A.8.1 Technological
User end point devices
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (24)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-19mostlycovers — Both controls establish requirements for managing and securing mobile and personally-owned endpoint devices, including registration, access controls, encryption, remote wipe, and separation of personal versus organizational use.
- CM-6mostlyaligns with — Both require standardized, centrally enforced configuration settings on endpoint devices such as software versions, automatic updates, port disabling, and firewall rules.
- CM-6mostlycovers — A.8.1's focus on securing endpoint devices (including their configuration against risks) accounts for the bulk of CM-6's requirement when the component is a user endpoint device, but leaves a real residual for non-endpoint system components and for the full organizational baseline/deviation process that CM-6 demands universally.
- MP-7mostlyaligns with — Both address restrictions on the use of removable media and physical ports on endpoint devices to limit unauthorized data transfer.
- AC-17partialaligns with — Both require controls on how endpoint devices connect to organizational networks and services from off-premises locations.
- AT-2partialaligns with — Both emphasize user awareness and responsibility for protecting endpoint devices and following security procedures.
- SC-28partialaligns with — Both require encryption of data stored on endpoint devices to protect information at rest.
- SI-3partialaligns with — Both mandate protection of endpoint devices against malware through technical and procedural controls.
- AC-17covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- MP-7covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- SC-28covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Aligned NIST CSF 2.0 outcomes (25)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.AA-05mostlyaligns with — Requirements for access controls, authentication, and authorization on endpoint devices map to the CSF outcome of defining, managing, and enforcing access permissions and entitlements.
- PR.DS-01mostlyaligns with — Mandating encryption, malware protection, and physical safeguards for data stored on endpoint devices aligns with protecting the confidentiality, integrity, and availability of data-at-rest.
- PR.PS-01mostlyaligns with — The ISO control's emphasis on establishing and enforcing secure configuration baselines for endpoint devices directly supports the CSF outcome of applying configuration management practices across technology platforms.
- PR.PS-05mostlyaligns with — Restrictions on software installation and the use of removable devices correspond to the CSF outcome of preventing installation and execution of unauthorized software.
- ID.AM-01partialaligns with — Registration of user endpoint devices supports the CSF outcome of maintaining inventories of hardware managed by the organization.
- PR.AT-01partialaligns with — The control's user-responsibility and awareness provisions contribute to ensuring personnel have the knowledge needed to protect endpoint devices.
- PR.IR-01partialaligns with — Rules governing network connections and remote access from endpoint devices help protect networks and environments from unauthorized logical access.
- ID.AM-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AT-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.DS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (7)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-539nonemitigates — Endpoint device configuration can enforce cookie lifetime and encryption policies.
- CWE-200prevents — Mandating encryption of storage devices and restricting what classified information may be stored on endpoints reduces the chance that sensitive data will be exposed if a device is lost or stolen.
- CWE-284prevents — Requiring access controls, device registration, and remote lock/wipe capabilities on endpoint devices directly blocks unauthorized actors from reaching protected resources or data.
- CWE-522mitigates — Requiring logical controls such as passwords or PINs on idle devices and the use of remote lockout mechanisms protects credentials and other sensitive material from offline extraction.
- CWE-732prevents — Enforcing secure default configurations, software restrictions, and physical-port controls limits the opportunity for incorrect or overly permissive permission assignments on endpoint resources.
Mitigated MITRE ATT&CK techniques (896)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1003detects — A.8.1 requires end-user awareness, device monitoring via analytics (8.16 cross-ref), malware protection, and configuration enforcement that can surface anomalous credential-dumping behaviors on managed endpoints, but this is scoped only to user devices under policy and leaves server-side, in-memory, or unmonitored techniques undetected.
- T1003prevents — A.8.1's policy, configuration enforcement, malware protection, access controls, endpoint encryption, device separation, remote wipe, and user training on locking/protecting devices raise the bar for many common T1003 vectors (e.g. malware-based dumping, unattended devices, weak BYOD separation) but leave residual paths such as privileged local access, memory scraping by already-authenticated processes, and unaddressed OS structures.
- T1003.001detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus malware protection, software/update controls and device monitoring that can surface anomalous LSASS access/dump activity on endpoints; this is a genuine but minority slice of the technique's surface (in-memory harvest, SSP modification, offline dump analysis).
- T1003.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, malware protection, access controls, encryption, updates, physical/logical protection, and BYOD separation) can stop many common LSASS dumping vectors on managed Windows endpoints, but leave open the administrative/SYSTEM-level in-memory harvest, SSP registry modification, and certain memory-dumping techniques that succeed even on hardened devices.
- T1003.002detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and malware protection can surface anomalous endpoint activity consistent with SAM dumping tools or registry access, but the control is scoped to user devices and policy rather than mandating comprehensive host/process monitoring that would catch the bulk of in-memory or registry-based credential extraction.
- T1003.002prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, access controls, malware protection, encryption, physical/logical device protection, automatic updates) can stop many common in-memory/registry SAM extraction vectors on managed Windows endpoints, but SYSTEM-level access and local admin tools remain reachable via unaddressed vectors such as unpatched privilege escalation or insider use of allowed admin processes.
- T1003.004detects — A.8.1's end-user behaviour analytics (explicitly referencing 8.16 monitoring) and requirements for malware protection, software restriction, and device configuration can surface anomalous access or tools (e.g. Mimikatz) used to dump LSA secrets on endpoints, but this is limited to monitored/analytic slices rather than reliably detecting the registry/memory technique itself.
- T1003.005detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration management and malware protection that can surface anomalous access or extraction of cached credential stores, but the control is scoped to endpoint policy and user responsibility rather than mandating specific detection of credential-dumping tools or cache-file access.
- T1003.005prevents — A.8.1's policy and guidance on endpoint configuration, software restrictions, access controls, encryption, malware protection, device registration, remote wipe, and separation of data directly constrain the SYSTEM/sudo-level extraction of cached credential stores on managed endpoints (Windows/Linux), but leave open the bounded remainder of unmanaged/BYOD devices, unmonitored personal devices, and post-compromise extraction that bypasses the listed safeguards.
- T1003.008prevents — A.8.1's policy and configuration requirements for access controls, storage encryption, malware protection, endpoint software updates, physical/logical device protection, and user responsibilities on Linux endpoints constrain many vectors for reading /etc/shadow (and combining with /etc/passwd), but do not guarantee prevention of all privilege-escalation paths or misconfigurations that still allow root-level dump.
- T1005detects — A.8.1 requires end-user awareness, device policy, monitoring via end-user behaviour analytics (explicit cross-ref to 8.16), and procedures for theft/loss response, all of which can surface anomalous local data access or exfiltration precursors on managed endpoints; this is only a slice because the control is scoped to user endpoint devices, leaves detection depth to other mechanisms, and does not address server-side, VM, or network-device collection.
- T1005prevents — A.8.1's policy, encryption, access controls, malware protection, device registration, remote wipe, BYOD separation, and endpoint configuration requirements stop many (but not all) local data-gathering paths on managed and personal endpoints; residual coverage gaps remain for unmonitored devices, in-memory collection, and post-compromise interpreters.
- T1006detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware, and configuration enforcement that can surface anomalous direct-volume access or related utilities, but this is scoped only to user endpoint devices under organizational policy rather than comprehensively detecting the technique across all platforms or system-level volume interactions.
- T1006prevents — A.8.1's policy and configuration requirements for endpoint devices (access controls, software restrictions, malware protection, removable-device/port controls, partitioning, encryption, and enforced configuration management) constrain many vectors for obtaining and abusing direct volume access on Windows endpoints, but leave open several named bypasses (e.g., signed admin tools, shadow-copy utilities, kernel-level or already-elevated processes) that the control does not address.
- T1011detects — A.8.1 requires monitoring via end user behaviour analytics (explicit cross-ref to 8.16) plus configuration of wireless connections and restrictions on removable devices/public networks, which can surface anomalous exfiltration over alternate media such as WiFi, Bluetooth or cellular; this is a genuine but minority slice of the technique (most exfil over other media is not user-behavior driven or caught by endpoint policy enforcement).
- T1011prevents — A.8.1's policy, configuration enforcement, wireless procedures, software restrictions, removable-device/port controls, partitioning, and user responsibilities on endpoint behavior directly constrain many of the alternate mediums (WiFi config, Bluetooth/cellular/modems via removable-device rules, physical proximity via device handling) named in T1011, but leave open-ended slices such as post-compromise use of already-authorized channels or unaddressed RF modalities.
- T1011.001detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus configuration/enforcement of wireless connections (including disabling vulnerable protocols) and monitoring of removable devices/ports, which can surface anomalous Bluetooth usage for exfiltration; this is a genuine but minority slice of the technique (Bluetooth-specific detection is not mandated, and the clause's scope is set by organisational requirements rather than universal instrumentation).
- T1011.001prevents — A.8.1's policy on endpoint configuration, software restrictions, removable-device/port controls (incl. USB), wireless procedures (e.g. disabling vulnerable protocols), and separation/partitioning directly constrains the local Bluetooth channel an adversary with proximity would use for exfiltration, but leaves open Bluetooth on unmanaged personal/BYOD devices, non-enforced user behavior, and non-Bluetooth vectors.
- T1014prevents — A.8.1's policy and enforcement on endpoint configuration, malware protection, software restrictions, updates, and user awareness reduce the attack surface and likelihood of initial malware that leads to rootkit installation, but do not stop kernel/bootkit techniques once code execution is achieved.
- T1016.002detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and monitoring of endpoint devices, which can surface anomalous Wi-Fi enumeration commands, file accesses, or connection attempts on managed endpoints; this is a genuine but minority slice of the technique because the control's scope is device policy and user responsibility rather than comprehensive host telemetry or network-level detection of all discovery methods.
- T1016.002prevents — A.8.1's policy and configuration requirements for endpoint devices (wireless connection procedures, disabling vulnerable protocols, software restrictions, access controls, malware protection, encryption, and user responsibilities) can stop many common discovery paths on managed devices, but the control is silent on credential storage hardening, keychain protections, file permissions on /etc/NetworkManager, or blocking the specific commands/APIs, leaving a genuine minority slice prevented.
- T1020detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), device monitoring for anomalies, malware protection, and configuration enforcement that can surface automated exfiltration behaviors on managed endpoints; this is limited to a slice because the control is scoped to user endpoint devices only (not network devices or non-endpoint exfil paths) and detection depends on what the organization actually instruments.
- T1021detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16) plus configuration of wireless connections, software updates, malware protection, and device monitoring elements that can surface anomalous remote-service logons or lateral movement from endpoints; this is a genuine but minority slice of the technique's surface (domain/RDP/SSH/SaaS abuse, legitimate admin tools, IaaS/ESXi) rather than a bounded remainder.
- T1021prevents — A.8.1's policy and configuration requirements for endpoint devices (access controls, software restrictions, malware protection, remote lock/wipe, physical/logical protections, wireless config) can stop some endpoint-based abuse of remote services such as RDP/SSH/VNC from stolen credentials or BYOD, but the technique also targets servers, IaaS, domains, and legitimate admin tools outside the endpoint-device scope.
- T1021.001detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and monitoring of endpoint devices, which can surface anomalous RDP logons or usage patterns after the fact; this is a genuine but minority slice of the technique (credentialed RDP from a valid account on an already-compromised endpoint) rather than broad detection of the class.
- T1021.001prevents — A.8.1's policy, configuration enforcement, access controls, software restrictions, MFA-capable endpoint hardening, remote lock/wipe, and user training on device protection reduce the likelihood and success rate of credentialed RDP logons from compromised endpoints or stolen devices, but do not eliminate the technique when valid domain accounts or enabled RDP services are already present on the target.
- T1021.002prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, access controls, malware protection, wireless config, removable media controls, encryption, and enforcement via 8.9) can block several common vectors that enable SMB admin-share abuse from an endpoint (e.g. malware delivery of tools, unauthorized software, weak wireless, or unpatched clients), but do not address the core prerequisites of valid admin accounts, domain-level share exposure, or pass-the-hash that the technique actually turns on.
- T1021.004detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus monitoring of endpoint connections, software use, and anomalous device activity, which surfaces SSH logins and remote shell behaviour on covered endpoints; this is a genuine but minority slice of the technique (only user-endpoint SSH, not all remote SSH, and only where analytics/monitoring scope includes it).
- T1021.004prevents — A.8.1's policy and configuration requirements for endpoint devices (access controls, software restrictions, malware protection, automatic updates, physical/logical device protection, wireless config, and user responsibilities) constrain many vectors that could enable or facilitate unauthorized SSH logins from compromised endpoints, but do not reach the dominant case of direct adversary use of valid accounts against hardened SSH servers on non-endpoint Linux/ESXi systems.
- T1021.005detects — A.8.1 requires user awareness, policies, configuration management, end-user behavior analytics (explicitly cross-referenced to 8.16), and procedures for wireless connections and device monitoring, which can surface anomalous VNC usage on endpoints; this is limited to a slice because the control is primarily about device policy and user responsibility rather than mandating comprehensive runtime detection of remote access techniques.
- T1021.005prevents — A.8.1's policy, configuration enforcement, access controls, software restrictions, malware protection, remote lockout, and wireless hardening can stop many VNC abuse vectors (especially on managed endpoints or BYOD), but leaves residual paths such as valid-account use of already-installed VNC, unmonitored personal devices, or brute-forceable implementations.
- T1021.006detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16) plus configuration of wireless connections, software restrictions, malware protection and device monitoring elements that can surface anomalous WinRM usage from endpoints; this is a genuine but minority slice of the technique's possible execution paths (e.g. non-endpoint, non-anomalous, or non-Windows-managed scenarios).
- T1021.006prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, access controls, malware protection, remote lockout, wireless config, and enforcement via 8.9) can block unauthorized WinRM use or lateral movement from compromised endpoints, but this is only a slice of the technique which also relies on valid accounts and can be invoked from non-endpoint vectors.
- T1025detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16) plus procedures for monitoring removable-device use and disabling ports, which can surface anomalous access to removable media; this is only a slice of the full technique because the clause is primarily about policy, configuration and user responsibilities rather than mandating comprehensive detection tooling or coverage of all collection methods.
- T1025prevents — A.8.1 explicitly requires policy, configuration management and technical measures (n: use of removable devices, possibility of disabling physical ports such as USB; o: partitioning; h: storage encryption; i: malware protection) that can stop an adversary from successfully searching or collecting files from removable media on a compromised endpoint.
- T1027prevents — A.8.1's policy and configuration requirements for endpoint software restriction, malware protection, updates, encryption, removable media controls, and user behavior directly stop many common T1027 payload obfuscation vectors (e.g. malicious archives, encoded scripts, split files) from executing or persisting on managed endpoints, but leave command obfuscation, in-transit use, and non-endpoint platforms untouched.
- T1027.004prevents — A.8.1's policy and enforcement on endpoint configuration (software installation restrictions, malware protection, updates, removable devices, partitioning, and automated config management) can block delivery/execution paths for uncompiled source payloads on managed endpoints, but leaves open vectors such as permitted compilers, BYOD, encrypted/embedded payloads, and non-endpoint delivery stages.
- T1027.006detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint malware protection, secure configuration enforcement, and monitoring of web services/applications and removable media, which can surface anomalous HTML/JS smuggling or post-smuggle execution on managed endpoints; this is only a slice because the control is scoped to user endpoint devices and does not mandate detection of the smuggling technique itself in transit or at web content filters.
- T1027.006prevents — A.8.1's policy and configuration requirements for endpoint software updates, malware protection, web service usage, removable devices, partitioning, and automated enforcement via 8.9 directly constrain the delivery vectors, execution, and local drop of smuggled HTML/JS payloads on user endpoints, but leave open web-content-filter bypasses, user behavior in public networks, and non-enforced policy slices.
- T1027.009prevents — A.8.1's policy and enforcement on endpoint configuration (malware protection, software installation restrictions, updates, removable devices, partitioning, and automated config management) directly constrain the delivery/execution vectors that let embedded payloads reach and run on user devices, but do not stop adversaries from creating or embedding the payloads themselves in files that may still reach the endpoint.
- T1027.011detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16), malware protection, software/update controls, and configuration enforcement that can surface anomalous registry/WMI/shared-memory activity on managed endpoints; this is a genuine but minority slice of the broad technique that also spans Linux volatiles, obfuscated payloads, and non-endpoint platforms.
- T1027.017detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint malware protection, secure configuration enforcement, and monitoring of device activity; these surface anomalous SVG-borne payloads or JavaScript execution on user endpoints, but only for the subset of delivery vectors that reach monitored endpoints rather than the full technique (e.g. server-side smuggling, email filters, or non-endpoint vectors).
- T1027.017prevents — A.8.1's policy, configuration management, malware protection, software restrictions, web-service rules, removable-device controls and user training on endpoint handling reduce the likelihood an SVG-smuggling payload reaches and executes on a managed device, but do not stop all delivery vectors or all forms of the technique (e.g. embedded in PDFs or exploiting unpatched viewers).
- T1036.003detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware and anomalous activity, and procedures that surface renamed/moved utilities via configuration enforcement and device analytics; this catches some but not most renaming cases, especially those not triggering behavioral signals or occurring outside monitored endpoints.
- T1036.004detects — A.8.1's end-user behaviour analytics (explicit cross-ref to 8.16) and malware protection requirements surface anomalous tasks/services that deviate from expected patterns or exhibit malicious traits, but the control is endpoint-policy focused and does not mandate detection of name/description masquerading itself
- T1036.007detects — A.8.1 requires end-user awareness training on safe device handling, end-user behavior analytics (8.16), malware protection, secure configuration enforcement, and procedures for theft/loss investigation, all of which can surface suspicious double-extension files or user execution of them after the fact, but only as a minority slice of possible detection surfaces.
- T1036.007prevents — A.8.1's policy and configuration requirements for endpoint devices (software restrictions, malware protection, user awareness of safe handling, removable-device controls, and enforcement via 8.9) reduce the chance of users receiving/executing disguised executables, but do not stop the filename-masquerading technique itself or guarantee it cannot succeed on managed devices.
- T1036.008detects — A.8.1 requires end-user awareness, endpoint configuration management, malware protection, device analytics (see 8.16), and procedures that can surface anomalous file behavior or masquerading on managed endpoints, but this is scoped to user responsibility and device policy rather than comprehensive file-signature or polyglot detection across all transfer/storage scenarios.
- T1036.008prevents — A.8.1's policy on endpoint configuration, software restrictions, malware protection, removable-device controls, and user training on safe handling lowers the chance of a masqueraded file being introduced or executed on managed endpoints, but does not stop adversaries from creating or transferring such files externally.
