NIST 800-53 System and Information Integrity Capability Group

All Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
SI-03 Malicious Code Protection mitigates T1001 Data Obfuscation
SI-04 System Monitoring mitigates T1001 Data Obfuscation
SI-12 Information Management and Retention mitigates T1003 OS Credential Dumping
SI-02 Flaw Remediation mitigates T1003 OS Credential Dumping
SI-07 Software, Firmware, and Information Integrity mitigates T1003 OS Credential Dumping
SI-16 Memory Protection mitigates T1003.001 LSASS Memory
SI-14 Non-persistence mitigates T1546.003 Windows Management Instrumentation Event Subscription
SI-14 Non-persistence mitigates T1547.004 Winlogon Helper DLL
SI-23 Information Fragmentation mitigates T1070.001 Clear Windows Event Logs
SI-23 Information Fragmentation mitigates T1072 Software Deployment Tools
SI-23 Information Fragmentation mitigates T1119 Automated Collection
SI-23 Information Fragmentation mitigates T1565 Data Manipulation
SI-08 Spam Protection mitigates T1137.002 Office Test
SI-08 Spam Protection mitigates T1204 User Execution
SI-08 Spam Protection mitigates T1204.002 Malicious File
SI-08 Spam Protection mitigates T1566 Phishing
SI-08 Spam Protection mitigates T1566.001 Spearphishing Attachment
SI-08 Spam Protection mitigates T1566.002 Spearphishing Link
SI-08 Spam Protection mitigates T1566.003 Spearphishing via Service
SI-08 Spam Protection mitigates T1598.003 Spearphishing Link
SI-12 Information Management and Retention mitigates T1020.001 Traffic Duplication
SI-12 Information Management and Retention mitigates T1040 Network Sniffing
SI-12 Information Management and Retention mitigates T1070.001 Clear Windows Event Logs
SI-12 Information Management and Retention mitigates T1114 Email Collection
SI-12 Information Management and Retention mitigates T1114.002 Remote Email Collection
SI-12 Information Management and Retention mitigates T1114.003 Email Forwarding Rule
SI-12 Information Management and Retention mitigates T1119 Automated Collection
SI-12 Information Management and Retention mitigates T1213.004 Customer Relationship Management Software
SI-12 Information Management and Retention mitigates T1530 Data from Cloud Storage
SI-12 Information Management and Retention mitigates T1548 Abuse Elevation Control Mechanism
SI-12 Information Management and Retention mitigates T1550.001 Application Access Token
SI-12 Information Management and Retention mitigates T1552 Unsecured Credentials
SI-12 Information Management and Retention mitigates T1552.004 Private Keys
SI-12 Information Management and Retention mitigates T1557 Adversary-in-the-Middle
SI-12 Information Management and Retention mitigates T1557.004 Evil Twin
SI-12 Information Management and Retention mitigates T1558 Steal or Forge Kerberos Tickets
SI-12 Information Management and Retention mitigates T1558.005 Ccache Files
SI-12 Information Management and Retention mitigates T1565 Data Manipulation
SI-16 Memory Protection mitigates T1047 Windows Management Instrumentation
SI-16 Memory Protection mitigates T1059 Command and Scripting Interpreter
SI-16 Memory Protection mitigates T1059.006 Python
SI-16 Memory Protection mitigates T1059.011 Lua
SI-16 Memory Protection mitigates T1218 System Binary Proxy Execution
SI-16 Memory Protection mitigates T1218.015 Electron Applications
SI-16 Memory Protection mitigates T1543 Create or Modify System Process
SI-16 Memory Protection mitigates T1543.002 Systemd Service
SI-16 Memory Protection mitigates T1547.004 Winlogon Helper DLL
SI-16 Memory Protection mitigates T1548 Abuse Elevation Control Mechanism
SI-16 Memory Protection mitigates T1565 Data Manipulation
SI-16 Memory Protection mitigates T1611 Escape to Host
SI-02 Flaw Remediation mitigates T1003.001 LSASS Memory
SI-02 Flaw Remediation mitigates T1027 Obfuscated Files or Information
SI-02 Flaw Remediation mitigates T1047 Windows Management Instrumentation
SI-02 Flaw Remediation mitigates T1059 Command and Scripting Interpreter
SI-02 Flaw Remediation mitigates T1059.006 Python
SI-02 Flaw Remediation mitigates T1072 Software Deployment Tools
SI-02 Flaw Remediation mitigates T1190 Exploit Public-Facing Application
SI-02 Flaw Remediation mitigates T1195 Supply Chain Compromise
SI-02 Flaw Remediation mitigates T1195.001 Compromise Software Dependencies and Development Tools
SI-02 Flaw Remediation mitigates T1203 Exploitation for Client Execution
SI-02 Flaw Remediation mitigates T1204 User Execution
SI-02 Flaw Remediation mitigates T1213.003 Code Repositories
SI-02 Flaw Remediation mitigates T1213.005 Messaging Applications
SI-02 Flaw Remediation mitigates T1542 Pre-OS Boot
SI-02 Flaw Remediation mitigates T1542.001 System Firmware
SI-02 Flaw Remediation mitigates T1546 Event Triggered Execution
SI-02 Flaw Remediation mitigates T1546.016 Installer Packages
SI-02 Flaw Remediation mitigates T1548 Abuse Elevation Control Mechanism
SI-02 Flaw Remediation mitigates T1548.006 TCC Manipulation
SI-02 Flaw Remediation mitigates T1552 Unsecured Credentials
SI-02 Flaw Remediation mitigates T1553 Subvert Trust Controls
SI-02 Flaw Remediation mitigates T1555 Credentials from Password Stores
SI-02 Flaw Remediation mitigates T1555.005 Password Managers
SI-02 Flaw Remediation mitigates T1566 Phishing
SI-02 Flaw Remediation mitigates T1566.001 Spearphishing Attachment
SI-02 Flaw Remediation mitigates T1566.003 Spearphishing via Service
SI-02 Flaw Remediation mitigates T1611 Escape to Host
SI-10 Information Input Validation mitigates T1036 Masquerading
SI-10 Information Input Validation mitigates T1059 Command and Scripting Interpreter
SI-10 Information Input Validation mitigates T1059.006 Python
SI-10 Information Input Validation mitigates T1090.003 Multi-hop Proxy
SI-10 Information Input Validation mitigates T1127.002 ClickOnce
SI-10 Information Input Validation mitigates T1176 Browser Extensions
SI-10 Information Input Validation mitigates T1190 Exploit Public-Facing Application
SI-10 Information Input Validation mitigates T1204 User Execution
SI-10 Information Input Validation mitigates T1204.002 Malicious File
SI-10 Information Input Validation mitigates T1218 System Binary Proxy Execution
SI-10 Information Input Validation mitigates T1218.011 Rundll32
SI-10 Information Input Validation mitigates T1218.015 Electron Applications
SI-10 Information Input Validation mitigates T1219 Remote Access Software
SI-10 Information Input Validation mitigates T1530 Data from Cloud Storage
SI-10 Information Input Validation mitigates T1537 Transfer Data to Cloud Account
SI-10 Information Input Validation mitigates T1547.004 Winlogon Helper DLL
SI-10 Information Input Validation mitigates T1548.006 TCC Manipulation
SI-10 Information Input Validation mitigates T1552 Unsecured Credentials
SI-10 Information Input Validation mitigates T1553 Subvert Trust Controls
SI-10 Information Input Validation mitigates T1557 Adversary-in-the-Middle
SI-10 Information Input Validation mitigates T1564.003 Hidden Window
SI-10 Information Input Validation mitigates T1572 Protocol Tunneling
SI-10 Information Input Validation mitigates T1574.001 DLL Search Order Hijacking
SI-10 Information Input Validation mitigates T1574.014 AppDomainManager
SI-15 Information Output Filtering mitigates T1090.003 Multi-hop Proxy
SI-15 Information Output Filtering mitigates T1218.015 Electron Applications
SI-15 Information Output Filtering mitigates T1219 Remote Access Software
SI-15 Information Output Filtering mitigates T1530 Data from Cloud Storage
SI-15 Information Output Filtering mitigates T1537 Transfer Data to Cloud Account
SI-15 Information Output Filtering mitigates T1552 Unsecured Credentials
SI-15 Information Output Filtering mitigates T1557 Adversary-in-the-Middle
SI-15 Information Output Filtering mitigates T1572 Protocol Tunneling
SI-03 Malicious Code Protection mitigates T1001.001 Junk Data
SI-03 Malicious Code Protection mitigates T1001.003 Protocol or Service Impersonation
SI-03 Malicious Code Protection mitigates T1003 OS Credential Dumping
SI-03 Malicious Code Protection mitigates T1003.001 LSASS Memory
SI-03 Malicious Code Protection mitigates T1003.005 Cached Domain Credentials
SI-03 Malicious Code Protection mitigates T1003.007 Proc Filesystem
SI-03 Malicious Code Protection mitigates T1027 Obfuscated Files or Information
SI-03 Malicious Code Protection mitigates T1027.013 Encrypted/Encoded File
SI-03 Malicious Code Protection mitigates T1027.014 Polymorphic Code
SI-03 Malicious Code Protection mitigates T1036 Masquerading
SI-03 Malicious Code Protection mitigates T1037 Boot or Logon Initialization Scripts
SI-03 Malicious Code Protection mitigates T1047 Windows Management Instrumentation
SI-03 Malicious Code Protection mitigates T1055.015 ListPlanting
SI-03 Malicious Code Protection mitigates T1056.002 GUI Input Capture
SI-03 Malicious Code Protection mitigates T1059 Command and Scripting Interpreter
SI-03 Malicious Code Protection mitigates T1059.006 Python
SI-03 Malicious Code Protection mitigates T1059.010 AutoHotKey & AutoIT
SI-03 Malicious Code Protection mitigates T1059.011 Lua
SI-03 Malicious Code Protection mitigates T1070.001 Clear Windows Event Logs
SI-03 Malicious Code Protection mitigates T1070.003 Clear Command History
SI-03 Malicious Code Protection mitigates T1070.010 Relocate Malware
SI-03 Malicious Code Protection mitigates T1071 Application Layer Protocol
SI-03 Malicious Code Protection mitigates T1071.002 File Transfer Protocols
SI-03 Malicious Code Protection mitigates T1071.003 Mail Protocols
SI-03 Malicious Code Protection mitigates T1072 Software Deployment Tools
SI-03 Malicious Code Protection mitigates T1092 Communication Through Removable Media
SI-03 Malicious Code Protection mitigates T1102 Web Service
SI-03 Malicious Code Protection mitigates T1105 Ingress Tool Transfer
SI-03 Malicious Code Protection mitigates T1176 Browser Extensions
SI-03 Malicious Code Protection mitigates T1190 Exploit Public-Facing Application
SI-03 Malicious Code Protection mitigates T1195 Supply Chain Compromise
SI-03 Malicious Code Protection mitigates T1203 Exploitation for Client Execution
SI-03 Malicious Code Protection mitigates T1204 User Execution
SI-03 Malicious Code Protection mitigates T1204.002 Malicious File
SI-03 Malicious Code Protection mitigates T1218 System Binary Proxy Execution
SI-03 Malicious Code Protection mitigates T1218.015 Electron Applications
SI-03 Malicious Code Protection mitigates T1219 Remote Access Software
SI-03 Malicious Code Protection mitigates T1485 Data Destruction
