.001 Credentials In Files
                                                                                                                                                                                              Comments
                                                                                                                                                                                              Infrastructure code, configuration files, deployment manifests, and automation scripts frequently create a risk of embedded passwords or tokens. Secure management should keep credentials out of source-controlled configuration and use protected secret stores or runtime injection.
                                                                                                                                                                                              References
                                                                                                                                                                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1552.004 Private Keys
                                                                                                                                                                                                Comments
                                                                                                                                                                                                SSH administration depends on protecting private keys and preventing them from being embedded in repositories or widely distributed. Managed key storage, permissions, and rotation reduce the likelihood that stolen keys can be used for administration.
                                                                                                                                                                                                References
                                                                                                                                                                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1610 Deploy Container
                                                                                                                                                                                                  Comments
                                                                                                                                                                                                  Requiring container deployments through approved, authenticated orchestration interfaces and version-controlled manifests reduces unauthorized container creation. A compromised orchestrator account or approved pipeline may still deploy a malicious container.
                                                                                                                                                                                                  References
                                                                                                                                                                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1612 Build Image on Host
                                                                                                                                                                                                    Comments
                                                                                                                                                                                                    Securing container-management APIs and restricting builds to controlled Infrastructure-as-Code or pipeline processes reduces unauthorized image construction on managed hosts. It does not prevent misuse by a compromised authorized build identity.
                                                                                                                                                                                                    References
                                                                                                                                                                                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1651 Cloud Administration Command
                                                                                                                                                                                                      Comments
                                                                                                                                                                                                      Version-controlled Infrastructure-as-Code and controlled cloud-administration interfaces reduce unreviewed interactive commands and restrict administration to approved mechanisms. The technique remains possible through a compromised privileged cloud account.
                                                                                                                                                                                                      References
                                                                                                                                                                                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1677 Poisoned Pipeline Execution
                                                                                                                                                                                                        Comments
                                                                                                                                                                                                        Version-controlled infrastructure and reviewed changes can prevent untrusted code or malicious Infrastructure-as-Code modifications from automatically reaching privileged deployment pipelines. Additional CI/CD isolation, branch protection, and secrets controls are required.
                                                                                                                                                                                                        References
                                                                                                                                                                                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1557.001 Name Resolution Poisoning and SMB Relay
                                                                                                                                                                                                          Comments
                                                                                                                                                                                                          SSH host-key validation, HTTPS certificate validation, SMB signing, and encrypted management channels reduce the ability to capture or relay administrative authentication. Disabling LLMNR, NBT-NS, and unnecessary SMB remains an important complementary control.
                                                                                                                                                                                                          References
                                                                                                                                                                                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1557.002 ARP Cache Poisoning
                                                                                                                                                                                                            Comments
                                                                                                                                                                                                            An adversary may still redirect management traffic through ARP poisoning, but properly validated SSH and HTTPS sessions protect the confidentiality and integrity of that traffic. The safeguard does not prevent the underlying ARP manipulation.
                                                                                                                                                                                                            References
                                                                                                                                                                                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1557.003 DHCP Spoofing
                                                                                                                                                                                                              Comments
                                                                                                                                                                                                              Secure protocols reduce credential theft and command manipulation even if DHCP spoofing redirects traffic. DHCP snooping and network-level controls are still required to prevent the spoofing behavior itself.
                                                                                                                                                                                                              References
                                                                                                                                                                                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1565 Data Manipulation
                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                Version-controlled configuration and authenticated encrypted management channels reduce unauthorized or undetected changes to enterprise configuration. The safeguard does not protect every type of business or application data.
                                                                                                                                                                                                                References
                                                                                                                                                                                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1565.001 Stored Data Manipulation
                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                  Version-controlled Infrastructure-as-Code provides history, review, comparison, and restoration for managed configurations, reducing the persistence of unauthorized configuration changes. This applies only where the affected configuration is actually managed as code.
                                                                                                                                                                                                                  References
                                                                                                                                                                                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1563 Remote Service Session Hijacking
                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                    Securely configuring remote services can reduce unnecessary sessions and restrict features that facilitate hijacking. Encryption does not prevent an adversary already executing on a system from taking control of an existing session.