- T1036.009detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus malware protection, software restriction, and configuration enforcement on endpoints, which can surface anomalous process-tree behaviour (e.g. double-fork or daemon detachment) when those analytics or monitoring tools are in scope; it is only a slice because the control is primarily about policy and user responsibilities rather than mandating host telemetry depth that would catch every PPID manipulation on Linux/macOS.
- T1037detects — A.8.1 requires end-user awareness, device policy, monitoring via end-user behaviour analytics (explicitly cross-referencing 8.16), malware protection, and configuration enforcement that can surface anomalous boot/logon script activity on managed endpoints; this is limited to the subset of T1037 that produces observable user/endpoint behaviour on covered devices rather than the full technique surface (e.g. remote scripts, network devices, or pre-enforcement persistence).
- T1037prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, access controls, endpoint analytics and user training on device handling reduce the feasible attack surface and likelihood of an adversary successfully planting or abusing boot/logon initialization scripts on managed endpoints, but do not eliminate the possibility on all platforms or in all configurations (e.g. unmanaged BYOD, network devices, or pre-existing scripts).
- T1037.001detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and monitoring of endpoint devices, which can surface anomalous logon-script activity at runtime; this is a genuine but minority slice of the class because the control's focus is device policy, physical/logical protection, malware defence and configuration baselines rather than dedicated detection of persistence mechanisms.
- T1037.001prevents — A.8.1's policy, configuration enforcement, software restrictions, access controls, malware protection, and endpoint management (including BYOD separation and remote lock/wipe) can stop many Windows logon-script persistence vectors at the device level, but the control is silent on the specific registry key and does not guarantee prevention of all admin-privileged or misconfigured script placements.
- T1037.002detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and monitoring of endpoint devices, which can surface anomalous login-hook modifications or plist changes on managed macOS endpoints; it is only a slice because the control is scoped to registered/organization-managed devices, leaves personal/BYOD devices optional, and does not mandate the specific telemetry or analytics depth needed to catch every hook insertion.
- T1037.002prevents — A.8.1's policy, configuration management, software restrictions, access controls, malware protection, endpoint analytics, and user responsibilities on macOS devices constrain the admin-level plist modification and script execution needed for a login hook, but the control is general-purpose, does not name or target this deprecated technique, and leaves residual paths (e.g., via permitted admin tools or unmonitored BYOD).
- T1037.003detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring) and requirements for secure configuration, software restriction, and anomaly-aware handling of endpoints can surface anomalous logon-script execution or persistence artifacts on monitored Windows user devices, but this is only a slice of the technique's possible deployment surfaces and detection vectors.
- T1037.004detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous RC-script changes or post-boot execution artefacts on covered user devices; this is only a slice of the technique's surface (lightweight/embedded/ESXi, network devices, pre-boot root changes, non-user endpoints).
- T1037.005detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16) plus monitoring of endpoint configuration, software installation, malware protection and anomalous device use, which can surface the creation or execution of a StartupItem at boot; the coverage is limited because the control is endpoint-policy oriented, the technique is deprecated and macOS-specific, and detection ultimately depends on the scope set by the referenced monitoring control (8.16).
- T1037.005prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, endpoint analytics, removable-device/port controls and user training on device handling reduce the likelihood an adversary can place or execute unauthorized startup items on managed endpoints, but do not guarantee prevention on unmanaged/BYOD devices, legacy macOS where the folder exists by default, or when the adversary already has root-equivalent access.
- T1040prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, updates, malware protection, wireless config, encryption, firewalls, access controls, and user training) can stop many endpoint-based sniffing vectors on Linux/Windows/macOS/IaaS, but leave network-device CLI captures, cloud traffic mirroring, and passive wired promiscuous-mode sniffing on unmanaged segments untouched.
- T1041detects — A.8.1 requires monitoring via end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration of connections, malware protection and wireless procedures that can surface anomalous exfiltration over C2; this is a genuine but minority slice of the technique's surface (most C2 exfil is not caught by endpoint-behaviour analytics alone).
- T1046detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and its malware-protection / configuration-management clauses can surface anomalous network-scanning or mDNS/Bonjour activity from an endpoint, but the control is scoped to user devices and does not mandate network- or service-level detection of port/vulnerability scans across the broader environment.
- T1046prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, malware protection, access controls, wireless config, device analytics, and automated enforcement) can block many common discovery tools and scans brought onto or launched from managed endpoints, but leave macOS Bonjour/mDNS, cloud API-based discovery, and network-infrastructure scanning outside its device-centric scope.
- T1047detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration enforcement and awareness that can surface anomalous WMI usage on managed endpoints, but the control is scoped to user endpoint devices and does not mandate instrumentation depth for all WMI abuse vectors (local COM APIs, remote over DCOM/WinRM, or non-endpoint Windows systems).
- T1047prevents — A.8.1's policy on endpoint configuration, software restriction, malware protection, access controls, and remote management can block some local WMI abuse vectors on managed endpoints, but leaves the bulk of the technique (remote WMI, COM APIs, PowerShell interfaces, and unmanaged/BYOD devices) untouched.
- T1048detects — A.8.1's policy, user awareness, endpoint analytics (explicitly cross-referencing 8.16), malware protection, and wireless configuration requirements can surface anomalous exfiltration behaviors on managed endpoints, but this is limited to a slice (e.g., user devices with enabled monitoring) while leaving cloud/IaaS/SaaS console downloads, network devices, and unmonitored protocols untouched.
- T1048prevents — A.8.1's policy and configuration requirements for endpoint devices (software restrictions, access controls, network connection rules, personal firewalls, malware protection, removable device controls, partitioning, and wireless config) constrain many common exfil vectors from user endpoints, but leave open alternate protocols from non-endpoint platforms, cloud APIs, and insider web-console downloads.
- T1048.001detects — A.8.1's policy, user awareness, endpoint analytics (see 8.16), malware protection, and wireless config requirements can surface anomalous exfiltration behaviors or unauthorized encrypted channels from endpoints, but this is limited to device-side observables and does not broadly detect the network technique itself.
- T1048.002detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), device monitoring for anomalous use, and procedures for wireless/config connections that can surface exfiltration anomalies on endpoints; this is a genuine but minority slice of the technique (endpoint-only, not network or server-side detection of asymmetric exfil).
- T1048.002prevents — A.8.1's policy, configuration enforcement, access controls, network connection rules, malware protection, and endpoint restrictions (including removable media and partitioning) can stop data from reaching an exfiltration channel on managed devices, but this is a minority slice: the technique can still run from unmanaged/BYOD devices, alternate locations, or once data has already left the endpoint.
- T1048.003detects — A.8.1's policy, user awareness, endpoint configuration (firewalls, malware protection, web service rules, EUBA per 8.16, wireless config), and procedures for loss/theft can surface anomalous exfiltration over unencrypted protocols from endpoints, but this is scoped only to user devices and leaves non-endpoint platforms, non-anomalous traffic, and non-monitored vectors untouched.
- T1048.003prevents — A.8.1's policy, configuration enforcement, software restrictions, access controls, encryption requirements, malware protection, and network-connection rules (including off-premises and wireless) can stop many endpoint-based exfiltration attempts over unencrypted non-C2 channels, but the control is silent on protocol-level enforcement, data-loss prevention, or outbound content inspection that would close the remainder.
- T1052detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), device registration, malware protection, physical protection awareness, and procedures for theft/loss; these surface anomalous use or introduction of removable media in some (but not all) scenarios, leaving the bulk of stealthy or air-gapped physical exfiltration undetected.
- T1052prevents — A.8.1's policy, configuration enforcement, restrictions on removable devices/USB ports, storage encryption, malware protection, physical/logical access controls, and user awareness directly constrain many vectors for introducing a removable medium and copying data onto it, but do not eliminate all possibilities (e.g., approved/required removable media, insider-authorized use, or non-enforced user behavior).
- T1052.001detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16), device registration, malware protection, physical/logical controls, and procedures for theft/loss — all of which can surface anomalous USB usage or removable-media events, but only as a slice of possible detection because the control is primarily about policy, configuration baselines and user responsibilities rather than mandating comprehensive monitoring instrumentation.
- T1052.001prevents — A.8.1's policy and guidance on restricting removable devices, disabling physical ports (e.g. USB), storage encryption, access controls, and user responsibilities directly constrain the introduction and use of USB media for data exfiltration in many scenarios, but leave open user-introduced devices, BYOD allowances, and cases where ports cannot be fully disabled.
- T1053detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16) plus configuration management and automated tools that can surface anomalous scheduled-task creation/execution on endpoints; this is genuine but only a slice of the full technique surface (remote scheduling, containers, network devices, privilege-escalation variants, and non-endpoint platforms lie outside its scope).
- T1053.002detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16) plus configuration enforcement and awareness that can surface anomalous endpoint scheduling or at usage; this is genuine detection coverage on the endpoint but only a minority slice of the full technique surface (remote WMI, Linux/macOS allow/deny bypass, sudo escalation, etc.).
- T1053.005detects — A.8.1 mandates end user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous scheduled-task creation/execution on Windows user devices; this is a genuine but minority slice of the technique (most coverage is post-creation behavioural detection, not the creation methods, hidden tasks, or non-endpoint platforms).
- T1053.005prevents — A.8.1's policy on endpoint configuration (software restrictions, updates, malware protection, access controls, least functionality via 8.9) can block many abuse vectors for creating/running scheduled tasks from user endpoints, but leaves open admin-level, remote, or hidden-task creation that does not rely on endpoint device policy.
- T1055detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16) plus malware protection, which can surface some process-injection anomalies on endpoints; this is a minority slice of the broad, platform-specific technique family (most variants stay masked under legitimate processes and outside user-device scope).
- T1055prevents — A.8.1's policy and configuration requirements for endpoint devices (malware protection, software restrictions, access controls, endpoint analytics, and automated enforcement via 8.9) can stop some process-injection vectors on user endpoints, but leave many platform-specific, legitimate-functionality, and memory-based techniques untouched.
- T1055.001detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16) plus malware protection, software restriction, and configuration enforcement on endpoints; these surface anomalous process behavior or known injection artifacts on managed devices, but the clause is silent on host telemetry depth, memory inspection, or non-endpoint processes and does not guarantee detection of reflective/module-stomping variants.
- T1055.001prevents — A.8.1's policy on endpoint configuration, malware protection, software restrictions, access controls, and user awareness can stop some vectors (e.g. blocking malicious DLLs via endpoint malware tools or least-privilege configs), but leaves the core in-memory injection techniques (reflective, hollowing, direct API writes) untouched on a running process.
- T1055.002detects — A.8.1 mandates end user behaviour analytics (explicitly referencing 8.16) plus malware protection, software restriction and configuration enforcement that can surface anomalous endpoint behaviour consistent with PE injection; this is a genuine but minority slice of detection because the control is scoped to user devices and user responsibility rather than comprehensive process-level or memory telemetry.
- T1055.002prevents — A.8.1's policy and configuration requirements for endpoint devices (malware protection, software installation restrictions, access controls, endpoint behavior analytics, and automated enforcement via 8.9) can constrain the execution environment and block some common PE injection vectors on user endpoints, but do not reach the core technique of arbitrary memory writes and thread creation inside a live process.
- T1055.003detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16) plus malware protection, software restriction, and configuration enforcement that can surface anomalous endpoint behavior consistent with thread hijacking; this is a genuine but minority slice of the technique's full surface (Windows process/memory manipulation) rather than the bulk with a bounded remainder.
- T1055.003prevents — A.8.1's policy and configuration requirements for endpoint devices (malware protection, software restriction, access controls, automatic updates, endpoint analytics, and enforced configuration management) reduce the likelihood of the initial compromise or the presence of vulnerable processes that an adversary would hijack on a managed endpoint, but do not stop the in-memory API sequence once a process is already running.
- T1055.004detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus malware protection and configuration enforcement on endpoints, which can surface anomalous APC-queue activity or early-bird/suspended-process injection on monitored Windows devices; this is only a slice because the control's scope is set by organisational policy on device handling rather than mandating comprehensive host telemetry or process-injection-specific detection.
- T1055.008detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration-driven monitoring of endpoint activity, software installation, and anomalous use; this surfaces some Linux ptrace-based injection via behavioral signals but leaves the bulk of in-process ptrace calls (especially those not tied to user-visible endpoint behavior) unreached.
- T1055.009detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus monitoring of endpoint devices for anomalous activity, which can surface proc-memory injection when it produces detectable behavioural deviations on Linux endpoints; this is only a slice because the control is scoped to user endpoint policy and user responsibility rather than mandating comprehensive process-injection telemetry.
- T1055.012detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and malware-protection requirements can surface anomalous endpoint behaviour consistent with process hollowing, but the control is a broad policy on device configuration/handling rather than mandating specific detection instrumentation, leaving most of the technique's stealth mechanisms (suspended-process creation, memory unmapping, API call sequences) outside its direct view.
- T1055.013detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16) plus malware protection, software restriction, and device monitoring via policy/enforcement, which can surface anomalous endpoint behavior consistent with process doppelgänging; this is a genuine but minority slice because the control is scoped to user devices and user responsibility rather than comprehensive process-level or TxF-specific detection.
- T1055.014detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus malware protection and configuration enforcement on endpoints, which can surface anomalous process behaviour or unexpected library mapping on Linux endpoints; this is a genuine but minority slice of the Linux-only technique whose primary evasion is against process-based products, not the broader monitoring scope set by the control.
- T1055.015detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring) and malware-protection clauses can surface anomalous endpoint behaviours that include ListPlanting artifacts, but the control is scoped to user endpoint device policy and does not mandate the process-level or message-passing telemetry needed to reliably detect the technique.
- T1056detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), malware protection, secure configuration enforcement, and awareness of input-related risks on endpoints; this surfaces some input-capture techniques (e.g., via anomalous behavior or malware indicators) but leaves transparent hooking, non-malware variants, and non-endpoint platforms outside its scope.
- T1056prevents — A.8.1's policy, configuration enforcement, malware protection, access controls, endpoint encryption, user training on device handling, and restrictions on software/installation reduce the attack surface and likelihood of input-capture techniques (e.g. keyloggers, hooks, or deceptive portals) being introduced or succeeding on managed endpoints, but do not stop all variants (transparent API hooking, web-based capture outside the device policy, or unmonitored personal/BYOD devices).
- T1056.001detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16), malware protection, secure configuration enforcement, and awareness of anomalous device use, which can surface keylogging as anomalous behaviour or malware on endpoints; this is a genuine but minority slice of the broad technique (API hooks, custom drivers, hardware buffer reads, registry mods, network devices).
- T1056.001prevents — A.8.1's policy+enforcement on endpoint configuration (malware protection, software restriction, updates, access controls, device encryption, user training on locking/protecting devices, and BYOD separation) stops many common keylogger installation vectors and some in-use methods, but leaves open custom drivers, hardware-buffer reads, OS image modification, and non-malware persistence on managed endpoints.
- T1056.002detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus awareness training on device handling and suspicious prompts, which can surface GUI input capture attempts when anomalous; this is only a slice of the technique's execution surface across platforms and languages.
- T1056.002prevents — A.8.1's policy, user training, endpoint configuration (malware protection, software restrictions, access controls, physical/logical device protection, and awareness of not leaving devices unattended) reduces the likelihood of users falling for mimicked GUI credential prompts on managed endpoints, but does not stop the adversary technique itself from executing via scripts or malicious processes.
- T1056.004detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16) plus malware protection, software restriction, and configuration enforcement that can surface anomalous hooking or credential-capture behaviors on endpoints; this is genuine detection coverage but only a slice (no requirement for comprehensive process-injection or API-hooking telemetry, and Linux/macOS LD_PRELOAD cases sit largely outside the endpoint-device focus).
- T1059prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, access controls, removable-device/port disabling, partitioning, wireless config, and user responsibilities) can stop many abuse paths for built-in interpreters on managed endpoints, but this is only a slice: the technique remains fully available on unmanaged/BYOD devices, in containers/IaaS/SaaS/Office Suite, via remote services, or when interpreters are required by the platform.
- T1059.001detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous PowerShell usage or related artifacts after the fact; this is a genuine but minority slice of the technique (e.g. not all in-memory or non-powershell.exe invocations are caught by endpoint analytics or malware signatures).
- T1059.001prevents — A.8.1's policy on endpoint configuration, software restriction, malware protection, updates, and removable-device/port controls can block common PowerShell abuse vectors on managed Windows endpoints, but leaves bypasses (DLL-based execution, whitelisted interpreters, admin rights, and unmonitored personal/BYOD devices) untouched.
- T1059.002detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and requirements for malware protection, software restrictions, and configuration management can surface anomalous AppleScript usage on managed endpoints, but the control is scoped to user endpoint devices under organizational policy and does not mandate detection of all execution vectors (e.g., in-memory NSAppleScript from within mach-O binaries or remote AppleEvents).
- T1059.002prevents — A.8.1's policy and configuration requirements for endpoint devices (software restrictions, malware protection, updates, access controls, removable media disablement, partitioning, and user training) can stop many vectors for introducing/running AppleScript on macOS endpoints, but do not block all execution paths (e.g. already-present interpreters, native API calls from binaries, or remote interaction with running apps).
- T1059.004prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, access controls, least functionality via 8.9, disabling ports/protocols) constrain the attack surface on which Unix shells can be abused for execution, but do not stop all variants, all platforms (e.g. ESXi, network devices), or all post-compromise script/command use.
- T1059.005prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, access controls, removable media disabling, partitioning, and user behavior rules) can stop many VB/VBA/VBScript abuse vectors on Windows endpoints, but do not reach all platforms (Linux/macOS), all execution paths (e.g. Office macros in spearphishing, legacy interpreters that cannot be removed), or non-endpoint vectors.
- T1059.006prevents — A.8.1's policy on endpoint configuration (software restrictions, updates, malware protection, removable devices, partitioning, wireless config) can block some abuse vectors for Python execution on user endpoints, but leaves many others (e.g. built-in interpreter on managed systems, compiled binaries, or non-endpoint platforms like ESXi) untouched.
- T1059.007detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and requirements for malware protection, software restriction, and configuration management can surface anomalous JavaScript execution or related indicators on managed endpoints, but the control is scoped to user endpoint policy and awareness rather than mandating broad runtime detection of script abuse across all platforms and vectors.
- T1059.007prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, access controls, removable device controls, partitioning, and user responsibilities) can stop many common JS abuse vectors such as downloaded secondary payloads, browser-based execution, and local script interpreters, but do not address all platform-specific JS runtimes, in-memory OSAKit usage, or web-hosted Drive-by Compromise.
- T1059.010detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring) and malware-protection clauses surface anomalous AHK/AutoIT script execution or compiled payloads on endpoints, but the control is scoped to user devices and does not mandate detection of all script interpreters or compiled binaries.