SI-03 Malicious Code Protection mitigates T1490 Inhibit System Recovery
SI-03 Malicious Code Protection mitigates T1539 Steal Web Session Cookie
SI-03 Malicious Code Protection mitigates T1543 Create or Modify System Process
SI-03 Malicious Code Protection mitigates T1543.002 Systemd Service
SI-03 Malicious Code Protection mitigates T1546.003 Windows Management Instrumentation Event Subscription
SI-03 Malicious Code Protection mitigates T1546.016 Installer Packages
SI-03 Malicious Code Protection mitigates T1547.009 Shortcut Modification
SI-03 Malicious Code Protection mitigates T1548 Abuse Elevation Control Mechanism
SI-03 Malicious Code Protection mitigates T1548.006 TCC Manipulation
SI-03 Malicious Code Protection mitigates T1554 Compromise Host Software Binary
SI-03 Malicious Code Protection mitigates T1557 Adversary-in-the-Middle
SI-03 Malicious Code Protection mitigates T1558 Steal or Forge Kerberos Tickets
SI-03 Malicious Code Protection mitigates T1560 Archive Collected Data
SI-03 Malicious Code Protection mitigates T1562 Impair Defenses
SI-03 Malicious Code Protection mitigates T1562.004 Disable or Modify System Firewall
SI-03 Malicious Code Protection mitigates T1562.006 Indicator Blocking
SI-03 Malicious Code Protection mitigates T1564.004 NTFS File Attributes
SI-03 Malicious Code Protection mitigates T1564.012 File/Path Exclusions
SI-03 Malicious Code Protection mitigates T1566 Phishing
SI-03 Malicious Code Protection mitigates T1566.001 Spearphishing Attachment
SI-03 Malicious Code Protection mitigates T1566.002 Spearphishing Link
SI-03 Malicious Code Protection mitigates T1566.003 Spearphishing via Service
SI-03 Malicious Code Protection mitigates T1572 Protocol Tunneling
SI-03 Malicious Code Protection mitigates T1573 Encrypted Channel
SI-03 Malicious Code Protection mitigates T1574.001 DLL Search Order Hijacking
SI-03 Malicious Code Protection mitigates T1574.014 AppDomainManager
SI-03 Malicious Code Protection mitigates T1598.003 Spearphishing Link
SI-03 Malicious Code Protection mitigates T1611 Escape to Host
SI-07 Software, Firmware, and Information Integrity mitigates T1020.001 Traffic Duplication
SI-07 Software, Firmware, and Information Integrity mitigates T1027 Obfuscated Files or Information
SI-07 Software, Firmware, and Information Integrity mitigates T1036 Masquerading
SI-07 Software, Firmware, and Information Integrity mitigates T1037 Boot or Logon Initialization Scripts
SI-07 Software, Firmware, and Information Integrity mitigates T1040 Network Sniffing
SI-07 Software, Firmware, and Information Integrity mitigates T1047 Windows Management Instrumentation
SI-07 Software, Firmware, and Information Integrity mitigates T1056.002 GUI Input Capture
SI-07 Software, Firmware, and Information Integrity mitigates T1059 Command and Scripting Interpreter
SI-07 Software, Firmware, and Information Integrity mitigates T1059.006 Python
SI-07 Software, Firmware, and Information Integrity mitigates T1059.010 AutoHotKey & AutoIT
SI-07 Software, Firmware, and Information Integrity mitigates T1059.011 Lua
SI-07 Software, Firmware, and Information Integrity mitigates T1070.001 Clear Windows Event Logs
SI-07 Software, Firmware, and Information Integrity mitigates T1070.003 Clear Command History
SI-07 Software, Firmware, and Information Integrity mitigates T1070.010 Relocate Malware
SI-07 Software, Firmware, and Information Integrity mitigates T1072 Software Deployment Tools
SI-07 Software, Firmware, and Information Integrity mitigates T1098.001 Additional Cloud Credentials
SI-07 Software, Firmware, and Information Integrity mitigates T1098.002 Additional Email Delegate Permissions
SI-07 Software, Firmware, and Information Integrity mitigates T1098.003 Additional Cloud Roles
SI-07 Software, Firmware, and Information Integrity mitigates T1114 Email Collection
SI-07 Software, Firmware, and Information Integrity mitigates T1114.002 Remote Email Collection
SI-07 Software, Firmware, and Information Integrity mitigates T1114.003 Email Forwarding Rule
SI-07 Software, Firmware, and Information Integrity mitigates T1119 Automated Collection
SI-07 Software, Firmware, and Information Integrity mitigates T1127.002 ClickOnce
SI-07 Software, Firmware, and Information Integrity mitigates T1136 Create Account
SI-07 Software, Firmware, and Information Integrity mitigates T1136.002 Domain Account
SI-07 Software, Firmware, and Information Integrity mitigates T1136.003 Cloud Account
SI-07 Software, Firmware, and Information Integrity mitigates T1176 Browser Extensions
SI-07 Software, Firmware, and Information Integrity mitigates T1190 Exploit Public-Facing Application
SI-07 Software, Firmware, and Information Integrity mitigates T1195 Supply Chain Compromise
SI-07 Software, Firmware, and Information Integrity mitigates T1195.001 Compromise Software Dependencies and Development Tools
SI-07 Software, Firmware, and Information Integrity mitigates T1203 Exploitation for Client Execution
SI-07 Software, Firmware, and Information Integrity mitigates T1204 User Execution
SI-07 Software, Firmware, and Information Integrity mitigates T1204.002 Malicious File
SI-07 Software, Firmware, and Information Integrity mitigates T1213 Data from Information Repositories
SI-07 Software, Firmware, and Information Integrity mitigates T1213.001 Confluence
SI-07 Software, Firmware, and Information Integrity mitigates T1213.002 Sharepoint
SI-07 Software, Firmware, and Information Integrity mitigates T1213.004 Customer Relationship Management Software
SI-07 Software, Firmware, and Information Integrity mitigates T1213.005 Messaging Applications
SI-07 Software, Firmware, and Information Integrity mitigates T1216.002 SyncAppvPublishingServer
SI-07 Software, Firmware, and Information Integrity mitigates T1218 System Binary Proxy Execution
SI-07 Software, Firmware, and Information Integrity mitigates T1218.011 Rundll32
SI-07 Software, Firmware, and Information Integrity mitigates T1218.015 Electron Applications
SI-07 Software, Firmware, and Information Integrity mitigates T1219 Remote Access Software
SI-07 Software, Firmware, and Information Integrity mitigates T1485 Data Destruction
SI-07 Software, Firmware, and Information Integrity mitigates T1485.001 Lifecycle-Triggered Deletion
SI-07 Software, Firmware, and Information Integrity mitigates T1490 Inhibit System Recovery
SI-07 Software, Firmware, and Information Integrity mitigates T1530 Data from Cloud Storage
SI-07 Software, Firmware, and Information Integrity mitigates T1542 Pre-OS Boot
SI-07 Software, Firmware, and Information Integrity mitigates T1542.001 System Firmware
SI-07 Software, Firmware, and Information Integrity mitigates T1543 Create or Modify System Process
SI-07 Software, Firmware, and Information Integrity mitigates T1543.002 Systemd Service
SI-07 Software, Firmware, and Information Integrity mitigates T1546 Event Triggered Execution
SI-07 Software, Firmware, and Information Integrity mitigates T1547.003 Time Providers
SI-07 Software, Firmware, and Information Integrity mitigates T1547.004 Winlogon Helper DLL
SI-07 Software, Firmware, and Information Integrity mitigates T1548 Abuse Elevation Control Mechanism
SI-07 Software, Firmware, and Information Integrity mitigates T1548.006 TCC Manipulation
SI-07 Software, Firmware, and Information Integrity mitigates T1550.001 Application Access Token
SI-07 Software, Firmware, and Information Integrity mitigates T1552 Unsecured Credentials
SI-07 Software, Firmware, and Information Integrity mitigates T1552.004 Private Keys
SI-07 Software, Firmware, and Information Integrity mitigates T1553 Subvert Trust Controls
SI-07 Software, Firmware, and Information Integrity mitigates T1554 Compromise Host Software Binary
SI-07 Software, Firmware, and Information Integrity mitigates T1556 Modify Authentication Process
SI-07 Software, Firmware, and Information Integrity mitigates T1556.001 Domain Controller Authentication
SI-07 Software, Firmware, and Information Integrity mitigates T1556.009 Conditional Access Policies
SI-07 Software, Firmware, and Information Integrity mitigates T1557 Adversary-in-the-Middle
SI-07 Software, Firmware, and Information Integrity mitigates T1557.004 Evil Twin
SI-07 Software, Firmware, and Information Integrity mitigates T1558 Steal or Forge Kerberos Tickets
SI-07 Software, Firmware, and Information Integrity mitigates T1558.005 Ccache Files
SI-07 Software, Firmware, and Information Integrity mitigates T1562 Impair Defenses
SI-07 Software, Firmware, and Information Integrity mitigates T1562.004 Disable or Modify System Firewall
SI-07 Software, Firmware, and Information Integrity mitigates T1562.006 Indicator Blocking
SI-07 Software, Firmware, and Information Integrity mitigates T1564.003 Hidden Window
SI-07 Software, Firmware, and Information Integrity mitigates T1564.004 NTFS File Attributes
SI-07 Software, Firmware, and Information Integrity mitigates T1565 Data Manipulation
SI-07 Software, Firmware, and Information Integrity mitigates T1574.001 DLL Search Order Hijacking
SI-07 Software, Firmware, and Information Integrity mitigates T1574.014 AppDomainManager
SI-07 Software, Firmware, and Information Integrity mitigates T1611 Escape to Host
SI-04 System Monitoring mitigates T1001.001 Junk Data
SI-04 System Monitoring mitigates T1001.003 Protocol or Service Impersonation
SI-04 System Monitoring mitigates T1003 OS Credential Dumping
SI-04 System Monitoring mitigates T1003.001 LSASS Memory
SI-04 System Monitoring mitigates T1003.005 Cached Domain Credentials
SI-04 System Monitoring mitigates T1003.007 Proc Filesystem
SI-04 System Monitoring mitigates T1020.001 Traffic Duplication
SI-04 System Monitoring mitigates T1021 Remote Services
SI-04 System Monitoring mitigates T1027 Obfuscated Files or Information
SI-04 System Monitoring mitigates T1027.011 Fileless Storage
SI-04 System Monitoring mitigates T1036 Masquerading
SI-04 System Monitoring mitigates T1036.010 Masquerade Account Name
SI-04 System Monitoring mitigates T1037 Boot or Logon Initialization Scripts
SI-04 System Monitoring mitigates T1040 Network Sniffing
SI-04 System Monitoring mitigates T1047 Windows Management Instrumentation
SI-04 System Monitoring mitigates T1053 Scheduled Task/Job
SI-04 System Monitoring mitigates T1053.002 At
SI-04 System Monitoring mitigates T1053.005 Scheduled Task
SI-04 System Monitoring mitigates T1056.002 GUI Input Capture
SI-04 System Monitoring mitigates T1059 Command and Scripting Interpreter
SI-04 System Monitoring mitigates T1059.006 Python
SI-04 System Monitoring mitigates T1059.010 AutoHotKey & AutoIT
