Improve protections and detections of threats from email and web vectors, as these are opportunities for attackers to manipulate human behavior through direct engagement.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1566.001 | Spearphishing Attachment |
Comments
Email-server attachment scanning and sandboxing can identify, quarantine, or remove malicious attachments before they reach the recipient.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1204.002 | Malicious File |
Comments
Removing a malicious attachment before delivery prevents the user from opening the file and initiating its execution chain. The safeguard is limited to malicious files delivered through the protected email environment.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1203 | Exploitation for Client Execution |
Comments
Email sandboxing can detonate weaponized Office documents, PDFs, archives, and other attachments to identify exploit behavior before delivery.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1221 | Template Injection |
Comments
Email detonation chambers can open suspicious documents and observe attempts to retrieve or execute remote templates and payloads before the message reaches the recipient.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.012 | LNK Icon Smuggling |
Comments
Email scanning can identify suspicious LNK attachments and inspect icon-location or target fields that reference remote payloads.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1036.008 | Masquerade File Type |
Comments
Anti-malware scanners can compare file headers, MIME types, extensions, and content to detect attachments disguised as benign file formats.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1566 | Phishing |
Comments
Email-server anti-malware directly addresses malicious attachments.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1204 | User Execution |
Comments
Blocking malicious attachments prevents one major form of user execution.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027 | Obfuscated Files or Information |
Comments
Email anti-malware can use static, heuristic, and behavioral analysis to identify obfuscated files before delivery.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.002 | Software Packing |
Comments
Heuristic scanning and sandbox detonation can identify packed executables attached to messages, even when packing changes their static signature.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.006 | HTML Smuggling |
Comments
A sandbox capable of executing active HTML attachments may detect JavaScript that reconstructs and writes a malicious payload to disk.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.009 | Embedded Payloads |
Comments
Attachment scanners and sandboxes can identify malicious payloads hidden within documents, scripts, executables, or other carrier files.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.013 | Encrypted/Encoded File |
Comments
Anti-malware can identify encoded or high-entropy attachments and may block encrypted archives that cannot be inspected.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.015 | Compression |
Comments
Email anti-malware capable of recursively unpacking ZIP, RAR, 7z, self-extracting archives, and nested archives can identify malicious files before delivery.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1027.017 | SVG Smuggling |
Comments
A sandbox that renders SVG attachments and executes their embedded scripts may identify payload construction or malicious follow-on behavior.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1036 | Masquerading |
Comments
Anti-malware analysis can identify malicious attachments whose content, signature, or behavior conflicts with their apparent name or file type.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1036.007 | Double File Extension |
Comments
Email gateways can inspect the complete filename and actual file type rather than relying on the first visible extension, allowing attachments such as invoice.pdf.exe or report.pdf.lnk to be blocked.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059.005 | Visual Basic |
Comments
Email anti-malware and sandboxing can analyze Visual Basic scripts and macro-enabled attachments and quarantine files that exhibit malicious behavior. This does not prevent Visual Basic abuse originating outside email.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059 | Command and Scripting Interpreter |
Comments
Email anti-malware can block suspicious script attachments before they reach an interpreter. Most command and scripting activity occurs after compromise or through channels unrelated to email.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059.001 | PowerShell |
Comments
Email scanning or sandboxing may identify PowerShell script attachments or documents that launch PowerShell.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059.006 | Python |
Comments
Email anti-malware may quarantine malicious Python scripts or packed Python payloads sent specifically as email attachments. Python activity originating from installed tools or post-compromise execution remains unaffected.
References
|
| CIS-9.7 | Deploy and Maintain Email Server Anti-Malware Protections | mitigates | T1059.007 | JavaScript |
Comments
A sandbox may execute JavaScript, JScript, HTA, HTML, or SVG attachments and identify malicious file creation or process execution. Depends on the email security product supporting active-content detonation.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1176.001 | Browser Extensions |
Comments
Browser extension allowlists, denylists, installation restrictions, and removal of unauthorized extensions directly prevent malicious browser extensions from establishing persistence or abusing inherited browser permissions.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1137.006 | Add-ins |
Comments
Disabling unauthorized Outlook add-ins prevents those add-ins from automatically loading code when the email client starts. This directly reduces persistence through email-client add-on functionality.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1176 | Software Extensions |
Comments
This technique includes browser extensions, which are directly addressed by the safeguard.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1137 | Office Application Startup |
Comments
Restricting email-client add-ins mitigates the add-in portion of this parent technique.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1539 | Steal Web Session Cookie |
Comments
Malicious browser extensions may access browser cookies and session information. Restricting extensions removes one important cookie-theft path.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Malicious extensions may access credentials stored in browsers. Extension restrictions reduce that attack surface, but malware already executing with access to the browser profile may still extract stored credentials.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1189 | Drive-by Compromise |
Comments
Removing unnecessary or vulnerable browser plug-ins reduces components that a malicious website can enumerate and exploit during a drive-by attack.
