Develop a plan to continuously assess and track vulnerabilities on all enterprise assets within the enterprise’s infrastructure, in order to remediate, and minimize, the window of opportunity for attackers. Monitor public and private industry sources for new threat and vulnerability information.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1602 | Data from Configuration Repository |
Comments
When known vulnerabilities affect network-device software, system images, or management components that expose configuration repositories, applying patches or supported software upgrades removes those weaknesses and reduces vulnerability dependent access to configuration data.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1602.001 | SNMP (MIB Dump) |
Comments
When known vulnerabilities affect SNMP-enabled network-device software or system images, applying patches or supported software upgrades removes those weaknesses and reduces opportunities to collect MIB data through vulnerable implementations.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1602.002 | Network Device Configuration Dump |
Comments
When known vulnerabilities affect network-device software or system images used to expose or retrieve device configurations, applying patches or supported software upgrades removes those weaknesses and reduces exploit-based opportunities to obtain configuration data.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
Remediating known vulnerabilities in kernels, drivers, services, and privileged applications directly removes exploit paths that adversaries could use to obtain elevated privileges. This does not prevent exploitation of unknown vulnerabilities or weaknesses that remain outside the remediation scope.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1189 | Drive-by Compromise |
Comments
Remediating detected vulnerabilities in browsers, plug-ins, and other client software reduces successful exploitation when users visit malicious or compromised websites. This does not prevent drive-by activity that relies on zero-day vulnerabilities, social engineering, or malicious content that does not require exploitation.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Correcting identified vulnerabilities in internet-facing applications, services, and appliances directly removes known initial-access paths. Remediation may include patching, upgrading, replacing, disabling, or isolating the vulnerable component.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1203 | Exploitation for Client Execution |
Comments
Remediating known vulnerabilities in browsers, Office products, PDF readers, and other client applications reduces successful exploit-based code execution. This does not prevent exploitation of unknown vulnerabilities or unremediated unsupported software.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1210 | Exploitation of Remote Services |
Comments
Patching or otherwise correcting vulnerabilities in remotely reachable services removes known lateral-movement and remote-execution paths.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1211 | Exploitation for Stealth |
Comments
Remediation can remove vulnerabilities in operating systems, applications, security tools, and logging components that adversaries could exploit to conceal activity or impair visibility. This relationship applies only when the stealth behavior depends on an identified vulnerability.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1212 | Exploitation for Credential Access |
Comments
Correcting vulnerabilities in authentication systems, credential-handling software, kernels, and related components prevents exploit-based access to credentials.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1611 | Escape to Host |
Comments
Remediating vulnerabilities in host kernels, hypervisors, and container runtimes reduces successful container or virtual-machine escape. This does not prevent escapes caused solely by unsafe configuration, privileged containers, or exposed management sockets.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1495 | Firmware Corruption |
Comments
Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1542 | Pre-OS Boot |
Comments
This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1542.001 | System Firmware |
Comments
Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1542.002 | Component Firmware |
Comments
Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1548 | Abuse Elevation Control Mechanism |
Comments
This is a partial parent mapping because remediation can remove known vulnerabilities and implementation weaknesses used to bypass elevation controls.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1548.002 | Bypass User Account Control |
Comments
Applying current Windows security updates and supported platform upgrades removes known UAC-bypass and auto-elevation weaknesses. This does not prevent every UAC bypass or activity performed by an account that already has administrative privileges.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1546 | Event Triggered Execution |
Comments
Remediation can remove specific vulnerable event-triggered execution mechanisms, including known AppInit DLL and Application Shimming behaviors. Most event-triggered persistence also depends on configuration and permissions.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1546.010 | AppInit DLLs |
Comments
Upgrading or patching affected Windows platforms removes older AppInit DLL behaviors and weaknesses that adversaries could abuse for persistence or execution. Configuration controls remain necessary where the feature is still supported.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1546.011 | Application Shimming |
Comments