SI-04 System Monitoring mitigates T1059.011 Lua
SI-04 System Monitoring mitigates T1070.001 Clear Windows Event Logs
SI-04 System Monitoring mitigates T1070.003 Clear Command History
SI-04 System Monitoring mitigates T1070.010 Relocate Malware
SI-04 System Monitoring mitigates T1071 Application Layer Protocol
SI-04 System Monitoring mitigates T1071.002 File Transfer Protocols
SI-04 System Monitoring mitigates T1071.003 Mail Protocols
SI-04 System Monitoring mitigates T1071.005 Publish/Subscribe Protocols
SI-04 System Monitoring mitigates T1072 Software Deployment Tools
SI-04 System Monitoring mitigates T1078 Valid Accounts
SI-04 System Monitoring mitigates T1078.001 Default Accounts
SI-04 System Monitoring mitigates T1078.003 Local Accounts
SI-04 System Monitoring mitigates T1078.004 Cloud Accounts
SI-04 System Monitoring mitigates T1087 Account Discovery
SI-04 System Monitoring mitigates T1087.001 Local Account
SI-04 System Monitoring mitigates T1087.002 Domain Account
SI-04 System Monitoring mitigates T1092 Communication Through Removable Media
SI-04 System Monitoring mitigates T1098 Account Manipulation
SI-04 System Monitoring mitigates T1098.001 Additional Cloud Credentials
SI-04 System Monitoring mitigates T1098.002 Additional Email Delegate Permissions
SI-04 System Monitoring mitigates T1098.003 Additional Cloud Roles
SI-04 System Monitoring mitigates T1098.007 Additional Local or Domain Groups
SI-04 System Monitoring mitigates T1102 Web Service
SI-04 System Monitoring mitigates T1105 Ingress Tool Transfer
SI-04 System Monitoring mitigates T1110 Brute Force
SI-04 System Monitoring mitigates T1114 Email Collection
SI-04 System Monitoring mitigates T1114.002 Remote Email Collection
SI-04 System Monitoring mitigates T1114.003 Email Forwarding Rule
SI-04 System Monitoring mitigates T1119 Automated Collection
SI-04 System Monitoring mitigates T1127.002 ClickOnce
SI-04 System Monitoring mitigates T1136 Create Account
SI-04 System Monitoring mitigates T1136.002 Domain Account
SI-04 System Monitoring mitigates T1136.003 Cloud Account
SI-04 System Monitoring mitigates T1176 Browser Extensions
SI-04 System Monitoring mitigates T1190 Exploit Public-Facing Application
SI-04 System Monitoring mitigates T1195 Supply Chain Compromise
SI-04 System Monitoring mitigates T1195.001 Compromise Software Dependencies and Development Tools
SI-04 System Monitoring mitigates T1203 Exploitation for Client Execution
SI-04 System Monitoring mitigates T1204 User Execution
SI-04 System Monitoring mitigates T1204.002 Malicious File
SI-04 System Monitoring mitigates T1213 Data from Information Repositories
SI-04 System Monitoring mitigates T1213.001 Confluence
SI-04 System Monitoring mitigates T1213.002 Sharepoint
SI-04 System Monitoring mitigates T1213.004 Customer Relationship Management Software
SI-04 System Monitoring mitigates T1213.005 Messaging Applications
SI-04 System Monitoring mitigates T1218 System Binary Proxy Execution
SI-04 System Monitoring mitigates T1218.011 Rundll32
SI-04 System Monitoring mitigates T1218.015 Electron Applications
SI-04 System Monitoring mitigates T1219 Remote Access Software
SI-04 System Monitoring mitigates T1484 Domain or Tenant Policy Modification
SI-04 System Monitoring mitigates T1485 Data Destruction
SI-04 System Monitoring mitigates T1489 Service Stop
SI-04 System Monitoring mitigates T1490 Inhibit System Recovery
SI-04 System Monitoring mitigates T1505.003 Web Shell
SI-04 System Monitoring mitigates T1528 Steal Application Access Token
SI-04 System Monitoring mitigates T1530 Data from Cloud Storage
SI-04 System Monitoring mitigates T1537 Transfer Data to Cloud Account
SI-04 System Monitoring mitigates T1539 Steal Web Session Cookie
SI-04 System Monitoring mitigates T1543 Create or Modify System Process
SI-04 System Monitoring mitigates T1543.002 Systemd Service
SI-04 System Monitoring mitigates T1546.003 Windows Management Instrumentation Event Subscription
SI-04 System Monitoring mitigates T1546.016 Installer Packages
SI-04 System Monitoring mitigates T1547.003 Time Providers
SI-04 System Monitoring mitigates T1547.004 Winlogon Helper DLL
SI-04 System Monitoring mitigates T1547.009 Shortcut Modification
SI-04 System Monitoring mitigates T1548 Abuse Elevation Control Mechanism
SI-04 System Monitoring mitigates T1548.006 TCC Manipulation
SI-04 System Monitoring mitigates T1550.001 Application Access Token
SI-04 System Monitoring mitigates T1552 Unsecured Credentials
SI-04 System Monitoring mitigates T1552.001 Credentials In Files
SI-04 System Monitoring mitigates T1552.004 Private Keys
SI-04 System Monitoring mitigates T1553 Subvert Trust Controls
SI-04 System Monitoring mitigates T1555 Credentials from Password Stores
SI-04 System Monitoring mitigates T1555.002 Securityd Memory
SI-04 System Monitoring mitigates T1555.005 Password Managers
SI-04 System Monitoring mitigates T1556 Modify Authentication Process
SI-04 System Monitoring mitigates T1556.001 Domain Controller Authentication
SI-04 System Monitoring mitigates T1556.009 Conditional Access Policies
SI-04 System Monitoring mitigates T1557 Adversary-in-the-Middle
SI-04 System Monitoring mitigates T1557.004 Evil Twin
SI-04 System Monitoring mitigates T1558 Steal or Forge Kerberos Tickets
SI-04 System Monitoring mitigates T1558.005 Ccache Files
SI-04 System Monitoring mitigates T1560 Archive Collected Data
SI-04 System Monitoring mitigates T1562 Impair Defenses
SI-04 System Monitoring mitigates T1562.004 Disable or Modify System Firewall
SI-04 System Monitoring mitigates T1562.006 Indicator Blocking
SI-04 System Monitoring mitigates T1563 Remote Service Session Hijacking
SI-04 System Monitoring mitigates T1564.004 NTFS File Attributes
SI-04 System Monitoring mitigates T1565 Data Manipulation
SI-04 System Monitoring mitigates T1566 Phishing
SI-04 System Monitoring mitigates T1566.001 Spearphishing Attachment
SI-04 System Monitoring mitigates T1566.002 Spearphishing Link
SI-04 System Monitoring mitigates T1566.003 Spearphishing via Service
SI-04 System Monitoring mitigates T1572 Protocol Tunneling
SI-04 System Monitoring mitigates T1573 Encrypted Channel
SI-04 System Monitoring mitigates T1574.001 DLL Search Order Hijacking
SI-04 System Monitoring mitigates T1574.014 AppDomainManager
SI-04 System Monitoring mitigates T1598.003 Spearphishing Link
SI-04 System Monitoring mitigates T1610 Deploy Container
SI-04 System Monitoring mitigates T1611 Escape to Host
SI-04 System Monitoring mitigates T1648 Serverless Execution
SI-04 System Monitoring mitigates T1651 Cloud Administration Command
SI-10 Information Input Validation mitigates T1021.002 SMB/Windows Admin Shares
SI-15 Information Output Filtering mitigates T1021.002 SMB/Windows Admin Shares
SI-05 Security Alerts, Advisories, and Directives mitigates T1068 Exploitation for Privilege Escalation
SI-23 Information Fragmentation mitigates T1070 Indicator Removal
SI-08 Spam Protection mitigates T1137 Office Application Startup
SI-05 Security Alerts, Advisories, and Directives mitigates T1210 Exploitation of Remote Services
SI-05 Security Alerts, Advisories, and Directives mitigates T1211 Exploitation for Defense Evasion
SI-05 Security Alerts, Advisories, and Directives mitigates T1212 Exploitation for Credential Access
SI-14 Non-persistence mitigates T1505 Server Software Component
SI-14 Non-persistence mitigates T1505.001 SQL Stored Procedures
SI-14 Non-persistence mitigates T1505.002 Transport Agent
SI-14 Non-persistence mitigates T1505.004 IIS Components
SI-14 Non-persistence mitigates T1547.006 Kernel Modules and Extensions
SI-23 Information Fragmentation mitigates T1070.002 Clear Linux or Mac System Logs
SI-23 Information Fragmentation mitigates T1565.001 Stored Data Manipulation
SI-08 Spam Protection mitigates T1137.001 Office Template Macros
SI-08 Spam Protection mitigates T1137.003 Outlook Forms
SI-08 Spam Protection mitigates T1137.004 Outlook Home Page
SI-08 Spam Protection mitigates T1137.005 Outlook Rules
SI-08 Spam Protection mitigates T1137.006 Add-ins
SI-08 Spam Protection mitigates T1204.001 Malicious Link
SI-08 Spam Protection mitigates T1204.003 Malicious Image
SI-08 Spam Protection mitigates T1221 Template Injection
SI-08 Spam Protection mitigates T1598 Phishing for Information
SI-08 Spam Protection mitigates T1598.001 Spearphishing Service
SI-08 Spam Protection mitigates T1598.002 Spearphishing Attachment
SI-12 Information Management and Retention mitigates T1003.003 NTDS
SI-12 Information Management and Retention mitigates T1070 Indicator Removal
SI-12 Information Management and Retention mitigates T1070.002 Clear Linux or Mac System Logs
SI-12 Information Management and Retention mitigates T1070.008 Clear Mailbox Data
SI-12 Information Management and Retention mitigates T1070.008 Clear Mailbox Data
SI-12 Information Management and Retention mitigates T1114.001 Local Email Collection
SI-12 Information Management and Retention mitigates T1548.004 Elevated Execution with Prompt
SI-12 Information Management and Retention mitigates T1557.002 ARP Cache Poisoning
SI-12 Information Management and Retention mitigates T1558.002 Silver Ticket
SI-12 Information Management and Retention mitigates T1558.003 Kerberoasting
SI-12 Information Management and Retention mitigates T1558.004 AS-REP Roasting
SI-12 Information Management and Retention mitigates T1565.001 Stored Data Manipulation
SI-12 Information Management and Retention mitigates T1565.002 Transmitted Data Manipulation
SI-12 Information Management and Retention mitigates T1602 Data from Configuration Repository
SI-12 Information Management and Retention mitigates T1602.001 SNMP (MIB Dump)
SI-12 Information Management and Retention mitigates T1602.002 Network Device Configuration Dump
SI-16 Memory Protection mitigates T1055.009 Proc Memory
SI-16 Memory Protection mitigates T1059.001 PowerShell
SI-16 Memory Protection mitigates T1059.002 AppleScript
SI-16 Memory Protection mitigates T1059.003 Windows Command Shell
SI-16 Memory Protection mitigates T1059.004 Unix Shell
SI-16 Memory Protection mitigates T1059.005 Visual Basic
SI-16 Memory Protection mitigates T1059.007 JavaScript
SI-16 Memory Protection mitigates T1059.008 Network Device CLI
SI-16 Memory Protection mitigates T1218.001 Compiled HTML File
SI-16 Memory Protection mitigates T1218.002 Control Panel
SI-16 Memory Protection mitigates T1218.003 CMSTP
SI-16 Memory Protection mitigates T1218.004 InstallUtil
SI-16 Memory Protection mitigates T1218.005 Mshta
SI-16 Memory Protection mitigates T1218.008 Odbcconf
