A.8.21 Technological
Security of network services
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (26)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AC-17mostlyaligns with — Both controls require organizations to define and enforce security requirements for remote or external network connections, including authentication, authorization, and monitoring of provider-managed services.
- AC-18mostlyaligns with — Both controls address the need to establish rules and technical controls governing access to wireless and other network services, including permitted usage and security features.
- AC-3mostlyaligns with — Both controls focus on enforcing authorization decisions that determine which users or entities may access specific network services and connections.
- AC-2partialaligns with — Both controls require procedures to manage who is permitted to access networks and services, including authentication and authorization tied to user accounts.
- AU-2partialaligns with — Both controls require monitoring and logging of network service usage to detect unauthorized or non-compliant access.
- CA-3partialaligns with — Both controls require organizations to establish security and monitoring expectations when exchanging information or services with external network providers.
- SC-7partialaligns with — Both controls emphasize implementing boundary and connection controls to protect access to network services from unauthorized or insecure entry points.
- SC-7partialcovers — A.8.21's broad requirement to ensure security when using network services (including their secure configuration and monitoring) addresses only a slice of SC-7's specific boundary-protection, subnetwork segmentation, and managed-interface mandates; the bulk of SC-7's technical controls sit elsewhere.
- AC-17covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- AC-18covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- AC-3covers — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- CA-3implements — A.8.21's governance mandate for secure network service usage directly encompasses the domain of controlled, documented information exchanges with external systems that ca-3 operationalizes
Aligned NIST CSF 2.0 outcomes (23)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- DE.CM-01mostlyaligns with — Requiring ongoing monitoring of network service usage and the provider’s performance implements continuous monitoring of networks to detect potentially adverse events.
- GV.SC-05mostlyaligns with — The control requires contractual and operational security requirements to be defined and enforced with network service providers, which directly supports embedding cybersecurity obligations into supplier agreements.
- GV.SC-07mostlyaligns with — Regular monitoring of the provider’s ability to deliver services securely and the use of third-party attestations both contribute to understanding and recording supplier risk.
- PR.AA-05mostlyaligns with — Defining and enforcing authorization procedures that determine who may access which networks and services directly addresses the management of access permissions and entitlements.
- PR.IR-01mostlyaligns with — Specifying authentication, encryption, connection controls, and authorization procedures for network services implements logical protections against unauthorized network access and usage.
- ID.AM-03partialaligns with — Documenting allowed networks, access methods, and connection rules contributes to maintaining representations of authorized network communication flows.
- PR.AA-03partialaligns with — Specifying authentication requirements and technical parameters for secure connections supports the authentication of users, services, and hardware accessing network services.
- DE.CM-01implements — DE.CM-01 names network monitoring as the required outcome; A.8.21's measures for securing network services (including monitoring and logging of usage) give operational effect to that outcome within the network-services domain, but the link is inferential rather than by explicit naming of monitoring.
- GV.SC-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- GV.SC-07implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- ID.AM-03implements — Assessed as NOT holding by the authoring instrument at v1.19-2026-08-23. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AA-03implements — A.8.21 operationalizes network-service security which directly includes authenticating users/services/hardware as a core means within that domain (per its implementation guidance on authentication and access to services), though PR.AA-03 is not named verbatim
- PR.AA-05implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.IR-01implements — A.8.21 operationalizes network-service security (including access/use restrictions) which sits inside the PR.IR-01 protection outcome; the link is by shared domain rather than explicit naming of the control's subject.
Related OWASP ASVS 5.0 requirements (12)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V13.2.4mostlycovers — The ISO control's requirement to define and enforce an allowlist of permitted networks and services directly implements the ASVS mandate that applications only communicate with explicitly approved external resources.
- V13.2.5mostlycovers — Specifying which resources a server may contact and restricting outbound connections aligns with the ISO guidance on formulating rules for allowed network access and technological controls.
- V12.3.5partialaligns with — Mandating strong authentication for internal service-to-service communications within the network aligns with the ASVS requirement that intra-service communications use strong authentication to ensure each endpoint is legitimate.
- V6.3.1partialaligns with — Requiring authentication and authorization procedures for network services supports the ASVS requirement for controls that defend against credential stuffing and brute-force attacks on authentication pathways.
- V8.2.1partialaligns with — The ISO control's authorization procedures for determining who may access which network services map to the ASVS requirement that function-level access be restricted to consumers with explicit permissions.
Related weaknesses / CWE (49)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-296nonemitigates — Secure network services depend on correct certificate chain validation.
- CWE-940nonemitigates — Security of network services includes validating the origin of service requests and connections.
- CWE-1125mitigates — Restricting network services reduces exposed interfaces, though broader attack-surface decisions may still remain.
- CWE-1327prevents — Security of network services includes hardening service bindings to prevent exposure on all interfaces.
- CWE-200prevents — Encryption, connection controls, and monitoring of network service usage reduce the chance that sensitive data traversing or accessible via those services will be exposed to unauthorized observers.
- CWE-284prevents — Defining allowed networks, authentication requirements, authorization procedures, and access attributes directly enforces who may reach which services, blocking unauthorized entry paths that improper access control would otherwise leave open.
- CWE-287mitigates — Requiring authentication mechanisms and technical parameters for secure connections ensures that network services verify user identity before granting access, preventing exploitation of missing or weak authentication.
- CWE-288mitigates — Security of network services may restrict alternate paths but does not enforce authentication requirements.
- CWE-291mitigates — Security of network services includes authentication mechanisms beyond source IP.
- CWE-300mitigates — Security of network services includes measures to verify endpoints and protect channel integrity.
- CWE-306mitigates — Mandating authentication for network services and critical functions stops attackers from invoking sensitive operations without credentials, closing gaps where authentication is absent for important capabilities.
- CWE-319prevents — Specifying encryption and other security technology for network services prevents transmission of sensitive information in cleartext over potentially untrusted channels.
- CWE-322mitigates — Security of network services includes requirements for authenticated key exchange in service protocols.
- CWE-345mitigates — Secure network services often include authenticity checks for data exchanged over those services.
- CWE-346mitigates — Security of network services includes validating the authenticity of service endpoints.
- CWE-350mitigates — Secure network services discourage use of unauthenticated reverse-DNS for access decisions.
- CWE-353prevents — Security requirements for network services can require integrity checks on data in transit.
- CWE-400prevents — Monitoring network service usage and applying controls to restrict access when necessary limits an attacker’s ability to consume excessive resources through unrestricted or unauthenticated service calls.
- CWE-406mitigates — Security of network services can impose volume controls on specific services, but does not address the weakness broadly.
- CWE-419prevents — Security of network services can enforce protection on the primary channel.
- CWE-420prevents — Security of network services requires consistent protection across all service channels, mitigating alternate-channel weaknesses.
- CWE-5prevents — Requires security measures for network services, which include encryption of transmitted data.
- CWE-523prevents — Addresses security of network services, which may include protecting authentication traffic.
- CWE-605mitigates — Security of network services includes configuration to prevent unauthorized services from binding to privileged ports.
- CWE-757mitigates — Ensures network services use secure cryptographic parameters, reducing downgrade risk.
- CWE-862mitigates — Authorization procedures and rules that determine who may access specific networks and services ensure that every request is checked for the required permissions before access is granted.
- CWE-923prevents — Security of network services includes authentication of endpoints and service-to-service channel protection.
- CWE-924prevents — Addresses security of network services, which may include integrity mechanisms.
Mitigated MITRE ATT&CK techniques (1023)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1001detects — A.8.21 explicitly requires monitoring of network service use plus consideration of authentication/encryption/connection controls that surface anomalous or non-compliant traffic; this detects some T1001 instances (e.g. protocol impersonation or conspicuous junk) but leaves steganography, well-mimicked legitimate flows, and non-monitored segments undetected.
- T1001.001detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, encryption and anomalous-behaviour detection, which surfaces C2 traffic containing junk data as an observable anomaly; the remainder is that the clause sets scope by organisational requirements rather than mandating universal deep-packet or protocol-specific analysis of junked payloads.
- T1001.002detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, encryption and anomalous-behaviour detection, which surfaces steganographic C2 hiding in monitored traffic but leaves unmonitored channels, non-network vectors and implementation-scope choices as a genuine slice
- T1001.003detects — A.8.21 explicitly requires monitoring of network service use plus consideration of authentication/encryption/connection controls and anomalous traffic detection via those features, which surfaces impersonation attempts that deviate from expected protocol handshakes or service patterns, but only for monitored/allowed services within the organization's defined scope rather than all possible impersonations.
- T1001.003prevents — A.8.21 requires identifying, implementing, and enforcing network service security features (authentication, encryption, connection controls, usage rules, monitoring) plus provider oversight, which directly constrains many impersonation vectors by mandating proper protocol handling and detection of anomalies; it leaves a slice unaddressed where the impersonation perfectly mimics allowed/encrypted traffic without violating the rules.
- T1003.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and connection controls that surface anomalous access attempts to domain controllers or NTDS-related resources, but does not address the offline/backup-copy or local Volume Shadow Copy methods that dominate the technique.
- T1003.003prevents — A.8.21 mandates network/service rules, authentication, authorization, monitoring, and connection controls that can block many remote or unauthorized access paths to a DC's NTDS.dit (and some backup copies), but leaves local admin/privileged execution on a compromised DC (e.g. via Volume Shadow Copy, ntdsutil.exe, or Invoke-NinjaCopy) untouched.
- T1003.005detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization controls that can surface anomalous access to credential caches (especially on Linux SSSD paths or Windows registry hives), but this is scoped only to network-service usage and does not broadly instrument local credential extraction or file/registry access.
- T1003.005prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, encryption, network connection controls, access restrictions, monitoring) that can block the network-based or privilege-escalation paths used to reach and dump cached credential stores, but does not reach the local extraction step once SYSTEM/sudo is obtained nor eliminate the existence of the caches themselves.
- T1003.006detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous access or replication behavior, which can detect DCSync's network-visible replication simulation; it is only partial because the clause scopes monitoring to organization-defined requirements rather than mandating host-level or API-specific detection of DCSync.
- T1003.006prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, authorization, monitoring, time/location attributes) and rules restricting network access; this can prevent DCSync replication abuse over the network from non-DC hosts or via weak connections, but does not reach the dominant privileged-group membership on the DC itself that enables the technique.
- T1003.008prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, monitoring) that can block unauthorized local or remote access needed to read/dump the files, but does not reach privilege escalation, root compromise, or all local vectors on Linux systems.
- T1007detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces many (but not all) instances of local service-discovery commands when they involve network-facing services or produce observable network telemetry.
- T1008detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication, authorization, connection controls and anomalous-access attributes, which surfaces fallback-channel behaviour when it deviates from the allowed baseline; the remainder is the slice of fallback activity that stays inside the permitted rules, uses approved channels or occurs outside monitored scope.
- T1008prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, allowed networks/services, access rules, and monitoring) for network services, which can block many alternate C2 channels but leaves residual cases such as adversary-controlled domains, novel protocols, or insider-allowed services that conform to the rules.
- T1011detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of technology and procedures that can surface anomalous use of alternate media (WiFi, cellular, Bluetooth, etc.), but the clause sets scope by business requirements rather than mandating universal coverage of every possible exfiltration medium, leaving a genuine slice unreached.
- T1011prevents — A.8.21 requires rules, authentication, authorization, network management controls, allowed media, and monitoring that can block or constrain exfiltration over alternate/less-defended media such as WiFi, Bluetooth or cellular when those are outside the permitted set; this is genuine but partial because the control is scoped to organization-approved services and cannot stop an adversary with sufficient proximity or access from using an unmonitored medium that evades the rules.
- T1011.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and authentication/authorization, which can surface anomalous Bluetooth exfiltration as an out-of-policy network channel; however this is scoped only to organizationally-allowed network services and does not broadly instrument or guarantee detection of ad-hoc Bluetooth data transfer by a proximate adversary.
- T1011.001prevents — A.8.21 requires rules, authentication, authorization, network management controls, allowed services, connection means (explicitly including wireless), and monitoring that can block or constrain unauthorized Bluetooth exfiltration channels when enforced; it does not reach all proximity-based or post-compromise Bluetooth use on all platforms.
- T1016.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous usage, which can surface Internet connectivity checks performed by adversaries as part of discovery.
- T1016.002detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous access or usage, which would detect the local commands, file reads, and API calls that realize T1016.002 on a monitored host; the remainder is that the clause's scope is set by organizational requirements and does not mandate host telemetry depth sufficient to catch every Wi-Fi-enumeration artifact on every platform.