- T1059.010prevents — A.8.1's policy and enforcement on restricting software installation, applying updates, malware protection, endpoint configuration management, and user awareness on Windows devices can stop many AHK/AutoIT script executions (especially unapproved .ahk/.au3 or compiled .exe), but leaves residual paths via allowed interpreters, compiled benign-looking binaries, or permitted automation tools.
- T1068detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), malware protection, software/update enforcement, and anomalous-use rules on endpoints, which can surface indicators of exploitation or post-exploit privilege-escalation behavior; this is a genuine but minority slice of the full technique surface (BYOVD, kernel/driver exploits, container escapes) that the control does not instrument.
- T1068prevents — A.8.1's policy and configuration requirements for endpoint devices (software restrictions, updates, malware protection, access controls, encryption, partitioning, BYOD separation) reduce the attack surface and block many common exploitation vectors for privilege escalation on endpoints, but do not address kernel/driver vulnerabilities, BYOVD, or all unpatched OS components the technique relies on.
- T1071.001detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration of wireless connections, software restrictions, and monitoring-enabling policies on endpoints; these surface anomalous web-protocol C2 blending in some but not all cases, leaving the bulk of network-layer or non-endpoint web traffic outside its scope.
- T1071.001prevents — A.8.1's policy and configuration rules on endpoint software restrictions, web service usage, malware protection, firewalls, access controls, and wireless config can block some common abuse vectors for embedding C2 in HTTP/S or WebSocket traffic from user devices, but do not stop all protocol abuse, all platforms, or non-endpoint vectors.
- T1071.004detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration of wireless connections, software restrictions, malware protection and network rules on endpoints; these surface anomalous DNS patterns or beaconing on managed devices but leave network-layer, pre-auth, or non-endpoint DNS tunneling outside the clause's device-centric scope.
- T1072prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, access controls, remote wipe, and endpoint management requirements constrain abuse of deployment tools on user endpoints (e.g. Intune, SCCM clients), but leave server-side suites, network devices, SaaS admin planes, and privileged credential abuse largely untouched.
- T1074detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), device monitoring for anomalies, and procedures that surface theft/loss or misuse of endpoints where data could be staged; this catches a slice of T1074 observables on user endpoints but not cloud-instance staging, central network shares, or non-endpoint exfil prep.
- T1074.001detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware, anomalous connections, and device loss/theft procedures, which can surface local staging activity on user endpoints; this is only a slice of the technique's scope across all platforms, formats, and non-user systems.
- T1074.001prevents — A.8.1's policy, encryption, access controls, malware protection, device restrictions, and separation/partitioning requirements can stop some local staging paths (e.g. on removable media, unencrypted stores, or BYOD without separation), but do not block core local file/registry staging performed by an already-authorized process or user on a managed endpoint.
- T1074.002detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16), malware protection, access controls, and device monitoring requirements can surface anomalous staging activity on endpoints, but the control is scoped to user endpoint devices and does not address cloud instances, ESXi, or server-side staging.
- T1078prevents — A.8.1's policy and configuration requirements for endpoint devices (access controls, MFA-capable auth, device encryption, malware protection, remote lock/wipe, physical/logical protections, and BYOD separation) stop many forms of credential abuse on endpoints but leave the technique's core (obtaining credentials, abusing inactive accounts, pivoting via overlapping permissions, and use on non-endpoint platforms) untouched.
- T1078.001prevents — A.8.1's policy on secure configuration, access controls, software restrictions, updates, encryption, and device management (including BYOD separation and remote wipe) can prevent abuse of default accounts on user endpoint devices, but the control is scoped only to endpoints and does not address the technique's broad coverage of network devices, IaaS, SaaS, containers, or post-setup default accounts on appliances/servers.
- T1078.003prevents — A.8.1's policy, access controls, device registration, software restrictions, malware protection, encryption, updates, and endpoint analytics reduce the attack surface and credential exposure for local accounts on managed endpoints, but do not stop an adversary who already has a foothold from obtaining or abusing valid local credentials (especially via reuse or dumping).
- T1080detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16), malware protection, software installation restrictions, and configuration management that can surface anomalous file changes or tainted content on endpoints and shares, but does not mandate monitoring of shared storage, code repositories, or the specific infection vectors described.
- T1080prevents — A.8.1's policy and configuration requirements for endpoint devices (malware protection, software installation restrictions, updates, removable devices, encryption, access controls, and user training on safe handling) reduce the likelihood that tainted shared content will successfully execute its payload on an endpoint, but do not stop the adversary from tainting the shared content itself nor block all execution vectors (e.g. certain binaries, SaaS, or unmonitored shares).
- T1083prevents — A.8.1's policy and configuration requirements for access controls, storage encryption, malware protection, device registration, physical/logical locks, and partitioning can stop many endpoint-based discovery actions (especially on user devices and BYOD), but the technique remains fully executable on network devices, via elevated permissions, or on unmanaged endpoints, leaving a large unaddressed slice.
- T1090.002detects — A.8.1's policy, user awareness, endpoint configuration (firewalls, malware protection, connection rules, analytics per 8.16), and monitoring of anomalous behavior on user devices can surface proxy usage or C2 redirection from endpoints, but this is limited to managed endpoints, leaves non-endpoint proxies and external infrastructure untouched, and does not guarantee detection of all masked C2 paths.
- T1091detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16), malware protection, device registration, and procedures for removable devices/ports, which can surface anomalous insertion or execution events from removable media; this is a genuine but minority slice of the full T1091 surface (air-gapped lateral movement, firmware manipulation, renamed executables, mobile-to-PC USB infection) that the control does not instrument.
- T1091prevents — A.8.1 explicitly requires policy, configuration management and automated enforcement on removable device use, disabling physical ports (e.g. USB), storage encryption, malware protection, and partitioning that together stop malware from being written to or executed from removable media, closing the Autorun and manual-copy vectors on managed endpoints; the bounded remainder is air-gapped systems or personal/BYOD devices outside the policy's reach.
- T1091responds — A.8.1 requires procedures for removable-device use, disabling physical ports (e.g. USB), malware protection, remote wipe/lockout on loss, and user training on not leaving devices unattended; these bound spread or enable containment/eradication once the removable-media replication technique is already underway, but address only a minority slice of the full technique surface (e.g. do not contain firmware-level or air-gap manual manipulation).
- T1092detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16), monitoring for anomalous device use, and procedures around removable media (including disabling ports), which can surface the technique when removable media is inserted or used for C2 on monitored endpoints; this is only a slice of the full technique because detection depends on chosen scope, analytics implementation, and does not guarantee observation of all air-gapped or stealthy uses.
- T1092prevents — A.8.1's policy, configuration enforcement, restrictions on removable device use, and port disabling (n) directly stop many removable-media C2 vectors on managed endpoints; partial because the technique can still succeed on unmanaged/BYOD devices, non-enforced policies, or air-gapped systems outside the control's scope.
- T1098.004prevents — A.8.1's policy on endpoint configuration, access controls, software restrictions, malware protection, and enforcement via config management (8.9) can block unauthorized modification of authorized_keys on managed Linux/macOS endpoints, but leaves cloud IaaS API paths, network devices, and unmonitored BYOD untouched.
- T1098.005detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16), registration of devices, and monitoring of connections/software/installation on endpoints, which can surface anomalous device enrollment or registration activity after the fact; this is a genuine but minority slice of the technique's surface (primarily identity-provider/MFA enrollment and conditional-access bypass rather than endpoint telemetry).
- T1098.005prevents — A.8.1's policy and enforcement on device registration, access controls, software restrictions, MFA-related configuration, and separation of business data directly stop many enrollment paths (especially BYOD and unmanaged endpoints), but leaves open credential-compromise self-enrollment, legacy MFA flows, and Intune/Entra ID admin-level registration that the control does not reach.
- T1102detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and its requirements for monitoring connections, software installation, and anomalous device use can surface indicators of web-service C2 traffic from endpoints, but this is only a slice of the technique's network-hidden, encrypted, and legitimate-looking traffic that lives mostly outside endpoint device policy scope.
- T1102.002detects — A.8.1's end-user behaviour analytics (explicitly referencing 8.16 monitoring), malware protection, and wireless/connection rules can surface anomalous endpoint use of web services for C2, but this is scoped only to user-managed devices and leaves server-side or non-endpoint instances undetected
- T1102.002prevents — A.8.1's policy and configuration rules on endpoint software restrictions, updates, malware protection, web service usage, partitioning, and wireless config can block many common vectors for initial compromise and subsequent bidirectional C2 over legitimate web services, but do not stop all (e.g., already-approved browser-based C2 or post-compromise abuse of allowed services).
- T1102.003detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16), malware protection, software restriction, wireless config rules, and monitoring of connections to public/web services can surface anomalous endpoint behaviour that is consistent with one-way C2 over legitimate web services, but the control is scoped to user endpoint devices and does not mandate network or service-layer detection of the technique itself.
- T1105detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring) and requirements for software updates, malware protection, and connection rules can surface anomalous downloads or tool ingress on managed endpoints, but the control is primarily about policy, configuration baselines, and user responsibilities rather than dedicated detection, and it does not address network devices, ESXi, or many of the listed transfer mechanisms.
- T1105prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, access controls, wireless config, removable media disabling, automatic updates, and enforced configuration management) directly constrain many of the native utilities, download channels, and post-compromise spread methods named in T1105, but leave open web-service abuse, cloud-sync vectors, and techniques that do not rely on endpoint software or device policy.
- T1110detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration of wireless connections, software updates, malware protection, and access controls on endpoints; these surface anomalous login or guessing patterns as part of monitoring but only for the subset of brute-force activity observable on managed user devices, leaving the bulk (offline, remote service, non-endpoint, or pre-compromise guessing) unreached.
- T1110prevents — A.8.1's policy and guidance on endpoint configuration (access controls, MFA-capable auth requirements via software versions/updates, encryption, malware protection, remote lockout, and user training on passwords) can stop many online brute-force attempts against endpoint logins, but leaves offline attacks, non-endpoint services, weak policies, and unconfigured devices untouched.
- T1110.001detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus policy-driven monitoring of endpoint activity, software use, connections and anomalies, which can surface password-guessing attempts against local or wireless services on managed devices; this is only a slice of the technique's broad remote-service, cloud, SSO and network-device surface.
- T1110.001prevents — A.8.1's policy and configuration requirements for endpoint devices (strong auth/access controls, MFA-capable restrictions, account lockout via failed-attempt rules, endpoint firewalls, wireless config, malware protection, and user training) stop most password guessing from succeeding on or from managed endpoints, with a nameable remainder for exempted/legacy accounts and non-endpoint services.
- T1110.002prevents — A.8.1's policy and configuration requirements for endpoint devices (strong auth, MFA-capable access controls, password-protected lockout, automatic updates, malware protection, device encryption, remote wipe, and user training on not leaving devices unattended) stop many common ways hashes are obtained from endpoints and reduce the value of any cracked credential, but do not block offline cracking itself once hashes are acquired elsewhere or on non-endpoint platforms.
- T1110.003prevents — A.8.1's policy and configuration requirements for endpoint devices (strong auth via access controls, MFA-capable software versions, automatic updates, personal firewalls, malware protection, wireless config, and user training on device protection) stop password spraying from succeeding against many managed endpoints and their services, but leave a large remainder for non-endpoint vectors (SSO, cloud apps, identity providers, network devices, and external services) plus unenforced or personal-device slices.
- T1110.004detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus monitoring of anomalous connection/use patterns on endpoints, which surfaces credential-stuffing attempts when they target or originate from managed devices; this is a genuine but minority slice of the technique that spans many non-endpoint vectors and services.
- T1110.004prevents — A.8.1's policy, configuration, MFA-capable access controls, endpoint malware protection, automatic updates, device encryption, remote wipe, and user training on passwords/BYOD reduce credential-stuffing success on managed endpoints and services, but do not stop the technique outright (e.g. no universal MFA mandate, external SSO/email vectors, or unmonitored personal devices remain reachable).
- T1111prevents — A.8.1's policy, configuration enforcement, malware protection, endpoint encryption, device registration, access controls, physical/logical protections, and user training on secure handling directly block keyloggers, malware-based interception, and insecure device use that enable MFA credential capture on endpoints, but leave out-of-band SMS/email interception, service-provider compromise, and non-endpoint MFA bypasses untouched.
- T1113detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration-driven monitoring of endpoint activity, which can surface anomalous screen-capture behaviours after the fact; it does not instrument or guarantee detection of every native utility or API call on every device.
- T1114.001detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware, anomalous connections, and device loss events, which can surface local email collection activity on managed endpoints; it does not mandate comprehensive host telemetry or email-specific detection, leaving a large slice of stealthy collection (e.g. on BYOD or unmonitored devices) unreached.
- T1114.001prevents — A.8.1's policy, encryption, malware protection, access controls, device separation, and user responsibilities on endpoints directly stop many local collection paths for .ost/.pst files (theft, malware, unauthorized access), but leave open collection by a malicious process already running with user privileges on the device.
- T1119detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16) plus configuration-driven monitoring of endpoint activity, software use, removable media, and anomalous connections that can surface automated collection behaviors after they begin; this is genuine detection coverage for the on-host, endpoint-visible slice of T1119 but leaves the bulk (cloud APIs, ETL pipelines, built-in RAT collection, off-host discovery) outside its scope.
- T1120detects — A.8.1's end-user-behaviour-analytics (explicit cross-ref to 8.16) and its device-configuration/monitoring elements can surface anomalous peripheral-discovery activity on managed endpoints, but the control is primarily about policy, user responsibility and configuration baselines rather than mandating detection of the discovery technique itself.
- T1120prevents — A.8.1's policy and enforcement on restricting/removing/disabling removable devices, physical ports (e.g. USB), partitioning, and related configuration directly stops many forms of peripheral discovery on endpoints; the remainder is non-removable peripherals (keyboards, built-in cameras, printers) plus discovery techniques that do not rely on the device being attached at the moment of enumeration.
- T1123detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration-enforced controls such as malware protection, software restriction, and device monitoring that can surface anomalous audio-capture activity on managed endpoints; this is only a slice because the control is scoped to registered/organization-managed devices, leaves personal/BYOD devices and non-monitored peripherals as open gaps, and does not itself perform detection.
- T1123prevents — A.8.1's policy and configuration requirements for endpoint devices (malware protection, software restrictions, access controls, device registration, remote lock/wipe, physical/logical protections, and separation/partitioning) can stop unauthorized audio-capture malware or scripts from being installed or executed on managed devices, but this is only a slice: it does not block all legitimate apps or OS APIs that an adversary can abuse, nor does it reach unmanaged/BYOD devices or post-compromise abuse of already-present peripherals.
- T1125detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), malware protection, device registration, access controls, and procedures for theft/loss response, all of which can surface anomalous video-capture activity on managed endpoints; this is only a slice because the control is scoped to user endpoint devices under organizational policy and does not mandate comprehensive runtime monitoring of all peripheral API calls or unmonitored personal/BYOD devices.
- T1125prevents — A.8.1's policy, configuration enforcement, malware protection, device registration, access controls, physical/logical locking, port disabling, and user training on not leaving devices unattended all constrain webcam access and malware/scripts that would activate it on endpoints, but leave open slices such as approved video-call apps, unmonitored BYOD, or post-compromise API abuse that the control does not reach.
- T1127prevents — A.8.1's policy and enforcement on restricting software installation, applying updates, malware protection, access controls, and configuration management (via 8.9) can block many untrusted developer utilities or their malicious use on endpoints, but leaves a remainder for signed/trusted ones that inherently support arbitrary code execution (as the technique explicitly bypasses application controls).
- T1127.001detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous use of MSBuild.exe for inline task execution; this is a genuine but minority slice of detection because the control's focus is device policy, physical/logical protection, and user responsibilities rather than comprehensive process/behavior monitoring.
- T1127.002detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16), malware protection, software installation restrictions, and monitoring of endpoint activity which can surface anomalous ClickOnce usage/installs on managed devices; this is limited to the subset of T1127.002 that produces observable endpoint behaviour rather than the full technique surface (e.g. purely file-based proxying or startup-folder abuse on unmanaged/BYOD endpoints).
- T1127.002prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, endpoint analytics, removable-device controls, and user training on safe behavior (including not executing unknown software) constrain several ClickOnce abuse vectors on managed endpoints, but leave open unmonitored personal/BYOD devices, web-based social-engineering installs, and startup-folder persistence that the control does not universally block.
- T1127.003detects — A.8.1's endpoint policy and user-awareness elements (malware protection, software restrictions, end-user behaviour analytics cross-referenced to 8.16, and configuration enforcement) can surface anomalous JamPlus/.jam usage on managed endpoints, but the control is scoped to device policy rather than mandating runtime detection of proxy execution or subverted build tools, leaving most of the technique unseen.
- T1133prevents — A.8.1's policy, configuration enforcement, access controls, device registration, software restrictions, malware protection, remote wipe, and wireless hardening can stop many endpoint-based abuses of external remote services (e.g. stolen device, BYOD, or exposed container service on an unmanaged endpoint), but the control does not reach gateway/service configuration itself, unauthenticated exposures, or credential theft vectors that enable T1133.
- T1134.003detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and its malware-protection / configuration-management clauses can surface anomalous token-creation or impersonation behaviours on managed endpoints, but the control is scoped to user endpoint devices and does not mandate the host telemetry depth required to reliably catch low-level Windows token API abuse.
- T1137detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection that can surface anomalous Office add-in/macro activity or suspicious startup behaviour on managed endpoints; this is a genuine but minority slice of the technique's possible abuse vectors (e.g. Office 365 rules, unmanaged BYOD, or non-malware persistence).
- T1137prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, endpoint analytics, removable-device controls and user training on secure handling reduce the chance of malicious Office add-ins, templates or macros being installed and surviving restarts, but do not guarantee their complete absence on every endpoint.
- T1137.001detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16) plus configuration management and automated tools that can surface anomalous macro-enabled templates or Office startup behaviour on endpoints; this is a genuine but minority slice of the technique (registry hijacks, remote template pulls, and macro-enablement policy bypasses sit outside endpoint device monitoring).
- T1137.001prevents — A.8.1's policy, configuration enforcement, software restriction, malware protection, endpoint analytics, removable-device controls and user training on secure handling reduce the chance of malicious Office-template macro insertion and execution on endpoints, but do not guarantee prevention of all vectors (e.g. registry hijacks, trusted-location bypasses, or macro-enablement policy gaps).