SI-16 Memory Protection mitigates T1218.009 Regsvcs/Regasm
SI-16 Memory Protection mitigates T1218.012 Verclsid
SI-16 Memory Protection mitigates T1218.013 Mavinject
SI-16 Memory Protection mitigates T1218.014 MMC
SI-16 Memory Protection mitigates T1505.004 IIS Components
SI-16 Memory Protection mitigates T1547.006 Kernel Modules and Extensions
SI-16 Memory Protection mitigates T1548.004 Elevated Execution with Prompt
SI-16 Memory Protection mitigates T1565.001 Stored Data Manipulation
SI-16 Memory Protection mitigates T1565.003 Runtime Data Manipulation
SI-02 Flaw Remediation mitigates T1027.002 Software Packing
SI-02 Flaw Remediation mitigates T1027.007 Dynamic API Resolution
SI-02 Flaw Remediation mitigates T1027.008 Stripped Payloads
SI-02 Flaw Remediation mitigates T1027.009 Embedded Payloads
SI-02 Flaw Remediation mitigates T1055 Process Injection
SI-02 Flaw Remediation mitigates T1055.001 Dynamic-link Library Injection
SI-02 Flaw Remediation mitigates T1055.002 Portable Executable Injection
SI-02 Flaw Remediation mitigates T1055.003 Thread Execution Hijacking
SI-02 Flaw Remediation mitigates T1055.004 Asynchronous Procedure Call
SI-02 Flaw Remediation mitigates T1055.005 Thread Local Storage
SI-02 Flaw Remediation mitigates T1055.008 Ptrace System Calls
SI-02 Flaw Remediation mitigates T1055.009 Proc Memory
SI-02 Flaw Remediation mitigates T1055.011 Extra Window Memory Injection
SI-02 Flaw Remediation mitigates T1055.012 Process Hollowing
SI-02 Flaw Remediation mitigates T1055.013 Process Doppelgänging
SI-02 Flaw Remediation mitigates T1055.014 VDSO Hijacking
SI-02 Flaw Remediation mitigates T1059.001 PowerShell
SI-02 Flaw Remediation mitigates T1059.005 Visual Basic
SI-02 Flaw Remediation mitigates T1068 Exploitation for Privilege Escalation
SI-02 Flaw Remediation mitigates T1106 Native API
SI-02 Flaw Remediation mitigates T1137 Office Application Startup
SI-02 Flaw Remediation mitigates T1137.003 Outlook Forms
SI-02 Flaw Remediation mitigates T1137.004 Outlook Home Page
SI-02 Flaw Remediation mitigates T1137.005 Outlook Rules
SI-02 Flaw Remediation mitigates T1189 Drive-by Compromise
SI-02 Flaw Remediation mitigates T1195.002 Compromise Software Supply Chain
SI-02 Flaw Remediation mitigates T1195.003 Compromise Hardware Supply Chain
SI-02 Flaw Remediation mitigates T1204.001 Malicious Link
SI-02 Flaw Remediation mitigates T1204.003 Malicious Image
SI-02 Flaw Remediation mitigates T1210 Exploitation of Remote Services
SI-02 Flaw Remediation mitigates T1211 Exploitation for Defense Evasion
SI-02 Flaw Remediation mitigates T1212 Exploitation for Credential Access
SI-02 Flaw Remediation mitigates T1221 Template Injection
SI-02 Flaw Remediation mitigates T1495 Firmware Corruption
SI-02 Flaw Remediation mitigates T1525 Implant Internal Image
SI-02 Flaw Remediation mitigates T1542.003 Bootkit
SI-02 Flaw Remediation mitigates T1542.004 ROMMONkit
SI-02 Flaw Remediation mitigates T1542.005 TFTP Boot
SI-02 Flaw Remediation mitigates T1546.006 LC_LOAD_DYLIB Addition
SI-02 Flaw Remediation mitigates T1546.010 AppInit DLLs
SI-02 Flaw Remediation mitigates T1546.011 Application Shimming
SI-02 Flaw Remediation mitigates T1547.006 Kernel Modules and Extensions
SI-02 Flaw Remediation mitigates T1548.002 Bypass User Account Control
SI-02 Flaw Remediation mitigates T1550.002 Pass the Hash
SI-02 Flaw Remediation mitigates T1552.006 Group Policy Preferences
SI-02 Flaw Remediation mitigates T1553.006 Code Signing Policy Modification
SI-02 Flaw Remediation mitigates T1559 Inter-Process Communication
SI-02 Flaw Remediation mitigates T1559.002 Dynamic Data Exchange
SI-02 Flaw Remediation mitigates T1574 Hijack Execution Flow
SI-02 Flaw Remediation mitigates T1574.002 DLL Side-Loading
SI-02 Flaw Remediation mitigates T1574.013 KernelCallbackTable
SI-02 Flaw Remediation mitigates T1601 Modify System Image
SI-02 Flaw Remediation mitigates T1601.001 Patch System Image
SI-02 Flaw Remediation mitigates T1601.002 Downgrade System Image
SI-02 Flaw Remediation mitigates T1606 Forge Web Credentials
SI-02 Flaw Remediation mitigates T1606.001 Web Cookies
SI-10 Information Input Validation mitigates T1021.005 VNC
SI-10 Information Input Validation mitigates T1027.010 Command Obfuscation
SI-10 Information Input Validation mitigates T1036.005 Match Legitimate Name or Location
SI-10 Information Input Validation mitigates T1036.008 Masquerade File Type
SI-10 Information Input Validation mitigates T1048 Exfiltration Over Alternative Protocol
SI-10 Information Input Validation mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
SI-10 Information Input Validation mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
SI-10 Information Input Validation mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
SI-10 Information Input Validation mitigates T1059.001 PowerShell
SI-10 Information Input Validation mitigates T1059.002 AppleScript
SI-10 Information Input Validation mitigates T1059.003 Windows Command Shell
SI-10 Information Input Validation mitigates T1059.004 Unix Shell
SI-10 Information Input Validation mitigates T1059.005 Visual Basic
SI-10 Information Input Validation mitigates T1059.007 JavaScript
SI-10 Information Input Validation mitigates T1059.008 Network Device CLI
SI-10 Information Input Validation mitigates T1071.004 DNS
SI-10 Information Input Validation mitigates T1080 Taint Shared Content
SI-10 Information Input Validation mitigates T1090 Proxy
SI-10 Information Input Validation mitigates T1095 Non-Application Layer Protocol
SI-10 Information Input Validation mitigates T1127 Trusted Developer Utilities Proxy Execution
SI-10 Information Input Validation mitigates T1129 Shared Modules
SI-10 Information Input Validation mitigates T1187 Forced Authentication
SI-10 Information Input Validation mitigates T1197 BITS Jobs
SI-10 Information Input Validation mitigates T1216 System Script Proxy Execution
SI-10 Information Input Validation mitigates T1216.001 PubPrn
SI-10 Information Input Validation mitigates T1218.001 Compiled HTML File
SI-10 Information Input Validation mitigates T1218.002 Control Panel
SI-10 Information Input Validation mitigates T1218.003 CMSTP
SI-10 Information Input Validation mitigates T1218.004 InstallUtil
SI-10 Information Input Validation mitigates T1218.005 Mshta
SI-10 Information Input Validation mitigates T1218.008 Odbcconf
SI-10 Information Input Validation mitigates T1218.009 Regsvcs/Regasm
SI-10 Information Input Validation mitigates T1218.010 Regsvr32
SI-10 Information Input Validation mitigates T1218.012 Verclsid
SI-10 Information Input Validation mitigates T1218.013 Mavinject
SI-10 Information Input Validation mitigates T1218.014 MMC
SI-10 Information Input Validation mitigates T1220 XSL Script Processing
SI-10 Information Input Validation mitigates T1221 Template Injection
SI-10 Information Input Validation mitigates T1498 Network Denial of Service
SI-10 Information Input Validation mitigates T1498.001 Direct Network Flood
SI-10 Information Input Validation mitigates T1498.002 Reflection Amplification
SI-10 Information Input Validation mitigates T1499 Endpoint Denial of Service
SI-10 Information Input Validation mitigates T1499.001 OS Exhaustion Flood
SI-10 Information Input Validation mitigates T1499.002 Service Exhaustion Flood
SI-10 Information Input Validation mitigates T1499.003 Application Exhaustion Flood
SI-10 Information Input Validation mitigates T1499.004 Application or System Exploitation
SI-10 Information Input Validation mitigates T1546.002 Screensaver
SI-10 Information Input Validation mitigates T1546.006 LC_LOAD_DYLIB Addition
SI-10 Information Input Validation mitigates T1546.008 Accessibility Features
SI-10 Information Input Validation mitigates T1546.009 AppCert DLLs
SI-10 Information Input Validation mitigates T1546.010 AppInit DLLs
SI-10 Information Input Validation mitigates T1547.006 Kernel Modules and Extensions
SI-10 Information Input Validation mitigates T1552.005 Cloud Instance Metadata API
SI-10 Information Input Validation mitigates T1553.001 Gatekeeper Bypass
SI-10 Information Input Validation mitigates T1553.003 SIP and Trust Provider Hijacking
SI-10 Information Input Validation mitigates T1553.005 Mark-of-the-Web Bypass
SI-10 Information Input Validation mitigates T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay
SI-10 Information Input Validation mitigates T1557.002 ARP Cache Poisoning
SI-10 Information Input Validation mitigates T1557.003 DHCP Spoofing
SI-10 Information Input Validation mitigates T1564.006 Run Virtual Instance
SI-10 Information Input Validation mitigates T1564.009 Resource Forking
SI-10 Information Input Validation mitigates T1570 Lateral Tool Transfer
SI-10 Information Input Validation mitigates T1574 Hijack Execution Flow
SI-10 Information Input Validation mitigates T1574.006 Dynamic Linker Hijacking
SI-10 Information Input Validation mitigates T1574.007 Path Interception by PATH Environment Variable
SI-10 Information Input Validation mitigates T1574.008 Path Interception by Search Order Hijacking
SI-10 Information Input Validation mitigates T1574.009 Path Interception by Unquoted Path
SI-10 Information Input Validation mitigates T1574.012 COR_PROFILER
SI-10 Information Input Validation mitigates T1574.013 KernelCallbackTable
SI-10 Information Input Validation mitigates T1599 Network Boundary Bridging
SI-10 Information Input Validation mitigates T1599.001 Network Address Translation Traversal
SI-10 Information Input Validation mitigates T1602 Data from Configuration Repository
SI-10 Information Input Validation mitigates T1602.001 SNMP (MIB Dump)
SI-10 Information Input Validation mitigates T1602.002 Network Device Configuration Dump
SI-10 Information Input Validation mitigates T1609 Container Administration Command
SI-10 Information Input Validation mitigates T1622 Debugger Evasion
SI-15 Information Output Filtering mitigates T1021.005 VNC
SI-15 Information Output Filtering mitigates T1048 Exfiltration Over Alternative Protocol
SI-15 Information Output Filtering mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
SI-15 Information Output Filtering mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
SI-15 Information Output Filtering mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
SI-15 Information Output Filtering mitigates T1071.004 DNS
SI-15 Information Output Filtering mitigates T1090 Proxy
SI-15 Information Output Filtering mitigates T1095 Non-Application Layer Protocol
SI-15 Information Output Filtering mitigates T1187 Forced Authentication
SI-15 Information Output Filtering mitigates T1197 BITS Jobs