                                                                                                                                                                                                                    References
                                                                                                                                                                                                                      CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1563.001 SSH Hijacking
                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                      Disabling SSH agent forwarding and tightly managing SSH configuration reduces some hijacking paths. It does not prevent local theft or reuse of an established SSH socket or session.
                                                                                                                                                                                                                      References
                                                                                                                                                                                                                        CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1563.002 RDP Hijacking
                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                        Secure RDP gateways and restricted administration reduce access to RDP sessions. They do not prevent a locally privileged adversary from taking control of an existing session.
                                                                                                                                                                                                                        References
                                                                                                                                                                                                                          CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1090.001 Internal Proxy
                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                          Secure SSH configuration can disable unnecessary forwarding and proxy features, reducing the ability to turn a managed asset into a pivot.
                                                                                                                                                                                                                          References
                                                                                                                                                                                                                            CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1572 Protocol Tunneling
                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                            Securely configuring SSH, VPN, and administrative tools can disable unnecessary port forwarding and tunneling functions. The safeguard does not prevent tunneling through an otherwise approved secure protocol when that capability is operationally required.
                                                                                                                                                                                                                            References
                                                                                                                                                                                                                              CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1484 Domain or Tenant Policy Modification
                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                              Version-controlled domain or tenant configuration can make unauthorized policy changes visible and allow restoration to approved state. Many identity policies are still managed directly through consoles or APIs rather than Infrastructure-as-Code.
                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1484.001 Group Policy Modification
                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                Managing Group Policy definitions through controlled configuration processes can identify or reverse unauthorized changes. Version control does not prevent direct modification by an account that retains write access to the policy.
                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                  CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1578 Modify Cloud Compute Infrastructure
                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                  Version-controlled Infrastructure-as-Code can define expected compute infrastructure and identify or reverse out-of-band changes. An adversary with sufficient cloud permissions may still modify resources directly.
                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                    CIS-4.6 Securely Manage Enterprise Assets and Software mitigates T1578.005 Modify Cloud Compute Configurations
                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                    Infrastructure-as-Code provides an approved baseline for quotas, instance settings, and compute configurations, allowing unauthorized drift to be identified or corrected.
                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021 Remote Services
                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                      A default-deny endpoint firewall directly restricts unsolicited remote-service connections and permits access only through explicitly approved services, ports, and management paths.
                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.001 Remote Desktop Protocol
                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                        Restricting TCP 3389 to approved management sources directly prevents unauthorized RDP connections and reduces RDP-based lateral movement.
                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.002 SMB/Windows Admin Shares
                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                          Blocking or tightly restricting TCP 445 and 139 directly impedes access to administrative shares and other SMB-based lateral movement paths.
                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.004 SSH
                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                            A default-deny firewall can block inbound SSH or restrict TCP 22 to approved management systems, directly limiting remote access to SSH-enabled end-user devices.
                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.005 VNC
                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                              VNC requires an accessible listener, commonly on TCP 5900 and related ports. Blocking those ports unless specifically authorized directly prevents unauthorized VNC access.
                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.006 Windows Remote Management
                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                Restricting TCP 5985 and 5986 to approved systems directly limits adversary use of WinRM for remote administration and lateral movement.
                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1210 Exploitation of Remote Services
                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                  Exploiting a remote service requires network reachability to that service. Default-deny endpoint rules remove unnecessary exposure and can restrict necessary services to trusted source systems.
                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1571 Non-Standard Port
                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                    Default-deny rules directly block arbitrary and unexpected ports unless they have been explicitly approved, limiting adversary communications over non-standard ports.
                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.003 Distributed Component Object Model
                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                      A firewall can restrict DCOM by controlling RPC endpoint mapper traffic and dynamic RPC ports. The relationship is direct, but implementation is more complex than filtering a single fixed port.
                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1048 Exfiltration Over Alternative Protocol
                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                        Restrictive outbound rules can prevent an endpoint from using unapproved protocols and ports for data exfiltration. The technique remains possible over protocols the organization must allow.