- T1137.002detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16), endpoint monitoring for anomalous software/installation behaviour, and procedures that surface theft/loss or policy violations on managed/BYOD devices; this can detect the anomalous Registry write or DLL load on a monitored endpoint, but the control's scope is user-device policy rather than guaranteed detection of this specific persistence mechanism.
- T1137.002prevents — A.8.1's policy, configuration management, software restriction, malware protection, access controls, and endpoint hardening (including registry baselines via 8.9) can stop the Office Test key from being added or honored on managed devices, but this is only a slice: unmanaged/BYOD devices, user-level registry writes, and non-enforced policies leave a large remainder
- T1137.004detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous Outlook customizations or the loading of malicious external HTML/URLs as behavioural indicators; this is a genuine but minority slice of the persistence technique, which is primarily a mailbox/registry configuration change rather than runtime endpoint behaviour.
- T1137.004prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, endpoint analytics, and user training on secure handling directly constrain the installation and execution of malicious Outlook Home Page customizations on managed endpoints, but leave open the slice of unmanaged/BYOD devices, legacy Outlook behavior, and post-compromise mailbox changes that the technique can still exploit.
- T1137.006detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection that can surface anomalous add-in installation or execution on endpoints; this is a genuine but minority slice of the technique's full surface (many add-in types are not caught by endpoint analytics or standard malware signatures).
- T1137.006prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, updates, malware protection, access controls, and partitioning) can block many add-in installation and auto-execution vectors on managed devices, but this is only a slice: it does not reach unmanaged/BYOD devices, all add-in types, or post-compromise abuse of already-installed legitimate add-ins, and the control is governance-oriented rather than a universal mechanism.
- T1176detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus malware protection, software installation restrictions, and configuration management that can surface anomalous or malicious extensions on endpoints; this is a genuine but minority slice of the T1176 surface (installation-time trust, marketplace bypasses, benign-abuse, and non-endpoint IDE extensions remain largely unreached).
- T1176prevents — A.8.1's policy and enforcement on restricting software installation, applying updates, malware protection, endpoint configuration management, and user awareness directly constrain malicious extension installation and persistence on user devices for a meaningful slice of the technique, but leave open marketplace trust, benign-abuse, and non-endpoint vectors.
- T1176.001detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus awareness, configuration enforcement and procedures that can surface anomalous extension installs or behaviours on managed endpoints; this is a genuine but minority slice of the technique's full surface (silent file modification, social engineering, app-store evasion, macOS profiles, etc.)
- T1176.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, access controls, removable devices, partitioning, user awareness) directly constrain many installation vectors and post-install behaviors for malicious browser extensions on user endpoints, but leave open social engineering, pre-compromise vectors, and non-enforced slices of the technique.
- T1176.002detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus malware protection, software installation restrictions, and configuration management that can surface anomalous IDE extensions or their behaviours on monitored endpoints.
- T1176.002prevents — A.8.1's policy and enforcement on endpoint software restrictions, installation controls, malware protection, updates, and configuration management (via 8.9) can block malicious IDE extensions on developer endpoints, but leaves benign-extension abuse, side-loading, and non-enforced developer workstations as open slices.
- T1185detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16) plus malware protection, software/update controls and device monitoring that can surface anomalous browser processes, injected extensions or pivoting behaviours on endpoints; this is a genuine but minority slice of the full technique surface (e.g. non-endpoint injection vectors, non-Windows platforms, or stealth that evades the analytics scope).
- T1185prevents — A.8.1's policy and enforcement on endpoint configuration, malware protection, software restrictions, access controls, and user behavior directly constrain several vectors for browser injection and session hijacking on managed devices, but leave open unaddressed slices such as zero-day browser vulnerabilities, BYOD separation gaps, and non-enforced user practices.
- T1187detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and requirements for monitoring anomalous device activity can surface forced-authentication attempts when they produce detectable endpoint or network anomalies, but the control is scoped to device policy and user awareness rather than mandating comprehensive detection coverage of all T1187 vectors (e.g. .LNK/.SCF icon loading or EFSRPC abuse).
- T1187prevents — A.8.1's policy, configuration enforcement, access controls, software restrictions, malware protection, endpoint encryption, remote wipe, and user training on not opening untrusted resources or attachments can stop many vectors (e.g. spearphishing docs, .LNK/.SCF files, unsafe SMB/WebDAV connections), but leaves residual paths such as internal EFSRPC abuse or already-compromised endpoints.
- T1189detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus awareness of anomalous usage patterns on endpoints, which can surface drive-by compromise indicators after the visit and initial execution; this is a genuine but minority slice of the full technique (most detection lives in dedicated monitoring or browser telemetry not required here).
- T1189prevents — A.8.1's policy, configuration enforcement, malware protection, software/update requirements, web-service rules, user training, and endpoint safeguards (e.g. partitioning, remote wipe) reduce the chance of successful browser exploitation on managed devices, but do not stop the initial visit, script execution, or all delivery vectors such as watering-hole compromises or unpatched browsers.
- T1197detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16), endpoint device monitoring for anomalous activity, malware protection, and configuration enforcement that can surface BITS job abuse when it deviates from approved baselines or exhibits suspicious transfer/persistence patterns; this is limited to a slice because the control is scoped to user endpoint devices and does not mandate comprehensive BITS-specific detection across all job creation, COM interfaces, or non-endpoint vectors.
- T1197prevents — A.8.1's policy and configuration guidance on endpoint software restrictions, updates, malware protection, access controls, removable devices, partitioning, and user behavior can block some common abuse vectors for BITS jobs (e.g. via PowerShell or unauthorized software), but leaves substantial residual paths such as legitimate updaters, COM-exposed interfaces, and built-in Windows mechanisms that adversaries routinely abuse.
- T1200detects — A.8.1 requires end-user awareness, physical protection, device registration, port disabling, malware protection, and monitoring via analytics (8.16), which can surface anomalies from introduced hardware (e.g. new devices, USB activity, or wireless additions) but does not systematically detect all vectors such as DMA, passive tapping, or pre-installed additions.
- T1200prevents — A.8.1's policy and enforcement on physical protection, device registration, port disabling (USB), removable device controls, software restrictions, partitioning, and wireless configuration directly stop many hardware-addition vectors (e.g. malicious USB devices, rogue APs, DMA peripherals) from being introduced or functioning, but leaves open vectors such as internal additions, supply-chain tampering, or non-removable network hardware that the control does not address.
- T1203detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), malware protection, software/update enforcement and anomaly-oriented device handling that can surface exploitation attempts or post-exploit artifacts on endpoints; this is a genuine but minority slice of the technique (mostly browser/office/third-party client exploits), not the dominant detection surface.
- T1203prevents — A.8.1's policy and configuration requirements for endpoint software updates, malware protection, restricted installations, partitioning, and secure handling of browsers/office apps reduce the attack surface and likelihood of successful client-side exploitation, but do not eliminate unpatched third-party vulnerabilities or all user-driven execution paths.
- T1204detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), malware protection, device monitoring via configuration management/automated tools, and awareness of anomalous user actions on endpoints; this surfaces some T1204 user-execution indicators (e.g. suspicious downloads/executions, malware artifacts) but does not systematically detect all social-engineering vectors, browser JS, or manual code execution across all platforms and device types.
- T1204prevents — A.8.1's policy, user training, malware protection, software restrictions, endpoint encryption, remote wipe, and configuration enforcement reduce the chance users will execute malicious payloads or enable adversary tools, but do not stop social engineering, all user actions, or execution vectors outside endpoint controls.
- T1204.001detects — A.8.1 requires end user behaviour analytics (explicitly cross-referenced to 8.16) plus awareness, logging, and configuration that can surface anomalous link-clicking or follow-on execution on managed endpoints; this is a genuine but minority slice of the technique (social engineering, unmonitored personal/BYOD devices, and links that trigger non-analytic execution paths remain outside the control's scope).
- T1204.001prevents — A.8.1's policy, user training, malware protection, software restrictions, web-service rules, endpoint analytics, and configuration enforcement reduce the chance users will click malicious links or that such clicks will lead to execution, but do not stop social engineering or all possible follow-on exploitation paths.
- T1204.002detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus malware protection, which can surface anomalous file-opening or execution behaviour on endpoints; this is a genuine but minority slice of the technique (most T1204.002 detections live in EDR/host monitoring or email attachment analysis, not endpoint policy).
- T1204.002prevents — A.8.1's policy, user training, malware protection, software restrictions, endpoint encryption, removable-device controls, and automated enforcement reduce the chance a user will open or successfully execute a malicious file on an endpoint, but do not stop social engineering, masquerading, or all delivery vectors (e.g. shared drives, internal spearphishing).
- T1204.003detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), malware protection, software/update controls, and awareness of anomalous device activity, which can surface suspicious image deployment or runtime behavior on endpoints; this is only a slice of the technique's IaaS/container surface where the malicious image is never instantiated on a monitored user device.
- T1204.003prevents — A.8.1's policy, configuration enforcement, malware protection, software restrictions, updates, and user training on endpoint devices reduce the chance of users deploying and running backdoored images/containers on managed endpoints, but do not stop malicious image deployment in IaaS/container platforms or address naming tricks.
- T1204.004detects — A.8.1 mandates end-user behaviour analytics (explicitly cross-referenced to 8.16) plus awareness training on safe device handling and not executing unknown commands, which can surface anomalous copy-paste-to-terminal behaviour after the fact; this is only a slice of the social-engineering vector rather than broad detection of the technique.
- T1204.004prevents — A.8.1's policy, user training, endpoint configuration rules (malware protection, software restrictions, web/app usage, removable devices, partitioning, automatic updates) and enforcement via config management reduce the likelihood and success of social-engineering tricks that rely on user copy-paste execution on managed endpoints, but do not stop the adversary's presentation of the prompt or the user's voluntary action in all cases.
- T1204.005prevents — A.8.1's policy and guidance on restricting software installation, applying updates, malware protection, endpoint configuration management, and user awareness of secure handling directly constrain the user-driven installation of malicious libraries from public repositories or package managers on endpoint devices.
- T1205.001detects — A.8.1's endpoint policy, user training, malware protection, endpoint analytics (8.16), wireless config, and remote-wipe procedures can surface anomalous port-knocking traffic or its artifacts on managed devices when those elements fall inside the chosen monitoring scope, but the control is silent on network-level packet-sequence detection and does not require instrumentation that would catch it universally.
- T1210prevents — A.8.1's policy and configuration requirements for endpoint devices (software updates, malware protection, access controls, firewalls, encryption, remote lock/wipe) reduce the attack surface and likelihood of successful exploitation of remote services on those endpoints, but do not address the core vulnerability exploitation on servers, hypervisors, or non-endpoint systems that are the technique's primary targets.
- T1216detects — A.8.1 requires end-user behavior analytics (explicit cross-ref to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous script proxying on managed devices; this is only a slice because the control is scoped to user endpoint devices, leaves detection depth to other clauses, and does not address the Windows-specific LOLBAS abuse in the technique description.
- T1216.001detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and its requirements for monitoring software installation, updates, removable devices, and anomalous use of endpoint devices can surface the execution of PubPrn.vbs with a remote script: moniker as anomalous endpoint behaviour; this is a genuine but minority slice of the technique (most variants are not distinguishable from legitimate printer-publication activity without deeper process or network telemetry).
- T1216.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, access controls, updates, and automated enforcement via 8.9) can block the local execution of PubPrn.vbs or the loading of the remote .sct payload on managed endpoints, but this is only a slice: the technique can still run from unmanaged/BYOD devices, non-Windows platforms, or where the policy is not fully enforced.
- T1216.002detects — A.8.1 mandates end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous use of SyncAppvPublishingServer.vbs or the resulting PowerShell activity; this is only a slice of the full technique surface because the control is scoped by organizational policy and device inventory rather than mandating universal behavioral instrumentation.
- T1217prevents — A.8.1's policy and guidance on endpoint configuration, access controls, storage encryption, malware protection, user behavior analytics, and separation/partitioning of organizational data on devices (including BYOD) directly constrain the local-file access and enumeration that T1217 relies on, but only for the subset of browser data classified as organizational; personal browser data, unpartitioned storage, and post-compromise credentialed access remain outside its reach.
- T1218detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and malware-protection requirements can surface anomalous proxy-execution activity on managed endpoints, but the control is scoped to user devices and policy rather than mandating comprehensive process-behaviour detection across all LOLBIN usage.
- T1218.001detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16), malware protection, secure configuration enforcement, and monitoring of endpoint activity which can surface anomalous .chm/hh.exe execution or payload delivery on managed devices; this is a genuine but minority slice of the technique's surface (delivery, user-triggered execution, and bypass of older controls).
- T1218.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, malware protection, updates, access controls, removable media, user behavior) can stop delivery/execution of malicious CHM files on managed endpoints, but this is only a slice: the technique can still succeed on unpatched systems, via user execution of delivered files, or on unmanaged/BYOD devices where enforcement is incomplete.
- T1218.002detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration enforcement for software restrictions, malware protection, removable devices, and wireless connections; these surface anomalous endpoint behaviour that can include Control Panel abuse, but the control is scoped to user devices and does not require host-level process or registry monitoring that would catch the full technique.
- T1218.002prevents — A.8.1's policy and enforcement on endpoint configuration, software restrictions, malware protection, removable devices, access controls, and automated configuration management (8.9) can block many abuse vectors for control.exe / .cpl proxying (e.g. unauthorized software, unpatched malware delivery, USB vectors), but leaves open paths such as phishing-delivered items, renamed/registered DLLs via user-approved actions, or already-installed legitimate Control Panel mechanisms.
- T1218.003detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16), endpoint monitoring for malware, software installation restrictions, and anomalous device/network activity that can surface CMSTP.exe abuse when it deviates from baselines, but this is scoped only to user endpoint devices and leaves server-side or non-endpoint execution of the technique undetected.
- T1218.003prevents — A.8.1's policy and enforcement on endpoint configuration (software installation restrictions, malware protection, application control via 8.9, removable-device/port controls) can stop many CMSTP abuse vectors on user devices, but leaves open signed-binary proxy execution, remote INF/SCT loading, and UAC-bypass paths that are outside its named scope.
- T1218.004detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16), malware protection, software restriction, and configuration enforcement that can surface anomalous use of InstallUtil or suspicious .NET installer activity on endpoints; this is a genuine but minority slice of the technique (mostly command-line/proxy execution on Windows, often not user-driven or endpoint-visible).
- T1218.004prevents — A.8.1's policy and enforcement on endpoint software restrictions, updates, malware protection, configuration management and removable-device/port controls can block many InstallUtil abuse paths (especially on managed devices and BYOD), but leaves a genuine remainder on unmanaged personal devices, signed Microsoft binaries that are allowed by design, and attacker-controlled .NET binaries that satisfy the RunInstaller attribute without violating the listed rules.
- T1218.005detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16) plus configuration enforcement for endpoint software, updates, malware protection, removable devices, wireless config, and logging-capable restrictions that can surface anomalous mshta.exe execution or HTA/script activity on managed endpoints, but this is scoped only to user devices under organizational policy and leaves unmanaged/BYOD, non-endpoint, or pre-execution proxying outside its view.
- T1218.005prevents — A.8.1's policy and enforcement on endpoint configuration, software restrictions, malware protection, updates, and removable-device/port controls can stop many mshta.exe abuse vectors (e.g. blocking unsigned HTA downloads, disabling vulnerable scripting hosts, or restricting execution from untrusted URLs), but leaves a bounded remainder where mshta is a built-in trusted binary required for legitimate Windows functions and can still be invoked by sophisticated adversaries.
- T1218.007detects — A.8.1 requires endpoint device monitoring via end-user behavior analytics (explicitly referencing 8.16) plus configuration enforcement and malware protection that can surface anomalous msiexec.exe abuse on managed endpoints, but this is scoped only to covered user devices and does not broadly instrument the technique itself.
- T1218.007prevents — A.8.1's policy and enforcement on restricting software installation, applying updates, malware protection, access controls, and configuration management (via 8.9) can block many forms of msiexec abuse on endpoints, but leaves open the signed-binary bypass, AlwaysInstallElevated policy, and network-launched MSI cases that the technique explicitly relies on.
- T1218.008detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration management and monitoring of endpoint software/installation/activity, which can surface anomalous use of a signed binary like odbcconf.exe for DLL proxying, but this is only a slice of possible detections rather than a broad or guaranteed mechanism.
- T1218.008prevents — A.8.1's policy and enforcement on endpoint software restriction, installation control, malware protection, configuration management and removable-device/port controls can block many abuse vectors for a signed living-off-the-land binary, but the control is silent on signed-utility allow-listing, REGSVR flag handling and the specific bypass of application control that the technique names, leaving a genuine minority slice prevented.
- T1218.009detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous use of signed binaries like Regsvcs/Regasm for proxy execution; this is a genuine but minority slice of the technique's possible execution paths and does not guarantee detection of the attribute-driven code run.
- T1218.010detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus monitoring of endpoint configuration, software installation, malware protection and anomalous use of removable/wireless connections, all of which can surface Regsvr32 abuse when it deviates from baseline; the control does not mandate comprehensive process-level or network-aware detection of Squiblydoo-style proxying.
- T1218.010prevents — A.8.1's policy and enforcement on endpoint configuration, software restrictions, malware protection, updates, and removable-device/port controls can stop many Regsvr32 abuse vectors (especially Squiblydoo from external URLs or unsigned COM scriptlets), but leaves a bounded remainder where signed regsvr32.exe is used under user permissions on managed software that is otherwise allowed.
- T1218.011detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus malware protection, software restriction, and monitoring-enabling configuration on endpoints; these surface anomalous rundll32.exe usage or proxying, but the control is a policy+awareness framework whose actual detection coverage depends on what the implementer instruments, leaving a large slice (e.g. non-monitored processes, masquerading, or non-malware vectors) unreached.
- T1218.012detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16) plus configuration of endpoint devices, software updates, malware protection and wireless procedures, all of which can surface anomalous use of verclsid.exe or related COM abuse on managed endpoints; this is a genuine but minority slice of the full technique surface (e.g. does not instrument the COM registry itself or catch every proxying variant).
- T1218.012prevents — A.8.1's policy and enforcement on endpoint configuration (software restrictions, malware protection, updates, access controls, removable devices, partitioning) can block many abuse vectors for verclsid.exe proxying on user devices, but leaves open signed-native binary abuse, COM registry manipulation, and non-endpoint-specific execution paths.
- T1218.013detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16) plus malware protection, software restriction, and configuration enforcement on endpoints; these surface anomalous process-injection behaviour or unsigned/malicious DLL activity, but the signed-LOLBIN nature of mavinject.exe itself plus the fact that analytics scope is implementation-defined leaves a large slice of stealthy abuse undetected.