SI-15 Information Output Filtering mitigates T1205 Traffic Signaling
SI-15 Information Output Filtering mitigates T1205.001 Port Knocking
SI-15 Information Output Filtering mitigates T1218.012 Verclsid
SI-15 Information Output Filtering mitigates T1498 Network Denial of Service
SI-15 Information Output Filtering mitigates T1498.001 Direct Network Flood
SI-15 Information Output Filtering mitigates T1498.002 Reflection Amplification
SI-15 Information Output Filtering mitigates T1499 Endpoint Denial of Service
SI-15 Information Output Filtering mitigates T1499.001 OS Exhaustion Flood
SI-15 Information Output Filtering mitigates T1499.002 Service Exhaustion Flood
SI-15 Information Output Filtering mitigates T1499.003 Application Exhaustion Flood
SI-15 Information Output Filtering mitigates T1499.004 Application or System Exploitation
SI-15 Information Output Filtering mitigates T1552.005 Cloud Instance Metadata API
SI-15 Information Output Filtering mitigates T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay
SI-15 Information Output Filtering mitigates T1557.002 ARP Cache Poisoning
SI-15 Information Output Filtering mitigates T1557.003 DHCP Spoofing
SI-15 Information Output Filtering mitigates T1564.009 Resource Forking
SI-15 Information Output Filtering mitigates T1570 Lateral Tool Transfer
SI-15 Information Output Filtering mitigates T1599 Network Boundary Bridging
SI-15 Information Output Filtering mitigates T1599.001 Network Address Translation Traversal
SI-15 Information Output Filtering mitigates T1602 Data from Configuration Repository
SI-15 Information Output Filtering mitigates T1602.001 SNMP (MIB Dump)
SI-15 Information Output Filtering mitigates T1602.002 Network Device Configuration Dump
SI-15 Information Output Filtering mitigates T1622 Debugger Evasion
SI-03 Malicious Code Protection mitigates T1001.002 Steganography
SI-03 Malicious Code Protection mitigates T1003.002 Security Account Manager
SI-03 Malicious Code Protection mitigates T1003.003 NTDS
SI-03 Malicious Code Protection mitigates T1003.004 LSA Secrets
SI-03 Malicious Code Protection mitigates T1003.006 DCSync
SI-03 Malicious Code Protection mitigates T1003.008 /etc/passwd and /etc/shadow
SI-03 Malicious Code Protection mitigates T1005 Data from Local System
SI-03 Malicious Code Protection mitigates T1008 Fallback Channels
SI-03 Malicious Code Protection mitigates T1011.001 Exfiltration Over Bluetooth
SI-03 Malicious Code Protection mitigates T1021.003 Distributed Component Object Model
SI-03 Malicious Code Protection mitigates T1021.005 VNC
SI-03 Malicious Code Protection mitigates T1025 Data from Removable Media
SI-03 Malicious Code Protection mitigates T1027.002 Software Packing
SI-03 Malicious Code Protection mitigates T1027.007 Dynamic API Resolution
SI-03 Malicious Code Protection mitigates T1027.008 Stripped Payloads
SI-03 Malicious Code Protection mitigates T1027.009 Embedded Payloads
SI-03 Malicious Code Protection mitigates T1027.010 Command Obfuscation
SI-03 Malicious Code Protection mitigates T1027.012 LNK Icon Smuggling
SI-03 Malicious Code Protection mitigates T1029 Scheduled Transfer
SI-03 Malicious Code Protection mitigates T1030 Data Transfer Size Limits
SI-03 Malicious Code Protection mitigates T1036.003 Rename System Utilities
SI-03 Malicious Code Protection mitigates T1036.005 Match Legitimate Name or Location
SI-03 Malicious Code Protection mitigates T1036.008 Masquerade File Type
SI-03 Malicious Code Protection mitigates T1037.002 Login Hook
SI-03 Malicious Code Protection mitigates T1037.003 Network Logon Script
SI-03 Malicious Code Protection mitigates T1037.004 RC Scripts
SI-03 Malicious Code Protection mitigates T1037.005 Startup Items
SI-03 Malicious Code Protection mitigates T1041 Exfiltration Over C2 Channel
SI-03 Malicious Code Protection mitigates T1046 Network Service Discovery
SI-03 Malicious Code Protection mitigates T1048 Exfiltration Over Alternative Protocol
SI-03 Malicious Code Protection mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
SI-03 Malicious Code Protection mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
SI-03 Malicious Code Protection mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
SI-03 Malicious Code Protection mitigates T1052 Exfiltration Over Physical Medium
SI-03 Malicious Code Protection mitigates T1052.001 Exfiltration over USB
SI-03 Malicious Code Protection mitigates T1055 Process Injection
SI-03 Malicious Code Protection mitigates T1055.001 Dynamic-link Library Injection
SI-03 Malicious Code Protection mitigates T1055.002 Portable Executable Injection
SI-03 Malicious Code Protection mitigates T1055.003 Thread Execution Hijacking
SI-03 Malicious Code Protection mitigates T1055.004 Asynchronous Procedure Call
SI-03 Malicious Code Protection mitigates T1055.005 Thread Local Storage
SI-03 Malicious Code Protection mitigates T1055.008 Ptrace System Calls
SI-03 Malicious Code Protection mitigates T1055.009 Proc Memory
SI-03 Malicious Code Protection mitigates T1055.011 Extra Window Memory Injection
SI-03 Malicious Code Protection mitigates T1055.012 Process Hollowing
SI-03 Malicious Code Protection mitigates T1055.013 Process Doppelgänging
SI-03 Malicious Code Protection mitigates T1055.014 VDSO Hijacking
SI-03 Malicious Code Protection mitigates T1059.001 PowerShell
SI-03 Malicious Code Protection mitigates T1059.002 AppleScript
SI-03 Malicious Code Protection mitigates T1059.003 Windows Command Shell
SI-03 Malicious Code Protection mitigates T1059.004 Unix Shell
SI-03 Malicious Code Protection mitigates T1059.005 Visual Basic
SI-03 Malicious Code Protection mitigates T1059.007 JavaScript
SI-03 Malicious Code Protection mitigates T1059.008 Network Device CLI
SI-03 Malicious Code Protection mitigates T1068 Exploitation for Privilege Escalation
SI-03 Malicious Code Protection mitigates T1070 Indicator Removal
SI-03 Malicious Code Protection mitigates T1070.002 Clear Linux or Mac System Logs
SI-03 Malicious Code Protection mitigates T1070.007 Clear Network Connection History and Configurations
SI-03 Malicious Code Protection mitigates T1070.008 Clear Mailbox Data
SI-03 Malicious Code Protection mitigates T1070.009 Clear Persistence
SI-03 Malicious Code Protection mitigates T1071.001 Web Protocols
SI-03 Malicious Code Protection mitigates T1071.004 DNS
SI-03 Malicious Code Protection mitigates T1080 Taint Shared Content
SI-03 Malicious Code Protection mitigates T1090 Proxy
SI-03 Malicious Code Protection mitigates T1090.001 Internal Proxy
SI-03 Malicious Code Protection mitigates T1090.002 External Proxy
SI-03 Malicious Code Protection mitigates T1091 Replication Through Removable Media
SI-03 Malicious Code Protection mitigates T1095 Non-Application Layer Protocol
SI-03 Malicious Code Protection mitigates T1098.004 SSH Authorized Keys
SI-03 Malicious Code Protection mitigates T1102.001 Dead Drop Resolver
SI-03 Malicious Code Protection mitigates T1102.002 Bidirectional Communication
SI-03 Malicious Code Protection mitigates T1102.003 One-Way Communication
SI-03 Malicious Code Protection mitigates T1104 Multi-Stage Channels
SI-03 Malicious Code Protection mitigates T1106 Native API
SI-03 Malicious Code Protection mitigates T1111 Multi-Factor Authentication Interception
SI-03 Malicious Code Protection mitigates T1129 Shared Modules
SI-03 Malicious Code Protection mitigates T1132 Data Encoding
SI-03 Malicious Code Protection mitigates T1132.001 Standard Encoding
SI-03 Malicious Code Protection mitigates T1132.002 Non-Standard Encoding
SI-03 Malicious Code Protection mitigates T1137 Office Application Startup
SI-03 Malicious Code Protection mitigates T1137.001 Office Template Macros
SI-03 Malicious Code Protection mitigates T1185 Browser Session Hijacking
SI-03 Malicious Code Protection mitigates T1189 Drive-by Compromise
SI-03 Malicious Code Protection mitigates T1201 Password Policy Discovery
SI-03 Malicious Code Protection mitigates T1204.001 Malicious Link
SI-03 Malicious Code Protection mitigates T1204.003 Malicious Image
SI-03 Malicious Code Protection mitigates T1210 Exploitation of Remote Services
SI-03 Malicious Code Protection mitigates T1211 Exploitation for Defense Evasion
SI-03 Malicious Code Protection mitigates T1212 Exploitation for Credential Access
SI-03 Malicious Code Protection mitigates T1218.001 Compiled HTML File
SI-03 Malicious Code Protection mitigates T1218.002 Control Panel
SI-03 Malicious Code Protection mitigates T1218.003 CMSTP
SI-03 Malicious Code Protection mitigates T1218.004 InstallUtil
SI-03 Malicious Code Protection mitigates T1218.005 Mshta
SI-03 Malicious Code Protection mitigates T1218.008 Odbcconf
SI-03 Malicious Code Protection mitigates T1218.009 Regsvcs/Regasm
SI-03 Malicious Code Protection mitigates T1218.012 Verclsid
SI-03 Malicious Code Protection mitigates T1218.013 Mavinject
SI-03 Malicious Code Protection mitigates T1218.014 MMC
SI-03 Malicious Code Protection mitigates T1221 Template Injection
SI-03 Malicious Code Protection mitigates T1486 Data Encrypted for Impact
SI-03 Malicious Code Protection mitigates T1491 Defacement
SI-03 Malicious Code Protection mitigates T1491.001 Internal Defacement
SI-03 Malicious Code Protection mitigates T1491.002 External Defacement
SI-03 Malicious Code Protection mitigates T1505.004 IIS Components
SI-03 Malicious Code Protection mitigates T1525 Implant Internal Image
SI-03 Malicious Code Protection mitigates T1546.002 Screensaver
SI-03 Malicious Code Protection mitigates T1546.004 Unix Shell Configuration Modification
SI-03 Malicious Code Protection mitigates T1546.006 LC_LOAD_DYLIB Addition
SI-03 Malicious Code Protection mitigates T1546.013 PowerShell Profile
SI-03 Malicious Code Protection mitigates T1546.014 Emond
SI-03 Malicious Code Protection mitigates T1547.002 Authentication Package
SI-03 Malicious Code Protection mitigates T1547.005 Security Support Provider
SI-03 Malicious Code Protection mitigates T1547.006 Kernel Modules and Extensions
SI-03 Malicious Code Protection mitigates T1547.007 Re-opened Applications
SI-03 Malicious Code Protection mitigates T1547.008 LSASS Driver
SI-03 Malicious Code Protection mitigates T1547.013 XDG Autostart Entries
SI-03 Malicious Code Protection mitigates T1548.004 Elevated Execution with Prompt
SI-03 Malicious Code Protection mitigates T1553.003 SIP and Trust Provider Hijacking
SI-03 Malicious Code Protection mitigates T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay
SI-03 Malicious Code Protection mitigates T1557.002 ARP Cache Poisoning
SI-03 Malicious Code Protection mitigates T1557.003 DHCP Spoofing