- T1018detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous discovery activity (e.g. ping, ARP, net view, CDP), but the clause sets scope by business requirements rather than mandating universal coverage of every passive/local or network-device technique, leaving a genuine implementer-chosen slice.
- T1018prevents — A.8.21 mandates rules, authentication, authorization, network management controls, monitoring, and security features (e.g. connection controls, encryption) that can block many active discovery utilities and unauthorized network access used in T1018, but leaves passive/local methods (hosts file, ARP cache), allowed networks, and on-device CLI commands on managed infrastructure as clear residual.
- T1020detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, encryption and anomalous usage patterns, which surfaces automated exfiltration when it traverses monitored network services but leaves substantial remainder (e.g., non-network exfil, unmonitored segments, or encrypted C2 channels outside the monitored scope).
- T1020prevents — A.8.21 mandates rules, authentication, authorization, network controls, monitoring and service-provider oversight that can block many automated exfiltration paths (e.g. by denying unauthorized services, enforcing VPN-only egress, or detecting anomalous transfers), but leaves residual cases such as authorized channels abused post-compromise or exfiltration that never traverses a monitored network boundary.
- T1020.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and third-party attestations, which can surface anomalous mirroring/redirect configurations or traffic; this is a genuine but minority slice of the technique (native device/cloud features, ROMMONkit/patch modifications, and post-compromise abuse often evade or sit outside routine service monitoring).
- T1020.001prevents — A.8.21 requires rules, authentication, authorization, network management controls, and monitoring of network services that can block unauthorized mirroring configuration or traffic redirection on allowed networks, but does not stop the technique on compromised devices, via firmware attacks, or in unmanaged cloud mirroring setups.
- T1021prevents — Requiring authentication, authorization, and connection controls for network services limits an adversary's ability to abuse remote services for lateral movement.
- T1021detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization rules and connection controls, which surfaces anomalous or unauthorized remote service logins (the core of T1021) within the scoped networks; it is partial because the clause sets requirements rather than mandating universal instrumentation depth, so coverage depends on what the organization chooses to monitor.
- T1021.001detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization rules and connection controls, which surfaces anomalous RDP logons or usage patterns after the fact; it is not scoped to all RDP instances or guaranteed to catch credentialed use that blends with legitimate activity.
- T1021.001prevents — A.8.21 requires formulating and implementing rules plus technical controls that explicitly cover authentication requirements, authorization procedures, allowed networks/services, VPN/wireless means, time/location attributes, network connection controls, and monitoring — all of which can stop an adversary from successfully using valid credentials over RDP; it is only partial because the control is a requirements-and-governance clause whose actual preventive effect depends on the rigor of the specific rules and mechanisms chosen by the implementer.
- T1021.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication, authorization, and connection controls that surface anomalous or unauthorized SMB/admin-share access when those fall inside the scoped monitoring rules.
- T1021.002prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, time/location attributes, monitoring) that can block unauthorized SMB/Windows Admin Share access when enforced; however, it is a governance-and-requirements clause whose effect depends on the rigor of the specific rules and provider implementations chosen, leaving substantial residual paths (e.g., legitimate admin accounts, pass-the-hash, misconfigured shares) unaddressed.
- T1021.003detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous access; DCOM lateral movement is observable RPC traffic over the network, but only a slice of the technique (remote activation/execution) falls inside network-service monitoring while local COM abuse, Office-object methods, and non-network aspects remain unseen.
- T1021.003prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, time/location attributes, monitoring) that can block unauthorized DCOM/RPC lateral movement when enforced at network or auth boundaries; this reaches only a slice of the technique (remote activation by valid but insufficiently constrained accounts), not the dominant local-privilege or insecure-method vectors inside an already-authenticated session.
- T1021.004detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization rules and anomalous-access attributes, which surfaces SSH logins (especially unauthorized or anomalous ones) but only as one configurable slice of network-service monitoring rather than a dedicated, guaranteed detection mechanism for the technique.
- T1021.004prevents — A.8.21 explicitly requires formulating and implementing rules plus technical controls (authentication requirements, authorization procedures, network connection controls, VPN/wireless means, time/location attributes, monitoring) that directly stop unauthorized SSH logins even with a valid account; the named remainder is post-auth lateral movement or unmonitored exempted SSH configurations.
- T1021.005detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and anomalous usage, which surfaces VNC-based remote access when it occurs inside the monitored scope; it does not guarantee detection of every VNC abuse (e.g. when excluded from monitoring scope, uses legitimate credentials without triggering rules, or exploits implementation flaws without observable network/service anomalies).
- T1021.005prevents — A.8.21 explicitly requires formulating/implementing rules on allowed networks/services, authentication requirements, authorization procedures, network management/technological controls (including VPNs), time/location attributes, and monitoring, plus considering encryption and connection controls; this directly constrains the remote VNC abuse path when enforced, but leaves residual exposure via valid accounts, misconfigurations, or unmonitored implementations.
- T1021.006detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and connection controls that surface anomalous or unauthorized WinRM usage on Windows networks.
- T1021.006prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, time/location attributes, monitoring) that can stop unauthorized use of WinRM over the network; this reaches only a slice of the technique because the control is silent on the dominant prerequisite of valid accounts already being compromised.
- T1021.007detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and connection controls, which surfaces anomalous logins to cloud services (a network service) but does not guarantee detection of all vectors such as application access tokens or post-auth management actions.
- T1021.007prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical features (authentication, authorization, network connection controls, VPNs, monitoring, time/location attributes) that directly constrain legitimate-but-abusable paths to cloud services; this stops many T1021.007 executions but leaves open the remainder of already-compromised valid accounts, application access tokens, and federated on-prem identities that satisfy the rules.
- T1021.008detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls, which surfaces anomalous or unauthorized direct VM console access attempts when those fall inside the monitored scope; it does not guarantee detection of every stealthy or out-of-scope instance.
- T1021.008prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, time/location attributes, monitoring) for network services; this constrains many default-privileged cloud VM direct-access paths (e.g. via enforced MFA, restricted auth methods, approved connection means), but leaves residual slices such as approved legitimate accounts using allowed SSH keys or console methods on IaaS.
- T1027.006detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous usage patterns that can surface HTML smuggling attempts delivered over the network, but it does not mandate inspection of HTML/JS payloads, Data URLs, or client-side blob generation.
- T1029detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of time/location/user attributes at access time, which surfaces anomalous scheduled exfiltration blending with normal traffic patterns; partial because the clause sets requirements rather than mandating specific detection instrumentation or coverage depth, leaving slices (e.g., non-network or unmonitored attributes) to the implementer.
- T1030detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and technical parameters, which can surface anomalous chunked or size-limited exfiltration that evades bulk-transfer thresholds; the remainder is that the clause sets requirements rather than mandating specific detection instrumentation depth or coverage of all such transfers.
- T1036.012detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization and connection controls that surface anomalous or unauthorized browser-like traffic; this catches some spoofed fingerprinting attempts that deviate from baselines but leaves the bulk (stealthy mimicry of legitimate patterns inside allowed sessions) undetected.
- T1037.001detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and access attribute checks that can surface anomalous logon-script execution when it traverses or is delivered via a network service; this is a genuine but minority slice of the technique's possible local-only or non-network vectors.
- T1037.001prevents — A.8.21 requires rules, authentication, authorization, network management controls, and monitoring that can block unauthorized logon-script execution at the network/service boundary for allowed services and access attributes, but the technique is a local registry-based persistence mechanism that can still be set by an already-authenticated user with sufficient rights on an allowed endpoint.
- T1037.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous logon-script execution when it occurs within the monitored scope; this is genuine detection of the technique but only a slice because the clause sets the monitoring scope by policy rather than mandating universal coverage of all logon-script invocations.
- T1037.003prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, authorization, network connection controls, monitoring, VPN/wireless means, time/location attributes) that can block unauthorized assignment or execution of network logon scripts via AD/GPO, but leaves residual paths such as privileged admin accounts legitimately configuring them or insider abuse of allowed services.
- T1037.004detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous access or configuration changes; this can detect RC script abuse on network devices and some Unix-like systems when it touches monitored network services or produces observable startup/network anomalies, but leaves the bulk of local RC-script modification on Linux/macOS/ESXi untouched.
- T1039detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and connection controls that surface anomalous access to shares; this detects the technique in flight on covered networks but is scoped by what the organization chooses to monitor and does not guarantee coverage of every share or every platform.
- T1039prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, time/location attributes, monitoring) that can block unauthorized access to network shares, directly stopping the technique on covered vectors; partial because it sets requirements rather than mandating universal mechanisms, leaving slices such as already-compromised legitimate sessions or unmanaged internal shares.
- T1040detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous-behaviour monitoring, which surfaces sniffing activity on covered networks; it does not mandate comprehensive packet-level or promiscuous-mode detection across all platforms, cloud mirroring, or network-device CLI captures, leaving a large named remainder.
- T1040prevents — A.8.21 mandates network rules, authentication/authorization, encryption, connection controls, and monitoring that stop sniffing of cleartext credentials and many forms of passive capture; it does not reach promiscuous-mode placement on unmanaged endpoints, cloud traffic-mirroring services, or network-device CLI captures, leaving a genuine minority slice unaddressed.
- T1041detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication/encryption/connection controls and anomalous-use procedures, which surfaces exfiltration blended into an existing C2 channel as anomalous traffic; this is only a slice because the clause sets requirements rather than mandating specific detection depth or coverage of all C2 protocols.
- T1041prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, access rules, monitoring) for network services; this can stop exfiltration by blocking unauthorized C2 channels or detecting anomalous use, but leaves residual cases (e.g., legitimate channels abused with proper auth/encryption, or unmonitored provider-managed services)
- T1046detects — A.8.21 explicitly requires monitoring of the use of network services plus procedures to restrict access and consider authentication/authorization controls, which can surface anomalous discovery scans or unauthorized service queries (especially on managed networks), but this is scoped by organizational rules rather than mandating broad detection of all T1046 methods such as mDNS/Bonjour or unmonitored cloud/port scans.
- T1046prevents — A.8.21 requires rules, authentication, authorization, network management controls, monitoring, and security features (e.g. connection controls, encryption) that can block many forms of unauthorized network service discovery and scanning, but leaves residual cases such as mDNS/Bonjour on allowed services, insider use of permitted tools, and discovery of services the rules explicitly allow access to.
- T1047detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication, authorization, and connection controls that surface anomalous or unauthorized WMI activity over its remote ports/protocols (DCOM/WinRM); this is genuine detection coverage for the remote slice of T1047 but leaves the dominant local-abuse surface (COM APIs, PowerShell, wbemtool) untouched.
- T1047prevents — A.8.21 requires identifying/implementing network-service security features (authentication, authorization, network connection controls, monitoring, allowed services) and provider oversight; this constrains remote WMI abuse over DCOM/WinRM ports and networks but leaves local WMI abuse (and many non-network vectors) untouched.
- T1048detects — A.8.21 explicitly requires monitoring of the use of network services plus identification and enforcement of allowed networks/protocols, authentication, authorization, and connection controls, which surfaces anomalous exfiltration over unapproved alternate protocols as a detectable deviation.
- T1048prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, allowed protocols/services, VPN/wireless means, monitoring) that can stop many alternate-protocol exfiltration paths when enforced at the network or service level, but leaves open-ended residual cases such as permitted web/HTTP/S, cloud APIs, or insider use of allowed channels.
- T1048.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of technology such as encryption and network connection controls, which surfaces anomalous or unauthorized exfiltration flows over symmetric-encrypted non-C2 channels when those flows deviate from allowed networks, authentication, authorization, or usage rules.
- T1048.001prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, network rules, and usage restrictions) for allowed network services, which can block many forms of unauthorized symmetric-encrypted exfiltration over non-C2 protocols; it does not reach adversary-controlled implementations or all possible alternate locations.
- T1048.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, encryption features and anomalous usage, which surfaces exfiltration over asymmetric encrypted non-C2 protocols when it falls inside the monitored scope; the remainder is usage outside the organisation's defined monitoring envelope or on unmanaged third-party networks.
- T1048.002prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, access rules, monitoring) for network services, which can block unauthorized exfiltration channels using asymmetric protocols when those rules and features are enforced.
- T1048.003detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, and technical parameters, which surfaces anomalous or policy-violating exfiltration over unencrypted non-C2 channels when those fall inside the monitored scope; it does not guarantee detection of every obfuscated case or every platform.