References
|
| CIS-9.4 | Restrict Unnecessary or Unauthorized Browser and Email Client Extensions | mitigates | T1203 | Exploitation for Client Execution |
Comments
Uninstalling unnecessary browser or email-client plug-ins removes potential client-side exploitation targets.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1071.004 | DNS |
Comments
DNS filtering can prevent resolution of known malicious domains used for DNS-based command and control and can sinkhole requests before an endpoint reaches adversary infrastructure.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1189 | Drive-by Compromise |
Comments
Blocking known malicious or compromised domains prevents browsers from reaching websites used to exploit users or deliver malicious content.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1566.002 | Spearphishing Link |
Comments
DNS filtering can block the destination of a malicious link delivered through email before the user reaches a credential-harvesting page, exploit site, or malware download. Newly registered, compromised, or uncategorized domains may initially evade filtering.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1204.001 | Malicious Link |
Comments
Even when a user clicks a malicious link, DNS filtering can prevent successful navigation when the destination domain is known to be malicious.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1071 | Application Layer Protocol |
Comments
DNS filtering directly affects DNS and can also prevent connections to malicious domains used for web-based application-layer command and control.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1071.001 | Web Protocols |
Comments
DNS filtering can prevent HTTP, HTTPS, and WebSocket command-and-control connections when the destination domain has been classified as malicious.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1048 | Exfiltration Over Alternative Protocol |
Comments
DNS and other domain-based destinations may be used as alternative exfiltration channels. DNS filtering only impedes implementations that depend on resolving a known malicious domain.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
Comments
DNS can carry encoded exfiltrated data over an unencrypted non-command-and-control protocol. Blocking resolution of an adversary-controlled domain can interrupt DNS-based exfiltration, although newly registered or uncategorized domains may initially be allowed.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1105 | Ingress Tool Transfer |
Comments
DNS filtering can prevent a compromised endpoint from resolving known malicious domains used to host tools or secondary payloads. Transfers over direct IP addresses, approved cloud services, compromised legitimate domains, or uncategorized domains may still succeed.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1566 | Phishing |
Comments
DNS filtering materially mitigates phishing that directs users to malicious domains. It does not mitigate phishing attachments, voice phishing, or messages that do not require visiting a domain.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1572 | Protocol Tunneling |
Comments
DNS filtering can block tunnels that depend on resolving known malicious domains, including some DNS and web-based tunnels. Tunnels using direct IP addresses, trusted domains, or infrastructure not yet classified as malicious may still succeed.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1568 | Dynamic Resolution |
Comments
DNS sinkholing and reputation-based filtering can prevent resolution of identified dynamic-DNS and generated domains used to reestablish command and control.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1568.002 | Domain Generation Algorithms |
Comments
DNS filtering services may block or sinkhole known and predicted algorithmically generated domains, for example those that have high entropy in the name.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
Comments
DNS filtering can block resolution of a known malicious exfiltration destination regardless of whether the transmitted data is encrypted.