SI-03 Malicious Code Protection mitigates T1558.002 Silver Ticket
SI-03 Malicious Code Protection mitigates T1558.003 Kerberoasting
SI-03 Malicious Code Protection mitigates T1558.004 AS-REP Roasting
SI-03 Malicious Code Protection mitigates T1559 Inter-Process Communication
SI-03 Malicious Code Protection mitigates T1559.001 Component Object Model
SI-03 Malicious Code Protection mitigates T1559.002 Dynamic Data Exchange
SI-03 Malicious Code Protection mitigates T1560.001 Archive via Utility
SI-03 Malicious Code Protection mitigates T1561 Disk Wipe
SI-03 Malicious Code Protection mitigates T1561.001 Disk Content Wipe
SI-03 Malicious Code Protection mitigates T1561.002 Disk Structure Wipe
SI-03 Malicious Code Protection mitigates T1562.001 Disable or Modify Tools
SI-03 Malicious Code Protection mitigates T1562.002 Disable Windows Event Logging
SI-03 Malicious Code Protection mitigates T1562.011 Spoof Security Alerting
SI-03 Malicious Code Protection mitigates T1564.008 Email Hiding Rules
SI-03 Malicious Code Protection mitigates T1564.009 Resource Forking
SI-03 Malicious Code Protection mitigates T1567 Exfiltration Over Web Service
SI-03 Malicious Code Protection mitigates T1568 Dynamic Resolution
SI-03 Malicious Code Protection mitigates T1568.002 Domain Generation Algorithms
SI-03 Malicious Code Protection mitigates T1569 System Services
SI-03 Malicious Code Protection mitigates T1569.002 Service Execution
SI-03 Malicious Code Protection mitigates T1570 Lateral Tool Transfer
SI-03 Malicious Code Protection mitigates T1571 Non-Standard Port
SI-03 Malicious Code Protection mitigates T1573.001 Symmetric Cryptography
SI-03 Malicious Code Protection mitigates T1573.002 Asymmetric Cryptography
SI-03 Malicious Code Protection mitigates T1574 Hijack Execution Flow
SI-03 Malicious Code Protection mitigates T1574.004 Dylib Hijacking
SI-03 Malicious Code Protection mitigates T1574.007 Path Interception by PATH Environment Variable
SI-03 Malicious Code Protection mitigates T1574.008 Path Interception by Search Order Hijacking
SI-03 Malicious Code Protection mitigates T1574.009 Path Interception by Unquoted Path
SI-03 Malicious Code Protection mitigates T1574.013 KernelCallbackTable
SI-03 Malicious Code Protection mitigates T1598 Phishing for Information
SI-03 Malicious Code Protection mitigates T1598.001 Spearphishing Service
SI-03 Malicious Code Protection mitigates T1598.002 Spearphishing Attachment
SI-03 Malicious Code Protection mitigates T1602 Data from Configuration Repository
SI-03 Malicious Code Protection mitigates T1602.001 SNMP (MIB Dump)
SI-03 Malicious Code Protection mitigates T1602.002 Network Device Configuration Dump
SI-03 Malicious Code Protection mitigates T1622 Debugger Evasion
SI-07 Software, Firmware, and Information Integrity mitigates T1003.003 NTDS
SI-07 Software, Firmware, and Information Integrity mitigates T1027.002 Software Packing
SI-07 Software, Firmware, and Information Integrity mitigates T1027.007 Dynamic API Resolution
SI-07 Software, Firmware, and Information Integrity mitigates T1027.008 Stripped Payloads
SI-07 Software, Firmware, and Information Integrity mitigates T1027.009 Embedded Payloads
SI-07 Software, Firmware, and Information Integrity mitigates T1036.001 Invalid Code Signature
SI-07 Software, Firmware, and Information Integrity mitigates T1036.005 Match Legitimate Name or Location
SI-07 Software, Firmware, and Information Integrity mitigates T1037.002 Login Hook
SI-07 Software, Firmware, and Information Integrity mitigates T1037.003 Network Logon Script
SI-07 Software, Firmware, and Information Integrity mitigates T1037.004 RC Scripts
SI-07 Software, Firmware, and Information Integrity mitigates T1037.005 Startup Items
SI-07 Software, Firmware, and Information Integrity mitigates T1053.006 Systemd Timers
SI-07 Software, Firmware, and Information Integrity mitigates T1059.001 PowerShell
SI-07 Software, Firmware, and Information Integrity mitigates T1059.002 AppleScript
SI-07 Software, Firmware, and Information Integrity mitigates T1059.003 Windows Command Shell
SI-07 Software, Firmware, and Information Integrity mitigates T1059.004 Unix Shell
SI-07 Software, Firmware, and Information Integrity mitigates T1059.005 Visual Basic
SI-07 Software, Firmware, and Information Integrity mitigates T1059.007 JavaScript
SI-07 Software, Firmware, and Information Integrity mitigates T1059.008 Network Device CLI
SI-07 Software, Firmware, and Information Integrity mitigates T1068 Exploitation for Privilege Escalation
SI-07 Software, Firmware, and Information Integrity mitigates T1070 Indicator Removal
SI-07 Software, Firmware, and Information Integrity mitigates T1070.002 Clear Linux or Mac System Logs
SI-07 Software, Firmware, and Information Integrity mitigates T1070.007 Clear Network Connection History and Configurations
SI-07 Software, Firmware, and Information Integrity mitigates T1070.008 Clear Mailbox Data
SI-07 Software, Firmware, and Information Integrity mitigates T1070.009 Clear Persistence
SI-07 Software, Firmware, and Information Integrity mitigates T1080 Taint Shared Content
SI-07 Software, Firmware, and Information Integrity mitigates T1112 Modify Registry
SI-07 Software, Firmware, and Information Integrity mitigates T1114.001 Local Email Collection
SI-07 Software, Firmware, and Information Integrity mitigates T1127 Trusted Developer Utilities Proxy Execution
SI-07 Software, Firmware, and Information Integrity mitigates T1129 Shared Modules
SI-07 Software, Firmware, and Information Integrity mitigates T1133 External Remote Services
SI-07 Software, Firmware, and Information Integrity mitigates T1136.001 Local Account
SI-07 Software, Firmware, and Information Integrity mitigates T1185 Browser Session Hijacking
SI-07 Software, Firmware, and Information Integrity mitigates T1189 Drive-by Compromise
SI-07 Software, Firmware, and Information Integrity mitigates T1195.003 Compromise Hardware Supply Chain
SI-07 Software, Firmware, and Information Integrity mitigates T1204.003 Malicious Image
SI-07 Software, Firmware, and Information Integrity mitigates T1210 Exploitation of Remote Services
SI-07 Software, Firmware, and Information Integrity mitigates T1211 Exploitation for Defense Evasion
SI-07 Software, Firmware, and Information Integrity mitigates T1212 Exploitation for Credential Access
SI-07 Software, Firmware, and Information Integrity mitigates T1216 System Script Proxy Execution
SI-07 Software, Firmware, and Information Integrity mitigates T1216.001 PubPrn
SI-07 Software, Firmware, and Information Integrity mitigates T1218.001 Compiled HTML File
SI-07 Software, Firmware, and Information Integrity mitigates T1218.002 Control Panel
SI-07 Software, Firmware, and Information Integrity mitigates T1218.003 CMSTP
SI-07 Software, Firmware, and Information Integrity mitigates T1218.004 InstallUtil
SI-07 Software, Firmware, and Information Integrity mitigates T1218.005 Mshta
SI-07 Software, Firmware, and Information Integrity mitigates T1218.008 Odbcconf
SI-07 Software, Firmware, and Information Integrity mitigates T1218.009 Regsvcs/Regasm
SI-07 Software, Firmware, and Information Integrity mitigates T1218.010 Regsvr32
SI-07 Software, Firmware, and Information Integrity mitigates T1218.012 Verclsid
SI-07 Software, Firmware, and Information Integrity mitigates T1218.013 Mavinject
SI-07 Software, Firmware, and Information Integrity mitigates T1218.014 MMC
SI-07 Software, Firmware, and Information Integrity mitigates T1220 XSL Script Processing
SI-07 Software, Firmware, and Information Integrity mitigates T1221 Template Injection
SI-07 Software, Firmware, and Information Integrity mitigates T1222 File and Directory Permissions Modification
SI-07 Software, Firmware, and Information Integrity mitigates T1222.001 Windows File and Directory Permissions Modification
SI-07 Software, Firmware, and Information Integrity mitigates T1222.002 Linux and Mac File and Directory Permissions Modification
SI-07 Software, Firmware, and Information Integrity mitigates T1486 Data Encrypted for Impact
SI-07 Software, Firmware, and Information Integrity mitigates T1491 Defacement
SI-07 Software, Firmware, and Information Integrity mitigates T1491.001 Internal Defacement
SI-07 Software, Firmware, and Information Integrity mitigates T1491.002 External Defacement
SI-07 Software, Firmware, and Information Integrity mitigates T1495 Firmware Corruption
SI-07 Software, Firmware, and Information Integrity mitigates T1505 Server Software Component
SI-07 Software, Firmware, and Information Integrity mitigates T1505.001 SQL Stored Procedures
SI-07 Software, Firmware, and Information Integrity mitigates T1505.002 Transport Agent
SI-07 Software, Firmware, and Information Integrity mitigates T1505.004 IIS Components
SI-07 Software, Firmware, and Information Integrity mitigates T1525 Implant Internal Image
SI-07 Software, Firmware, and Information Integrity mitigates T1542.003 Bootkit
SI-07 Software, Firmware, and Information Integrity mitigates T1542.004 ROMMONkit
SI-07 Software, Firmware, and Information Integrity mitigates T1542.005 TFTP Boot
SI-07 Software, Firmware, and Information Integrity mitigates T1546.002 Screensaver
SI-07 Software, Firmware, and Information Integrity mitigates T1546.004 Unix Shell Configuration Modification
SI-07 Software, Firmware, and Information Integrity mitigates T1546.006 LC_LOAD_DYLIB Addition
SI-07 Software, Firmware, and Information Integrity mitigates T1546.008 Accessibility Features
SI-07 Software, Firmware, and Information Integrity mitigates T1546.009 AppCert DLLs
SI-07 Software, Firmware, and Information Integrity mitigates T1546.010 AppInit DLLs
SI-07 Software, Firmware, and Information Integrity mitigates T1546.013 PowerShell Profile
SI-07 Software, Firmware, and Information Integrity mitigates T1547.002 Authentication Package
SI-07 Software, Firmware, and Information Integrity mitigates T1547.005 Security Support Provider
SI-07 Software, Firmware, and Information Integrity mitigates T1547.006 Kernel Modules and Extensions
SI-07 Software, Firmware, and Information Integrity mitigates T1547.008 LSASS Driver
SI-07 Software, Firmware, and Information Integrity mitigates T1547.013 XDG Autostart Entries
SI-07 Software, Firmware, and Information Integrity mitigates T1548.004 Elevated Execution with Prompt
SI-07 Software, Firmware, and Information Integrity mitigates T1550.004 Web Session Cookie
SI-07 Software, Firmware, and Information Integrity mitigates T1553.001 Gatekeeper Bypass