                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                          The firewall can block unapproved encrypted protocols, ports, or destinations used for exfiltration. It generally cannot identify malicious content inside an allowed encrypted connection.
                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                            Default-deny egress controls can prevent asymmetric encrypted sessions using unauthorized ports or services. Connections through an approved service may still succeed.
                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                              Unapproved outbound services and ports used for cleartext exfiltration can be directly blocked. Effectiveness decreases when the adversary uses an operationally required protocol.
                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071 Application Layer Protocol
                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                Endpoint firewalls can restrict which application protocols and services may communicate externally. The mapping is partial because common application protocols may need to remain available.
                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.002 File Transfer Protocols
                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                  FTP, SFTP, FTPS, and related file-transfer traffic can be denied or limited to approved destinations. File transfer over a generally permitted web protocol may remain possible.
                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.003 Mail Protocols
                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                    SMTP, IMAP, and POP traffic can be restricted to authorized mail infrastructure, reducing adversary use of attacker-controlled mail services for command and control.
                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.004 DNS
                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                      The firewall can force devices to use approved DNS resolvers and block direct DNS traffic to external systems. It does not by itself identify malicious data embedded in DNS traffic sent through an approved resolver.
                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.005 Publish/Subscribe Protocols
                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                        Default-deny policies can block MQTT and other publish/subscribe services unless they are explicitly required. An approved publish/subscribe service could still be misused.
                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1090.001 Internal Proxy
                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                          Restricting inbound listeners and lateral outbound connections makes it more difficult for a compromised endpoint to act as an unauthorized proxy for other systems.
                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1095 Non-Application Layer Protocol
                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                            A host firewall can deny unnecessary ICMP, GRE, raw IP, and other non-application protocols that adversaries may use for command and control.
                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1105 Ingress Tool Transfer
                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                              Default-deny egress policies can prevent compromised endpoints from retrieving payloads from unapproved systems, ports, or protocols. Transfers from an approved destination remain possible.
                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1187 Forced Authentication
                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                Blocking outbound SMB, NetBIOS, and unnecessary WebDAV traffic prevents many attempts to coerce an endpoint into authenticating to an attacker-controlled system. WebDAV over permitted web ports may require application-aware filtering.
                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1205 Traffic Signaling
                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                  Stateful default-deny firewalls can block unsolicited signaling traffic and the resulting unauthorized connections for some implementations of this technique. Effectiveness depends on the signaling mechanism.
                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1205.001 Port Knocking
                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                    A managed firewall can prevent unauthorized knock sequences from opening services and can preserve the default-deny state. The relationship becomes weaker if malware has already obtained privileges to modify firewall rules.
                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1219 Remote Access Tools
                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                      Application-aware or destination-restricted firewall policies can block communications to unauthorized remote-access services. Tools communicating through generally permitted HTTPS may bypass basic port filtering.
                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1219.002 Remote Desktop Software
                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                        The firewall can block application traffic, service endpoints, or dedicated ports associated with unauthorized remote-desktop products. Effectiveness depends on whether the product uses an otherwise permitted web connection.
                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1557 Adversary-in-the-Middle
                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                          Blocking unnecessary local-link, legacy name-resolution, and file-sharing protocols reduces the network conditions available for several adversary-in-the-middle behaviors. Other sub-techniques require switch or network-infrastructure protections.
                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1557.001 Name Resolution Poisoning and SMB Relay
                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                            Blocking LLMNR, NBT-NS, mDNS, NetBIOS, and unnecessary SMB traffic reduces poisoning and relay opportunities involving end-user devices. Disabling the protocols and enforcing SMB signing remain stronger complementary mitigations.
                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1570 Lateral Tool Transfer
                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                              Restricting SMB, WinRM, SSH, VNC, and other peer-to-peer services impedes common channels used to transfer adversary tools between endpoints.
                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1572 Protocol Tunneling
                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                Limiting approved ports, protocols, services, and destinations can prevent many unauthorized tunnels. Tunnels encapsulated within an approved HTTPS, DNS, or SSH connection may still succeed.