- T1048.003prevents — A.8.21 requires identifying, implementing, and enforcing security features (authentication, encryption, connection controls, usage rules, monitoring) for network services, which directly stops unencrypted exfiltration over protocols like HTTP/FTP/DNS when those rules mandate encryption or block the unencrypted path; it is only partial because the control is a requirement on providers and rules rather than a universal mechanism, leaving slices such as allowed unencrypted services, alternate locations, or obfuscation without encryption untouched.
- T1049detects — A.8.21 explicitly requires monitoring of the use of network services plus procedures to restrict access and consider authentication/authorization/network controls, which can surface anomalous discovery commands (netstat, lsof, who, show ip sockets, etc.) when they trigger the monitored rules; this is only a slice because the clause sets requirements rather than mandating universal instrumentation depth or coverage of all discovery vectors on every platform.
- T1049prevents — A.8.21 requires rules, authentication, authorization, network management controls, and monitoring that can block or constrain many of the discovery commands and network queries on allowed services and connections, but leaves open-ended residual cases (e.g., already-authenticated local execution of netstat/lsof on permitted networks, or discovery inside unmanaged cloud/IaaS slices).
- T1052.001detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and connection controls that can surface anomalous USB-based exfiltration when it traverses or is governed by those monitored network services; this is a genuine but minority slice of the technique (most T1052.001 paths are purely physical/air-gapped device hops that never touch a network service).
- T1053detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous scheduling (especially remote), but this is scoped only to network-mediated use of the technique and leaves local-only or non-network task abuse undetected.
- T1053prevents — A.8.21 requires formulating and implementing rules on allowed networks/services, authentication, authorization, network management controls, access means (e.g. VPN), user attributes, and monitoring, plus considering authentication/encryption/connection controls; this constrains remote scheduling (which requires proper auth and often privileged group membership) and some local abuse vectors on managed networks, but leaves the bulk of local task/job abuse (especially on endpoints) untouched.
- T1053.002prevents — A.8.21 requires formulating and implementing rules on allowed networks/services, authentication, authorization, network management controls, access means (e.g. VPN), user attributes, monitoring, and restricting access to services/applications where necessary; this can prevent unauthorized at/abuse on many platforms by enforcing allow/deny lists, authz, and network-level blocks, but leaves open the remainder where at runs under permitted admin/superuser contexts or via local WMI/sudo without violating the network-service rules.
- T1053.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and network connection controls that can surface anomalous scheduled tasks or cron abuse when it traverses or is observed on allowed network paths; this is a genuine but minority slice of the technique (most cron abuse is purely local and never touches the network).
- T1053.005detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous or unauthorized scheduled-task activity when it traverses or uses those services; this catches a slice (remote/lateral use, network-visible execution) but not local-only or hidden task creation on an endpoint.
- T1053.005prevents — A.8.21 mandates rules, authentication, authorization, network/technological controls, and monitoring that can block unauthorized creation or execution of scheduled tasks over networks or via remote access vectors, but leaves local abuse, privilege-escalated local creation, and hidden-task techniques on the host untouched.
- T1053.007detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and network connection controls, which can surface anomalous container-orchestration job scheduling over the network in monitored environments, but the clause's scope is limited to network services and does not mandate host or orchestration-specific detection of job abuse.
- T1055detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces some in-process injection where observable via network, IPC pipes, or connection anomalies, but leaves the bulk of platform-specific memory-injection techniques (the dominant slice of T1055) outside its defined scope.
- T1055.001detects — A.8.21 explicitly requires monitoring of network service use plus network-level technological controls that can surface anomalous process-injection behaviour when it traverses or uses monitored network connections, but the technique is fundamentally a local in-process memory technique that can succeed entirely without network activity.
- T1055.002detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this surfaces some in-process PE injection where it produces observable network artefacts or anomalies, but the core technique (VirtualAllocEx/WriteProcessMemory/CreateRemoteThread inside a process) is not a network-service event and is outside the clause's named scope
- T1055.003detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which can surface some in-process thread-hijacking artifacts when they involve network activity or observable anomalies, but the core technique (SuspendThread/WriteProcessMemory/SetThreadContext in a live process) is local process memory manipulation with no necessary network footprint.
- T1055.004detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; APC injection produces observable process/thread anomalies that fall inside that scope on monitored Windows endpoints, but the clause's scope is set by organisational requirements rather than mandating universal host telemetry, leaving a large slice of unmonitored or non-network-linked injections undetected.
- T1055.005detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this can surface network-visible artifacts or anomalies from a live TLS-callback-injected process (e.g. unexpected network activity from the host process), but the core in-memory PE/TLS manipulation itself is invisible to network-service monitoring and is only a minority slice of what the technique does.
- T1055.008detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces ptrace-based injection when it crosses a monitored network boundary or produces observable anomalies, but the clause's scope is set by organisational requirements and does not mandate host-level syscall or process-injection telemetry, leaving most in-process Linux ptrace activity unseen.
- T1055.009detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; proc memory injection produces observable anomalies (unexpected memory-map writes via /proc, ROP gadget execution, process-context anomalies) that fall inside that scope on Linux, but the clause's scope is set by organisational requirements rather than mandating universal host-level instrumentation, leaving a genuine slice of unmonitored processes or non-network-linked injection outside what the control necessarily surfaces.
- T1055.011detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; EWM injection produces observable process anomalies (shared-section writes, window-class registration, unexpected execution under a legitimate process) that fall inside that scope on monitored Windows endpoints, but the clause's network-service focus and implementer-defined scope leave substantial residue for in-process techniques that never touch the network.
- T1055.013detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that can surface anomalous process/memory behavior when it traverses the network (e.g. lateral movement or C2), but the core technique is local TxF-based in-memory injection that never requires network activity, leaving the bulk of its realizations outside the clause's named scope.
- T1055.014detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; VDSO hijacking produces observable process anomalies (syscall redirection, GOT patching, unexpected library mapping) that fall inside that scope on Linux, but the clause's scope is set by organisational requirements rather than mandating host-level instrumentation that would catch every in-process hijack, leaving a genuine implementation-dependent slice
- T1055.015detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls, which can surface anomalous process-injection behaviors (including ListPlanting) when they traverse or are observable over monitored network connections; this is only a slice of the Windows-local technique, not its dominant in-process execution path.
- T1056detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces many input-capture techniques (especially those involving network deception, web portals, or anomalous credential prompts) but leaves transparent in-process hooking on endpoints outside its named scope
- T1056.001detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces many (but not all) keylogging implementations that rely on network activity, registry changes, or detectable hooks/drivers
- T1056.003detects — A.8.21 explicitly requires monitoring of network service use plus consideration of authentication/encryption/connection controls and anomalous access attributes, which surfaces anomalous credential-capture behavior on externally facing portals such as VPN login pages; it does not mandate instrumentation depth sufficient to catch all variants (e.g., fully in-memory or non-network-visible implementations).
- T1056.003prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can stop adversaries from installing credential-capturing code on VPN/portal login pages; however, it is a governance-and-requirements clause whose effectiveness depends on the rigor of the specific measures chosen and does not guarantee prevention of all post-compromise or initial-exploitation vectors for this technique.
- T1056.004detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this surfaces some in-process hooking that touches network APIs (e.g. libc read for SSH/SCP) but leaves the bulk of non-network credential API hooking (most Windows hooks, IAT/inline on non-network functions) outside its named scope.
- T1057detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces process-discovery activity when it traverses or is visible from the network layer, but the technique is predominantly local (ps, Tasklist, /proc, Get-Process, CLI show processes) and can be performed without touching monitored network services.
- T1059detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces many interpreter-abuse indicators (especially remote or network-visible execution) but leaves local-only, non-networked interpreter activity outside its named scope.
- T1059prevents — A.8.21 requires rules, authentication, authorization, network connection controls, and usage restrictions that can block many abuse paths (e.g. via allowed networks, auth requirements, VPN-only access, or monitored/denied interpreters), but leaves the built-in interpreters themselves present and usable on the platforms where the technique is defined.
- T1059.004detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and anomalous-access controls that surface shell abuse when it occurs over allowed network paths (e.g. SSH, VPN, or remote shells), but the clause is silent on local shell execution, non-networked scripts, or Busybox on embedded/ESXi systems outside monitored network services.
- T1059.004prevents — A.8.21 mandates rules, authentication, authorization, network/technological controls (including VPNs), monitoring, and service-provider security features that can block unauthorized shell access or script execution on covered networks and endpoints; this stops many abuse paths but leaves a remainder on local interactive use, stripped-down Busybox shells, and post-compromise execution inside already-authorized sessions.
- T1059.007detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces many (but not all) JS-based execution events that involve network activity such as drive-by delivery or remote payload fetch; local-only JS/JXA abuse (e.g. in-memory OSAKit or standalone Node) lies outside that scope.
- T1059.007prevents — A.8.21 requires rules, authentication, authorization, network connection controls, monitoring, and security features (e.g. encryption) that can block many common abuse vectors for JavaScript execution such as drive-by delivery, unauthorized downloads, and network-based secondary payloads, but leaves substantial residual paths (local interpreters, in-memory OSAKit, obfuscated scripts already present, and non-network execution) untouched.
- T1059.008detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, authorization, network connection controls and other attributes, which surfaces anomalous CLI usage on network devices; this is a genuine but minority slice of the technique (remote access vectors, post-authentication abuse, and non-network-device interpreters sit outside its scope).
- T1059.008prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network connection controls, access rules by time/location/means) for network services, which constrains remote CLI abuse vectors like telnet/SSH on network devices but leaves direct console access, permission-level gaps, and post-authentication command execution unaddressed.
- T1059.009detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and anomalous-access controls, which surfaces abuse of cloud APIs when performed through monitored network paths or shells; the remainder (direct SDK use from compromised on-prem hosts or non-networked credential abuse) lies outside the clause's network-service scope
- T1059.009prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, VPNs, monitoring, time/location attributes) that can block unauthorized abuse of cloud APIs from disallowed networks, unauthenticated sessions, or out-of-policy access vectors; this stops a meaningful slice of the technique but leaves the dominant authorized-credential path (T1550) and in-tenant abuse untouched.
- T1059.013detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; container CLI/API calls are observable network or API activity when the control's scope includes them, but the clause sets scope by business requirements so coverage is an implementer-chosen slice rather than a bounded remainder.
- T1059.013prevents — A.8.21 requires identifying/implementing network-service security features (authentication, authorization, network connection controls, monitoring, VPN/wireless means, time/location attributes) and rules on allowed networks/services; this can prevent some abuse of exposed container CLIs/APIs (e.g. via network-level auth, monitoring, or connection rules on Docker/K8s APIs) but leaves the bulk of the technique (local CLI use, in-container execution, image pulling, orchestration commands) untouched.
- T1069.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous or unauthorized enumeration attempts (e.g. via LDAP or domain queries) when those controls are in scope; the remainder is local non-networked discovery methods (net group, dscacheutil) outside the clause's network-service boundary.
- T1069.003prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, authorization procedures, network connection controls, monitoring, and access restrictions) that directly constrain the discovery techniques (e.g., blocking unauthenticated or unauthorized enumeration APIs, role/policy queries, and ACL reads), but leaves a bounded remainder for post-authentication discovery by already-compromised accounts that satisfy the rules.
- T1071detects — A.8.21 explicitly requires monitoring of network service use plus consideration of authentication/encryption/connection controls and anomalous access attributes, which surfaces T1071 traffic that deviates from allowed networks, authz rules, or behavioral baselines; partial because the control's scope is limited to organization-approved services and provider attestations rather than universal deep-packet or protocol-anomaly detection across all possible application-layer abuse.
- T1071prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, encryption, VPNs, monitoring, and usage restrictions) that directly constrain which application-layer protocols and connections an adversary can use or abuse for C2, blocking many common instances of T1071 while leaving residual cases (e.g., blending into allowed web/DNS/SMB traffic or internal enclave use of permitted protocols).
- T1071.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection via its monitoring clause, which surfaces web-protocol C2 blending in with legitimate traffic; this is a genuine but minority slice because the control's scope is set by organisational rules rather than mandating comprehensive protocol anomaly or behavioural detection across all web traffic.
- T1071.001prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, rules on allowed networks/services, authorization, monitoring) that can stop unauthorized C2 blending into web traffic when enforced on allowed services and connections, but leaves open abuse of permitted common web protocols/fields by mimicking expected traffic.