SI-07 Software, Firmware, and Information Integrity mitigates T1553.003 SIP and Trust Provider Hijacking
SI-07 Software, Firmware, and Information Integrity mitigates T1553.005 Mark-of-the-Web Bypass
SI-07 Software, Firmware, and Information Integrity mitigates T1553.006 Code Signing Policy Modification
SI-07 Software, Firmware, and Information Integrity mitigates T1556.003 Pluggable Authentication Modules
SI-07 Software, Firmware, and Information Integrity mitigates T1556.004 Network Device Authentication
SI-07 Software, Firmware, and Information Integrity mitigates T1556.008 Network Provider DLL
SI-07 Software, Firmware, and Information Integrity mitigates T1557.002 ARP Cache Poisoning
SI-07 Software, Firmware, and Information Integrity mitigates T1558.002 Silver Ticket
SI-07 Software, Firmware, and Information Integrity mitigates T1558.003 Kerberoasting
SI-07 Software, Firmware, and Information Integrity mitigates T1558.004 AS-REP Roasting
SI-07 Software, Firmware, and Information Integrity mitigates T1561 Disk Wipe
SI-07 Software, Firmware, and Information Integrity mitigates T1561.001 Disk Content Wipe
SI-07 Software, Firmware, and Information Integrity mitigates T1561.002 Disk Structure Wipe
SI-07 Software, Firmware, and Information Integrity mitigates T1562.001 Disable or Modify Tools
SI-07 Software, Firmware, and Information Integrity mitigates T1562.002 Disable Windows Event Logging
SI-07 Software, Firmware, and Information Integrity mitigates T1562.009 Safe Mode Boot
SI-07 Software, Firmware, and Information Integrity mitigates T1562.010 Downgrade Attack
SI-07 Software, Firmware, and Information Integrity mitigates T1562.011 Spoof Security Alerting
SI-07 Software, Firmware, and Information Integrity mitigates T1562.012 Disable or Modify Linux Audit System
SI-07 Software, Firmware, and Information Integrity mitigates T1564.006 Run Virtual Instance
SI-07 Software, Firmware, and Information Integrity mitigates T1564.008 Email Hiding Rules
SI-07 Software, Firmware, and Information Integrity mitigates T1564.009 Resource Forking
SI-07 Software, Firmware, and Information Integrity mitigates T1564.010 Process Argument Spoofing
SI-07 Software, Firmware, and Information Integrity mitigates T1565.001 Stored Data Manipulation
SI-07 Software, Firmware, and Information Integrity mitigates T1565.002 Transmitted Data Manipulation
SI-07 Software, Firmware, and Information Integrity mitigates T1565.003 Runtime Data Manipulation
SI-07 Software, Firmware, and Information Integrity mitigates T1569 System Services
SI-07 Software, Firmware, and Information Integrity mitigates T1569.002 Service Execution
SI-07 Software, Firmware, and Information Integrity mitigates T1574 Hijack Execution Flow
SI-07 Software, Firmware, and Information Integrity mitigates T1574.004 Dylib Hijacking
SI-07 Software, Firmware, and Information Integrity mitigates T1574.006 Dynamic Linker Hijacking
SI-07 Software, Firmware, and Information Integrity mitigates T1574.007 Path Interception by PATH Environment Variable
SI-07 Software, Firmware, and Information Integrity mitigates T1574.008 Path Interception by Search Order Hijacking
SI-07 Software, Firmware, and Information Integrity mitigates T1574.009 Path Interception by Unquoted Path
SI-07 Software, Firmware, and Information Integrity mitigates T1574.012 COR_PROFILER
SI-07 Software, Firmware, and Information Integrity mitigates T1574.013 KernelCallbackTable
SI-07 Software, Firmware, and Information Integrity mitigates T1599 Network Boundary Bridging
SI-07 Software, Firmware, and Information Integrity mitigates T1599.001 Network Address Translation Traversal
SI-07 Software, Firmware, and Information Integrity mitigates T1601 Modify System Image
SI-07 Software, Firmware, and Information Integrity mitigates T1601.001 Patch System Image
SI-07 Software, Firmware, and Information Integrity mitigates T1601.002 Downgrade System Image
SI-07 Software, Firmware, and Information Integrity mitigates T1602 Data from Configuration Repository
SI-07 Software, Firmware, and Information Integrity mitigates T1602.001 SNMP (MIB Dump)
SI-07 Software, Firmware, and Information Integrity mitigates T1602.002 Network Device Configuration Dump
SI-07 Software, Firmware, and Information Integrity mitigates T1609 Container Administration Command
SI-07 Software, Firmware, and Information Integrity mitigates T1647 Plist File Modification
SI-04 System Monitoring mitigates T1001.002 Steganography
SI-04 System Monitoring mitigates T1003.002 Security Account Manager
SI-04 System Monitoring mitigates T1003.003 NTDS
SI-04 System Monitoring mitigates T1003.004 LSA Secrets
SI-04 System Monitoring mitigates T1003.006 DCSync
SI-04 System Monitoring mitigates T1003.008 /etc/passwd and /etc/shadow
SI-04 System Monitoring mitigates T1005 Data from Local System
SI-04 System Monitoring mitigates T1008 Fallback Channels
SI-04 System Monitoring mitigates T1011 Exfiltration Over Other Network Medium
SI-04 System Monitoring mitigates T1011.001 Exfiltration Over Bluetooth
SI-04 System Monitoring mitigates T1021.001 Remote Desktop Protocol
SI-04 System Monitoring mitigates T1021.002 SMB/Windows Admin Shares
SI-04 System Monitoring mitigates T1021.003 Distributed Component Object Model
SI-04 System Monitoring mitigates T1021.004 SSH
SI-04 System Monitoring mitigates T1021.005 VNC
SI-04 System Monitoring mitigates T1021.006 Windows Remote Management
SI-04 System Monitoring mitigates T1021.008 Direct Cloud VM Connections
SI-04 System Monitoring mitigates T1025 Data from Removable Media
SI-04 System Monitoring mitigates T1027.002 Software Packing
SI-04 System Monitoring mitigates T1027.007 Dynamic API Resolution
SI-04 System Monitoring mitigates T1027.008 Stripped Payloads
SI-04 System Monitoring mitigates T1027.009 Embedded Payloads
SI-04 System Monitoring mitigates T1027.010 Command Obfuscation
SI-04 System Monitoring mitigates T1027.012 LNK Icon Smuggling
SI-04 System Monitoring mitigates T1029 Scheduled Transfer
SI-04 System Monitoring mitigates T1030 Data Transfer Size Limits
SI-04 System Monitoring mitigates T1036.001 Invalid Code Signature
SI-04 System Monitoring mitigates T1036.003 Rename System Utilities
SI-04 System Monitoring mitigates T1036.005 Match Legitimate Name or Location
SI-04 System Monitoring mitigates T1036.007 Double File Extension
SI-04 System Monitoring mitigates T1036.008 Masquerade File Type
SI-04 System Monitoring mitigates T1037.002 Login Hook
SI-04 System Monitoring mitigates T1037.003 Network Logon Script
SI-04 System Monitoring mitigates T1037.004 RC Scripts
SI-04 System Monitoring mitigates T1037.005 Startup Items
SI-04 System Monitoring mitigates T1041 Exfiltration Over C2 Channel
SI-04 System Monitoring mitigates T1046 Network Service Discovery
SI-04 System Monitoring mitigates T1048 Exfiltration Over Alternative Protocol
SI-04 System Monitoring mitigates T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
SI-04 System Monitoring mitigates T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
SI-04 System Monitoring mitigates T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
SI-04 System Monitoring mitigates T1052 Exfiltration Over Physical Medium
SI-04 System Monitoring mitigates T1052.001 Exfiltration over USB
SI-04 System Monitoring mitigates T1053.003 Cron
SI-04 System Monitoring mitigates T1053.006 Systemd Timers
SI-04 System Monitoring mitigates T1055 Process Injection
SI-04 System Monitoring mitigates T1055.001 Dynamic-link Library Injection
SI-04 System Monitoring mitigates T1055.002 Portable Executable Injection
SI-04 System Monitoring mitigates T1055.003 Thread Execution Hijacking
SI-04 System Monitoring mitigates T1055.004 Asynchronous Procedure Call
SI-04 System Monitoring mitigates T1055.005 Thread Local Storage
SI-04 System Monitoring mitigates T1055.008 Ptrace System Calls
SI-04 System Monitoring mitigates T1055.009 Proc Memory
SI-04 System Monitoring mitigates T1055.011 Extra Window Memory Injection
SI-04 System Monitoring mitigates T1055.012 Process Hollowing
SI-04 System Monitoring mitigates T1055.013 Process Doppelgänging
SI-04 System Monitoring mitigates T1055.014 VDSO Hijacking
SI-04 System Monitoring mitigates T1059.001 PowerShell
SI-04 System Monitoring mitigates T1059.002 AppleScript
SI-04 System Monitoring mitigates T1059.003 Windows Command Shell
SI-04 System Monitoring mitigates T1059.004 Unix Shell
SI-04 System Monitoring mitigates T1059.005 Visual Basic
SI-04 System Monitoring mitigates T1059.007 JavaScript
SI-04 System Monitoring mitigates T1059.008 Network Device CLI
SI-04 System Monitoring mitigates T1059.009 Cloud API
SI-04 System Monitoring mitigates T1068 Exploitation for Privilege Escalation
SI-04 System Monitoring mitigates T1070 Indicator Removal
SI-04 System Monitoring mitigates T1070.002 Clear Linux or Mac System Logs
SI-04 System Monitoring mitigates T1070.007 Clear Network Connection History and Configurations
SI-04 System Monitoring mitigates T1070.008 Clear Mailbox Data
SI-04 System Monitoring mitigates T1070.009 Clear Persistence
SI-04 System Monitoring mitigates T1071.001 Web Protocols
SI-04 System Monitoring mitigates T1071.004 DNS
SI-04 System Monitoring mitigates T1078.002 Domain Accounts
SI-04 System Monitoring mitigates T1080 Taint Shared Content
SI-04 System Monitoring mitigates T1090 Proxy
SI-04 System Monitoring mitigates T1090.001 Internal Proxy
SI-04 System Monitoring mitigates T1090.002 External Proxy
SI-04 System Monitoring mitigates T1091 Replication Through Removable Media
SI-04 System Monitoring mitigates T1095 Non-Application Layer Protocol
SI-04 System Monitoring mitigates T1098.004 SSH Authorized Keys
SI-04 System Monitoring mitigates T1102.001 Dead Drop Resolver
SI-04 System Monitoring mitigates T1102.002 Bidirectional Communication
SI-04 System Monitoring mitigates T1102.003 One-Way Communication
SI-04 System Monitoring mitigates T1104 Multi-Stage Channels
SI-04 System Monitoring mitigates T1106 Native API
SI-04 System Monitoring mitigates T1110.001 Password Guessing
SI-04 System Monitoring mitigates T1110.002 Password Cracking
SI-04 System Monitoring mitigates T1110.003 Password Spraying
SI-04 System Monitoring mitigates T1110.004 Credential Stuffing
SI-04 System Monitoring mitigates T1111 Multi-Factor Authentication Interception
SI-04 System Monitoring mitigates T1114.001 Local Email Collection
SI-04 System Monitoring mitigates T1127 Trusted Developer Utilities Proxy Execution
SI-04 System Monitoring mitigates T1127.001 MSBuild
SI-04 System Monitoring mitigates T1129 Shared Modules
SI-04 System Monitoring mitigates T1132 Data Encoding