                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1071.001 Web Protocols
                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                  Destination-aware or application-aware firewall restrictions can disrupt web-based command and control, but basic port filtering cannot distinguish malicious traffic from legitimate browsing.
                                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1090 Proxy
                                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                                    Blocking known proxy infrastructure and unauthorized listeners can disrupt some proxy usage. Proxies operating through approved web services or destinations may remain accessible.
                                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1090.002 External Proxy
                                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                                      Firewall egress restrictions can block known or unauthorized external proxy destinations. External proxies commonly operate over permitted HTTP or HTTPS, limiting basic port-filtering effectiveness.
                                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1090.003 Multi-hop Proxy
                                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                                        Destination filtering may prevent access to identified anonymity or command-and-control infrastructure.
                                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1133 External Remote Services
                                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                                          Host firewall map help when an external remote service terminates directly on the end-user device. Many VPN, VDI, and access-gateway implementations terminate on centralized infrastructure outside the endpoint firewall's control.
                                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1197 BITS Jobs
                                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                                            Process-aware firewall rules may restrict BITS to approved destinations. The firewall does not prevent local creation or execution of a BITS job and may not distinguish BITS traffic over allowed web ports.
                                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1205.002 Socket Filters
                                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                                              Stateful firewall may block the triggering traffic or resulting connection. Socket filters may observe raw traffic or reuse an already permitted protocol, limiting the safeguard's effectiveness.
                                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1218.012 Verclsid
                                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                                Process-aware host firewall can prevent verclsid.exe from making outbound connections which is part of the outcomes of this technique. But it does not prevent the local signed-binary proxy-execution behavior that defines the technique.
                                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1219.001 IDE Tunneling
                                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                                  Firewall policy can block unapproved IDE-tunneling services or destinations. Developer endpoints may legitimately require the same HTTPS or SSH channels, reducing the usefulness of simple port filtering.
                                                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1499 Endpoint Denial of Service
                                                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                                                    Host firewall can discard traffic targeting blocked ports, protocols, or identified hostile sources, reducing malicious traffic processed by the endpoint.
                                                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1499.001 OS Exhaustion Flood
                                                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                                                      Dropping unwanted inbound traffic through dynamic host based firewalls may reduce some operating-system resource floods.
                                                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1499.002 Service Exhaustion Flood
                                                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                                                        The firewall can block floods against services that do not need to be exposed or restrict permitted sources.
                                                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1499.003 Application Exhaustion Flood
                                                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                                                          Application-aware or source-restricted firewall rules may reduce hostile requests reaching an exposed endpoint application. Basic port filtering cannot distinguish an exhaustion attack from legitimate requests to an explicitly allowed application service.
                                                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1537 Transfer Data to Cloud Account
                                                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                                                            Destination-aware egress rules may block connections to unauthorized cloud environments. Basic port filtering cannot determine which cloud account owns an HTTPS destination, and some transfers occur entirely within the cloud.
                                                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1563 Remote Service Session Hijacking
                                                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                                                              Blocking unnecessary remote-service connectivity reduces the opportunity to reach a session that could be hijacked.
                                                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1563.001 SSH Hijacking
                                                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                                                Restricting SSH reachability reduces remote paths to SSH sessions.
                                                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1563.002 RDP Hijacking
                                                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                                                  Restricting RDP to approved sources limits remote access to sessions.
                                                                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.007 Cloud Services
                                                                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                                                                    Destination-aware or application-aware endpoint firewall can restrict access to unauthorized cloud consoles, APIs, and command-line management endpoints.
                                                                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                                                                      CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1021.008 Direct Cloud VM Connections
                                                                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                                                                      Endpoint egress rules can prevent a compromised end-user device from reaching cloud-native VM connection services, APIs, or management endpoints. Cloud-native console access targets the cloud control plane and may not traverse the destination VM's host firewall.
                                                                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                                                                        CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1102 Web Service
                                                                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                                                                        An application-aware or destination-restricted endpoint firewall can block unauthorized web, cloud, file-sharing, or social-media services used for command and control.