Applying the relevant Windows security updates removes known auto-elevation behavior associated with application-shim installation. Remediation does not prevent all shim abuse by an adversary that already has sufficient privileges.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1552 | Unsecured Credentials |
Comments
Remediation can correct specific software weaknesses that store credentials insecurely, including the Group Policy Preferences implementation. Most unsecured credential exposures require separate configuration, access-control, or secret-management controls.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1552.006 | Group Policy Preferences |
Comments
Applying the applicable Microsoft security update prevents newly configured Group Policy Preferences from storing credentials in a recoverable form. Previously stored credentials may still require separate identification, removal, and rotation.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1550.002 | Pass the Hash |
Comments
Applying relevant Windows security updates can restrict default remote access available to local administrator accounts and reduce some pass-the-hash activity. Remediation does not eliminate hash theft, NTLM use, or pass-the-hash through accounts that retain applicable privileges.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1574 | Hijack Execution Flow |
Comments
Remediation can correct vulnerable library-loading behavior and unsafe execution paths in affected software. Many other execution-flow hijacking methods depend on writable paths, permissions, or configuration rather than a software vulnerability.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1574.001 | DLL |
Comments
Vendor patches can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. This does not prevent DLL hijacking in unsupported software.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1072 | Software Deployment Tools |
Comments
Remediating vulnerabilities in centralized software-deployment and endpoint-management products prevents exploit-based privileged access and enterprise-wide remote execution. This does not prevent abuse through stolen administrator credentials or legitimate product functionality.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1137 | Office Application Startup |
Comments
This is a partial parent mapping because product remediation can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup methods may require configuration and application-control safeguards.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1137.003 | Outlook Forms |
Comments
Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. Unsupported or unpatched Outlook installations remain exposed.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1137.004 | Outlook Home Page |
Comments
Applying the relevant Outlook updates removes or restricts the legacy Home Page functionality used to load malicious content when a folder is accessed.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1137.005 | Outlook Rules |
Comments
Applying current Outlook updates reduces abuse of rule-triggered execution mechanisms. This does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1555 | Credentials from Password Stores |
Comments
Remediation can correct vulnerabilities in browsers, password managers, and other credential-storage applications. It does not address every operating-system, application, or cloud credential store.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Correcting identified browser vulnerabilities reduces exploit-based extraction of stored passwords, tokens, and other authentication data. This does not prevent theft by malware that already has sufficient access to the browser profile.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1555.005 | Password Managers |
Comments
Updating, upgrading, or replacing a vulnerable password-manager product removes known credential-exposure vulnerabilities. This does not prevent theft through a compromised master password, an unlocked vault, or an authorized session.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1539 | Steal Web Session Cookie |
Comments
Remediating vulnerabilities in browsers and related applications reduces exploit-based extraction of session cookies. This does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.
References
|
| CIS-7.7 | Remediate Detected Vulnerabilities | mitigates | T1686.002 | Network Device Firewall |
Comments
Applying security patches or supported software upgrades to vulnerable firewall appliances and network-device operating environments reduces exploit-based modification or disabling of firewall policy. This does not prevent changes made with valid administrative access.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1189 | Drive-by Compromise |
Comments
Automated application patching keeps browsers and browser plug-ins current, removing known vulnerabilities that malicious or compromised websites could exploit for client execution. The safeguard does not prevent drive-by attacks relying on zero-day vulnerabilities, social engineering, or malicious browser notifications.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1190 | Exploit Public-Facing Application |
Comments
Automated application patching removes known vulnerabilities from externally exposed web applications, databases, VPN products, management platforms, and other application services. It does not correct insecure configurations, unsupported custom code, or vulnerabilities for which no vendor patch exists.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1203 | Exploitation for Client Execution |
Comments