- T1218.014detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous MMC.exe invocation of unusual .msc files or CLSID payloads; this is a genuine but minority slice of the full technique surface (most variants are not caught by endpoint analytics or standard malware signatures).
- T1218.014prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, access controls, updates, removable devices, partitioning, and automated enforcement via 8.9) constrain many vectors for introducing and executing malicious .msc files or snap-ins on Windows endpoints, but leave open the use of legitimate signed MMC binaries and .msc files that adversaries can still abuse via registry/CLSID manipulation or built-in tools like wbadmin.msc.
- T1218.015detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint malware protection, secure configuration enforcement, and monitoring of device activity which can surface anomalous Electron app behavior or malicious JS/commands, but this is scoped only to the subset of techniques observable at the managed endpoint layer rather than the full class (e.g. does not address pre-compromise Electron app modification or non-endpoint vectors).
- T1218.015prevents — A.8.1's policy and enforcement on endpoint configuration, software restrictions, malware protection, access controls, and partitioning can block some abuse vectors (e.g. restricting Electron app installs, blocking malicious JS via malware controls, or separating business data), but leaves open abuse of pre-installed legitimate Electron apps like Teams/Slack and their built-in command/JS execution mechanics.
- T1219detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16), malware protection, software installation restrictions, remote lock/wipe, and configuration enforcement that can surface anomalous remote-tool usage or installation on endpoints; this is a genuine but minority slice of the technique (post-compromise legitimate RATs, EDR-abuse, persistence via existing modules, non-endpoint vectors).
- T1219prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, access controls, remote lock/wipe, device registration, and automated enforcement via 8.9) can stop many legitimate RATs from being installed or executed on managed endpoints, but this is only a slice: post-compromise abuse of built-in or already-approved tools (e.g. Chrome Remote Desktop, EDR response features), unmanaged/BYOD devices, and techniques that do not rely on new software installation remain possible.
- T1219.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, updates, malware protection, access controls, removable devices, partitioning, and user behavior) can block unauthorized IDE tunneling tools/extensions or their execution on managed endpoints, but this is only a slice — the technique can still run via built-in IDE features, on unmanaged/BYOD devices, or through legitimate developer workflows that the control explicitly accommodates.
- T1219.002detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware, unauthorized software, anomalous connections, and device loss/theft procedures, which can surface use of unauthorized or anomalous remote desktop tools but does not mandate comprehensive detection of all legitimate RMM software (especially when whitelisted by app control) across all platforms and usage scenarios.
- T1219.002prevents — A.8.1's policy, software restrictions, access controls, endpoint configuration management, malware protection, remote lock/wipe, and BYOD separation can block unauthorized installation or use of many listed RMM tools on managed endpoints, but cannot stop all legitimate desktop support software (including built-in modules in Zoom/Chrome or admin-approved tools) from being leveraged for C2.
- T1219.003detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), physical protection, device registration, port disabling, and configuration management that can surface anomalous hardware attachments or KVM usage on managed endpoints; this is a genuine but minority slice of the technique (post-compromise physical installation on Linux/macOS/Windows, often on unmanaged or air-gapped systems).
- T1219.003prevents — A.8.1's policy and enforcement on registration, physical protection, removable-device/port controls, software restrictions, configuration management, and separation/partitioning directly constrain post-compromise installation and use of remote-access hardware on endpoints, but leaves a bounded remainder for pre-installed or externally introduced devices that policies may still allow.
- T1220detects — A.8.1's end-user behaviour analytics (explicitly referencing 8.16 monitoring) and requirements for malware protection, software restriction, and configuration management can surface anomalous endpoint activity consistent with msxsl.exe/wmic XSL script abuse after it occurs, but the control is scoped to user devices and policy rather than mandating broad detection coverage of this specific technique.
- T1221detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and malware protection requirements surface anomalous endpoint behaviour or fetched payloads on user devices, but the control is silent on static document/template inspection or network-level detection of the reference injection itself.
- T1221prevents — A.8.1's policy on endpoint configuration (software restrictions, malware protection, updates, removable devices, web services, partitioning, and enforced config management) can block template fetching/execution paths on managed endpoints, but leaves open vectors such as modified RTF files, delivered documents that trigger on open, and personal/BYOD devices where enforcement is weaker.
- T1222.001detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring) and requirements for secure configuration, malware protection, and logging-capable controls on endpoints can surface anomalous permission changes via icacls/takeown/etc., but this is only a slice of possible detection rather than broad coverage of the technique.
- T1222.001prevents — A.8.1's policy and enforcement on access controls, software restriction, malware protection, endpoint configuration management, and user responsibilities constrain many vectors for running icacls/takeown/attrib/PowerShell to alter DACLs on Windows endpoints, but do not block all (e.g. admin-privileged or BYOD-bypassed modification of organization files remains possible).
- T1222.002prevents — A.8.1's policy, access controls, software restrictions, malware protection, endpoint analytics, and configuration enforcement (via 8.9) constrain how endpoints are set up and used, which can block many adversary opportunities to run chown/chmod on protected files, but leaves open cases where an already-compromised process or permitted user can still alter permissions.
- T1485detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16) plus malware protection, backups, remote lockout/wipe and configuration management that can surface anomalous destruction activity on endpoints; this detects a slice of T1485 (local endpoint execution) but leaves cloud, VM, container, and propagation aspects untouched.
- T1485prevents — A.8.1's policy, configuration enforcement, malware protection, encryption, backups, remote wipe, and device-separation measures stop many endpoint-local data-destruction vectors (especially on managed/BYOD user devices), but leave the bulk of the technique (worm-like propagation, credentialed lateral movement, cloud-object deletion, hypervisor VM deletion) untouched.
- T1485recovers — A.8.1 explicitly requires backups of endpoint data plus procedures for theft/loss (which can trigger recovery), directly restoring availability after T1485 file destruction on managed endpoints; partial because it addresses only user endpoints (not network-wide, cloud, VM, or propagation vectors) and recovery depends on pre-existing un-destroyed backups.
- T1485.001recovers — A.8.1 explicitly requires backups of endpoint-stored information (and procedures for loss/theft), which directly enables recovery of data destroyed by lifecycle-triggered deletion when the affected objects were replicated from or synchronized to covered user endpoint devices.
- T1486prevents — A.8.1's policy, configuration enforcement, encryption requirements, malware protection, backups, device separation, and remote-wipe guidance can stop many endpoint ransomware vectors before encryption occurs, but leaves gaps for already-compromised admin accounts, hypervisor/ESXi paths, cloud storage objects, and propagation via other TTPs that the endpoint-device control does not address.
- T1486recovers — A.8.1 explicitly requires backups of endpoint data plus procedures for theft/loss (which routinely include restore from backup), directly enabling recovery of the files rendered unavailable by T1486 ransomware; the named remainder is data written after the last backup or backups themselves rendered unreachable by the malware.
- T1486responds — A.8.1's policy, user training, remote wipe/lockout, backups, and theft/loss procedures enable containment (e.g. isolating devices) and eradication (e.g. wiping compromised endpoints or restoring from backups) once ransomware encryption is underway.
- T1489detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring) and requirements for secure configuration, malware protection, and remote lockout can surface anomalous service-stop activity on managed endpoints, but the control is scoped to user endpoint devices only and does not address cloud/IaaS/ESXi service stops or non-endpoint platforms.
- T1490prevents — A.8.1's policy, configuration enforcement, backups, encryption, malware protection, remote wipe, and partitioning directly stop many endpoint techniques (vssadmin/wmic/bcdedit on Windows, local snapshot deletion, malware-driven deletion) but leave network-device, cloud IaaS, and non-endpoint recovery-inhibition vectors untouched.
- T1490recovers — A.8.1 explicitly requires backups of endpoint devices plus procedures for theft/loss (which includes recovery from ransomware-style destruction), directly restoring state after T1490 has deleted shadow copies, disabled recovery features or corrupted backups; the named remainder is non-endpoint systems (network devices, cloud IaaS, ESXi) where the control has no view.
- T1491.001detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring), malware protection, and configuration-management enforcement can surface anomalous changes such as desktop wallpaper replacement or login-message tampering on managed endpoints; this is limited to a slice because the control is scoped to user endpoint devices, does not require real-time integrity monitoring of all internal assets (e.g. web servers, ESXi), and many defacement vectors occur post-compromise without triggering the listed endpoint safeguards.
- T1491.001recovers — A.8.1 explicitly requires backups of endpoint devices and user awareness of procedures for theft/loss (which can include restoring from backup after defacement); this recovers the pre-event state for affected user systems but does not address internal websites, server login messages, or non-endpoint platforms.
- T1496detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring) and requirements for malware protection, software restriction, and anomalous usage patterns on endpoints can surface resource-abuse indicators (e.g. unexpected CPU/network spikes from cryptomining or proxying), but this is limited to monitored endpoints under the policy and does not systematically detect all forms (IaaS/SaaS, non-endpoint containers, or bandwidth/SMS abuse).
- T1496prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, access controls, endpoint analytics, and device management (including remote lock/wipe and BYOD separation) stop many hijacking vectors on user endpoints before they can install miners, proxies, or spam tools; partial because it does not reach IaaS/SaaS/cloud messaging abuse or non-endpoint platforms named in the technique.
- T1496.001detects — A.8.1's end-user behavior analytics (explicitly cross-referenced to 8.16), malware protection, software restriction, and configuration-management enforcement can surface anomalous compute consumption or mining artifacts on endpoints, but the control is scoped to user endpoint devices and does not address servers, IaaS, Linux containers, or cloud-scale hijacking.
- T1496.001prevents — A.8.1's policy, configuration enforcement, malware protection, software restrictions, endpoint analytics, and remote-wipe measures can stop mining malware from installing or running on user endpoints (explicitly named as targets), but this is only a slice: the control does not reach servers, cloud IaaS, containers, or non-malware vectors such as exposed APIs or compromised credentials.
- T1496.001recovers — A.8.1 explicitly requires backups (item k) plus procedures for theft/loss and remote wipe/lockout, which recover availability and data state after compute-hijacking impact is realised; this is a genuine but minority slice of the technique's full scope (resource exhaustion on servers/containers/IaaS where backups alone do not restore live compute capacity).
- T1496.002detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration of wireless connections, software updates, malware protection, and network connection rules on endpoints; these surface anomalous bandwidth consumption or botnet/proxyjacking activity on managed devices, but the control is scoped only to user endpoint devices (not all platforms) and does not mandate comprehensive network-level monitoring of bandwidth hijacking.
- T1496.002prevents — A.8.1's policy and configuration requirements for endpoint software restrictions, updates, malware protection, network connection rules (including off-premises and wireless), firewalls, and user awareness directly stop many bandwidth-hijacking vectors (botnet malware, proxyware, scanning) from being installed or phoning home on managed endpoints; partial because it is silent on already-compromised systems, non-endpoint IaaS/containers, and does not guarantee complete enforcement against all malware families.
- T1498recovers — A.8.1 requires backups and procedures for theft/loss of endpoint devices, which can restore availability of data/services hosted on or accessed via those devices after a network DoS event, but this is a minority slice of the technique's scope (primarily external bandwidth exhaustion against non-endpoint resources).
- T1499recovers — A.8.1 explicitly requires backups (item k) and references recovery procedures for lost/stolen devices, which restore availability after an endpoint resource exhaustion or crash DoS; this is only a slice of the technique (not all DoS vectors leave data in a recoverable state, and the control is endpoint-focused rather than service-redundancy focused).
- T1499.001detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration of wireless connections, software updates, malware protection, and connection rules that can surface anomalous traffic or device behavior consistent with an OS-exhaustion flood; this is a genuine but minority slice of the technique (network/endpoint monitoring scope chosen by the implementer, not exhaustive OS-resource monitoring).
- T1518.001prevents — A.8.1's policy and configuration requirements for endpoint devices (malware protection, software restrictions, updates, access controls, EDR/analytics, remote lock/wipe) directly stop many discovery commands and sensors on managed endpoints; partial because the control is endpoint-centric, leaves cloud/IaaS discovery (Cloud API, agents) untouched, and does not reach unmonitored or personal devices.
- T1518.002detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and its malware-protection / configuration-management clauses can surface anomalous commands (netsh, reg query, tasklist, dir) that enumerate backup tools, but the control is scoped to endpoint policy and user awareness rather than mandating broad telemetry or anomaly detection, leaving most of the technique's platform-specific discovery methods outside its direct view.
- T1528detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and requirements for monitoring anomalous device activity can surface token theft or misuse on managed endpoints, but the control is scoped to user endpoint devices and does not address token theft in containers, CI/CD pipelines, IaaS, or OAuth phishing flows.
- T1528prevents — A.8.1's policy, configuration enforcement, access controls, encryption, malware protection, device registration, remote wipe, and user training on endpoints reduce token exposure and theft vectors (especially on user devices, BYOD, and containers), but do not stop container compromise, IMDS token requests, OAuth phishing/social engineering, or CI/CD pipeline token theft.
- T1529recovers — A.8.1 explicitly requires backups and references recovery procedures for lost/stolen devices, which can restore availability after a shutdown/reboot (especially when used to impede recovery), but does not address non-bootable states, hypervisor-level actions, or full system restoration in all cases.
- T1530prevents — A.8.1's policy, configuration, access controls, encryption, malware protection, and device management on endpoints reduce the risk of credential compromise or malware enabling cloud storage access from those devices, but do not address cloud-side misconfigurations, IAM issues, or API abuse that are the dominant vectors for T1530.
- T1534prevents — A.8.1's policy, configuration enforcement, malware protection, software restrictions, user training on device handling, and endpoint safeguards (e.g. encryption, updates, removable media controls) can stop device compromise vectors that enable the initial account takeover stage of internal spearphishing, but do not address credential compromise, internal chat abuse, or post-compromise impersonation.
- T1539detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16) plus malware protection, device monitoring via configuration management, and procedures that surface theft/loss or anomalous device use, which can detect local malware or anomalous browser activity that steals cookies; it does not address network/proxy/AiTM vectors or JS injection.
- T1539prevents — A.8.1's policy and configuration requirements for endpoint devices (malware protection, software restrictions, access controls, encryption, user behavior analytics, physical/logical protections, and secure web usage) directly constrain several local vectors for stealing cookies from disk, memory, or browser processes, but leave remote vectors (e.g. malicious proxy/AiTM, JS injection, phishing) untouched.
- T1542.003prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, malware protection, updates, access controls, removable-device/port disabling, encryption, and partitioning) can stop the initial compromise or raw boot-drive access needed for bootkit installation on user endpoints, but do not reach firmware/BIOS/UEFI protections, MBR/VBR/ESP modifications at the pre-OS layer, or non-endpoint systems.
- T1542.003recovers — A.8.1 explicitly requires backups of endpoint devices (and procedures for loss/theft), which can restore a clean boot sector/image after a bootkit has been remediated, but does not address the bootkit's low-level persistence or guarantee restoration of the exact pre-compromise boot state.
- T1543detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring) and requirements for software installation/update/malware protection can surface anomalous service/daemon creation or modification on endpoints, but the control is scoped to user endpoint devices and does not mandate detection of the full technique across all platforms or system-level changes.
- T1543prevents — A.8.1's policy and enforcement on endpoint configuration (software installation restrictions, malware protection, access controls, updates, removable devices, partitioning) can stop some vectors for installing/modifying malicious services on user endpoints, but leaves many others (privileged admin actions, container platforms, non-endpoint systems, or policy-only gaps) untouched.
- T1543.001detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and malware-protection clauses can surface anomalous launch-agent behaviour on monitored endpoints, but the control is a broad policy on device configuration/handling rather than mandating specific detection of plist modifications or launchd abuse, leaving most of the technique unseen.
- T1543.001prevents — A.8.1's policy on endpoint configuration, software installation restrictions, malware protection, access controls, and automated enforcement via config management (8.9) can stop unauthorized .plist placement or launch-agent execution on managed macOS endpoints, but leaves a large remainder for personal/BYOD devices, user-installed agents, and non-enforced configurations.
- T1543.002prevents — A.8.1's policy on endpoint-device configuration, software installation restrictions, access controls, malware protection, and enforcement via configuration management (8.9) can block some vectors for creating/modifying systemd services on user endpoints, but leaves system-level services, generators, and many Linux persistence paths untouched.
- T1543.004detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16), malware protection, secure configuration enforcement via 8.9/automation, and procedures for device monitoring; these surface anomalous Launch Daemon creation/modification on managed endpoints but only as a slice (BYOD, non-enrolled devices, or analytics not scoped to plist changes leave gaps).
- T1543.004prevents — A.8.1's policy on endpoint configuration, software installation restrictions, malware protection, updates, access controls, and configuration management enforcement can stop many Launch Daemon persistence vectors on managed macOS endpoints, but leaves a remainder for elevated-privilege installer abuse, poor configurations enabling writable directories, and BYOD/personal devices where enforcement is weaker.
- T1546.001detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous file-association changes or the resulting malicious handler execution; this is a genuine but minority slice of the full technique surface (registry writes by any process with access, not limited to user-driven or malware-detectable actions).
- T1546.001prevents — A.8.1's policy and enforcement on endpoint configuration, software restrictions, malware protection, access controls, and automated configuration management (via 8.9) constrain the ability to alter default file associations on managed devices, but leave open user/admin Registry edits, personal/BYOD devices, and unmanaged endpoints where the technique can still succeed.
- T1546.002detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration management and monitoring of endpoint devices, which can surface anomalous screensaver changes or execution after inactivity; this is a genuine but minority slice of the technique (registry manipulation or PE execution) rather than broad detection.
- T1546.002prevents — A.8.1's policy and configuration requirements for endpoint devices (software restrictions, malware protection, access controls, automatic updates, user behavior analytics, and physical/logical protections) can block malicious screensaver installation or execution on managed devices, but this is a minority slice of the technique's attack surface (registry manipulation on any Windows endpoint, including unmanaged/BYOD systems where the control's enforcement is optional or limited).
- T1546.003detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration management and monitoring of endpoint devices, which can surface anomalous WMI activity or unauthorized subscriptions after the fact; it is not scoped to reliably catch the technique itself.
- T1546.004prevents — A.8.1's policy, configuration management, software restrictions, malware protection, access controls, and endpoint hardening (including on Unix/macOS devices) can stop many malicious modifications to shell config files, but the control is high-level governance that does not mandate or enforce specific mechanisms to block all insertion paths (e.g. root-level edits to /etc/profile or ~/.bash_profile).
- T1546.006detects — A.8.1 requires end-user behavior analytics (explicit cross-ref to 8.16), malware protection, software restriction, configuration management and monitoring of endpoint devices, which can surface anomalous dylib loads or binary tampering on managed macOS endpoints; this is only a slice because the control is scoped to user-owned/BYOD devices under policy rather than comprehensive host telemetry or kernel-level detection of all Mach-O header changes.