                                                                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                                                                          CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1102.001 Dead Drop Resolver
                                                                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                                                                          A firewall that restricts outbound applications or destinations can prevent malware from contacting unauthorized web services used to retrieve secondary command-and-control addresses.
                                                                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                                                                            CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1102.002 Bidirectional Communication
                                                                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                                                                            Blocking unauthorized web-service destinations or preventing unapproved processes from accessing the network can disrupt bidirectional command-and-control communications.
                                                                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                                                                              CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1102.003 One-Way Communication
                                                                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                                                                              Endpoint firewall policy can prevent malware from sending data or retrieving instructions through unauthorized web services. One-way traffic to an approved and commonly used service may be difficult to distinguish from legitimate activity through basic port filtering.
                                                                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                                                                CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1498 Network Denial of Service
                                                                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                                                                A host firewall can discard traffic targeting blocked ports, protocols, or identified hostile sources, reducing the amount of malicious traffic processed by the endpoint.
                                                                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                                                                  CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1498.001 Direct Network Flood
                                                                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                                                                  A host firewall rules can block unnecessary protocols, targeted ports, or known attacking sources and may reduce endpoint resource consumption during smaller floods. High-volume floods normally require upstream filtering because traffic may saturate the connection before reaching the device.
                                                                                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                                                                                    CIS-4.5 Implement and Manage a Firewall on End-User Devices mitigates T1498.002 Reflection Amplification
                                                                                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                                                                                    A host firewall can drop unsolicited reflected traffic and deny unnecessary UDP protocols used in amplification attacks. It cannot recover bandwidth already consumed by the reflected traffic, and spoofed or distributed sources reduce source-based filtering effectiveness.
                                                                                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                                                                                      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.002 SMB/Windows Admin Shares
                                                                                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                                                                                      Blocking inbound SMB (TCP 445/139) is a primary server firewall function and directly reduces lateral movement via administrative shares.
                                                                                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                                                                                        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.001 Remote Desktop Protocol
                                                                                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                                                                                        Restricting TCP 3389 to authorized management hosts directly limits unauthorized RDP access to servers.
                                                                                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                                                                                          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021 Remote Services
                                                                                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                                                                                          A default-deny host firewall directly restricts inbound remote service access to servers, reducing opportunities for remote administration and lateral movement.
                                                                                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                                                                                            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.003 Distributed Component Object Model
                                                                                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                                                                                            DCOM relies on RPC communications that can be restricted through host firewall rules, limiting remote DCOM access to authorized systems. Dynamic RPC ports make the effectiveness dependent on careful firewall configuration.
                                                                                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                                                                                              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.004 SSH
                                                                                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                                                                                              A default-deny server firewall can directly restrict inbound SSH, normally TCP 22, to approved management systems. This reduces unauthorized remote administration and lateral movement against Linux, macOS, and other SSH-enabled servers.
                                                                                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                                                                                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.005 VNC
                                                                                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                                                                                A server firewall prevents unauthorized inbound VNC connections unless the relevant service and source systems are explicitly permitted.
                                                                                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                                                                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1021.006 Windows Remote Management
                                                                                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                                                                                  Restricting WinRM ports, commonly TCP 5985 and 5986, to approved administrative systems directly limits unauthorized remote management of servers.
                                                                                                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                                                                                                    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1048 Exfiltration Over Alternative Protocol
                                                                                                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                                                                                                    When outbound filtering is configured, a server firewall can block unauthorized protocols used to exfiltrate data. Effectiveness depends on whether egress rules are enforced rather than allowing unrestricted outbound traffic.
                                                                                                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                                                                                                      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
                                                                                                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                                                                                                      Outbound firewall restrictions can block unapproved encrypted non-C2 protocols or destinations used for exfiltration. The control is less effective when the traffic uses an explicitly permitted protocol and destination.
                                                                                                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                                                                                                        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
                                                                                                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                                                                                                        A managed egress policy can prevent servers from establishing unapproved asymmetric encrypted connections used to transfer data. This mitigation depends on restrictive outbound rules and destination controls.
