CRI Profile DE.CM-01.05

The organization implements measures to detect and block access to unauthorized, inappropriate, or malicious websites and services (e.g. social media, messaging, file sharing).

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
DE.CM-01.05 Website and service blocking Mitigates T1204.001 Malicious Link
Comments
This diagnostic statement protects user execution through the implementation of tools and measures to block unknown or unused files in transit.
DE.CM-01.05 Website and service blocking Mitigates T1102.003 One-Way Communication
Comments
This diagnostic statement helps mitigate web service techniques through the implementation of tools and measures to detect and block access to unauthorized, inappropriate, or malicious websites and services.
DE.CM-01.05 Website and service blocking Mitigates T1102.002 Bidirectional Communication
Comments
This diagnostic statement helps mitigate web service techniques through the implementation of tools and measures to detect and block access to unauthorized, inappropriate, or malicious websites and services.
DE.CM-01.05 Website and service blocking Mitigates T1102.001 Dead Drop Resolver
Comments
This diagnostic statement helps mitigate web service techniques through the implementation of tools and measures to detect and block access to unauthorized, inappropriate, or malicious websites and services.
DE.CM-01.05 Website and service blocking Mitigates T1102 Web Service
Comments
This diagnostic statement helps mitigate web service techniques through the implementation of tools and measures to detect and block access to unauthorized, inappropriate, or malicious websites and services.
DE.CM-01.05 Website and service blocking Mitigates T1204.002 Malicious File
Comments
This diagnostic statement protects user execution through the implementation of tools and measures to block unknown or unused files in transit.
DE.CM-01.05 Website and service blocking Mitigates T1204 User Execution
Comments
This diagnostic statement protects user execution through the implementation of tools and measures to block unknown or unused files in transit.
DE.CM-01.05 Website and service blocking Mitigates T1550 Use Alternate Authentication Material
Comments
This diagnostic statement provides for implementing tools and measures for such as allowing/denying types of third-party applications which can help prevent adversary use of alternate authentication material.
DE.CM-01.05 Website and service blocking Mitigates T1218.001 Compiled HTML File
Comments
This diagnostic statement can help prevent adversaries from abusing HTML files by implementing tools and measures to block download/transfer of uncommon file types known to be used in adversary campaigns.
DE.CM-01.05 Website and service blocking Mitigates T1218 System Binary Proxy Execution
Comments
This diagnostic statement can help prevent execution of malicious content with signed files or trusted binaries through tools and measures restricting or blocking certain websites, blocking downloads/attachments, and restricting browser extensions.
DE.CM-01.05 Website and service blocking Mitigates T1539 Steal Web Session Cookie
Comments
This diagnostic statement provides for implementing tools and measures for web-based content and browser security settings that can help prevent session cookie theft.
DE.CM-01.05 Website and service blocking Mitigates T1528 Steal Application Access Token
Comments
This diagnostic statement provides for implementing tools and measures such as disabling users from authorizing third-party apps and forcing administrative consent for all requests that can help prevent token theft.
DE.CM-01.05 Website and service blocking Mitigates T1566.003 Spearphishing via Service
Comments
This diagnostic statement provides for implementing tools and measures such as filtering messages and restricting certain websites or attachment types, which can help block phishing attempts.
DE.CM-01.05 Website and service blocking Mitigates T1566.002 Spearphishing Link
Comments
This diagnostic statement provides for implementing tools and measures such as filtering messages and restricting certain websites or attachment types, which can help block phishing attempts.
DE.CM-01.05 Website and service blocking Mitigates T1566.001 Spearphishing Attachment
Comments
This diagnostic statement provides for implementing tools and measures such as filtering messages and restricting certain websites or attachment types, which can help block phishing attempts.
DE.CM-01.05 Website and service blocking Mitigates T1566 Phishing
Comments
This diagnostic statement provides for implementing tools and measures such as filtering messages and restricting certain websites or attachment types, which can help block phishing attempts.
DE.CM-01.05 Website and service blocking Mitigates T1189 Drive-by Compromise
Comments
This diagnostic statement helps mitigate drive-by compromise through the implementation of tools and measures such as adblockers to prevent and block malicious code execution and script blocking extensions to block execution of scripts.
DE.CM-01.05 Website and service blocking Mitigates T1555.003 Credentials from Web Browsers
Comments
This diagnostic statement provides for implementing tools and measures for web-based content and browser security settings that can help prevent session cookie theft.
DE.CM-01.05 Website and service blocking Mitigates T1659 Content Injection
Comments
This diagnostic statement provides for implementing tools and measures such as blocking download/transfer and execution of uncommon file types which can help prevent content injection.
DE.CM-01.05 Website and service blocking Mitigates T1059.007 JavaScript
Comments
This diagnostic statement prevents adversaries from abusing various implementation of JavaScript for execution by blocking the execution of scripts and malicious code that pop up via adblockers and ads.
DE.CM-01.05 Website and service blocking Mitigates T1059 Command and Scripting Interpreter
Comments
This diagnostic statement prevents adversaries from abusing commands, scripts, or binaries by blocking the execution of scripts and malicious code that pop up via adblockers and ads.
DE.CM-01.05 Website and service blocking Mitigates T1059.005 Visual Basic
Comments
This diagnostic statement prevents adversaries from abusing commands, scripts, or binaries by blocking the execution of scripts and malicious code that pop up via adblockers and ads.