- T1071.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, encryption and anomalous usage, which surfaces abuse of common file-transfer protocols when it deviates from allowed rules or patterns, but the clause sets scope by policy rather than mandating universal deep-packet or behavioral detection of embedded C2 inside ostensibly legitimate FTP/SMB/TFTP flows.
- T1071.002prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, allowed services, monitoring) that can block or constrain use/abuse of file transfer protocols like FTP/SMB/TFTP for C2, but leaves open many implementation-dependent gaps (e.g., approved services that are still abused, legacy protocols, incomplete enforcement, or concealment within legitimate traffic).
- T1071.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and anomalous usage rules, which surfaces abuse of common mail protocols (SMTP/POP3/IMAP) when it deviates from expected patterns, but the clause sets scope by organizational requirements rather than mandating universal deep packet or behavioral inspection of every mail flow.
- T1071.003prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, rules on allowed networks/services, authorization, monitoring) for network services including mail protocols; this can block covert C2 abuse of SMTP/POP3/IMAP by enforcing proper usage and detecting anomalies, but does not guarantee prevention of all embedding or blending-in variants.
- T1071.004detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and anomalous usage patterns, which surfaces DNS tunneling/beaconing when it deviates from baseline; it does not mandate the depth or specificity of instrumentation that would catch every stealthy or low-frequency case.
- T1071.004prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, usage rules, monitoring) for allowed network services, which can block or constrain unauthorized/abusive DNS tunneling when the service is governed by those rules; it does not reach all cases (e.g. pre-auth DNS, unmanaged external resolvers, or when the organization must permit the service).
- T1071.005detects — A.8.21 explicitly requires monitoring of network service use plus identification/implementation of security features (authentication, encryption, connection controls) that surface anomalous pub/sub traffic when enforced; this is genuine detection of the technique but only a slice, as the clause sets requirements rather than mandating instrumentation depth or coverage of all broker-mediated blending.
- T1071.005prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, allowed services, monitoring) that can block or constrain abuse of pub/sub protocols such as MQTT/XMPP when they are treated as managed network services; this stops the technique in many enterprise settings but leaves residual cases (e.g. allowed brokers, external CDNs, or unmonitored devices) where the adversary can still blend in.
- T1072detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous or unauthorized access to centralized management suites when they traverse or rely on monitored network services; this is genuine but only a slice because the technique can succeed via local credentials, direct non-network access, or already-compromised admin sessions that never trigger network-service monitoring.
- T1072prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network connection controls, access rules by time/location/means) for network services including management suites; this constrains adversary access to and abuse of deployment tools but leaves residual paths via compromised credentials, direct local access, or unmonitored SaaS/cloud instances.
- T1074detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network connection controls that surface anomalous staging activity (especially exfil-prep movement or new cloud instances), but this is scoped only to network-visible behavior and does not address local file-system staging inside a process or VM.
- T1078detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization rules and anomaly-enabling attributes (time, location, access means), which surfaces abuse of valid accounts on networks, VPNs, remote services and devices; the named remainder is non-network account abuse (local OS, inactive accounts, pure cloud identity without network touch).
- T1078prevents — A.8.21 requires formulating and implementing rules on allowed networks/services, authentication/authorization requirements, network management controls, VPN/wireless means, user attributes, and monitoring — directly constraining how valid (including compromised or inactive) accounts can be abused for access, persistence, or pivoting; however, it is a requirements-setting clause whose coverage depends on the rigor of implementation and does not reach all credential-abuse vectors (e.g., local account overlap or inactive accounts outside monitored services).
- T1078.001prevents — A.8.21 requires identification, implementation, and monitoring of network service security features (authentication, authorization, access rules, VPN/wireless means, time/location attributes, monitoring) plus provider oversight, which directly constrains abuse of preset/default network device or service accounts but leaves non-network defaults (OS built-ins, cloud root, app/service accounts, post-integration vpxuser) and private-key scenarios outside its scope.
- T1078.002detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization controls that surface anomalous domain-account access events when they align with the defined scope and rules, but this is scoped only to network-layer usage rather than credential dumping or reuse that obtains the account itself.
- T1078.002prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, authorization, network connection controls, VPNs, monitoring, time/location attributes) that directly constrain how and when domain accounts can be used for access, blocking many abuse paths even if credentials are obtained.
- T1078.003detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization controls that surface anomalous local-account access or reuse across the network; this detects the technique in flight on monitored paths but leaves local-only abuse, offline credential dumping, and unmonitored systems as a large uncovered slice.
- T1078.003prevents — A.8.21 requires identification, implementation, and monitoring of network service security features including authentication, authorization, access rules, and technological controls that can block unauthorized local-account abuse over allowed networks, but leaves local account creation, credential strength, and on-host abuse vectors (e.g., dumping, password reuse) untouched.
- T1078.004detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's ability to manage services securely (including via audits and attestations), which surfaces anomalous or unauthorized use of cloud accounts that rely on those network services; this is a genuine but minority slice of the technique (e.g., it does not address credential creation, role misconfigurations, or non-network vectors).
- T1078.004prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, VPNs, monitoring, time/location attributes) for network services that directly constrain how cloud accounts can be accessed or abused for initial access/persistence/escalation, but leaves the core account-compromise vectors (phishing, brute force, credential theft, misconfigured roles, managed-identity abuse) untouched as they sit outside network-service usage rules.
- T1080detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous usage, which can surface tainted content or unexpected binary changes on monitored shares, but this is scoped only to allowed/authorized network services and does not broadly instrument file-integrity or content changes across all shared repositories.
- T1080prevents — A.8.21 requires rules, authentication, authorization, network management controls, monitoring, and security features (e.g. encryption, connection controls) for network services including shared storage; this constrains some vectors for tainting shared content (esp. via access rules and monitoring) but leaves many others (e.g. supply-chain compromise of repos, permitted-write access, or non-network vectors) untouched.
- T1087prevents — A.8.21 mandates rules, authentication, authorization, network controls, monitoring and service-provider oversight that can block many discovery vectors (e.g. unauthenticated enumeration APIs, open network access to account-listing interfaces, or misconfigured services that leak accounts), but leaves intact local command-line, file-search and already-authenticated methods on the broad platform set.
- T1087.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization controls that surface anomalous enumeration attempts over LDAP, SMB, or other network channels; this catches the technique when it traverses monitored network services but leaves local non-network execution (e.g. offline registry or cache reads) outside scope.
- T1087.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and anomaly-oriented network connection controls, which surfaces Exchange/Outlook GAL enumeration and similar directory-listing activity when it traverses monitored network paths or violates access rules; this is genuine but only a slice because the technique can be performed entirely in authenticated local sessions or via allowed directory queries that never trigger the network-service monitoring scope.
- T1087.003prevents — A.8.21 mandates rules, authentication, authorization, network controls, monitoring and service-provider measures that can block unauthenticated or unauthorized enumeration of email accounts via network services such as Exchange or Google Workspace directories; this reaches only a slice of the technique because the prose explicitly allows the same action from an already-authenticated session, which the control's requirements do not universally prohibit.
- T1087.004prevents — A.8.21 requires formulating and implementing rules on allowed networks/services, authentication, authorization, monitoring, and network controls that can block unauthenticated or unauthorized enumeration paths, but the technique explicitly runs after authenticated access and many listed commands remain available to permitted users.
- T1090detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, and anomalous usage patterns, which surfaces proxy-based C2 redirection when it occurs inside the monitored scope; it does not guarantee detection of all proxy chaining or CDN routing outside that scope.
- T1090prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, monitoring, and explicit procedures to restrict access to network services) that stop many classes of unauthorized proxy use and CDN routing abuse for C2; it leaves open adversary-controlled proxies on allowed paths, insider misuse of permitted services, and unmonitored edge cases, so the covered slice is genuine but not the bulk with a named remainder.
- T1090.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection, which surfaces internal proxying of C2 traffic when it deviates from allowed services, authentication, or connection rules; partial because the control's scope is set by the organisation's chosen rules and monitoring requirements, leaving unmonitored internal lateral proxy use (e.g. via common p2p protocols on un-instrumented segments) outside its reach.
- T1090.001prevents — A.8.21 requires identifying, implementing, and monitoring network service security features (authentication, authorization, connection controls, monitoring, rules on allowed networks/services) that can block or constrain unauthorized internal proxy setup and C2 redirection on managed networks, but leaves residual coverage for proxies using allowed p2p protocols or on unmanaged/compromised hosts.
- T1090.002detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, and anomalous patterns, which surfaces external-proxy C2 traffic when it traverses monitored paths or violates allowed-network rules; the remainder is traffic that never crosses an observed boundary or uses an allowed/stealthy proxy path that conforms to the organization's own rules.
- T1090.002prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, monitoring) that can block or constrain use of unauthorized external proxies for C2, but leaves open many implementation-dependent gaps such as allowed services, unmonitored paths, or permitted third-party infrastructure.
- T1090.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, encryption and anomalous usage patterns; this surfaces multi-hop proxy traffic (especially when it traverses monitored enterprise networks or uses detectable protocols like Tor/ICMP) but leaves substantial coverage gaps for decentralized P2P/blockchain routing, compromised external ORB/IoT chains, and fully encrypted onion routing that never touches the monitored perimeter.
- T1090.003prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, usage rules, monitoring) and provider oversight, which can block many multi-hop proxy chains (e.g. via VPN enforcement, disallowed services, or boundary rules) but leaves open slices such as P2P/blockchain routing, compromised internal devices, or Tor-like overlays that conform to allowed encrypted tunnels.
- T1090.004detects — A.8.21 explicitly requires monitoring of network service use plus consideration of caching/CDN parameters and connection rules, which can surface anomalous routing or mismatched SNI/Host behavior in CDNs; this is only a slice of the technique because the control is scoped to allowed/authorized services rather than mandating detection of domain-fronting obfuscation itself.
- T1090.004prevents — A.8.21 explicitly requires identifying/implementing network service security features (authentication, encryption, connection controls, technical parameters for secured connections, caching parameters respecting confidentiality, and procedures to restrict access), plus rules on allowed networks/services, authorization, and monitoring; these directly constrain or block the mismatched-SNI/Host routing abuse that domain fronting relies on when enforced at the CDN/provider or client side, but only a slice is covered because the control is a requirement on providers rather than a universal mechanism that stops all CDN configurations or domainless variants.
- T1095detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of technology for network connection controls and authentication/encryption, which surfaces anomalous non-application-layer protocol use (e.g. ICMP, VMCI) when it falls inside the scoped monitoring; this is a genuine but implementation-defined slice rather than the bulk of the technique.
- T1095prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, usage rules, monitoring) for allowed network services and providers; this constrains many non-app-layer protocols (e.g. via auth/encryption rules, monitoring of ICMP/UDP/SOCKS, or restricting disallowed ones) but leaves residual cases (e.g. required protocols like ICMP, VMCI localized traffic invisible to external monitoring, or provider-managed services where rules are incompletely enforced).
- T1098detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization controls that can surface anomalous account activity (e.g. permission changes or iterative password updates) when it traverses or uses those services; this is genuine detection coverage for the technique but only a slice, as most account manipulation (local, offline, or on non-networked assets) falls outside network-service monitoring scope.
- T1098.001detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's ability to manage services securely (including via audits and third-party attestations), which surfaces anomalous credential-addition activity in cloud network/service usage but only for the subset that manifests in monitored network or provider logs rather than all IaaS/identity-provider mechanisms.
- T1098.001prevents — A.8.21 requires identification, implementation, authentication, authorization, network management controls, monitoring, and rules on allowed access and service usage that can block many (but not all) unauthorized credential-addition paths in cloud network services; it does not reach every IaaS/identity-provider mechanism or post-compromise privilege slice.
- T1098.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls, which can surface anomalous role/permission changes in cloud IAM (a network service) but does not mandate detection of the specific API calls or external-account role additions described.
- T1098.003prevents — A.8.21 requires identification, implementation, monitoring and enforcement of network-service rules covering authentication, authorization, allowed services, management controls and monitoring; these constrain the cloud/IAM surface where network-service access is the vector, but the technique can still succeed via direct API abuse on an already-compromised account without touching network services.
- T1098.004detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls; this surfaces anomalous SSH authorized_keys changes or access on covered network services, but the clause's scope is set by the implementer and leaves many local file edits, cloud API calls, and non-networked vectors outside monitored network services.