                                                                                                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                                                                                                          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
                                                                                                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                                                                                                          A host firewall can block unauthorized outbound protocols and ports used for unencrypted data exfiltration. Exfiltration over an explicitly permitted service may remain possible.
                                                                                                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                                                                                                            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1071 Application Layer Protocol
                                                                                                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                                                                                                            Application-aware or restrictive outbound firewall rules can limit unauthorized HTTP, HTTPS, DNS, SMTP, and other application-layer communications used for command and control. A basic port-only policy provides limited protection when adversaries use permitted protocols.
                                                                                                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                                                                                                              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1090 Proxy
                                                                                                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                                                                                                              Restricting outbound server connections can prevent malware from reaching unauthorized proxy infrastructure or accepting proxy traffic on unapproved ports. Proxy activity over approved channels may still succeed.
                                                                                                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                                                                                                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1095 Non-Application Layer Protocol
                                                                                                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                                                                                                Host firewalls can restrict raw IP, ICMP, GRE, and other non-application-layer protocols used for command and control. The mitigation depends on denying protocols that the server does not explicitly require.
                                                                                                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                                                                                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1105 Ingress Tool Transfer
                                                                                                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                                                                                                  Restrictive outbound firewall rules can prevent a compromised server from downloading tools or payloads from unapproved external systems. The mapping is partial because transfers over approved destinations and protocols may still be possible.
                                                                                                                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                                                                                                                    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1133 External Remote Services
                                                                                                                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                                                                                                                    A default-deny host firewall reduces the exposure of externally accessible remote services by permitting only explicitly authorized ports, protocols, and source systems.
                                                                                                                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                                                                                                                      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1190 Exploit Public-Facing Application
                                                                                                                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                                                                                                                      A host firewall cannot remove vulnerabilities in a public-facing application, but it can ensure that only intended application ports are reachable and restrict access by source where operationally feasible. This reduces unnecessary exposure and possible exploitation paths.
                                                                                                                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                                                                                                                        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1205.001 Port Knocking
                                                                                                                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                                                                                                                        Port knocking relies on specific traffic patterns that cause a firewall or related mechanism to expose a service port. Managed default-deny rules and monitoring of unauthorized firewall changes can restrict the trigger traffic and prevent unapproved ports from being opened.
                                                                                                                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                                                                                                                          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1210 Exploitation of Remote Services
                                                                                                                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                                                                                                                          Exploitation of a remote service requires network reachability to the vulnerable service. A default-deny server firewall reduces the number of reachable services and limits access to authorized source systems.
                                                                                                                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                                                                                                                            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1219 Remote Access Tools
                                                                                                                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                                                                                                                            Host firewall rules can block inbound or outbound communications associated with unauthorized remote access software. The firewall does not prevent the software from being installed or executed when it communicates over an allowed channel.
                                                                                                                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                                                                                                                              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1537 Transfer Data to Cloud Account
                                                                                                                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                                                                                                                              Egress filtering can restrict server connections to unauthorized cloud services or accounts, making cloud-based data transfer more difficult. The mitigation depends on destination-aware outbound controls.
                                                                                                                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                                                                                                                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1557.001 Name Resolution Poisoning and SMB Relay
                                                                                                                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                                                                                                                Blocking unnecessary LLMNR, NBT-NS, mDNS, NetBIOS, and SMB traffic can reduce name-resolution poisoning and relay opportunities involving servers. Disabling the protocols and enforcing SMB signing remain stronger primary mitigations.
                                                                                                                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                                                                                                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1557.002 ARP Cache Poisoning
                                                                                                                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                                                                                                                  A host firewall may restrict follow-on connections created through ARP poisoning, but it has limited ability to prevent manipulation of Layer 2 address resolution itself. This is therefore a weak and environment-dependent mitigation.
                                                                                                                                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                                                                                                                                    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1557.003 DHCP Spoofing
                                                                                                                                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                                                                                                                                    A host firewall may limit some follow-on communications after a malicious DHCP configuration is accepted, but it does not directly prevent DHCP spoofing. Network access controls and DHCP protections are the primary mitigations.