Applying current security updates to browsers, Office products, PDF readers, and other client applications reduces successful exploitation of known application vulnerabilities. Operating-system vulnerabilities and unknown application vulnerabilities require separate protections.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1072 | Software Deployment Tools |
Comments
Patching centralized deployment and endpoint-management applications removes known vulnerabilities that could provide adversaries with privileged access or enterprise-wide remote execution. The safeguard does not prevent abuse through stolen administrator credentials or legitimate product functionality.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1137.003 | Outlook Forms |
Comments
Applying current Outlook security updates can disable or restrict custom forms that adversaries may abuse for persistence and execution. The safeguard does not prevent all malicious Office content or abuse of an unpatched or unsupported Outlook installation.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1137.004 | Outlook Home Page |
Comments
Outlook application updates remove or restrict the legacy Home Page feature used to load malicious content when a folder is accessed. The relationship depends on deploying the relevant Outlook security updates.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1137.005 | Outlook Rules |
Comments
Applying current Outlook patches reduces abuse of rule-triggered Visual Basic and related persistence mechanisms. It does not prevent all malicious mailbox-rule activity or activity performed through valid cloud-account access.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Automated browser updates remove known vulnerabilities that could expose stored passwords, tokens, or browser authentication data. Patching does not prevent credential theft by malware already executing with sufficient access to the browser profile.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1555.005 | Password Managers |
Comments
Automated updates to password-manager applications remove known vulnerabilities that could expose stored or decrypted credentials.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1574.001 | DLL |
Comments
Applying vendor patches to vulnerable applications can correct unsafe DLL search paths, missing library references, and other side-loading conditions that allow an adversary-controlled DLL to execute. It does not prevent DLL hijacking in unpatched software or through writable application directories.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
Application patching removes known vulnerabilities in privileged applications, agents, services, and third-party drivers that could allow escalation of privileges. Operating-system and kernel vulnerabilities are addressed separately through operating-system patch management.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1210 | Exploitation of Remote Services |
Comments
Application patching removes known vulnerabilities from third-party database, web, virtualization, file-transfer, remote-management, and similar services used for lateral movement. Vulnerabilities in operating-system-supplied remote services require operating-system patching.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1211 | Exploitation for Stealth |
Comments
Updating applications and security products can remove known vulnerabilities that adversaries could exploit to conceal activity or impair application-level visibility. Operating-system and kernel implementations are outside this safeguard's application scope.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1212 | Exploitation for Credential Access |
Comments
Application patching removes known vulnerabilities in authentication products, browsers, identity applications, network-management products, and other credential-handling software. Vulnerabilities in operating-system authentication components require operating-system patching.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1137 | Office Application Startup |
Comments
Application patches can restrict specific Outlook startup and persistence mechanisms, including Outlook Forms, Home Page, and Rules. Other Office startup mechanisms that rely on macros, add-ins, templates, or configuration changes are not necessarily prevented by patching.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1555 | Credentials from Password Stores |
Comments
Application patching can remove browser and password-manager vulnerabilities used to extract stored credentials. Operating-system credential stores and cloud secrets platforms may require different update mechanisms.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1574 | Hijack Execution Flow |
Comments
Application updates can correct unsafe DLL search paths and other software defects that permit DLL side-loading. Most other execution-flow hijacking implementations require permissions, application control, or operating-system configuration protections.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1176 | Software Extensions |
Comments
Updating browsers and IDEs can remove insecure extension mechanisms, but it does not prevent a user or adversary from installing an otherwise permitted malicious extension.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1176.001 | Browser Extensions |
Comments
Automated browser updates can remove deprecated extension-loading mechanisms and strengthen extension permission and installation controls. Extension allowlisting and trusted-source restrictions remain necessary to prevent malicious extensions.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1176.002 | IDE Extensions |
Comments
Updating IDE applications can correct vulnerabilities in extension loading and provide improved extension security controls. The safeguard does not independently prevent installation of a malicious or compromised extension from an approved marketplace.