- T1098.004prevents — A.8.21 requires identifying/implementing network service security features (authentication, authorization, network connection controls, monitoring) and rules on allowed networks/services plus monitoring of their use; this constrains some vectors for adding SSH keys (e.g. via network APIs or unauthorized access) but leaves direct local file edits, config changes, and many platform-specific methods untouched.
- T1098.005detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's secure management of agreed services, which surfaces anomalous device registrations in MFA or device-management systems that handle network authentication and access; this is genuine but only a slice because the clause's scope is limited to network services and provider-level oversight rather than all device-registration events or non-network MFA bypasses.
- T1098.005prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network connection controls, access rules by time/location/attributes, and procedures to restrict network service usage), which directly constrains the enrollment/registration paths adversaries abuse to add rogue devices to MFA or device management systems; this stops the technique in many configurations but leaves a slice (e.g., self-enrollment flows needing only compromised credentials, unmanaged providers, or incomplete attribute enforcement) unreached.
- T1098.006detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's secure management ability and right to audit, which can surface anomalous role/permission additions in container orchestration systems accessed over the network; this is a genuine but minority slice of the technique (only the network-visible subset, not local or non-networked modifications).
- T1098.006prevents — A.8.21 requires formulating/implementing rules on allowed networks/services plus authentication, authorization, network controls, and monitoring of usage; this directly constrains the permission-addition path in container orchestration systems (a form of network service) when those rules and features are enforced on the orchestration plane, but leaves open the remainder where the adversary already holds sufficient initial permissions to create bindings or alter ABAC policies.
- T1098.007prevents — A.8.21 requires formulating and implementing rules plus technical controls (authentication, authorization procedures, network management controls, VPN/wireless means, time/location attributes, monitoring) that can block unauthorized group-addition commands or VPN-group membership on managed networks, but leaves local account/group manipulation (net localgroup, usermod, sudoers) on endpoints entirely unreached.
- T1102detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization rules and connection controls that surface anomalous or unauthorized web-service traffic as part of the allowed-network baseline, but the clause is scoped only to organization-approved services and does not mandate detection of covert C2 inside expected legitimate web-service noise.
- T1102prevents — A.8.21 requires identifying, implementing, and monitoring security measures (authentication, authorization, network controls, monitoring, allowed services) for network services including external ones, which can block unauthorized or anomalous use of web services for C2 but leaves residual paths via permitted popular services that blend with expected traffic.
- T1102.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and anomalous usage patterns, which can surface dead-drop resolver C2 traffic when it deviates from approved services or exhibits encoded redirects, but the control's scope is limited to organization-approved or monitored services and does not guarantee detection of covert use of common legitimate web services that blend with expected noise.
- T1102.001prevents — A.8.21 requires identifying/implementing network service security features (auth, encryption, connection controls), formulating rules on allowed networks/services, authentication/authorization, monitoring, and restricting access where necessary; this can block use of unapproved external web services as dead drop resolvers but leaves residual risk for approved popular services (e.g. Google/Twitter) that adversaries leverage for cover.
- T1102.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and anomalous usage patterns, which surfaces bidirectional Web-service C2 when it deviates from approved services, baselines or expected traffic; it does not guarantee detection of every stealthy implementation that blends with legitimate use of the same popular sites.
- T1102.002prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, allowed services, monitoring) that can block or constrain use of unapproved external web services for C2; this stops the technique on covered services and connections but leaves a large slice (approved popular services, legitimate-looking traffic, and post-compromise abuse of allowed channels) untouched.
- T1102.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and anomalous usage patterns, which surfaces one-way C2 beaconing over common web/social services as anomalous traffic; it does not guarantee detection of every implementation (e.g. fully mimicked legitimate traffic or non-monitored channels), so the coverage is a chosen slice rather than a bounded remainder.
- T1102.003prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, allowed services, monitoring) that can block unauthorized or anomalous use of external web services for one-way C2, but leaves residual coverage for common legitimate services (e.g. Google/Twitter) that are typically allowed and use provider encryption.
- T1104detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication, authorization, and connection controls that surface anomalous or unauthorized multi-stage C2 callbacks and redirects when they traverse monitored networks.
- T1105detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous ingress activity (including tool-bearing transfers over allowed protocols), but the clause's scope is set by the organization's chosen rules and does not mandate instrumentation that would catch every listed vector (e.g. living-off-the-land abuse of native tools, cloud-sync clients, or search-ms).
- T1105prevents — A.8.21 requires rules, authentication, authorization, network connection controls, allowed services, and monitoring that can block many ingress vectors (e.g. restricting protocols, VPN-only access, or unauthorized external transfers), but leaves open vectors that still satisfy the rules such as approved web services, sync clients, or post-authentication abuse of allowed utilities.
- T1110detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization rules and anomaly-enabling features (e.g. location-based access attributes), which surfaces brute-force attempts against network-facing services but does not instrument or guarantee detection of offline hash cracking or non-network vectors.
- T1110prevents — A.8.21 explicitly requires authentication requirements, authorization procedures, network/technological controls (including encryption and connection rules), time/location/user-attribute restrictions, and monitoring — all of which directly stop brute-force guessing from succeeding against network services, with the bounded remainder being offline attacks against already-acquired hashes that the control does not reach.
- T1110.001detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and anomalous access attributes, which surfaces password guessing attempts (especially on the listed management ports and protocols) once they occur; the remainder is non-monitored or out-of-scope services.
- T1110.001prevents — A.8.21 explicitly requires formulating and implementing rules that cover authentication requirements, authorization procedures, network management/technological controls to protect access to services, allowed networks/services, monitoring, and security features such as authentication/encryption/connection controls; this directly stops password guessing against covered network services (the technique's dominant vector) before it succeeds, with the bounded remainder being exempted/legacy identities or unmonitored wireless paths.
- T1110.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization rules and anomalous-access detection via network management controls, which surfaces password-cracking attempts against network services or devices; this is only a slice of the technique (network-facing cracking) rather than the dominant offline, adversary-controlled-system cracking described in the bulk of the T1110.002 prose.
- T1110.002prevents — A.8.21 mandates authentication requirements, authorization procedures, network connection controls, technological protections (including encryption), usage rules, and monitoring for network services; these directly stop most offline cracking from yielding usable network logins (e.g. via strong auth, MFA, or connection rules), with a bounded remainder for non-network or exempted accounts.
- T1110.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, connection controls and anomalous usage patterns, which surfaces many password-spraying attempts against the listed management ports and protocols; it does not mandate detection of every possible vector (e.g., throttled SSO/cloud federated attempts outside monitored network services)
- T1110.003prevents — A.8.21 requires identifying/implementing network-service security features (authentication, connection controls, authorization, monitoring, allowed services, time/location attributes) and enforcing rules that directly stop password spraying against the listed management ports/protocols before successful credential acquisition.
- T1110.004detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, authorization, and anomalous access attributes, which surfaces credential-stuffing attempts against the listed management ports and protocols; it does not mandate detection of the credential-overlap technique itself or of attempts against SSO/federated/cloud login paths outside network-service scope.
- T1110.004prevents — A.8.21 requires identification, implementation, and monitoring of network service security features (authentication, authorization, connection controls, VPN/wireless means, time/location attributes, usage monitoring) that can stop credential stuffing on covered services, but leaves open-ended the specific strength of those features (e.g., MFA, rate limiting) and does not reach all listed platforms or non-network vectors such as SSO/federated apps.
- T1111detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization procedures and network connection controls, which can surface anomalous MFA-interception artifacts (e.g., unexpected token replay, anomalous proxy use of hardware tokens, or suspicious out-of-band code access) when they touch monitored networks; this is only a slice of the technique's surface because the control is scoped to network services and does not address endpoint keyloggers, local smart-card proxying, or non-network MFA vectors.
- T1111prevents — A.8.21 mandates authentication requirements, authorization procedures, network connection controls, technological protections (including encryption), and monitoring for network services, which directly blocks many interception vectors (e.g. weak MFA over unsecured channels, provider compromise of SMS, improper proxying to network resources); it does not address endpoint keyloggers, hardware token capture on the client, or out-of-band device compromise that precedes network use.
- T1114.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization controls that surface anomalous credentialed access to remote email services such as Exchange or Office 365; this detects the technique in a meaningful slice (especially internal or monitored external connections) but leaves gaps for stealthy token-based or external-only use outside the monitored scope.
- T1114.002prevents — A.8.21 mandates identifying/implementing network-service security features (auth, encryption, connection controls, access rules, monitoring) and provider oversight; this constrains credentialed remote access to Exchange/Office 365 services for many configurations but leaves slices such as already-compromised legitimate credentials, insider use, or exempted legacy access paths.
- T1114.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and audit rights, which can surface anomalous forwarding-rule creation or hidden MAPI changes when those actions traverse monitored network services or produce observable logs; this is a genuine but minority slice of the technique (most rule creation is local client-side or admin console with no network-service footprint).
- T1114.003prevents — A.8.21 requires rules on allowed networks/services, authentication, authorization, monitoring, and network-level controls (VPNs, connection rules, etc.) that can block creation or use of forwarding rules over external/unapproved channels or via unmonitored access, but leaves internal authenticated abuse (e.g. by any user/admin with valid creds via MAPI, local clients, or org-wide transport rules) untouched.
- T1119detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and connection controls that surface anomalous or unauthorized automated collection activity over the network; this catches a slice (network-borne automated exfiltration or discovery) but leaves local non-network collection, in-memory tools, and cloud API usage inside the boundary unaddressed.
- T1123detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous access or usage; this can detect audio-capture malware that phones home, uses C2, or traverses the network, but the core local API call to a microphone leaves no network footprint and is therefore unseen.
- T1127detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous or unauthorized execution through developer utilities when they involve network activity, but the technique is not inherently network-bound and can run locally without triggering those monitors.
- T1127.001detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous use; this can detect MSBuild abuse when it occurs over or reaches a monitored network service, but the technique itself is local process execution on Windows with no inherent network component, leaving most instances outside the clause's scope.
- T1127.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that can surface anomalous or unauthorized ClickOnce delivery over the network (e.g. from web shares or malicious sites), but the technique itself is local proxy execution that can also occur without network involvement (startup folder, rundll32) and without touching monitored network services.
- T1127.002prevents — A.8.21 requires rules, authentication, authorization, network connection controls, monitoring, and security features (e.g. authentication/encryption) for allowed network services; this can block some abuse vectors that rely on untrusted web/file-share delivery or unauthorized network access to ClickOnce content, but leaves the majority of the technique (local proxy execution, Rundll32 abuse, startup folder persistence, and user execution of already-present .appref-ms files) untouched.
- T1127.003detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous or unauthorized use, which would detect JamPlus abuse when it involves network activity or monitored build-tool execution; this is only a slice of the technique (most instances are local process execution with no network component).
- T1132detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, encryption and anomalous-behaviour monitoring, which surfaces encoded C2 traffic as an observable anomaly on monitored networks; this is a genuine but minority slice because the clause sets scope by business requirements rather than mandating universal deep-packet or behavioural analysis that would catch every encoding variant.
- T1132.001detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, encryption and anomalous-behaviour monitoring, which surfaces encoded C2 traffic as an observable anomaly on monitored networks; it does not guarantee detection of every encoding variant or every platform.
- T1132.002detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, encryption and anomalous-behaviour monitoring, which surfaces non-standard encoding in C2 traffic that deviates from protocol norms; the remainder is traffic that stays inside allowed services, uses permitted means (e.g. VPN), and evades the chosen monitoring scope.
- T1133prevents — Defining allowed networks, authentication rules, and monitoring for external network services restricts adversaries from establishing persistent external remote access.
- T1133detects — A.8.21 explicitly requires monitoring of the use of network services plus determining/regularly monitoring the provider's ability to manage them securely, which surfaces anomalous or unauthorized use of external remote services (including exposed unauthenticated ones), but this is scoped only to allowed/monitored services and does not broadly instrument all adversary behaviors such as Tor hidden services or post-compromise persistence mechanics.
- T1134.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization rules and network connection controls, which can surface anomalous token creation or impersonation attempts when they traverse or abuse monitored network services or access paths; this is a genuine but minority slice of the Windows-local technique (most instances occur without network involvement).
- T1134.003prevents — A.8.21 mandates authentication, authorization, network connection controls, monitoring, and rules on allowed access methods (including VPNs), which directly constrain the credential-based creation of new tokens via LogonUser on Windows; however, the control is scoped to network services and does not address local process/thread token creation or all non-network privilege-escalation paths.