                                                                                                                                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                                                                                                                                      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1570 Lateral Tool Transfer
                                                                                                                                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                                                                                                                                      Lateral tool transfers often rely on SMB, WinRM, SSH, or other network services that are directly governed by server firewall rules. Restricting those services to approved systems impedes common transfer channels.
                                                                                                                                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                                                                                                                                        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1571 Non-Standard Port
                                                                                                                                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                                                                                                                                        A default-deny firewall blocks communication over arbitrary or non-standard ports unless they are explicitly permitted, directly limiting adversary use of unexpected ports.
                                                                                                                                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                                                                                                                                          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1572 Protocol Tunneling
                                                                                                                                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                                                                                                                                          Restricting permitted ports, protocols, and destinations can impede protocol tunneling from compromised servers. Tunnels carried inside an explicitly allowed protocol may still bypass simple port-based filtering.
                                                                                                                                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                                                                                                                                            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1602.001 SNMP (MIB Dump)
                                                                                                                                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                                                                                                                                            Blocking unnecessary SNMP traffic and restricting authorized SNMP sources reduces the ability to query management information from servers or server-hosted management services. The applicability depends on whether the server exposes SNMP.
                                                                                                                                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                                                                                                                                              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1686 Disable or Modify System Firewall
                                                                                                                                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                                                                                                                                              Adversaries may disable or alter host firewall configurations to expose services or enable unrestricted network communication, directly undermining the safeguard. Implementing and actively managing the firewall establishes the required configuration and supports identifying or correcting unauthorized changes.
                                                                                                                                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                                                                                                                                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1686.001 Cloud Firewall
                                                                                                                                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                                                                                                                                This sub-technique concerns changes to cloud firewall rules or security groups rather than a host-based firewall installed on a server. The relationship to Safeguard 4.4 is therefore indirect and primarily relevant where server firewall management also encompasses associated cloud firewall controls.
                                                                                                                                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                                                                                                                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1686.002 Network Device Firewall
                                                                                                                                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                                                                                                                                  This sub-technique targets firewalls implemented on network infrastructure rather than host-based firewalls on servers. Its relationship to Safeguard 4.4 is weak and applies only where the server firewall management process also governs supporting network firewall policy.
                                                                                                                                                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                                                                                                                                                    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1686.003 Windows Host Firewall
                                                                                                                                                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                                                                                                                                                    This sub-technique explicitly covers disabling or modifying the Windows host firewall, including changing profiles or rules to expose services or permit command-and-control traffic. Implementing and managing the required firewall configuration helps identify, prevent, or reverse unauthorized changes.
                                                                                                                                                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                                                                                                                                                      CIS-4.7 Manage Default Accounts on Enterprise Assets and Software mitigates T1586.003 Cloud Accounts
                                                                                                                                                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                                                                                                                                                      Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.
                                                                                                                                                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                                                                                                                                                        CIS-4.7 Manage Default Accounts on Enterprise Assets and Software mitigates T1078.003 Local Accounts
                                                                                                                                                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                                                                                                                                                        Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.
                                                                                                                                                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                                                                                                                                                          CIS-4.7 Manage Default Accounts on Enterprise Assets and Software mitigates T1078.002 Domain Accounts
                                                                                                                                                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                                                                                                                                                          Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.
                                                                                                                                                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                                                                                                                                                            CIS-4.7 Manage Default Accounts on Enterprise Assets and Software mitigates T1078.001 Default Accounts
                                                                                                                                                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                                                                                                                                                            Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.
                                                                                                                                                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                                                                                                                                                              CIS-4.7 Manage Default Accounts on Enterprise Assets and Software mitigates T1078 Valid Accounts
                                                                                                                                                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                                                                                                                                                              Default accounts are defined as built-in or factory/provider-set accounts across systems, software, and devices. Managing, changing default passwords, disabling state accounts, or otherwise hardening them through additional mechanisms directly constrains an adversary's abuse of the valid account technique.