- T1546.007detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), endpoint monitoring for anomalous activity, malware protection, and configuration enforcement that can surface suspicious Netsh Helper DLL registrations or execution on user endpoints; this is a genuine but minority slice of the technique's possible triggers (e.g., non-endpoint or non-user contexts remain out of scope).
- T1546.008detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus malware protection, software restriction, and configuration management that can surface anomalous accessibility-feature abuse or binary replacement on endpoints; this is genuine detection coverage but only a slice of the full technique surface (registry pointer changes, pre-login triggers, signed WFP-protected binaries, and non-malware persistence vectors remain outside the named mechanisms).
- T1546.009detects — A.8.1's endpoint policy and user-responsibility clauses require awareness, monitoring via end-user behaviour analytics (explicit cross-ref to 8.16), malware protection, and configuration enforcement that can surface anomalous DLL loading or registry changes on managed endpoints; this is a genuine but minority slice of the technique (Windows-specific registry+process injection, not all endpoints, not guaranteed by the policy text itself).
- T1546.010detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and malware-protection clauses surface anomalous DLL loading or registry changes on endpoints when those are inside the chosen monitoring scope, but the control is a broad policy on device handling rather than mandating specific detection of this registry-based persistence technique.
- T1546.010prevents — A.8.1's policy and enforcement on endpoint configuration, software restriction, malware protection, updates, access controls, and removable-device/port controls can block malicious DLL registration or loading on managed endpoints, but leaves open unmanaged/BYOD devices, non-enforced policies, and the technique's native disablement only under secure boot.
- T1546.011detects — A.8.1 requires end-user behavior analytics (explicitly referencing 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous shim installation/usage on Windows devices; this is only a slice of the full technique surface (e.g., no coverage of registry or file-based indicators outside monitored analytics or malware tools).
- T1546.011prevents — A.8.1's policy and enforcement on endpoint configuration (software restriction, malware protection, updates, access controls, removable devices, partitioning) can block many vectors for installing or triggering malicious shims on user devices, but leaves open administrator-privileged shim installation, custom database abuse on unmanaged endpoints, and non-endpoint Windows systems.
- T1546.013detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous PowerShell profile modifications or execution on Windows devices, but only for a slice of the technique (e.g. observable anomalies rather than all profile tampering or privilege-escalation paths).
- T1546.013prevents — A.8.1's policy on endpoint configuration, software restrictions, malware protection, updates, access controls, and user responsibilities for not leaving devices unattended can stop many profile modifications on managed endpoints, but leaves open slices such as unmanaged BYOD, admin-level profile changes, and -NoProfile bypasses.
- T1546.014prevents — A.8.1's policy on endpoint configuration, software restriction, malware protection, access controls, and enforced baselines can block rule installation or emond abuse on managed devices, but leaves open unmanaged/BYOD endpoints, physical access, and non-enforced user actions on macOS.
- T1546.016detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus malware protection, software installation restrictions and configuration management that can surface anomalous installer activity or post-install behaviour on endpoints; this is a genuine but minority slice of the technique (installer script abuse during legitimate install), not the dominant mechanism that would reach mostly.
- T1546.016prevents — A.8.1's policy and enforcement on endpoint configuration, software installation restrictions, malware protection, updates, access controls, and user responsibilities constrain many vectors for malicious installer scripts (especially on managed devices), but do not stop modified legitimate installers or post-install actions that inherit elevated rights when users explicitly authorize them.
- T1546.017detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16), monitoring of device use, and procedures for configuration/handling of endpoints including removable devices and ports; this surfaces anomalous udev rule changes or triggered behaviour on managed endpoints but only for the slice inside the organisation's device inventory and chosen monitoring scope, leaving unmanaged Linux systems or stealthy rule additions outside it.
- T1546.017prevents — A.8.1's policy and enforcement on endpoint configuration, software restrictions, removable-device/port controls, malware protection, and physical/logical access directly constrain udev rule abuse on user endpoints (a Linux device-management vector), but the control is silent on Linux-specific udev rule-file hardening and does not reach non-endpoint Linux systems.
- T1547detects — A.8.1 requires end-user behavior analytics (explicit cross-ref to 8.16), endpoint monitoring for anomalies, malware protection, and configuration enforcement that can surface unauthorized autostart changes or persistence artifacts on managed devices, but this is scoped only to user endpoints (not kernel mods, network devices, or all boot mechanisms) and depends on what the organization actually instruments.
- T1547prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, access controls, and endpoint management reduce the attack surface for autostart/persistence mechanisms (especially on user devices), but do not stop all vectors such as kernel modifications or privileged system-level autostart changes.
- T1547.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, access controls, automatic updates, user behavior rules, and enforced configuration management) directly constrain many common vectors for adding/modifying Registry run keys or startup-folder items on user endpoints, but leave a bounded remainder (e.g., admin-privileged or non-endpoint boot-time mechanisms, policy gaps, or pre-existing entries).
- T1547.003detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware, and configuration management that can surface anomalous DLL registrations or time-provider changes; this catches some instances of the technique but leaves the bulk (stealthy admin-privileged registry changes on unmonitored endpoints or non-behavioural variants) unreached.
- T1547.004detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous Winlogon/helper-DLL activity after the fact; this is a genuine but minority slice of the class (most detections live in dedicated host monitoring or EDR, not in this endpoint-policy control).
- T1547.004prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, malware protection, access controls, updates, and automated enforcement via 8.9) can stop malicious Winlogon helper DLL modifications on managed Windows endpoints, but this is only a slice: the technique can still be introduced via unmanaged/BYOD devices, pre-existing registry abuse before policy applies, or non-endpoint vectors, leaving a genuine remainder.
- T1547.005detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and its malware-protection / configuration-management clauses can surface anomalous SSP Registry changes or LSA loading on monitored endpoints, but the control's scope is device policy and user responsibility rather than mandating comprehensive detection coverage of this specific persistence technique.
- T1547.006prevents — A.8.1's policy on endpoint configuration, software installation restrictions, malware protection, updates, access controls, and removable-device/port controls can stop some LKM/kext loading vectors on user endpoints (especially BYOD or unmanaged devices), but leaves a large remainder on Linux servers, kernel-level bypasses, and signed/privileged loads that the control does not reach.
- T1547.007prevents — A.8.1's policy and enforcement on endpoint configuration (software installation restrictions, access controls, malware protection, configuration management via 8.9) can stop plist modification for malicious persistence on managed devices, but leaves a named remainder for BYOD, personal devices, and user-enabled reopen behavior that the control explicitly accommodates rather than universally blocks.
- T1547.009detects — A.8.1 requires end-user behavior analytics (explicit cross-ref to 8.16), endpoint monitoring for anomalies, malware protection, and configuration enforcement that can surface shortcut modifications in the startup folder or anomalous persistence changes on managed devices, but this is scoped by policy and does not guarantee coverage of all creation/modification vectors (e.g., personal/BYOD devices, non-monitored processes, or pre-compromise changes).
- T1547.009prevents — A.8.1's policy and enforcement on endpoint configuration, software restrictions, malware protection, access controls, automatic updates, and removable-device/port controls can stop many vectors for creating/modifying malicious startup shortcuts (especially via malware or untrusted software), but leaves open slices such as direct admin-level or signed-tool abuse that the control does not reach.
- T1547.010detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous boot-time DLL loading or spoolsv behaviour; this is a genuine but minority slice of the technique (registry writes and boot persistence on Windows endpoints only).
- T1547.012detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware, and anomaly detection via secure configuration enforcement, which can surface suspicious print-processor registration or spooler activity on managed devices; this is only a slice because the control is scoped to user endpoint devices and user behavior rather than comprehensive system-level detection of boot-time DLL loading or registry changes.
- T1547.012prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, access controls, updates, removable devices, partitioning) can block some vectors for installing/running a malicious print processor DLL, but do not reach the privileged spoolsv.exe boot-time loading path, SeLoadDriverPrivilege, or registry-based registration on managed endpoints.
- T1547.013detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16), endpoint monitoring for anomalies, and procedures that surface unauthorized changes or suspicious autostart-like behaviour on user devices; this surfaces the technique in a minority of implementations (analytics/monitoring scope chosen by the org) but does not guarantee detection of .desktop file tampering itself.
- T1547.013prevents — A.8.1's policy and enforcement on endpoint configuration (software installation restrictions, access controls, malware protection, removable devices, partitioning, and automated config management) can stop many user-level autostart abuses on Linux endpoints, but leaves a bounded remainder: system-wide entries in /etc/xdg/autostart (requiring elevated rights the control does not universally block) and cases where the policy is not enforced on unmanaged/BYOD devices.
- T1547.015detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16) plus configuration management and automated tools that can surface anomalous login-item additions or suspicious auto-start entries on managed endpoints; this is genuine detection coverage for the technique, but only a slice because the control is scoped to organization-managed devices, leaves personal/BYOD devices largely to user responsibility, and does not mandate host-level monitoring of the specific persistence locations or launchd changes.
- T1547.015prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, access controls, and endpoint management directly constrain the ability to add and persist malicious login items on user devices, but remain a slice (policy-driven, not a universal mechanism, and limited to managed/BYOD endpoints with possible gaps in enforcement or unmanaged devices).
- T1548prevents — A.8.1's policy, configuration enforcement, access controls, software restrictions, malware protection, and device separation requirements constrain several common abuse vectors (e.g. unauthorized software, weak configs, BYOD elevation paths) on endpoints, but do not reach the full class of native elevation mechanisms (UAC bypasses, sudo abuse, token manipulation) across all platforms and methods.
- T1548.002detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), malware protection, secure configuration enforcement, and monitoring of endpoint activity which can surface UAC-bypass artifacts or anomalous privilege-elevation behavior on managed devices; this is a genuine but minority slice of the broad technique space (many bypasses are fileless, in-memory, or leverage already-elevated remote sessions that analytics may not flag).
- T1548.002prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, updates, malware protection, access controls, encryption, removable media controls, and user responsibilities) reach a slice of UAC-bypass vectors that rely on unpatched software, malware injection, weak defaults, or unauthorized software/installers, but leave the bulk of known UACME-style bypasses (COM auto-elevation, eventvwr.exe, DLL sideloading, and credentialed lateral movement) untouched.
- T1548.003prevents — A.8.1's policy and configuration guidance on endpoint devices (access controls, software restriction, updates, malware protection, user awareness, and least-privilege separation) can constrain some poor sudo/sudoers configurations and related abuse vectors on user endpoints, but leaves the dominant configuration and abuse surface (sudoers file edits, timestamp/timeout mechanics, tty_tickets) untouched.
- T1548.004detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration-driven monitoring of endpoint activity, software installation, and anomalous use; this surfaces suspicious privilege-prompt or world-writable-file abuse on managed devices, but remains a chosen slice of scope rather than universal coverage of the macOS-specific API call.
- T1548.004prevents — A.8.1's policy and enforcement on endpoint configuration (software restrictions, updates, malware protection, access controls, removable devices, partitioning, user responsibilities, and BYOD separation) constrain many abuse vectors for AuthorizationExecuteWithPrivileges on macOS endpoints, but leave open the core API call itself plus world-writable file and masquerading paths that the technique relies on.
- T1548.006detects — A.8.1's policy, user awareness, endpoint analytics (explicitly cross-referencing 8.16), malware protection, access controls, and configuration enforcement can surface anomalous TCC permission grants or related endpoint behaviors on managed devices, but this is scoped only to what the organization's policy and monitoring choose to instrument rather than a dedicated TCC-database or permission-abuse detector.
- T1548.006prevents — A.8.1's policy, configuration enforcement, access controls, software restrictions, malware protection, endpoint analytics, and device separation requirements constrain how TCC-manipulating binaries can be introduced, executed, or granted elevated permissions on managed macOS endpoints; this blocks a genuine slice of the technique but leaves open vectors such as abused native apps with pre-granted TCC, SIP-disabled systems, or user-approved personal/BYOD devices.
- T1550.004detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus malware protection and device monitoring procedures that can surface anomalous cookie theft/import or session use on endpoints; this is a genuine but minority slice of the technique's full surface (primarily post-theft browser replay on any platform).
- T1550.004prevents — A.8.1's policy and guidance on endpoint configuration, malware protection, access controls, software restrictions, encryption, remote wipe, user training, and BYOD separation reduce the likelihood of session cookie theft on the endpoint (the dominant acquisition vector), but do not stop post-theft import/use of an already-stolen cookie or all exfiltration paths.
- T1552detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration management and procedures that can surface anomalous credential-access or storage patterns on endpoints; this is genuine detection coverage for a slice of T1552 but remains partial because the clause is scoped to user endpoint devices only, does not mandate specific credential-scanning sensors, and leaves many non-endpoint platforms (SaaS, IaaS, network devices, etc.) outside its view.
- T1552prevents — A.8.1's policy and configuration requirements for endpoint devices (encryption, access controls, malware protection, software restrictions, device separation, remote wipe, and user responsibilities) stop many common forms of credential exposure on endpoints, but the technique's scope includes non-endpoint platforms, non-device credential stores, and post-compromise search behaviors that the control does not address.
- T1552.001detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection that can surface anomalous access to credential files or suspicious extraction from backups/configs on endpoints; this is a genuine but minority slice of the technique, which also occurs in non-endpoint locations (domain controllers, container logs, remote shares) outside the control's scope.
- T1552.001prevents — A.8.1's policy and guidance on endpoint configuration (software restrictions, encryption, malware protection, access controls, backups, removable devices, partitioning, and user responsibilities) directly constrain many common insecure credential storage practices on user endpoints, but leave open-ended residual cases such as embedded credentials in custom source/config files, container logs, or Group Policy Preferences that the control does not address.
- T1552.003prevents — A.8.1's policy and guidance on endpoint configuration (software restrictions, access controls, encryption, malware protection, user training on secure behavior, and automated enforcement) can stop users from typing credentials into command lines that get persisted to history files, but this is only a slice of the weakness since the technique can still succeed via non-interactive credential use, misconfigured shells, or on unmanaged/BYOD devices.
- T1552.004prevents — A.8.1's policy and guidance on endpoint configuration (encryption, access controls, malware protection, software restrictions, device registration, remote wipe, physical/logical protections, and separation on BYOD) directly constrain insecure storage and exposure of private keys on user endpoints, but do not reach network devices, do not guarantee correct key handling or passphrase strength, and leave residual paths such as export via CLI or post-compromise search.
- T1552.008detects — A.8.1 requires end user behaviour analytics (explicit cross-ref to 8.16) plus awareness, device monitoring via configuration management, and procedures that can surface anomalous credential sharing in chat apps on endpoints; this detects the technique on a slice of user-endpoint activity but not on SaaS servers, admin portals, or compromised integration tools (the technique's primary vectors).
- T1552.008prevents — A.8.1's policy, configuration enforcement, malware protection, access controls, device encryption, user training on secure handling, and BYOD separation requirements constrain credential sharing and exposure on endpoints (and some server-side slices via referenced controls), but do not stop users from sending credentials in chat services nor block all collection paths (e.g. SaaS portals, compromised integrations, or server-side storage).
- T1553detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), malware protection, software/update controls, and device monitoring that can surface anomalous activity indicative of trust-subversion (e.g. unauthorized software installs, registry/file changes, or suspicious binaries), but this is indirect, user-focused, and configuration-driven rather than targeted detection of T1553 techniques such as code-signing abuse or mark-of-the-web bypass.
- T1553prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, access controls, encryption, device management) close some avenues for subverting trust controls on endpoints but do not address certificate theft/creation, registry or permission changes that enable the technique.
- T1553.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, access controls, updates, removable-device handling, and automated enforcement via 8.9) directly address vectors that set or subvert the quarantine flag and Gatekeeper checks on macOS user endpoints, but leave residual bypasses such as logic errors, first-launch timing, unchecked file types, and non-quarantined transfer methods (USB, curl, network shares).
- T1553.004prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, malware protection, access controls, updates, removable devices, partitioning, wireless config) can stop the installation step of T1553.004 on managed endpoints, but this is only a slice: the control is silent on certificate stores, does not reach pre-installed supply-chain roots, cloned certs used for signing, or unmanaged/BYOD devices where the technique can still succeed.
- T1553.005detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16), endpoint malware protection, secure configuration enforcement, and procedures for removable media/wireless/use in unprotected areas; these surface anomalous downloads, container handling, or execution of unmarked payloads on endpoints, but only as a minority slice of the technique's core (container format abuse that evades NTFS tagging), with most of the attack surface outside this control's scope.
- T1553.005prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, removable-device controls, partitioning, and automated enforcement via 8.9) directly constrain the delivery vectors, extraction, and execution of container-borne payloads that bypass MOTW, but leave residual gaps in user behavior, personal/BYOD devices, and non-enforced configurations.
- T1553.006detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and its emphasis on awareness/reporting of loss/theft plus configuration enforcement can surface anomalous policy changes or device state on endpoints, but this is indirect, user-dependent, and limited to a minority slice of the technique's methods (registry, kernel, bcdedit, csrutil) rather than broad detection of the class.
- T1553.006prevents — A.8.1's policy, configuration enforcement, software restrictions, malware protection, access controls and endpoint management directly constrain many of the user-level and configuration-based ways an adversary can modify signing policy (e.g. bcdedit, registry, GUI utilities, test-signing artifacts), but the technique's kernel-memory and signed-vulnerable-driver exploitation paths (plus SIP disable in recovery) sit outside what endpoint-device policy and configuration management can stop.
- T1554detects — A.8.1 requires end-user awareness, endpoint policy, malware protection, software update enforcement, EUBA (see 8.16), and configuration management that can surface anomalous binaries or update-blocking; this catches some post-modification indicators on user endpoints but leaves server-side, ESXi, and non-monitored binaries outside its scope.
- T1554prevents — A.8.1's policy and enforcement on endpoint software installation restrictions, version/update management, malware protection, configuration management (8.9), and BYOD separation directly stop many classes of binary replacement, patching or infection on user endpoints; it does not reach server-side or non-endpoint binaries and cannot stop every post-modification impair-update step.
- T1555detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), malware protection, and configuration management that can surface anomalous access to common credential stores or password-manager processes; this is genuine detection coverage for a slice of T1555 but leaves the bulk (static searches of standard locations, offline vaults, or non-anomalous reads) unreached because the control is scoped to endpoint policy and user responsibility rather than comprehensive monitoring.
- T1555prevents — A.8.1's policy, configuration enforcement, access controls, storage encryption, malware protection, device registration, remote wipe, and user training on endpoint handling reduce the feasibility or success of locating/extracting credentials from common password stores on managed endpoints (including BYOD separation), but do not stop the search technique outright on all platforms or unmanaged cases.