- T1135detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous or unauthorized share enumeration over SMB and similar protocols; this is genuine detection coverage for the technique but only a slice, as the clause leaves scope, depth, and alert thresholds to the implementer rather than mandating universal instrumentation of all discovery commands or endpoints.
- T1135prevents — A.8.21 requires rules, authentication, authorization, network management controls, and monitoring that directly constrain which network services (including SMB shares) can be accessed or enumerated, preventing the discovery technique on covered services and paths; partial because the control sets requirements rather than mandating universal mechanisms, leaving slices such as exempted services, local shares, or implementations that do not fully restrict enumeration.
- T1137.001prevents — A.8.21 requires rules, authentication, authorization, network management controls, monitoring, and security features (e.g. encryption, connection controls) for allowed network services; this constrains remote/shared template loading (one documented vector for T1137.001) but leaves local template modification, registry hijacking, search-order abuse, and macro policy entirely untouched.
- T1137.003detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which can surface the suspicious crafted emails and form-loading behaviour that realise T1137.003; it does not guarantee detection of the initial form-installation step itself.
- T1137.004detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and connection controls that surface anomalous access or loading of external URLs in Outlook, but this is scoped only to network-layer activity and does not broadly instrument the client-side persistence or HTML execution itself.
- T1137.005detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces the anomalous mail flow, rule creation events or triggered code execution that realise T1137.005; the remainder is the slice of rule abuse that never touches monitored network services or produces observable anomalies.
- T1176.001detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this surfaces some post-install behaviours of malicious browser extensions (C2, background web requests, data exfiltration) but does not address silent file-based installation or pre-execution detection, leaving a large slice of the technique unreached.
- T1176.001prevents — A.8.21 requires formulating/implementing rules on allowed networks/services, authentication, authorization, technological controls (including authentication/encryption), and monitoring of network service use; this constrains some installation vectors (e.g. app-store downloads over networks, unauthorized extension update channels) and post-install C2/stealth use but leaves local file/silent file-modification/social-engineering vectors and many browser-internal behaviors untouched.
- T1185detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, and anomalous access attributes (time/location), which can surface browser pivoting or anomalous intranet sessions once they generate observable network traffic; it does not instrument the browser process injection or session-hijacking techniques themselves.
- T1185prevents — A.8.21 requires identifying, implementing, and monitoring network service security features (authentication, encryption, connection controls, access rules, monitoring) plus provider oversight; this constrains several T1185 vectors (e.g. unauthorized intranet pivoting, weak SSL cert inheritance, network-level proxying) but leaves residual browser-process injection, local SeDebugPrivilege abuse, and same-origin session hijacking untouched.
- T1187detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption and network connection controls; this surfaces anomalous forced-authentication SMB/WebDAV/EFSRPC traffic when it falls inside the chosen monitoring scope, but the clause sets that scope by policy rather than mandating universal coverage of every possible trigger vector.
- T1187prevents — A.8.21 requires identification, implementation, and monitoring of network service security features (authentication, connection controls, rules on allowed networks/services, VPN/wireless means, and monitoring), which can stop forced outbound SMB/WebDAV/EFSRPC authentication to adversary-controlled external resources in many enterprise configurations, but leaves residual cases such as internal-network relay attacks, legacy protocols, or unmonitored caching/connection paths.
- T1189detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous-behaviour monitoring, which can surface drive-by compromise activity (e.g. unexpected script execution or outbound connections from a visited site) when it traverses monitored network paths, but the clause's scope is limited to network-layer visibility and does not guarantee detection of the client-side browser exploit itself.
- T1189prevents — A.8.21 mandates rules, authentication, authorization, network connection controls, VPN/wireless means, time/location attributes, and monitoring that can block many watering-hole vectors (e.g. restricting allowed sites, enforcing MFA/VPN, blocking unauthorized connections), but leaves open client-side browser/plugin exploits on permitted legitimate sites that match the rules.
- T1190prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which stops many classes of public-facing exploit (e.g. weak auth, exposed management ports, unencrypted channels) but leaves residual paths such as application-layer bugs, zero-days, or misconfigurations inside allowed services.
- T1197detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous usage rules, which can surface BITS job abuse when it traverses monitored networks or violates allowed service parameters, but leaves substantial residue for purely local COM/PowerShell BITS activity that never touches the network.
- T1199detects — A.8.21 explicitly requires monitoring the provider's ability to manage services securely plus monitoring of network service use, which surfaces anomalous or unauthorized activity stemming from a trusted third-party relationship (the core of T1199); this is genuine detection but only a slice, as the control does not mandate detection of the initial breach of the provider, the compromise of their account, or the abuse itself before it reaches the monitored network/services.
- T1199prevents — A.8.21 requires identifying, implementing, and monitoring security measures (including authentication, authorization, network controls, and provider auditing) for network services and third-party providers, which constrains the abuse of trusted relationships by limiting access scope and scrutiny gaps, but does not stop all such breaches (e.g., via compromised valid accounts or unmonitored delegated admin offers).
- T1204.001prevents — A.8.21 mandates rules, authentication, authorization, monitoring, and technical controls (VPNs, connection restrictions, time/location attributes) that can block access to malicious network destinations or services, preventing the link from successfully delivering execution in covered cases, but leaves social engineering, user clicking, local exploitation, and unmonitored paths untouched.
- T1205detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of technology such as network connection controls and authentication, which can surface anomalous signaling packets or sequences on allowed networks; this is a genuine but minority slice because the control's scope is set by the organization's chosen rules and allowed services, leaving most custom or embedded-device signaling (e.g. raw sockets, Wake-on-LAN, Synful Knock on unmonitored ports) outside its view per the event-lane anchors for A.8.16 and SI-4.
- T1205prevents — A.8.21 requires identifying, implementing, and enforcing network service security features (authentication, encryption, connection controls, access rules, monitoring, and usage restrictions) that directly block many forms of traffic signaling by rejecting non-compliant packets, sequences, or magic values before they trigger responses.
- T1205.001detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls and anomalous access patterns, which can surface port-knocking signal sequences; it stops short of mandating the specific packet-level instrumentation (libpcap/raw sockets) needed to reliably catch every implementation, leaving a genuine slice uncovered.
- T1205.001prevents — A.8.21 requires rules, authentication, authorization, network connection controls, monitoring, and security features (e.g. network connection controls) that can block unauthorized port-opening sequences or the resulting listening ports on allowed services; this stops the technique in many implementations but leaves a bounded remainder (custom software triggers, already-open ports via raw sockets, or unmonitored internal sequences).
- T1205.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous traffic patterns, which can surface socket-filter installation or triggered activation on monitored interfaces; it stops short of mandating the raw-socket or libpcap visibility needed to catch all stealthy cases described in the technique.
- T1205.002prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, monitoring, usage rules) and provider oversight, which can block unauthorized socket filter installation/activation on managed networks but leaves gaps for local elevated-privilege raw socket use, libpcap/setsockopt on endpoints, and unmonitored interfaces.
- T1210detects — A.8.21 explicitly requires monitoring of network service use plus consideration of security features that can surface anomalous access or exploitation attempts, but this is scoped only to allowed/authorized services and does not broadly instrument for remote service exploitation post-compromise.
- T1210prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can block many exploitation paths for remote services but leaves residual unpatched vulnerabilities, misconfigurations, and zero-days that the clause does not itself close.
- T1212prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, usage rules, monitoring) for network services, which can prevent some exploitation vectors like replay attacks or weak credential mechanisms when properly enforced, but does not address arbitrary software vulnerabilities in credentialing code or services.
- T1213prevents — A.8.21 mandates identifying/implementing network-service security features (authentication, authorization, access rules, monitoring, encryption, connection controls) and provider oversight, which directly blocks the overly-broad or unauthenticated repository access that the technique exploits on network-hosted stores; it leaves a remainder for non-network repositories, misconfigurations inside allowed services, and external-sharing abuse after legitimate access.
- T1213.001prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, VPNs, monitoring, etc.) for network services; this constrains adversary access to a Confluence SaaS repository in many realistic configurations, but leaves open slices such as legitimate-user credential abuse, misconfigured public permissions, or insider access that the control does not itself block.
- T1213.002detects — A.8.21 explicitly requires monitoring of the use of network services (and related authentication/authorization controls that surface anomalous access), which can detect SharePoint mining when it occurs over monitored network paths; this is only a slice of the technique because local Office-client access, non-network vectors, or unmonitored services fall outside its scope.
- T1213.002prevents — A.8.21 requires rules, authentication, authorization, network controls, monitoring and service-provider oversight that can block unauthorized access to the SharePoint service itself, thereby stopping the mining technique from running; it does not reach the separate data-classification or least-privilege decisions that determine whether the mined content (diagrams, credentials, source snippets) is present and readable once access is obtained.
- T1213.003detects — A.8.21 explicitly requires monitoring of the use of network services (and related authentication/authorization controls), which can surface adversary access to or exfiltration from a SaaS code repository once inside the victim network, but does not address the distinct post-access collection step itself or non-network indicators.
- T1213.003prevents — A.8.21 mandates rules, authentication, authorization, network controls, monitoring and service-provider oversight that can block unauthorized access to (especially internal/private) code repositories, but leaves the post-authentication collection step and public-repository cases untouched.
- T1213.005detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this surfaces adversary activity inside enterprise messaging platforms (a network service) but does not guarantee coverage of all SaaS/Office-Suite vectors or post-exfiltration use of the mined data.
- T1213.006detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous or unauthorized database access attempts over the network; this detects a slice of T1213.006 (network-borne mining) but leaves local, already-authenticated, or non-network vectors (e.g. compromised app inside perimeter, direct cloud console) untouched.
- T1213.006prevents — A.8.21 requires identifying/implementing network-service security features (authentication, authorization, access rules, monitoring, VPNs, etc.) and provider oversight, which can block many unauthorized database access paths but leaves residual vectors such as already-authenticated sessions, insider abuse, application-level flaws, or misconfigured cloud IAM that the control does not itself close.
- T1216detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network connection controls that can surface anomalous proxy script execution when it traverses or uses those services, but this is scoped only to network activity and does not address the local process/script-proxy technique itself.
- T1216.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous or unauthorized use of allowed services; this can detect the technique when it traverses or abuses a network service (e.g. via VPN, remote App-V publishing, or wscript.exe over the network), but the core local LOLBin abuse of SyncAppvPublishingServer.vbs to proxy PowerShell does not require or involve network services and therefore sits outside the clause's scope.
- T1218detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous or unauthorized proxy execution of binaries over allowed networks.
- T1218.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication, authorization, and network connection controls that surface anomalous or unauthorized remote-access profile activity, but the technique is a local process abuse of a signed binary that does not require network services and can be confined to non-network vectors.
- T1218.004detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous or unauthorized proxy execution; this catches the technique when it traverses or is observed on allowed network paths, but the control is silent on host-process execution of a signed binary that never touches the network, leaving most of the class (local LOLBIN abuse) unreached.
- T1218.005detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; the technique's dominant in-the-wild executions fetch remote .hta/.sct payloads over HTTP/HTTPS, which is observable as anomalous network service use, but local-only or non-network mshta abuse (and monitoring scope set by the implementer) leaves a large remainder
- T1218.005prevents — A.8.21 requires rules, authentication, authorization, network connection controls, allowed networks/services, and monitoring that can block many network-based mshta.exe executions (e.g. from unapproved URLs or without proper auth), but leaves local/script-based abuse and unmonitored internal use untouched
- T1218.008detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous or unauthorized execution of signed binaries such as odbcconf.exe when used to proxy DLLs
- T1218.008prevents — A.8.21 mandates rules, authentication, authorization, network management controls, and monitoring that can block unauthorized use of signed binaries like odbcconf.exe for DLL proxying when the technique traverses or depends on network services, but most instances of local abuse of this living-off-the-land binary do not involve network services at all.
- T1218.009detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous or unauthorized execution; this catches the technique when it traverses or is observed over monitored networks but does not address purely local Regsvcs/Regasm abuse on an endpoint.
- T1218.012detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; verclsid.exe abuse that reaches remote SCT payloads over the network is observable inside that scope, but purely local COM abuse (no network) sits outside the clause's named focus.
- T1218.012prevents — A.8.21 mandates network-service rules, authentication/authorization, technological controls, and monitoring that can block unauthorized proxy execution via verclsid.exe when it traverses the network (e.g. remote SCT loads), but the technique is a local signed-binary abuse that does not require network services and is therefore only a minority slice of the class.