                                                                                                                                                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                                                                                                                                                CIS-4.3 Configure Automatic Session Locking on Enterprise Assets mitigates T1078 Valid Accounts
                                                                                                                                                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                The safeguard forces a renewed authentication checkpoint after inactivity and therefore reduces any possibility of opportunistic use of a still-authenticated user on an open unlocked enterprise asset.
                                                                                                                                                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                                                                                                                                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1041 Exfiltration Over C2 Channel
                                                                                                                                                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                  This technique may be mitigated depending on where ingress and egress is tightly controlled. For example, the use network signatures such as IP addresses or domain names to identify traffic for specific adversary malware can be used to mitigate activity at the network level.
                                                                                                                                                                                                                                                                                                                                                                                                                                  References
                                                                                                                                                                                                                                                                                                                                                                                                                                    CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1205.002 Socket Filters
                                                                                                                                                                                                                                                                                                                                                                                                                                    Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                    ATT&CK mentions that the mitigation of some variants of this technique could be achieved through the use of stateful firewalls, depending upon how it is implemented.
                                                                                                                                                                                                                                                                                                                                                                                                                                    References
                                                                                                                                                                                                                                                                                                                                                                                                                                      CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1552.005 Cloud Instance Metadata API
                                                                                                                                                                                                                                                                                                                                                                                                                                      Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                      ATT&CK mentions to limit access to the Instance Metadata API using a host-based firewall such as iptables. A properly configured Web Application Firewall (WAF) may help prevent external adversaries from exploiting Server-side Request Forgery (SSRF) attacks that allow access to the Cloud Instance Metadata API.
                                                                                                                                                                                                                                                                                                                                                                                                                                      References
                                                                                                                                                                                                                                                                                                                                                                                                                                        CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1218.012 Verclsid
                                                                                                                                                                                                                                                                                                                                                                                                                                        Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                        Consider modifying host firewall rules to prevent egress traffic from verclsid.exe.
                                                                                                                                                                                                                                                                                                                                                                                                                                        References
                                                                                                                                                                                                                                                                                                                                                                                                                                          CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1090.003 Multi-hop Proxy
                                                                                                                                                                                                                                                                                                                                                                                                                                          Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                          This technique may be lessened or mitigated though the use of firewall policy that constrains relay and redirect paths.
                                                                                                                                                                                                                                                                                                                                                                                                                                          References
                                                                                                                                                                                                                                                                                                                                                                                                                                            CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1197 BITS Jobs
                                                                                                                                                                                                                                                                                                                                                                                                                                            Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                            Modify network and/or host firewall rules, as well as other network controls, to only allow legitimate BITS traffic.
                                                                                                                                                                                                                                                                                                                                                                                                                                            References
                                                                                                                                                                                                                                                                                                                                                                                                                                              CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1205 Traffic Signaling
                                                                                                                                                                                                                                                                                                                                                                                                                                              Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                              ATT&CK mentions that the mitigation of some variants of this technique could be achieved through the use of stateful firewalls, depending upon how it is implemented.
                                                                                                                                                                                                                                                                                                                                                                                                                                              References
                                                                                                                                                                                                                                                                                                                                                                                                                                                CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1071.001 Web Protocols
                                                                                                                                                                                                                                                                                                                                                                                                                                                Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                                Adversaries use web protocols to blend with normal traffic. A server firewall can partially restrict which destinations, ports, and web services a server may contact, though it will not stop all HTTP/S abuse.
                                                                                                                                                                                                                                                                                                                                                                                                                                                References
                                                                                                                                                                                                                                                                                                                                                                                                                                                  CIS-4.4 Implement and Manage a Firewall on Servers mitigates T1563.002 RDP Hijacking
                                                                                                                                                                                                                                                                                                                                                                                                                                                  Comments
                                                                                                                                                                                                                                                                                                                                                                                                                                                  Adversaries leverage RDP if it is reachable. Firewall rules are among the most direct ways to prevent unauthorized RDP reachability to servers.
                                                                                                                                                                                                                                                                                                                                                                                                                                                  References

                                                                                                                                                                                                                                                                                                                                                                                                                                                    Capabilities