References
|
| CIS-9.2 | Use DNS Filtering Services | mitigates | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
Comments
Blocking a known malicious destination domain may interrupt an asymmetric encrypted exfiltration channel.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1212 | Exploitation for Credential Access |
Comments
Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1068 | Exploitation for Privilege Escalation |
Comments
Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1211 | Exploitation for Stealth |
Comments
Browsers and email clients are common targets for vulnerabilities. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1189 | Drive-by Compromise |
Comments
Fully supported, current browsers contain vendor patches and modern security features that reduce successful exploitation when users visit compromised or malicious websites.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1203 | Exploitation for Client Execution |
Comments
Browsers and email clients are common targets for vulnerabilities that provide adversary code execution. Requiring the latest vendor-supported versions directly reduces exposure to known client-software vulnerabilities.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1137.003 | Outlook Forms |
Comments
Current Outlook versions include vendor changes that restrict or warn about custom Outlook forms that may otherwise be abused for persistence and execution. The safeguard ensures those security updates are present.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1137.004 | Outlook Home Page |
Comments
Microsoft updates removed or restricted the legacy Outlook Home Page functionality used for persistence. Preventing obsolete Outlook versions from executing directly prevents continued access to older vulnerable implementations.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1137.005 | Outlook Rules |
Comments
Vendor patches address Outlook mechanisms that adversaries may use to establish rule-triggered persistence or execution. Requiring current supported Outlook versions ensures the relevant security changes are applied.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1689 | Downgrade Attack |
Comments
Allowing only the latest supported browser and email-client versions prevents adversaries or users from running obsolete versions that lack current protections. This directly reduces downgrade opportunities involving older, weaker software versions.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1137 | Office Application Startup |
Comments
This is a partial mapping because several sub-techniques specifically abuse Outlook features addressed by vendor patches. Other Office startup methods involving templates, test keys, and general add-ins are outside the browser-and-email-client scope.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1176.001 | Browser Extensions |
Comments
Current browsers incorporate newer extension permission models, security controls, and protections against outdated installation methods. This does not prevent users or adversaries from installing an otherwise permitted malicious extension.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1539 | Steal Web Session Cookie |
Comments
Updating browsers reduces the likelihood that known vulnerabilities can be exploited to extract cookies from browser storage or memory. It does not prevent malware with sufficient local access from directly reading cookies or browser data.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1555.003 | Credentials from Web Browsers |
Comments
Current browser versions reduce exploitation of known weaknesses that expose stored passwords and authentication data. Updating the browser does not prevent credential theft by malware already executing with access to the user's browser profile.
References
|
| CIS-9.1 | Ensure Use of Only Fully Supported Browsers and Email Clients | mitigates | T1176 | Software Extensions |
Comments
Keeping browsers current affects browser extensions.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1667 | Email Bombing |
Comments
ATT&CK explicitly discusses DMARC, SPF, and DKIM on the Email bombing technique page, including how enabling these mechanisms within an organization (through policies such as DMARC) may enable recipients (intra-org and cross domain) to perform similar message filtering and validation to mitigate this technique.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1566.002 | Spearphishing Link |
Comments
DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains. DMARC may reduce link-led spearphishing at the sender-authentication and mail acceptance time. It does not inspect the attachment itself though.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1566.001 | Spearphishing Attachment |
Comments
DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains. DMARC may reduce attachment-led spearphishing when the campaign depends on spoofed sender trust and domain authentication failure. It does not inspect the attachment itself though.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1566 | Phishing |
Comments
DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1684 | Social Engineering |
Comments
Social engineering is broadly defined as influencing users into actions while minimizing technical indicators, DMARC can be a meaningful control against the email-spoofing branch of this broader technique.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1684.001 | Impersonation |
Comments
DMARC may not stop all impersonation, but it reduces a major subset where trust is created through control of the visible sender identity and aligned sending domain.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1684.002 | Email Spoofing |
Comments
ATT&CK explicitly discusses DMARC, SPF, and DKIM on the Email Spoofing technique page, including how weak or absent DMARC leaves spoofed messages deliverable and how DMARC-enabled filtering mitigates the behavior
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1553.005 | Mark-of-the-Web Bypass |
Comments
Adversaries may abuse container files such as compressed/archive (.arj, .gzip) and/or disk image (.iso, .vhd) file formats to deliver malicious payloads. The execution prevention mitigation mentions the use of blocking container file types at web and/or email gateways which could apply to the implementation of this safeguard.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1059.005 | Visual Basic |
Comments
Adversaries may use VB payloads to execute malicious commands. Common malicious usage includes automating execution of behaviors with VBScript or embedding VBA content into spearphishing Attachment payloads. If .VB objects are blocked at the email boundary then it can mitigate the spearphishing delivery of this technique.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1218.001 | Compiled HTML File |
Comments