SI-04 System Monitoring mitigates T1132.001 Standard Encoding
SI-04 System Monitoring mitigates T1132.002 Non-Standard Encoding
SI-04 System Monitoring mitigates T1133 External Remote Services
SI-04 System Monitoring mitigates T1135 Network Share Discovery
SI-04 System Monitoring mitigates T1136.001 Local Account
SI-04 System Monitoring mitigates T1137 Office Application Startup
SI-04 System Monitoring mitigates T1137.001 Office Template Macros
SI-04 System Monitoring mitigates T1185 Browser Session Hijacking
SI-04 System Monitoring mitigates T1187 Forced Authentication
SI-04 System Monitoring mitigates T1189 Drive-by Compromise
SI-04 System Monitoring mitigates T1197 BITS Jobs
SI-04 System Monitoring mitigates T1201 Password Policy Discovery
SI-04 System Monitoring mitigates T1204.001 Malicious Link
SI-04 System Monitoring mitigates T1204.003 Malicious Image
SI-04 System Monitoring mitigates T1205 Traffic Signaling
SI-04 System Monitoring mitigates T1205.001 Port Knocking
SI-04 System Monitoring mitigates T1205.002 Socket Filters
SI-04 System Monitoring mitigates T1210 Exploitation of Remote Services
SI-04 System Monitoring mitigates T1211 Exploitation for Defense Evasion
SI-04 System Monitoring mitigates T1212 Exploitation for Credential Access
SI-04 System Monitoring mitigates T1216 System Script Proxy Execution
SI-04 System Monitoring mitigates T1216.001 PubPrn
SI-04 System Monitoring mitigates T1218.001 Compiled HTML File
SI-04 System Monitoring mitigates T1218.002 Control Panel
SI-04 System Monitoring mitigates T1218.003 CMSTP
SI-04 System Monitoring mitigates T1218.004 InstallUtil
SI-04 System Monitoring mitigates T1218.005 Mshta
SI-04 System Monitoring mitigates T1218.008 Odbcconf
SI-04 System Monitoring mitigates T1218.009 Regsvcs/Regasm
SI-04 System Monitoring mitigates T1218.010 Regsvr32
SI-04 System Monitoring mitigates T1218.012 Verclsid
SI-04 System Monitoring mitigates T1218.013 Mavinject
SI-04 System Monitoring mitigates T1218.014 MMC
SI-04 System Monitoring mitigates T1220 XSL Script Processing
SI-04 System Monitoring mitigates T1221 Template Injection
SI-04 System Monitoring mitigates T1222 File and Directory Permissions Modification
SI-04 System Monitoring mitigates T1222.001 Windows File and Directory Permissions Modification
SI-04 System Monitoring mitigates T1222.002 Linux and Mac File and Directory Permissions Modification
SI-04 System Monitoring mitigates T1486 Data Encrypted for Impact
SI-04 System Monitoring mitigates T1491 Defacement
SI-04 System Monitoring mitigates T1491.001 Internal Defacement
SI-04 System Monitoring mitigates T1491.002 External Defacement
SI-04 System Monitoring mitigates T1499 Endpoint Denial of Service
SI-04 System Monitoring mitigates T1499.001 OS Exhaustion Flood
SI-04 System Monitoring mitigates T1499.002 Service Exhaustion Flood
SI-04 System Monitoring mitigates T1499.003 Application Exhaustion Flood
SI-04 System Monitoring mitigates T1499.004 Application or System Exploitation
SI-04 System Monitoring mitigates T1505 Server Software Component
SI-04 System Monitoring mitigates T1505.002 Transport Agent
SI-04 System Monitoring mitigates T1505.004 IIS Components
SI-04 System Monitoring mitigates T1505.005 Terminal Services DLL
SI-04 System Monitoring mitigates T1525 Implant Internal Image
SI-04 System Monitoring mitigates T1542.004 ROMMONkit
SI-04 System Monitoring mitigates T1542.005 TFTP Boot
SI-04 System Monitoring mitigates T1546.002 Screensaver
SI-04 System Monitoring mitigates T1546.004 Unix Shell Configuration Modification
SI-04 System Monitoring mitigates T1546.006 LC_LOAD_DYLIB Addition
SI-04 System Monitoring mitigates T1546.008 Accessibility Features
SI-04 System Monitoring mitigates T1546.013 PowerShell Profile
SI-04 System Monitoring mitigates T1546.014 Emond
SI-04 System Monitoring mitigates T1547.002 Authentication Package
SI-04 System Monitoring mitigates T1547.005 Security Support Provider
SI-04 System Monitoring mitigates T1547.006 Kernel Modules and Extensions
SI-04 System Monitoring mitigates T1547.007 Re-opened Applications
SI-04 System Monitoring mitigates T1547.008 LSASS Driver
SI-04 System Monitoring mitigates T1547.012 Print Processors
SI-04 System Monitoring mitigates T1547.013 XDG Autostart Entries
SI-04 System Monitoring mitigates T1548.001 Setuid and Setgid
SI-04 System Monitoring mitigates T1548.002 Bypass User Account Control
SI-04 System Monitoring mitigates T1548.003 Sudo and Sudo Caching
SI-04 System Monitoring mitigates T1548.004 Elevated Execution with Prompt
SI-04 System Monitoring mitigates T1550.003 Pass the Ticket
SI-04 System Monitoring mitigates T1552.002 Credentials in Registry
SI-04 System Monitoring mitigates T1552.003 Bash History
SI-04 System Monitoring mitigates T1552.005 Cloud Instance Metadata API
SI-04 System Monitoring mitigates T1552.006 Group Policy Preferences
SI-04 System Monitoring mitigates T1552.008 Chat Messages
SI-04 System Monitoring mitigates T1553.001 Gatekeeper Bypass
SI-04 System Monitoring mitigates T1553.003 SIP and Trust Provider Hijacking
SI-04 System Monitoring mitigates T1553.004 Install Root Certificate
SI-04 System Monitoring mitigates T1553.005 Mark-of-the-Web Bypass
SI-04 System Monitoring mitigates T1555.001 Keychain
SI-04 System Monitoring mitigates T1555.004 Windows Credential Manager
SI-04 System Monitoring mitigates T1556.002 Password Filter DLL
SI-04 System Monitoring mitigates T1556.003 Pluggable Authentication Modules
SI-04 System Monitoring mitigates T1556.004 Network Device Authentication
SI-04 System Monitoring mitigates T1556.008 Network Provider DLL
SI-04 System Monitoring mitigates T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay
SI-04 System Monitoring mitigates T1557.002 ARP Cache Poisoning
SI-04 System Monitoring mitigates T1557.003 DHCP Spoofing
SI-04 System Monitoring mitigates T1558.002 Silver Ticket
SI-04 System Monitoring mitigates T1558.003 Kerberoasting
SI-04 System Monitoring mitigates T1558.004 AS-REP Roasting
SI-04 System Monitoring mitigates T1559 Inter-Process Communication
SI-04 System Monitoring mitigates T1559.002 Dynamic Data Exchange
SI-04 System Monitoring mitigates T1559.003 XPC Services
SI-04 System Monitoring mitigates T1560.001 Archive via Utility
SI-04 System Monitoring mitigates T1561 Disk Wipe
SI-04 System Monitoring mitigates T1561.001 Disk Content Wipe
SI-04 System Monitoring mitigates T1561.002 Disk Structure Wipe
SI-04 System Monitoring mitigates T1562.001 Disable or Modify Tools
SI-04 System Monitoring mitigates T1562.002 Disable Windows Event Logging
SI-04 System Monitoring mitigates T1562.003 Impair Command History Logging
SI-04 System Monitoring mitigates T1562.010 Downgrade Attack
SI-04 System Monitoring mitigates T1562.011 Spoof Security Alerting
SI-04 System Monitoring mitigates T1562.012 Disable or Modify Linux Audit System
SI-04 System Monitoring mitigates T1563.001 SSH Hijacking
SI-04 System Monitoring mitigates T1563.002 RDP Hijacking
SI-04 System Monitoring mitigates T1564.002 Hidden Users
SI-04 System Monitoring mitigates T1564.006 Run Virtual Instance
SI-04 System Monitoring mitigates T1564.007 VBA Stomping
SI-04 System Monitoring mitigates T1564.008 Email Hiding Rules
SI-04 System Monitoring mitigates T1564.009 Resource Forking
SI-04 System Monitoring mitigates T1564.010 Process Argument Spoofing
SI-04 System Monitoring mitigates T1565.001 Stored Data Manipulation
SI-04 System Monitoring mitigates T1565.002 Transmitted Data Manipulation
SI-04 System Monitoring mitigates T1565.003 Runtime Data Manipulation
SI-04 System Monitoring mitigates T1567 Exfiltration Over Web Service
SI-04 System Monitoring mitigates T1568 Dynamic Resolution
SI-04 System Monitoring mitigates T1568.002 Domain Generation Algorithms
SI-04 System Monitoring mitigates T1569 System Services
SI-04 System Monitoring mitigates T1569.002 Service Execution
SI-04 System Monitoring mitigates T1570 Lateral Tool Transfer
SI-04 System Monitoring mitigates T1571 Non-Standard Port
SI-04 System Monitoring mitigates T1573.001 Symmetric Cryptography
SI-04 System Monitoring mitigates T1573.002 Asymmetric Cryptography
SI-04 System Monitoring mitigates T1574 Hijack Execution Flow
SI-04 System Monitoring mitigates T1574.004 Dylib Hijacking
SI-04 System Monitoring mitigates T1574.005 Executable Installer File Permissions Weakness
SI-04 System Monitoring mitigates T1574.007 Path Interception by PATH Environment Variable
SI-04 System Monitoring mitigates T1574.008 Path Interception by Search Order Hijacking
SI-04 System Monitoring mitigates T1574.009 Path Interception by Unquoted Path
SI-04 System Monitoring mitigates T1574.010 Services File Permissions Weakness
SI-04 System Monitoring mitigates T1574.013 KernelCallbackTable
SI-04 System Monitoring mitigates T1578 Modify Cloud Compute Infrastructure
SI-04 System Monitoring mitigates T1578.001 Create Snapshot
SI-04 System Monitoring mitigates T1578.002 Create Cloud Instance
SI-04 System Monitoring mitigates T1578.003 Delete Cloud Instance
SI-04 System Monitoring mitigates T1598 Phishing for Information
SI-04 System Monitoring mitigates T1598.001 Spearphishing Service
SI-04 System Monitoring mitigates T1598.002 Spearphishing Attachment
SI-04 System Monitoring mitigates T1599 Network Boundary Bridging
SI-04 System Monitoring mitigates T1599.001 Network Address Translation Traversal
SI-04 System Monitoring mitigates T1601 Modify System Image
SI-04 System Monitoring mitigates T1601.001 Patch System Image
SI-04 System Monitoring mitigates T1601.002 Downgrade System Image
SI-04 System Monitoring mitigates T1602 Data from Configuration Repository
SI-04 System Monitoring mitigates T1602.001 SNMP (MIB Dump)
SI-04 System Monitoring mitigates T1602.002 Network Device Configuration Dump
SI-04 System Monitoring mitigates T1612 Build Image on Host
SI-04 System Monitoring mitigates T1613 Container and Resource Discovery
SI-04 System Monitoring mitigates T1622 Debugger Evasion
SI-04 System Monitoring mitigates T1647 Plist File Modification
SI-04 System Monitoring mitigates T1653 Power Settings

Capabilities

Capability ID Capability Name Number of Mappings
SI-12 Information Management and Retention 35
SI-03 Malicious Code Protection 226
SI-23 Information Fragmentation 7
SI-15 Information Output Filtering 42
SI-07 Software, Firmware, and Information Integrity 209
SI-04 System Monitoring 375
SI-08 Spam Protection 20
SI-02 Flaw Remediation 84
SI-14 Non-persistence 7
SI-10 Information Input Validation 101
SI-16 Memory Protection 36
SI-05 Security Alerts, Advisories, and Directives 4