References
|
| CIS-7.4 | Perform Automated Application Patch Management | mitigates | T1539 | Steal Web Session Cookie |
Comments
Updating browsers, password managers, and related applications reduces exploitation of known vulnerabilities used to extract session cookies. It does not prevent cookie theft by malware or an adversary that already has sufficient access to browser storage or memory.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1495 | Firmware Corruption |
Comments
Applying BIOS, UEFI, device, and component firmware updates can remove vulnerabilities that permit unauthorized firmware modification or corruption. Other protections are still required against adversaries that already possess authorized firmware-update capability.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1542 | Pre-OS Boot |
Comments
This is a partial parent mapping because remediation of vulnerable BIOS, UEFI, and component firmware can remove known pre-OS exploitation paths. Other pre-OS persistence methods may require boot-integrity, signing, and hardware-root-of-trust controls.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1542.001 | System Firmware |
Comments
Applying current BIOS and UEFI updates directly remediates known system-firmware vulnerabilities that could enable persistence or execution below the operating system.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1542.002 | Component Firmware |
Comments
Firmware updates for storage devices, controllers, network adapters, and other components remove known vulnerabilities that could allow malicious component-level persistence or modification.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1176.002 | IDE Extensions |
Comments
ATT&CK mentions ensuring operating systems and software are using the most current version.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1176.001 | Browser Extensions |
Comments
ATT&CK mentions ensuring operating systems and software are using the most current version.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1176 | Software Extensions |
Comments
ATT&CK mentions ensuring operating systems and software are using the most current version.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1072 | Software Deployment Tools |
Comments
ATT&CK mentions having a patch deployment systems regularly to prevent potential remote access through Exploitation for Privilege Escalation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1195.002 | Compromise Software Supply Chain |
Comments
ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1195.001 | Compromise Software Dependencies and Development Tools |
Comments
ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1195 | Supply Chain Compromise |
Comments
ATT&CK mentions a patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1546 | Event Triggered Execution |
Comments
OS patches that address specific Windows event-triggered execution mechanisms, particularly Application Shimming.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1552 | Unsecured Credentials |
Comments
ATT&CK specifically recommends applying patch KB2962486 which prevents credentials from being stored in GPPs.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1686.002 | Network Device Firewall |
Comments
ATT&CK specifically recommends maintaining network firewalls with current security patches. Include this where network firewall appliances and their operating systems are considered enterprise assets covered by the automated an OS-patching process.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1548 | Abuse Elevation Control Mechanism |
Comments
OS updates can close vulnerabilities and implementation weaknesses used to bypass native elevation mechanisms, especially UAC, but they do not prevent abuse of sudo permissions, temporary cloud elevation, or other correctly functioning mechanisms.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1211 | Exploitation for Stealth |
Comments
OS updates can correct vulnerabilities in kernels, logging components, security tools, and system services that could be exploited to conceal activity. Application-specific exploitation remains outside 7.3.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1210 | Exploitation of Remote Services |
Comments
OS patching directly addresses vulnerabilities in operating-system services such as SMB, RDP, RPC, SSH components, and other built-in remote services. The technique also includes independently installed applications that would fall under application patch management instead.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1550.002 | Pass the Hash |
Comments
ATT&CK identifies Windows 7 and higher system patch KB2871997 as limiting default access available to local administrator accounts, reducing some pass-the-hash lateral movement.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1552.006 | Group Policy Preferences |
Comments
ATT&CK identifies Windows patch KB2962486, which prevents credentials from being stored in Group Policy Preferences. This is a direct OS-patch implementation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1546.011 | Application Shimming |
Comments
ATT&CK identifies a specific Windows patch, KB3045645, that removes an auto-elevation behavior used to abuse application shims. Automated OS patch deployment directly applies this type of mitigation.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1548.002 | Bypass User Account Control |
Comments
Windows updates include changes that close known UAC-bypass methods and improve elevation protections. ATT&CK directly recommends maintaining the latest Windows version and patch level.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1611 | Escape to Host |
Comments
Container and VM escapes may exploit vulnerabilities in the host kernel, hypervisor, or operating-system components. ATT&CK explicitly recommends keeping hosts current with security patches.
References
|
| CIS-7.3 | Perform Automated Operating System Patch Management | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
OS and kernel vulnerabilities are a primary means of escalating from user privileges to SYSTEM or root. Automated OS patching directly removes known vulnerable code paths. ATT&CK specifically recommends patch management for internal endpoints and servers.
References
|
| Capability ID | Capability Name | Number of Mappings |
|---|---|---|
| CIS-7.7 | Remediate Detected Vulnerabilities | 35 |
| CIS-7.4 | Perform Automated Application Patch Management | 21 |
| CIS-7.3 | Perform Automated Operating System Patch Management | 23 |