- T1218.013detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous access and usage, which can detect mavinject.exe proxying when it traverses or is observed on allowed/monitored networks; this is a genuine but minority slice of the technique (most abuse is local process injection without network involvement).
- T1218.014detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous access or usage; this can detect the network-borne or remote-management aspects of MMC abuse (e.g. remote snap-in execution), but the core local .msc/CLSID abuse is outside the network-service scope so only a minority slice is covered.
- T1218.014prevents — A.8.21 requires rules, authentication, authorization, network management controls, and monitoring for network services; this can block some remote or network-borne MMC abuse vectors (e.g. via allowed networks, auth requirements, or monitoring), but the core technique is local Windows binary abuse of .msc/CLSID execution with no network component required.
- T1219detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous usage rules, which surfaces post-compromise RAT sessions that match those observables; it does not instrument or guarantee detection of every installation vector, protocol tunnel, or EDR-abuse case on all platforms.
- T1219prevents — A.8.21 requires rules, authentication, authorization, network controls, monitoring, and security features (e.g. VPN, encryption, connection restrictions) that can stop many legitimate remote access tools from being installed/used as C2, but leaves open slices such as approved management tools, post-compromise abuse of built-in features, or EDR response channels that conform to the rules.
- T1219.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous usage patterns, which surfaces IDE tunneling when it produces observable network activity; this is limited to a slice because the control is scoped to allowed/authorized services and does not mandate deep inspection of proprietary IDE protocols or extension-based tunneling that blends with developer workflows.
- T1219.001prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, monitoring, and usage restrictions) that can block unauthorized IDE tunneling sessions and their C2/persistence use; however, it is a governance-and-requirements clause whose effect depends on what the organization actually chooses to allow for developer workflows, leaving a large slice of legitimate IDE tunneling unaddressed.
- T1219.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and access attributes, which surfaces anomalous or unauthorized use of remote desktop tools when they operate over monitored networks; this is only a slice because the control is scoped to network-service rules and does not mandate host-level behavioral detection of the legitimate desktop-support binaries themselves.
- T1219.002prevents — A.8.21 requires formulating and implementing rules on allowed networks/services, authentication, authorization, technological controls (including VPNs), time/location attributes, and monitoring; this constrains many legitimate desktop support/RMM tools used in T1219.002 but leaves a bounded remainder (e.g., tools already approved for support, built-in modules like Chrome Remote Desktop, or cases where rules are satisfied yet the technique still runs).
- T1219.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous usage, which surfaces hardware-based remote access channels when they traverse monitored networks; it does not guarantee detection of purely physical/local KVM installation or out-of-band use.
- T1219.003prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network connection controls, allowed services, monitoring) for network services, which can block unauthorized use of remote access hardware like KVM as an alternate C2 channel when treated as a network service; however, the control is scoped to network services and does not address physical installation or peripheral policies that allow such hardware.
- T1484detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's ability to manage services securely (including via audits and third-party attestations), which can surface anomalous policy modifications over identity-management network services; this is a genuine but minority slice of the technique's surface (GPO edits, trust changes, rogue DC, or federated IdP additions can occur without touching monitored network services or provider-level indicators).
- T1484prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network connection controls, rules on allowed services) for network services including identity tenants; this constrains many abuse vectors (e.g. unauthorized trust/federation changes or GPO mods) but leaves a slice reachable via sufficient permissions or insider/provider actions.
- T1484.001prevents — A.8.21 requires formulating and implementing rules plus technological controls (authentication, authorization, network connection controls, monitoring) that can block unauthorized modification of SYSVOL-hosted GPOs when performed over the network; this stops a meaningful slice of the technique but leaves local/admin-privileged or delegated-write paths untouched.
- T1484.002detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's ability to manage services securely (including via audits and third-party attestations); this surfaces anomalous trust modifications that affect network/service authentication/authorization properties, but only for the network-service slice of the technique (not all AD/IdP trust changes or offline config edits).
- T1484.002prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network connection controls, rules on allowed services and access attributes) for network services including those involving federation and identity providers; this constrains many trust-modification vectors (e.g., unauthorized addition of IdPs or certs) but leaves residual paths via privileged insiders or misconfigured providers.
- T1486recovers — A.8.21 requires monitoring of network service use, formulation of rules covering allowed networks/services, authentication/authorization, and technological controls (including encryption and connection protections), plus regular provider audits; these enable detection of anomalous encryption activity and support post-impact recovery of availability via controlled, monitored network-based backups or restored services, though not all T1486 impacts (e.g., local offline encryption or destroyed recovery points) are addressed.
- T1489detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces service-stop activity when it affects monitored network services or produces detectable anomalies, but the clause's scope is limited to network services and does not broadly instrument local process/service control on endpoints or cloud management-plane actions.
- T1490recovers — A.8.21 requires formulating/implementing rules on network use plus monitoring of network services, and explicitly calls out considering caching parameters for availability requirements; this directly supports recovery of backups and recovery options stored or accessed via network services (online/cloud/network storage, snapshots, versioning), though it does not itself restore the deleted state and leaves local/non-network recovery features untouched.
- T1491.001detects — A.8.21 explicitly requires monitoring of network service use plus anomalous behaviour detection via its security features and rules, which surfaces internal defacement once it touches monitored networks, websites or login services; this is only a slice of the technique (e.g. desktop wallpaper changes on endpoints are outside its network-service scope).
- T1491.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection, which surfaces external defacement of web properties when it traverses or alters monitored network paths, but leaves the bulk of the technique (direct CMS/admin interface or supply-chain compromise of the external site itself) outside its network-service scope.
- T1496detects — A.8.21 explicitly requires monitoring of the use of network services plus determining/regularly monitoring the provider's ability to manage services securely, which surfaces anomalous resource consumption patterns (e.g. cryptomining, proxying, or spam traffic) on IaaS/SaaS/cloud-hosted networks; this is a genuine but minority slice of the technique's surface (compute, SMS, containers, non-networked Windows/Linux/macOS endpoints remain outside its named scope).
- T1496prevents — A.8.21 requires identifying, implementing, enforcing and monitoring network/service rules plus features (authentication, authorization, access controls, monitoring of usage) that can block unauthorized co-opting of bandwidth, compute or messaging services on allowed networks; this stops many hijacking forms but leaves residual vectors such as already-authenticated insiders, misconfigured allowed services, or non-network resource abuse.
- T1496.001detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces compute-hijacking (especially in IaaS/containers via exposed APIs or anomalous resource use), but the clause's scope is set by organisational requirements rather than mandating universal coverage of all hijacking vectors (e.g. stealthy endpoint mining without network indicators).
- T1496.001prevents — A.8.21 requires rules, authentication, authorization, network management controls, monitoring, and service-provider oversight that can block unauthorized compute-intensive workloads (especially in IaaS/containers via exposed APIs or unmanaged services), but leaves open vectors such as post-authentication abuse, endpoint compromise, or insider misuse of allowed resources.
- T1496.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous usage, which surfaces bandwidth hijacking when it occurs inside the monitored scope, but the clause sets scope by business requirements rather than mandating universal bandwidth or outbound-traffic instrumentation, leaving a large slice of implementations that would miss it (e.g. only authenticating allowed services without usage anomaly detection).
- T1496.002prevents — A.8.21 requires rules, authentication, authorization, network management controls, monitoring, and security features (e.g. connection controls, encryption) that can block unauthorized bandwidth-consuming outbound activity such as botnet participation, proxyjacking, or scanning; this stops many but not all instances (e.g. authorized services, insider abuse, or post-compromise use of allowed channels).
- T1496.003detects — A.8.21 explicitly requires monitoring of the use of network services plus identification and regular monitoring of the provider's ability to manage services securely, which surfaces anomalous SMS-pumping traffic that overwhelms channels or inflates costs, but only for the slice of network/provider-level usage that falls inside the chosen monitoring scope rather than the full technique.
- T1496.003prevents — A.8.21 requires rules, authentication, authorization, monitoring, and network/service security features that can block or rate-limit abusive SMS-pumping traffic at the application and network layers, but leaves open the common case of public unauthenticated web forms (OTP/verification fields) that the technique explicitly relies on.
- T1496.004detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's ability to manage services securely (including via audits and third-party attestations), which surfaces anomalous resource consumption or hijacking in SaaS/networked services; this is a genuine but minority slice because the control is scoped to network-service governance and monitoring rather than comprehensive runtime detection of all SaaS abuse vectors such as LLMjacking or quota exhaustion inside already-authenticated sessions.
- T1496.004prevents — A.8.21 requires identifying, implementing, enforcing and monitoring security features (authentication, authorization, network controls, usage rules, monitoring) for network/SaaS services, which directly constrains the initial compromise or unauthorized enablement step needed for hijacking in many cases, but leaves open post-compromise abuse of already-authorized SaaS quotas and does not reach every vector (e.g. supply-chain compromise of the provider itself).
- T1498detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous traffic indicators, which surfaces many (but not all) Network DoS patterns such as bandwidth exhaustion or reflection attacks; the remainder is volumetric floods that saturate links before monitoring can act or attacks outside the scoped services.
- T1498prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can prevent some volumetric or spoofing-based Network DoS vectors via filtering and rate controls, but leaves the bulk of bandwidth-exhaustion DDoS (e.g. massive botnets) unaddressed as the control is not a dedicated anti-DoS mechanism.
- T1498recovers — A.8.21 requires monitoring of network service use plus identification and implementation of security features (including network connection controls and parameters for secured connections), which can enable detection and subsequent recovery actions for availability-impacting DoS events, but the control focuses primarily on preventive service agreements, rules, and features rather than explicit post-event state restoration.
- T1498.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection, which surfaces high-volume flooding traffic in scoped environments, but the clause sets scope by business requirements rather than mandating universal instrumentation depth so only a chosen slice is covered
- T1498.001prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can block many direct flood vectors (e.g. via auth, rate limits, or filtering) but leaves residual exposure to high-volume stateless floods (UDP/ICMP) or massive botnets that saturate bandwidth before controls engage.
- T1498.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous traffic patterns that would surface reflection/amplification floods, but the clause's scope is set by organizational requirements rather than mandating universal coverage of all reflector protocols or all amplification vectors.
- T1498.002prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, usage rules, monitoring) and provider oversight, which can block spoofed-source reflection/amplification at allowed services or entry points but leaves residual exposure for unaddressed protocols, unmanaged reflectors, or external amplification vectors outside the organization's network rules.
- T1499detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour indicators, which surfaces some endpoint DoS activity (especially resource-exhaustion patterns visible at the network/service layer) but leaves the majority of host-layer or application-specific DoS techniques (OS crashes, in-process exhaustion, non-network botnet effects) outside its defined scope.
- T1499prevents — A.8.21 requires identification, implementation, and monitoring of network service security features (authentication, authorization, connection controls, monitoring, usage rules) that can block many endpoint DoS vectors at the network/service boundary, but leaves application-layer resource exhaustion, local crashes, and non-network vectors untouched.
- T1499.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection at the network layer, which surfaces many TCP state-exhaustion floods (SYN/ACK floods are observable at the boundary); it does not guarantee detection of every local OS-level exhaustion vector or non-network resource limits, leaving a genuine slice uncovered.
- T1499.001prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can prevent some TCP state-exhaustion vectors at the network boundary but leaves residual exposure on the endpoint OS itself (e.g., local SYN/ACK handling limits, unmonitored internal services).
- T1499.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous usage patterns, which surfaces many volumetric floods and renegotiation spikes once underway, but does not guarantee detection of every protocol-specific or low-and-slow exhaustion variant outside the chosen monitoring scope.
- T1499.002prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, usage rules, monitoring) and provider oversight, which can stop some exhaustion vectors (e.g. renegotiation via protocol controls or rate-limiting rules) but leaves the bulk of volumetric HTTP floods and resource-exhaustion variants untouched.
- T1499.003detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces resource-exhaustion patterns from repeated requests to intensive application features, but only where those patterns cross the monitored network or application boundary rather than purely in-process or unmonitored resource consumption.
- T1499.003prevents — A.8.21 requires identifying/implementing network-service security features (authentication, connection controls, usage rules, monitoring) and provider oversight that can block many flood vectors at the network boundary or via rate/authz limits, but leaves application-layer resource-exhaustion features inside allowed services untouched.
