Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
---|---|---|---|---|---|
DE.CM-01.05 | Website and service blocking | Mitigates | T1204.001 | Malicious Link |
Comments
This diagnostic statement protects user execution through the implementation of tools and measures to block unknown or unused files in transit.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1102.003 | One-Way Communication |
Comments
This diagnostic statement helps mitigate web service techniques through the implementation of tools and measures to detect and block access to unauthorized, inappropriate, or malicious websites and services.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1102.002 | Bidirectional Communication |
Comments
This diagnostic statement helps mitigate web service techniques through the implementation of tools and measures to detect and block access to unauthorized, inappropriate, or malicious websites and services.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1102.001 | Dead Drop Resolver |
Comments
This diagnostic statement helps mitigate web service techniques through the implementation of tools and measures to detect and block access to unauthorized, inappropriate, or malicious websites and services.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1102 | Web Service |
Comments
This diagnostic statement helps mitigate web service techniques through the implementation of tools and measures to detect and block access to unauthorized, inappropriate, or malicious websites and services.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1204.002 | Malicious File |
Comments
This diagnostic statement protects user execution through the implementation of tools and measures to block unknown or unused files in transit.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1204 | User Execution |
Comments
This diagnostic statement protects user execution through the implementation of tools and measures to block unknown or unused files in transit.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1550 | Use Alternate Authentication Material |
Comments
This diagnostic statement provides for implementing tools and measures for such as allowing/denying types of third-party applications which can help prevent adversary use of alternate authentication material.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1218.001 | Compiled HTML File |
Comments
This diagnostic statement can help prevent adversaries from abusing HTML files by implementing tools and measures to block download/transfer of uncommon file types known to be used in adversary campaigns.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1218 | System Binary Proxy Execution |
Comments
This diagnostic statement can help prevent execution of malicious content with signed files or trusted binaries through tools and measures restricting or blocking certain websites, blocking downloads/attachments, and restricting browser extensions.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1539 | Steal Web Session Cookie |
Comments
This diagnostic statement provides for implementing tools and measures for web-based content and browser security settings that can help prevent session cookie theft.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1528 | Steal Application Access Token |
Comments
This diagnostic statement provides for implementing tools and measures such as disabling users from authorizing third-party apps and forcing administrative consent for all requests that can help prevent token theft.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1566.003 | Spearphishing via Service |
Comments
This diagnostic statement provides for implementing tools and measures such as filtering messages and restricting certain websites or attachment types, which can help block phishing attempts.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1566.002 | Spearphishing Link |
Comments
This diagnostic statement provides for implementing tools and measures such as filtering messages and restricting certain websites or attachment types, which can help block phishing attempts.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1566.001 | Spearphishing Attachment |
Comments
This diagnostic statement provides for implementing tools and measures such as filtering messages and restricting certain websites or attachment types, which can help block phishing attempts.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1566 | Phishing |
Comments
This diagnostic statement provides for implementing tools and measures such as filtering messages and restricting certain websites or attachment types, which can help block phishing attempts.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1189 | Drive-by Compromise |
Comments
This diagnostic statement helps mitigate drive-by compromise through the implementation of tools and measures such as adblockers to prevent and block malicious code execution and script blocking extensions to block execution of scripts.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1555.003 | Credentials from Web Browsers |
Comments
This diagnostic statement provides for implementing tools and measures for web-based content and browser security settings that can help prevent session cookie theft.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1659 | Content Injection |
Comments
This diagnostic statement provides for implementing tools and measures such as blocking download/transfer and execution of uncommon file types which can help prevent content injection.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1059.007 | JavaScript |
Comments
This diagnostic statement prevents adversaries from abusing various implementation of JavaScript for execution by blocking the execution of scripts and malicious code that pop up via adblockers and ads.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1059 | Command and Scripting Interpreter |
Comments
This diagnostic statement prevents adversaries from abusing commands, scripts, or binaries by blocking the execution of scripts and malicious code that pop up via adblockers and ads.
|
DE.CM-01.05 | Website and service blocking | Mitigates | T1059.005 | Visual Basic |
Comments
This diagnostic statement prevents adversaries from abusing commands, scripts, or binaries by blocking the execution of scripts and malicious code that pop up via adblockers and ads.
|