A custom CHM file containing embedded payloads could be delivered to a victim through email then triggered by User Execution If those custom CHM files are blocked at the email boundary, then it can mitigate the delivery of this technique.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1137.006 | Add-ins |
Comments
dversaries often weaponize Office add-ins (e.g., Excel .xll files or Outlook .wll / .ecf extensions) by sending them via phishing campaigns. Blocking these file types at the email boundary prevents the initial execution and subsequent installation of malicious persistence mechanisms.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1027.009 | Embedded Payloads |
Comments
File blocking mitigates embedded payloads by completely stripping high-risk file types at the perimeter, denying attackers the ability to deliver the initial malicious file or its nested, obfuscated components. Attackers frequently embed malicious scripts (e.g., .js, .vbs) inside legitimate document formats (e.g., PDFs, Word docs). By blocking macro-enabled or script-based file types, gateways prevent these malicious combinations from ever reaching the user's inbox
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1027.012 | LNK Icon Smuggling |
Comments
LNK files are used as phishing payloads and when a user invokes them they can download or execute additional payloads. If .lnk objects are blocked at the email boundary then it can mitigate the delivery of this technique.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1027.006 | HTML Smuggling |
Comments
For this technique, adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files. If the implementation for 9.3 can mitigate this technique if it disallows .html, .htm, .hta, and similar active content files as email attachments on the block list.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1027.015 | Compression |
Comments
9.6 can prevent this type of technique if it blocks RAR, 7z, and other known unauthorized self-extracting archive types from specific machines.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1204.002 | Malicious File |
Comments
9.6 enforcement can reduce user exposure by removing risky files upstream at the point of email delivery.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1204 | User Execution |
Comments
9.6 enforcement can reduce user exposure by removing risky files upstream at the point of email delivery.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1566.001 | Spearphishing Attachment |
Comments
9.6 is a preventive email-gateway control that blocks disallowed attachment types before delivery.
References
|
| CIS-9.6 | Block Unnecessary File Types | mitigates | T1566 | Phishing |
Comments
9.6 is a preventive email-gateway control that blocks disallowed attachment types before delivery.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1189 | Drive-by Compromise |
Comments
CIS 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1105 | Ingress Tool Transfer |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists.
In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 implementation blocks outbound traffic from machines to unapproved external destinations. Restricting access to known, trusted IP addresses and protocols can prevent attackers from downloading malicious tools or payloads onto compromised servers after gaining initial access.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1567.003 | Exfiltration to Text Storage Sites |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. Adversaries may exfiltrate data to text storage sites instead of their primary command and control channel. If 9.3 implementation blocks unauthorized text storage sites, the technique is defensible.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1567.002 | Exfiltration to Cloud Storage |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved sites. If 9.3 implementation blocks the URLs of unauthorized cloud storage services that are not approved by the organization then this technique is defensible.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1593.003 | Code Repositories |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content. If 9.3 implementation blocks unapproved code repositories and repository APIs, this is applicable.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1102.002 | Bidirectional Communication |
Comments
If 9.3 implementation includes outbound web-service use broadly enough to block unauthorized services and risky websites, then this technique is applicable. ATT&CK describes two-way C2 via legitimate web services and again points to web proxies and blocking unauthorized external services as mitigation.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1102.003 | One-Way Communication |
Comments
Popular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise.
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content. If 9.3 implementation includes outbound web-services used broadly enough to block unauthorized services and restrict access to unsafe websites, then this technique is defensible.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1102.001 | Dead Drop Resolver |
Comments
CIS 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content. If 9.3 implementation blocks unapproved social media, code repositories, paste sites, and similar web services across enterprise HTTP/S traffic, this becomes defensible. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1102 | Web Service |
Comments
CIS 9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 implementation includes certain risky or suspicious web-services used broadly enough to block unauthorized services, then this technique is applicable.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1204 | User Execution |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 is implemented as a secure web gateway or proxy that can stop the post-click fetch/download, then this technique is applicable.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1204.001 | Malicious Link |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery. If 9.3 is implemented as a secure web gateway or proxy that can stop the post-click fetch/download, then this technique is applicable.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1566.002 | Spearphishing Link |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery.
References
|
| CIS-9.3 | Maintain and Enforce Network-Based URL Filters | mitigates | T1566 | Phishing |
Comments
9.3 helps prevent link-based and web-based initial access by stopping users from reaching malicious or unapproved content in the first place. It does this by requiring updated network-based URL filtering across all enterprise assets, using methods such as category-based filtering, reputation-based filtering, and block lists. In practice, this means enforcing controls that restrict access to unsafe websites, malicious downloads, risky scripts, and unauthorized browser extensions, reducing the risk of phishing, exploitation, and malware delivery.
References
|