- T1555.001detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus monitoring of endpoint configuration, software, connections, and removable media; these surface anomalous access or use of Keychain (e.g. via security command or file reads) when the activity falls inside the chosen monitoring scope, but the control is a policy-plus-configuration framework that does not mandate specific detection instrumentation for credential dumping.
- T1555.001prevents — A.8.1's policy and guidance on endpoint device configuration (encryption, access controls, malware protection, software restrictions, physical/logical locks, and separation) directly constrain the ability to run the `security` utility or read the Keychain file on macOS user endpoints, but only for a slice of the technique (unlocked or weakly-protected devices); the remainder (post-authentication access by a logged-in adversary or memory scraping) is not reached by this governance clause.
- T1555.003detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration management and procedures that can surface anomalous browser access or credential extraction attempts on managed endpoints; this is a genuine but minority slice of the technique (file reads, memory searches, and post-acquisition use on unmanaged/BYOD devices fall outside the control's scope).
- T1555.003prevents — A.8.1's policy+enforcement on endpoint configuration (software restriction, malware protection, access controls, encryption, device separation, automatic updates, remote wipe, and user training) directly stops many common extraction vectors on the device itself; it leaves open memory scraping, unpatched browser credential stores, and certain BYOD edge cases.
- T1555.004detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection that can surface anomalous Credential Manager access or extraction attempts on managed endpoints; this is only a slice of the full technique surface (e.g. direct file reads, API abuse, or offline backups on unmanaged/BYOD devices).
- T1555.004prevents — A.8.1's policy+enforcement on endpoint configuration (software restrictions, malware protection, encryption, access controls, physical/logical device protection, removable media/USB disabling, and user responsibilities) directly stops many of the listed access vectors (file reads, vaultcmd.exe, API abuse, backups, password tools) on managed endpoints; it does not reach every possible credential extraction path or unmanaged/BYOD devices.
- T1555.005detects — A.8.1 requires end-user behavior analytics (explicitly referencing 8.16) plus configuration management and monitoring of endpoint devices, which can surface anomalous access or extraction attempts against password manager processes/databases; this is a genuine but minority slice of the technique (memory scraping or brute-force of the master password), as the control is scoped to device policy and user behavior rather than comprehensive credential-access detection.
- T1555.005prevents — A.8.1's policy, configuration enforcement, access controls, storage encryption, malware protection, endpoint analytics, and user training on device handling reduce the attack surface for memory scraping, brute-force on master passwords, and credential extraction from password-manager apps on endpoints, but do not stop all vectors (e.g., post-unlock in-memory access or exploitation of the manager itself).
- T1555.006detects — A.8.1 requires end-user behaviour analytics (explicit cross-ref to 8.16) plus device monitoring elements (malware protection, access controls, wireless config, remote lockout) that can surface anomalous API calls or privilege abuse reaching cloud secrets managers from managed endpoints; this is a genuine but minority slice of the IaaS technique, which is primarily a cloud-privilege-abuse vector not limited to endpoints.
- T1556.008detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and its malware-protection / configuration-management clauses can surface anomalous credential-manager DLL registration or logon-time behaviour on endpoints, but the control is scoped to user endpoint devices and does not mandate detection of this specific Registry-based persistence on servers or domain controllers.
- T1557detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16) plus configuration of wireless connections, software updates, malware protection, and device monitoring that can surface anomalous network behavior or AiTM indicators on managed endpoints; this is a genuine but minority slice of the technique (e.g., host-visible anomalies vs. network-layer ARP/DNS/LLMNR manipulation on unmanaged or network devices).
- T1557prevents — A.8.1's policy and configuration requirements for endpoint devices (firewalls, encryption, malware protection, software/update controls, wireless config, partitioning, and user behavior) reduce the attack surface and block several common AiTM vectors on the endpoint itself, but do not stop network-level protocol abuse (ARP/DNS/LLMNR poisoning) or downgrade attacks that can still position the adversary between devices.
- T1557.001detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration of wireless connections, malware protection, and network connection rules on endpoints; these surface anomalous name-resolution or SMB-relay traffic on monitored Windows endpoints, but the control's scope is device-centric and does not mandate network-wide monitoring of LLMNR/NBT-NS/mDNS poisoning itself.
- T1557.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, malware protection, access controls, wireless config, automatic updates, firewalls, encryption, and user behavior) can block common vectors and tools (e.g. Responder) on managed endpoints, but do not stop network-level spoofing of LLMNR/NBT-NS/mDNS or the relay step itself.
- T1557.004detects — A.8.1 requires end-user awareness, device configuration management, wireless connection procedures (e.g. disabling vulnerable protocols), and end-user behavior analytics (explicitly cross-referenced to 8.16), all of which can surface anomalous Wi-Fi connections or evil-twin indicators on managed endpoints; this is only a slice because the control is scoped to user endpoint devices and does not mandate network-level detection of rogue APs or PNL spoofing.
- T1557.004prevents — A.8.1's policy and configuration requirements for endpoint wireless connections (disabling vulnerable protocols, appropriate connections per policy, personal firewalls, encryption, malware protection, user awareness of public-network risks) stop many evil-twin connection and follow-on behaviors on managed devices, but leave residual exposure on unmanaged/BYOD devices, probe-response spoofing, and physical rogue-AP placement outside endpoint control.
- T1558.005detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous access to /tmp/krb5cc_* files, klist/kinit usage, or related Kerberos anomalies on Linux/macOS devices; this is only a slice of the technique because the control's scope is set by organizational policy rather than mandating comprehensive credential-cache monitoring.
- T1558.005prevents — A.8.1's policy and configuration requirements for endpoint devices (encryption, access controls, malware protection, software restrictions, physical/logical locking, removable media controls, and separation/partitioning) directly constrain the exposure and theft of on-disk ccache files on Linux and the credential-handling surface on macOS, but leave a bounded remainder (in-memory ccache, misconfigured /tmp permissions, and user-behavior elements that the control only advises rather than enforces).
- T1559.002detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous DDE usage or poisoned documents in monitored environments, but the control is scoped to device policy and user responsibilities rather than mandating comprehensive runtime detection of this specific IPC technique.
- T1560.001detects — A.8.1's endpoint policy, user awareness, EUBA (8.16 cross-ref), malware protection, and configuration enforcement can surface anomalous archiving/compression utilities or behaviors on monitored endpoints, but this is scoped only to covered devices and chosen analytics rather than broadly detecting the technique wherever it runs.
- T1560.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, access controls, removable device controls, and enforced configuration management) can block many common utilities and third-party archivers on managed endpoints, but preinstalled native tools (tar, zip, certutil, xcopy, makecab) and personal/BYOD devices remain reachable, leaving a genuine minority slice prevented.
- T1561recovers — A.8.1 explicitly requires backups of endpoint devices plus procedures for theft/loss (which often trigger recovery from backup), directly restoring availability after a disk wipe on user endpoints; the named remainder is network devices (explicitly in T1561 scope) where the control has no view.
- T1561.001detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint device monitoring for anomalies, malware protection, and procedures for theft/loss events that can surface disk-wiping activity on user endpoints; this is a genuine but minority slice of the technique (limited to monitored user endpoints, not network devices or non-endpoint Linux/macOS/Windows systems, and does not address direct raw-disk access or worm-like propagation).
- T1561.001prevents — A.8.1's policy and configuration requirements for endpoint encryption, malware protection, physical/logical access controls, remote wipe/lockout, backups, and device management directly stop many (but not all) vectors for arbitrary disk-content overwrite, especially on managed endpoints; the remainder includes physical attacks, unmonitored devices, and techniques that bypass the listed safeguards.
- T1561.001recovers — A.8.1 explicitly requires backups of endpoint devices (item k) plus procedures for theft/loss cases that include recovery, directly restoring state after disk-wipe impact; mostly because the control is scoped to user endpoints and does not address network devices or non-backed-up data.
- T1561.002detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware and anomalous activity, and procedures for theft/loss response that can surface indicators of a wipe attempt, but this is limited to user-managed endpoints and does not broadly instrument disk-level or network-device reformatting activity.
- T1561.002prevents — A.8.1's policy and enforcement on endpoint configuration (software restriction, malware protection, encryption, backups, remote wipe, physical/logical controls, and partitioning) can stop many endpoint-based wipe vectors before execution, but leaves network-device reformatting, worm propagation via credentials/shares, and non-endpoint platforms untouched.
- T1561.002recovers — A.8.1 explicitly requires backups of endpoint devices plus procedures for theft/loss (which includes remote wipe/lockout and recovery from such events); this restores availability after a disk-structure wipe has rendered the system unbootable, matching the recovers verb, with the named remainder being non-backed-up or non-restorable systems.
- T1563detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16), device monitoring via configuration management, malware protection, and awareness of anomalous use/loss, which can surface session hijacking indicators on endpoints; this is only a slice because the control is scoped to user endpoint devices and does not require network/session telemetry or centralized detection of hijacks on remote services.
- T1563prevents — A.8.1's policy and configuration requirements for endpoint devices (access controls, software restrictions, malware protection, automatic updates, wireless config, physical/logical locking, and separation on BYOD) reduce the attack surface and likelihood of session hijacking vectors on user endpoints, but do not address hijacking of remote service sessions on non-endpoint systems or all hijacking mechanics.
- T1563.001detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16) plus monitoring of endpoint configuration, software, connections, and anomalies on user devices where SSH sessions occur; this surfaces hijacking indicators on covered Linux/macOS endpoints but is scoped by policy and does not mandate host-level agent or SSH-agent socket monitoring everywhere.
- T1563.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, malware protection, access controls, automatic updates, physical/logical device protection, and wireless config) reduce the likelihood of initial compromise or root access needed to hijack an active SSH agent/socket, but do not address the technique once a session is established on a trusted endpoint.
- T1563.002detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16), device monitoring for anomalies, and procedures that surface theft/loss or unauthorized use, which can detect RDP hijacking in flight on managed endpoints; this is only a slice because the control is scoped to user endpoint devices, leaves detection depth to policy/implementation, and does not address hijacking of non-endpoint RDP sessions or purely network-based variants.
- T1563.002prevents — A.8.1's policy and configuration requirements for endpoint devices (access controls, software restrictions, malware protection, automatic updates, physical/logical protections, user awareness, and wireless config) can block several hijacking vectors on Windows endpoints, but the technique's core (tscon.exe with System privileges on an already-authenticated RDP session) is not directly closed by endpoint device policy and survives on servers or unaddressed RDP configurations.
- T1564detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16 monitoring) and requirements for malware protection, software updates, access controls and device registration can surface some hiding techniques on managed endpoints, but the control is governance-oriented, does not mandate instrumentation depth, and leaves virtualization/container hiding plus many platform-specific artifacts outside its scope.
- T1564.006detects — A.8.1's policy, user awareness, endpoint analytics (explicitly cross-referencing 8.16), malware protection, software restriction, and configuration enforcement can surface anomalous virtualization activity or unauthorized VM/sandbox use on managed endpoints, but this is limited to a slice (e.g., monitored corporate devices with EDR/analytics enabled) while the technique's stealth, native hypervisors, rogue ESXi VMs, and unmonitored personal/BYOD instances remain largely unseen.
- T1564.009detects — A.8.1 mandates end user behaviour analytics (explicit cross-ref to 8.16), malware protection, secure configuration enforcement via 8.9/automation, and awareness of device handling; these surface anomalous endpoint activity that can include resource-fork abuse on macOS, but the control is scoped to user responsibility and policy rather than mandating specific fork/extended-attribute inspection, leaving most of the technique's stealth mechanisms unreached.
- T1564.009prevents — A.8.1's policy and enforcement on endpoint configuration (malware protection, software restrictions, updates, removable devices, partitioning, encryption, access controls) can stop resource-fork abuse on managed macOS devices, but the control is a governance clause that does not itself implement the blocking mechanisms and leaves unmanaged/BYOD slices untouched.
- T1564.012prevents — A.8.1's policy and configuration requirements for endpoint devices (malware protection, software restrictions, updates, access controls, removable devices, partitioning) can constrain where and how adversaries place hidden artifacts to abuse AV exclusions, but do not stop the technique outright as exclusions are often default/hardcoded and the control does not mandate their review or removal.
- T1565.001prevents — A.8.1's policy and configuration requirements for endpoint devices (encryption at rest, access controls, malware protection, software restrictions, device registration, remote wipe/lock, and separation via partitioning) stop many common vectors for unauthorized stored-data manipulation on endpoints, but leave open expert post-compromise or insider manipulation of complex non-endpoint stores (databases, custom formats) after initial access.
- T1565.001recovers — A.8.1 explicitly requires backups of endpoint-stored data (item k) plus procedures for theft/loss that restore availability/integrity after manipulation; this recovers the pre-event state for the bulk of endpoint data-at-rest cases, with a named remainder for non-backed-up or complex custom formats needing specialized recovery.
- T1566detects — A.8.1 requires end-user awareness training on recognizing phishing indicators plus endpoint analytics (8.16 cross-ref) and malware protection that can surface suspicious messages/links/attachments on the device; this detects some realized phishing but leaves the social-engineering delivery, spoofing, and pre-delivery vectors outside endpoint scope
- T1566prevents — A.8.1's policy, user training, malware protection, software restrictions, endpoint encryption, remote wipe, and configuration enforcement reduce successful execution of delivered phishing payloads on endpoints, but do not stop delivery, spoofing, or user clicking on links/attachments.
- T1566.001detects — A.8.1 requires end-user awareness training on endpoint device security, malware protection, safe handling of attachments/removable media, and end-user behavior analytics (cross-referenced to 8.16), which can surface suspicious attachments or anomalous user execution but only as a minority slice of the technique's full attack surface (email delivery, social engineering, and boundary evasion remain out of scope).
- T1566.001prevents — A.8.1's policy, configuration enforcement, malware protection, endpoint restrictions, user training, and device controls (e.g. no unauthorized software, updates, removable media controls) reduce the chance of opening malicious attachments on managed endpoints, but do not stop the social engineering delivery itself or guarantee prevention on unmanaged/BYOD devices or when users bypass controls.
- T1566.002detects — A.8.1 mandates end-user behavior analytics (explicitly cross-referenced to 8.16), malware protection, secure configuration, and awareness of endpoint risks, which can surface anomalous clicks, downloads, or device compromise after a spearphishing link is followed; this is a genuine but minority slice of the technique (the social-engineering delivery and link obfuscation live upstream of the endpoint).
- T1566.002prevents — A.8.1's policy, user training, endpoint hardening (malware protection, software restrictions, web usage rules, automatic updates, device encryption, remote wipe, BYOD separation) and configuration enforcement reduce the chance that a clicked spearphishing link succeeds in delivering/executing malware or stealing tokens on managed endpoints, but do not stop the email from being delivered or the user from being socially engineered into clicking.
- T1566.003prevents — A.8.1's policy, user training, endpoint restrictions (software install, malware protection, web/app usage, removable media, encryption, remote wipe, BYOD separation) and enforcement via config management reduce the likelihood of users opening malicious links/attachments from third-party services on work endpoints, but do not stop the social-engineering delivery itself or all user behavior.
- T1567detects — A.8.1 explicitly requires end user behaviour analytics (see 8.16) plus monitoring of web services/web application usage on endpoints, which surfaces anomalous exfiltration over web services; this is only a slice of the technique (endpoint-focused, not network or cloud-service telemetry) so partial rather than mostly.
- T1567prevents — A.8.1's policy and configuration requirements for endpoint software restrictions, web service usage rules, malware protection, access controls, encryption, and automated enforcement (via 8.9) constrain the ability of endpoints to exfiltrate data over web services, but do not eliminate all such channels (e.g., legitimate business web services or unmonitored personal/BYOD devices).
- T1567.001detects — A.8.1 requires end-user behaviour analytics (explicitly referencing 8.16), endpoint monitoring for malware, anomalous connections and device usage, which can surface exfiltration to a code repo from a managed endpoint; this is only a slice because the control is scoped to user endpoint devices and does not mandate detection on the repository side, network boundaries or non-endpoint vectors.
- T1567.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, access controls, network connection rules, web service usage, partitioning, malware protection, and automated enforcement) can stop data from reaching an exfiltration channel on managed endpoints, but this is only a slice: it does not block the technique on unmanaged/BYOD devices, non-endpoint platforms, or when the repository is an approved internal service already used by the organization.
- T1567.002detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware, anomalous connections, and device policy enforcement that can surface exfiltration to cloud storage when it occurs on managed endpoints; this is only a slice because the control is scoped to user endpoint devices, leaves detection entirely to separate analytics/monitoring clauses, and does not address exfiltration from non-endpoint platforms such as ESXi.
- T1567.002prevents — A.8.1's policy, configuration enforcement, access controls, storage encryption, malware protection, removable-device restrictions, partitioning, and wireless procedures can block many common vectors for endpoint data reaching unauthorized cloud storage, but do not universally stop all exfiltration paths (e.g., approved business cloud services, browser-based uploads, or already-permitted connections).
- T1567.003detects — A.8.1's policy, user awareness, endpoint configuration (firewalls, malware protection, web service rules, EUBA cross-ref to 8.16), and monitoring of connections/behaviour can surface anomalous outbound traffic or use of pastebin-like sites from managed endpoints; partial because it is scoped to organization-managed or BYOD devices under policy and does not guarantee detection on unmanaged assets or encrypted/obfuscated exfil.
- T1567.003prevents — A.8.1's policy, restrictions on software installation, network connection rules (e.g. personal firewall), access controls, web service usage rules, and endpoint configuration management can block or constrain many common exfiltration paths from user endpoints to public text storage sites, but do not universally stop all variants (e.g. approved browsers, custom tools, or non-endpoint vectors).
- T1567.004detects — A.8.1's policy, user awareness, endpoint analytics (explicitly cross-referencing 8.16), malware protection, access controls, and configuration enforcement can surface anomalous webhook-bound exfiltration from managed endpoints, but this is limited to a slice (e.g., monitored devices and user-driven behaviors) rather than broadly detecting the technique across all platforms and manual/SaaS-linked variants.
- T1567.004prevents — A.8.1's policy and configuration requirements for endpoint software restrictions, access controls, network connection rules, malware protection, and web service usage can block many endpoint-based webhook exfiltration paths (especially manual posts or SaaS-linked automation from managed devices), but leave open adversary-controlled SaaS configurations, non-endpoint exfil, and policy-only slices that do not guarantee enforcement.
- T1569detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus configuration management and monitoring of endpoint devices, which can surface anomalous service creation/execution on managed endpoints; this is only a slice of the technique's surface (local/remote abuse across all platforms, including non-endpoint and unmonitored systems).
- T1570detects — A.8.1 mandates endpoint monitoring via end-user behaviour analytics (explicitly cross-referenced to 8.16), malware protection, and configuration enforcement that can surface anomalous file-copy activity or tool staging on managed endpoints; this is limited to the user-device slice of the technique and does not address server-to-server, ESXi, or non-endpoint transfers.
- T1570prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, access controls, malware protection, removable device controls, wireless config, partitioning, and user responsibilities) can block several common vectors for internal tool/file transfer such as unauthorized software, USB, weak wireless, or unapproved web services, but leave many native protocols, RDP/SMB shares, and already-present tools on managed endpoints untouched.
- T1571detects — A.8.1's policy, configuration management, malware protection, endpoint analytics (8.16), and wireless procedures can surface anomalous non-standard port usage on managed endpoints, but this is scoped only to user devices (not all platforms) and relies on indirect/optional mechanisms rather than mandating port-aware detection.
- T1572detects — A.8.1 requires end-user behavior analytics (explicit cross-ref to 8.16), endpoint malware protection, secure configuration enforcement, and monitoring of wireless/USB/removable usage which can surface anomalous tunneling (e.g. unexpected SSH, DoH, or encapsulated flows) on managed devices; this is a genuine but minority slice of the technique's full scope across platforms, networks, and non-endpoint vectors.
- T1572prevents — A.8.1's policy and configuration requirements for endpoint devices (software restrictions, malware protection, firewalls, wireless config, encryption, access controls) can stop many common tunneling vectors (e.g. unauthorized SSH clients, disallowed tools, blocked vulnerable protocols) on managed endpoints, but leave open vectors that use permitted channels, native OS features, or occur outside the device itself.
- T1574detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16), malware protection, secure configuration enforcement, and monitoring of endpoint activity which can surface anomalous execution flow or hijack artifacts on managed devices; this is a genuine but minority slice of T1574 (many hijacks are fileless/in-memory, Registry-only, or occur on unmanaged/BYOD endpoints outside the policy's enforceable scope).
- T1574prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, access controls, removable devices, partitioning, and automated enforcement via 8.9) stop many common hijack vectors such as DLL search-order poisoning, untrusted library loading, and malicious binaries on endpoints, but leave untouched other T1574 sub-techniques that live in application-specific or OS-kernel mechanisms not governed by endpoint-device policy.
- T1574.001detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16) plus malware protection and configuration enforcement on endpoints, which can surface anomalous DLL loading or side-loading on monitored Windows devices; this is only a slice of the full technique surface (remote hijacks, phantom DLLs, and substitution outside analytics scope remain unseen).
- T1574.001prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, updates, access controls, removable media, partitioning, and automated enforcement via 8.9) can stop several Windows-side-loading and search-order vectors when applied to endpoints, but leave a bounded remainder: remote DLL hijacking, phantom/substitution attacks on non-endpoint processes, and any unmonitored or unmanaged device.
- T1574.004detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16), malware protection, software installation restrictions, and configuration management that can surface anomalous dylib loads or unexpected library behaviour on monitored endpoints; this is a genuine but minority slice of the technique (runtime search-path hijack on macOS, often masked under legitimate processes), not the dominant family of insertion or weak-linking mechanics themselves.
- T1574.004prevents — A.8.1's policy and enforcement on endpoint configuration, software installation restrictions, malware protection, updates, access controls, and removable-device/port controls (via 8.9 automation) can stop many hijack vectors on managed macOS devices, but leaves open developer-controlled search paths, weak linking, and unpatched vulnerable apps as a genuine minority slice.
- T1574.005prevents — A.8.1's policy and guidance on endpoint configuration, software installation restrictions, malware protection, access controls, encryption, removable devices, partitioning, and automated enforcement via 8.9 directly constrain installer permission weaknesses and untrusted code execution on user endpoints (including %TEMP% scenarios), but only for managed/BYOD devices under the policy — not for all installers or non-endpoint Windows systems.
- T1574.006prevents — A.8.1's policy on endpoint configuration, software installation restrictions, malware protection, access controls, and enforced updates can block many LD_PRELOAD/DYLD_INSERT_LIBRARIES abuse vectors on managed devices, but leaves open developer/debug use, unmonitored personal/BYOD devices, and runtime environment variable manipulation that the control does not directly constrain.
- T1574.007detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration management and malware protection on endpoints, which can surface anomalous PATH modifications or unexpected binaries in searched directories; this is a genuine but minority slice of the technique (most PATH hijacks are not caught by endpoint analytics or standard malware signatures).
- T1574.007prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, malware protection, access controls, secure configuration enforcement via 8.9, user responsibilities, and BYOD separation) constrain many vectors for placing or executing a malicious binary via PATH hijacking on managed endpoints, but leave open slices such as direct $PATH/$HOME modification by privileged users, shell config changes, and unmanaged personal devices.
- T1574.008detects — A.8.1 mandates end-user behavior analytics (explicitly referencing 8.16 monitoring) plus malware protection and secure configuration enforcement that can surface anomalous executables or search-order anomalies on endpoints; this is a genuine but minority slice of the technique (mostly post-execution behavioral detection rather than the placement or hijack itself).
- T1574.008prevents — A.8.1's policy and enforcement on endpoint configuration, software installation restrictions, malware protection, updates, access controls, and removable-device/port controls constrain the placement and execution of hijacking binaries on Windows endpoints, but do not guarantee full-path usage or eliminate all vulnerable calling programs.
- T1574.009detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), endpoint monitoring for malware and anomalous activity, and procedures that surface theft/loss or misconfiguration on user devices; these can detect the anomalous executable launch or placement that realises T1574.009 on managed endpoints, but the control's scope is limited to user endpoint devices and does not address service paths, registry-stored shortcuts, or non-endpoint Windows processes.
- T1574.009prevents — A.8.1's policy and configuration requirements for endpoint devices (software installation restrictions, access controls, malware protection, secure configuration via 8.9, user responsibilities, and BYOD separation) can stop unquoted-path hijacking on managed Windows endpoints by blocking malicious placement or execution, but this is only a slice: the control is endpoint-focused, does not mandate path-quoting or registry hardening, leaves unmanaged/BYOD devices and non-endpoint services vulnerable, and relies on implementation rigor rather than a universal mechanism.
- T1574.014detects — A.8.1 mandates end-user behaviour analytics (explicit cross-ref to 8.16) plus configuration enforcement and malware protection on endpoints, which can surface anomalous .NET AppDomainManager loading or tampering as behavioural deviation; this is a genuine but minority slice of the technique (most variants are fileless config/env hijacks inside already-compromised processes, outside endpoint analytics scope).
- T1589.001prevents — A.8.1's policy, training, MFA-enabling configs, endpoint encryption, malware protection, device separation (BYOD), remote wipe, and secure handling reduce credential exposure on endpoints and reuse risks, but do not stop external elicitation, site compromises, dark-web purchases, or pre-existing leaks.
- T1598.003prevents — A.8.1's policy, user training, endpoint hardening (malware protection, web restrictions, device separation, automatic updates, remote wipe) and configuration enforcement reduce successful clicks on malicious links and subsequent credential theft on managed/BYOD endpoints, but do not stop the social-engineering delivery or user decision to click.
- T1608.004prevents — A.8.1's policy and configuration rules on endpoint software updates, malware protection, web service usage, partitioning, and user behavior (e.g. not visiting risky sites) constrain some browser-targeted drive-by delivery vectors on managed endpoints, but the technique's core (adversary staging on external infrastructure) and many delivery methods sit outside endpoint device policy.
- T1611detects — A.8.1 requires end-user behaviour analytics (explicitly cross-referencing 8.16), endpoint monitoring for malware, anomalous connections, and device policy enforcement that can surface suspicious activity indicative of a breakout, but this is scoped only to user endpoint devices and does not address container/VM escape techniques on servers, hypervisors, or non-endpoint platforms.
- T1611prevents — A.8.1's policy and configuration requirements for endpoint devices (software restriction, access controls, partitioning, malware protection, physical/logical locks, and separation on BYOD) can stop some container/VM escape vectors that rely on misconfigured endpoints or user actions, but the control is scoped to user endpoint devices and does not address host/hypervisor configuration, privileged containers, kernel modules, or most of the cited escape techniques on Linux/Containers/ESXi platforms.
- T1620detects — A.8.1 mandates end-user behavior analytics (explicit cross-ref to 8.16) plus malware protection, software restriction, and configuration enforcement on endpoints; these surface anomalous reflective loading in user processes or via EDR-like tooling, but the control is scoped to user endpoint devices and does not require host/process memory instrumentation that would catch all in-memory loading across Linux/macOS/Windows platforms or non-user contexts.
- T1620prevents — A.8.1's policy and enforcement on endpoint configuration (software restrictions, malware protection, updates, access controls, partitioning, and automated config management) can block common vectors and tools for reflective loading on user devices, but leaves open in-memory techniques inside already-approved processes or interpreters (e.g. PowerShell Assembly.Load) that the control does not reach.
- T1621detects — A.8.1's end-user behaviour analytics (explicitly cross-referenced to 8.16) and requirements for monitoring anomalous login patterns or device usage can surface repeated MFA request generation or fatigue indicators on managed endpoints, but this is limited to device-side observables and does not address the core authentication-service or identity-provider layer where most of the technique occurs.
- T1621prevents — A.8.1's endpoint policy and user training on MFA-aware access controls, device separation, and secure configuration (including wireless and removable media) can constrain some MFA fatigue vectors on managed endpoints, but leaves the core technique (credentialed login bombing of push/SMS/SSPR) untouched on identity-provider and SaaS surfaces.
- T1647prevents — A.8.1's policy on endpoint configuration (software restrictions, access controls, malware protection, updates, and configuration management enforcement) can stop many plist modifications on managed macOS devices, but leaves open user-owned/BYOD devices, physical/local admin bypasses, and post-compromise changes to user plist files that the control does not universally block.
- T1649prevents — A.8.1's policy and configuration requirements for endpoint devices (encryption, access controls, malware protection, software restrictions, physical/logical protections, remote wipe, and separation on BYOD) directly block several common theft vectors from endpoints (e.g., stealing from stores, files, or via malware), but do not address forging, CA private-key compromise, enrollment-rights abuse, or non-endpoint certificate sources.
- T1653prevents — A.8.1's policy and configuration requirements for endpoint devices (including software restrictions, updates, malware protection, access controls, and automated enforcement via 8.9) reach the abuse of powercfg/settings and related configuration changes on managed endpoints, but leave a bounded remainder: deletion of shutdown-related files, abuse on unmanaged/BYOD devices, network devices, and cases where the policy is not enforced or the device is already compromised.
- T1657prevents — A.8.1's endpoint policy, configuration enforcement, malware protection, encryption, access controls, device management (remote wipe, updates), and user training on BYOD/physical protection close slices of technical theft, ransomware extortion, and account compromise vectors that rely on unmanaged endpoints, but leave social engineering (BEC, pig butchering), off-endpoint bank hacking, crypto exploits, and many non-device financial fraud paths untouched.
- T1657recovers — A.8.1 explicitly requires backups (item k) and procedures for theft/loss of endpoint devices that carry sensitive information; these enable recovery of monetary resources lost via endpoint-compromised ransomware or technical theft, but do not address non-endpoint vectors such as BEC, social engineering, or cryptocurrency exploits.
- T1659detects — A.8.1's end-user behavior analytics (explicitly cross-referenced to 8.16), malware protection, secure configuration enforcement, and awareness of anomalous device behavior can surface indicators of injected malicious content reaching endpoints, but the control is scoped to device-level policy and user responsibility rather than network-channel or upstream ISP monitoring that would catch most content-injection techniques at their source.
- T1669detects — A.8.1 requires end-user behavior analytics (explicitly cross-referenced to 8.16), wireless connection configuration procedures, and awareness of device usage rules, all of which can surface anomalous Wi-Fi connections or proximity-based access attempts on managed endpoints, but this is scoped only to organization-controlled user devices and leaves the bulk of external adversary proximity, dual-homed bridging, and open-network exploitation undetected.
- T1669prevents — A.8.1's policy and configuration requirements for endpoint wireless connections (e.g. disabling vulnerable protocols, requiring personal firewalls, access controls, and secure configuration) directly constrain the ability of adversaries to connect to or exploit Wi-Fi networks from managed endpoints, but this is a slice: the technique can still succeed via open networks, stolen credentials, physical proximity to non-endpoint APs, or dual-homed third-party bridges outside the policy's enforcement.
- T1674detects — A.8.1 explicitly requires end-user behaviour analytics (see 8.16) plus malware protection, device registration, and monitoring-enabling configuration (firewalls, wireless config, remote lockout, etc.), which can surface anomalous keystroke-like input or HID activity on managed endpoints; this is only a slice because the control is primarily about policy and configuration rather than mandating comprehensive runtime detection of simulated input techniques, and personal/BYOD devices plus physical HID vectors sit mostly outside its reach.
- T1674prevents — A.8.1's policy and configuration requirements for endpoint devices (software restrictions, malware protection, physical/logical access controls, USB/port disabling, device registration, and automated enforcement) can stop many HID-based or malware-driven keystroke injection vectors before they execute, but leave open slices such as pre-installed legitimate software, unmonitored physical devices, or social-engineering vectors that still allow simulation of user input.
- T1680prevents — A.8.1's policy on endpoint configuration (software restriction, removable-device/port disabling, partitioning, encryption, malware protection, and enforced config management) can block several common discovery vectors on managed endpoints, but leaves many others (native commands like df/lsblk/Get-PSDrive, IaaS APIs, hypervisor CLI, and unmonitored BYOD) untouched.
- T1684detects — A.8.1 requires user awareness of endpoint security requirements plus end-user behavior analytics (explicitly cross-referenced to 8.16), which can surface anomalous actions that result from social engineering; this is only a slice of the broad technique (which spans voice, email, help-desk, and non-endpoint channels) rather than a bounded remainder.
- T1684prevents — A.8.1's policy, user training, configuration enforcement (e.g. malware protection, software restrictions, removable device controls, encryption, remote wipe) and awareness of social engineering risks reduce the chance users will fall for influence attempts that lead to malicious software execution or disclosure, but do not stop the human-targeted technique itself or its non-technical vectors such as voice calls or urgent emotional manipulation.
- T1685prevents — A.8.1's policy, configuration enforcement, malware protection, software/update requirements, access controls, remote lockout/wipe, and endpoint analytics directly constrain many of the on-host tampering, disabling, and update-blocking actions against EDR/AV/sensors described in T1685, but leave untouched advanced in-memory/driver-based bypasses, network/cloud telemetry disruption, and non-endpoint logging infrastructure.
- T1686detects — A.8.1 requires end-user awareness, device policies, configuration management, and monitoring via end user behaviour analytics (explicitly cross-referenced to 8.16), which can surface anomalous firewall changes on managed endpoints; this is limited to a slice because the control is endpoint-focused, does not mandate specific detection of firewall tampering, excludes many platforms (e.g. network devices, ESXi), and relies on separate monitoring rather than directly performing detection.
- T1686prevents — A.8.1's policy and configuration requirements for endpoint devices (firewall use on public networks, software restrictions, malware protection, automated enforcement via 8.9) constrain many common ways an adversary could disable or modify a host firewall, but do not reach all platforms/behaviors (e.g. ESXi, network devices, privileged post-compromise tampering) and leave residual gaps where policy is not enforced.
- T1686.003detects — A.8.1 requires end-user awareness, device policy, configuration management, malware protection, endpoint analytics (see 8.16), and procedures for loss/theft response, which can surface anomalous firewall changes on monitored endpoints but does not mandate or guarantee detection of the specific technique across all vectors or unmonitored devices.
- T1686.003prevents — A.8.1's policy and configuration requirements for endpoint devices (firewall use on public networks, software restrictions, malware protection, automated enforcement via 8.9) constrain many of the modification vectors and reduce the likelihood the technique can be executed successfully, but do not block all listed mechanisms (e.g. registry edits, admin-level netsh/PowerShell, or post-compromise local changes) on all devices.
- T1687prevents — A.8.1's policy and configuration mandates for endpoint hardening (malware protection, software updates, restricted installation, EDR-relevant controls, remote wipe, etc.) reduce the attack surface and likelihood that exploitable vulnerabilities will exist or be introduced in defensive components on user endpoints, but do not guarantee absence of 0-days or cover non-endpoint infrastructure/SaaS layers named in T1687.
- T1689prevents — A.8.1's policy and enforcement on software versions, automatic updates, restriction of installations, malware protection, and configuration management directly stop many downgrade vectors on endpoint features and software (e.g. forcing current PowerShell or disabling vulnerable protocols), but leave gaps for boot manager, network protocol, and non-endpoint downgrades.
Prevented OWASP Web Top 10 (2025) risks (10)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01mitigates — A.8.1's access controls, device encryption, malware protection, remote wipe, physical/logical locking, and partitioning limit the blast radius or consequence of a realized broken-access-control flaw on an endpoint (e.g., stolen device, malware exfiltrating data, or unauthorized local access), but do not address the root authorization-decision failures that are the class's dominant members (IDOR, CSRF, path traversal, missing function-level checks).
- A02mitigates — A.8.1's endpoint policy, configuration enforcement, encryption, malware protection, access controls, and device separation reduce the realized impact or exploitability of many misconfigurations on user endpoints (e.g., weak defaults on BYOD or wireless), but do not address server/cloud/framework misconfigurations that dominate the OWASP class.
- A02prevents — A.8.1's policy, configuration enforcement, software restrictions, updates, encryption, malware protection, and partitioning directly close many common misconfiguration vectors on endpoints (e.g., weak defaults, exposed services, unpatched software, open ports); residual attack surface remains in non-endpoint layers (servers, cloud, frameworks) and in incomplete policy implementation.
- A04mitigates — A.8.1 requires storage device encryption, malware protection, secure configuration, and separation on endpoints (including BYOD), which bounds the realized impact of weak/misused cryptography for data at rest on those devices without addressing transit, key management, algorithm selection, or in-transit exposure.
- A05mitigates — A.8.1's endpoint policy, malware protection, software restrictions, encryption, partitioning, and wireless config can bound the consequence or block some delivery vectors for realized injection (e.g. XSS on endpoint, malicious payloads via removable media or untrusted wireless), but the core interpreter-boundary neutralization failure in web/server code is untouched.
- A08mitigates — A.8.1's policy, configuration, malware protection, encryption, remote wipe, and separation mechanisms on endpoints can bound the consequences of realized integrity failures (e.g. preventing malicious code from unsigned updates or deserialization from escalating via endpoint compromise), but do not address the core weakness of missing integrity checks on software/data/CI-CD paths themselves.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.