- T1505.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication/authorization/network connection controls that surface anomalous or unauthorized web-server activity, which can detect web shell deployment or use on openly accessible servers; this is only a slice because the clause is scoped to allowed/authorized network services rather than exhaustive host-level or code-level detection of backdoors.
- T1505.003prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network connection controls, access rules, monitoring) for network services including web servers, which directly constrains the open placement and unauthenticated use of a web shell as a persistent gateway.
- T1526prevents — A.8.21 requires rules, authentication, authorization, network controls, monitoring and service-provider oversight that can block many discovery vectors (especially unauthenticated or external enumeration of cloud services), but leaves an open remainder once initial access is already achieved and the adversary is operating with a valid identity inside the environment.
- T1528detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls, which can surface anomalous token use or OAuth flows over monitored networks, but the technique's dominant vectors (container compromise, IMDS requests, local CI/CD theft, social-engineering OAuth consent) sit outside network-service monitoring and are not required to be instrumented by the clause.
- T1528prevents — A.8.21 requires identifying/implementing network-service security features (authentication, authorization, encryption, connection controls, monitoring, usage rules) and provider oversight; this constrains several T1528 vectors (e.g. stolen Kubernetes/service-account tokens, IMDS token requests, weak OAuth flows over networks) but leaves social-engineering OAuth phishing, CI/CD pipeline compromise, and refresh-token theft largely untouched.
- T1529detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous or unauthorized access attempts, which would detect many network-based or remote shutdown/reboot commands (e.g. via CLI or hypervisor consoles) but leaves local API-based or privilege-escalated methods on endpoints largely unreached.
- T1530detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls, which can surface anomalous or unauthorized access to cloud storage APIs/objects over those networks, but does not mandate detection of the data-access technique itself or of misconfigurations that enable it.
- T1530prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, VPNs, monitoring) for network services that directly constrain unauthenticated/public or overly-broad access to cloud storage APIs and objects, but leaves residual paths via leaked credentials, misconfigurations outside the provider contract, and non-network vectors.
- T1534detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces internal spearphishing when it traverses monitored network paths, chat apps, or anomalous internal mail flows; this is only a slice because the technique can also succeed via direct device compromise, local credential theft, or unmonitored internal channels that fall outside the clause's scoped requirements.
- T1534prevents — A.8.21 mandates rules, authentication, authorization, monitoring, and network-level controls (VPNs, connection restrictions, time/location attributes) that can block many internal spearphishing delivery vectors such as unauthorized chat-app abuse or untrusted internal links/attachments; it leaves the initial account compromise stage and social-engineering success rate untouched.
- T1535detects — A.8.21 explicitly requires monitoring the use of network services plus determining/regularly monitoring the provider's ability to manage services securely (including via audits or attestations), which surfaces anomalous creation of instances in unused regions as part of that oversight; however, it is scoped only to network services and provider management rather than broadly to all cloud resource provisioning or region-specific detection gaps.
- T1535prevents — A.8.21 requires formulating and implementing rules on allowed networks/services plus authentication, authorization, monitoring, and technological controls that can explicitly restrict creation and use of cloud instances to approved regions, thereby stopping the technique from running in the disallowed remainder.
- T1537detects — A.8.21 explicitly requires monitoring the use of network services plus authentication, authorization, and network connection controls that surface anomalous internal transfers or unauthorized sharing to another cloud account; this catches a slice of T1537 (especially API-driven or backup transfers that cross account boundaries) but leaves the bulk of cloud-native mechanisms (anonymous links, SAS URIs, or same-provider internal traffic that blends in) outside the clause's network-service focus.
- T1537prevents — A.8.21 requires identifying/implementing network service security features (auth, encryption, connection controls, access rules, monitoring) and provider oversight, which can block unauthorized intra-cloud transfers via enforced authz, VPN/encrypted channels, and usage rules; however, it is scoped only to network services and leaves many cloud-native sharing/backups (e.g. SAS URIs, anonymous links, API-driven account transfers) untouched as they are not network-service mechanisms.
- T1538detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication, authorization, and anomalous-access procedures, which surfaces credentialed dashboard access in IaaS/SaaS environments; it does not guarantee detection of every GUI-based enumeration path or non-network vectors.
- T1538prevents — A.8.21 requires formulating/implementing rules on allowed networks/services plus authentication, authorization, monitoring, and technological controls (e.g. VPN, connection rules) that can block stolen-credential dashboard access when those rules are enforced at the network or auth layer; this reaches only a minority slice of T1538 because the technique's dominant vector is post-auth GUI use of already-valid credentials inside the cloud tenant, which the control's network-service focus does not address.
- T1539detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication features and anomalous access attributes (time/location), which can surface cookie-theft indicators in network traffic or service misuse but does not address local malware extraction, in-memory theft or malicious JS injection vectors.
- T1539prevents — A.8.21 mandates network rules, authentication/authorization requirements, monitoring, encryption, and connection controls that can stop session-cookie theft vectors over the network (e.g. MitM proxies, unencrypted traffic, unauthorized access), but leaves local theft (malware, JS injection, browser memory) untouched.
- T1542.005detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization and connection controls that surface anomalous TFTP boot activity or unauthorized server use; this is genuine detection but only a slice (network-layer visibility of boot traffic), not the dominant boot-sequence or device-configuration manipulation slice of the technique.
- T1542.005prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, usage rules, monitoring) and provider oversight, which can block unauthorized TFTP servers or malformed netboot configs on covered services, but leaves residual paths on unmanaged devices, unmonitored boot sequences, and legacy network hardware where the control's scoping and rigour are implementation-dependent.
- T1543.002detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this surfaces some systemd-service anomalies (e.g. unexpected network-facing daemons or connection patterns) but does not address file creation, generator execution, or non-network persistence artifacts, leaving a large slice of the technique undetected.
- T1543.002prevents — A.8.21 requires formulating and implementing rules on allowed networks/services, authentication, authorization, network management controls, access means (e.g. VPN), user attributes, and monitoring, plus considering technology like authentication/encryption and procedures to restrict access; this constrains some vectors for creating/modifying systemd services (especially those involving network-exposed or unauthorized access paths) but leaves the bulk of local privilege-escalation and generator-based persistence on Linux untouched.
- T1543.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous service-related activity on the network; this detects some Windows service abuse (especially driver loading or network-visible persistence) but misses purely local Registry/API modifications, hidden services, and non-networked execution.
- T1546detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces many but not all T1546 triggers (e.g. local logon, WMI, or cloud function events outside network telemetry).
- T1546.002detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which can surface registry changes or anomalous .scr execution on a monitored endpoint as part of broader network-service security monitoring, but the control's scope is limited to network services and does not mandate host-level registry or screensaver-specific detection.
- T1546.003detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this can surface anomalous WMI activity when it traverses or is observable on the network (e.g. lateral movement or remote subscriptions), but the core local technique (installing filters/consumers via mofcomp.exe or local WMI) has no necessary network footprint and is therefore only a slice of what the control actually catches.
- T1546.004detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this surfaces suspicious shell-configuration changes when they occur over monitored network paths (e.g. SSH logins, remote shells) but does not address local-only or non-network-triggered modifications.
- T1546.004prevents — A.8.21 requires formulating and implementing rules on allowed networks/services, authentication, authorization, network management controls, access means (e.g. VPN), user attributes, and monitoring, plus considering authentication/encryption/connection controls; this constrains remote login vectors (e.g. SSH) and some shell config triggers but leaves local shell modification, file permission issues, and non-networked persistence vectors untouched.
- T1546.007detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous helper-DLL registration or netsh.exe execution tied to network configuration changes.
- T1546.010detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which can surface the anomalous process behaviour and registry changes of AppInit DLL abuse when those fall inside the chosen monitoring scope.
- T1546.014detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization rules and network connection controls, which can surface anomalous emond rule additions or launches on macOS when they involve network-triggered events or remote access, but the control is scoped only to network services and does not broadly instrument local LaunchDaemon rule abuse.
- T1546.017detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; udev rule abuse can be surfaced as anomalous file writes (to rules.d directories) or anomalous process spawning from udev context, but this is only a slice of the technique's surface (e.g. no network component, limited by sandbox, and monitoring scope is set by organisational requirements rather than mandating udev-specific coverage).
- T1547.001detects — A.8.21 explicitly requires monitoring the use of network services plus authentication/authorization and connection controls that surface anomalous or unauthorized persistence mechanisms when they involve network activity, but the technique itself is a local registry/startup-folder modification with no inherent network component.
- T1547.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that can surface anomalous time-provider registration or network-timestamp activity, but the control's scope is limited to network services and does not broadly instrument the registry, service-control-manager, or boot-time DLL loading that actually realises T1547.003.
- T1547.012detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous access or configuration changes; this can catch the registry edit, spooler restart, or anomalous SYSTEM-level DLL load in some network-visible cases, but the technique is a local boot-time persistence mechanism with no inherent network component, leaving most executions outside the clause's scoped monitoring.
- T1548.003prevents — A.8.21 requires formulating and implementing rules on authentication, authorization, network management controls, and monitoring of network services, which can constrain sudo/sudoers abuse when it occurs over a network (e.g. via SSH); this is a genuine but minority slice of the local tty/caching/sudoers-file technique described.
- T1548.005detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls, which can surface anomalous just-in-time elevation, impersonation, or PassRole abuse when those actions traverse monitored network paths; this is a genuine but minority slice of the technique (most abuse is local to cloud IAM/CLI without network traversal).
- T1548.005prevents — A.8.21 requires identification, implementation, monitoring and enforcement of network-service rules covering authentication, authorization, allowed services, technological controls and monitoring; these directly constrain the permission configurations and misconfigurations that enable temporary elevated cloud access via JIT, impersonation or role-passing, but the clause is scoped to network services and does not reach the full breadth of cloud IAM, approval workflows or non-network privilege-escalation paths.
- T1548.006detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous access patterns; TCC database manipulation or inheritance via injection/AppleScript can be observed as anomalous network-service or privilege-use events when those controls are instrumented, but the clause's scope is limited to network services and does not broadly cover local TCC abuse on macOS.
- T1548.006prevents — A.8.21 requires identification, implementation, and monitoring of network service security features (authentication, authorization, network connection controls, VPN/wireless means, time/location attributes, monitoring) which can prevent some TCC abuse vectors that rely on network services or remote access, but the technique is a local macOS privilege-abuse method (database manipulation, process injection, SIP bypass) unrelated to network services in its core paths.
- T1550detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls, which can surface anomalous use of stolen alternate auth material (e.g. pass-the-hash or ticket replay) during lateral movement; this is a genuine but minority slice because the control is scoped to network services rather than host memory, process injection, or non-network credential abuse.
- T1550prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, authorization procedures, monitoring, time/location attributes, VPN/wireless means) and provider oversight, which constrains some vectors for acquiring or using stolen alternate auth material (e.g. Kerberos tickets or tokens) over networks but leaves many others (e.g. local credential dumping, in-memory theft, non-networked lateral movement) untouched.
- T1550.001detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and anomaly-capable features (e.g. connection controls, time/location attributes); this surfaces token abuse that traverses monitored network paths or deviates from expected patterns, but leaves substantial residue (e.g. purely API-layer token replay inside SaaS, offline token theft, or unmonitored cloud-to-cloud flows)
- T1550.001prevents — A.8.21 mandates identifying/implementing network-service security features (authentication, authorization, monitoring, connection controls, VPNs) and provider oversight, which constrains token theft and misuse vectors that rely on network/API access; this is a genuine but minority slice of the technique (remainder includes non-network token compromise, misconfigured permissions, and refresh-token abuse).
- T1550.002prevents — A.8.21 requires identification and enforcement of authentication requirements, authorization procedures, network connection controls, and monitoring for network services, which can block many PtH lateral-movement paths that rely on weak network auth or unmonitored hash usage; however, it is silent on the core credential-theft prerequisite, local hash extraction, and non-network PtH variants, leaving a large remainder.
- T1550.003detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization controls that surface anomalous Kerberos ticket usage (e.g. unexpected service tickets or lateral movement patterns), but this is scoped only to network-layer observables and does not address the credential-dumping or ticket-creation steps that precede PtT.
- T1550.003prevents — A.8.21 mandates network service rules, authentication/authorization requirements, monitoring, and security features (e.g. encryption, connection controls) that can block some PtT lateral movement vectors when enforced on allowed networks/services, but leaves the core credential theft/preparation (T1003) and ticket forgery untouched.
- T1550.004detects — A.8.21 explicitly requires monitoring of network service use plus consideration of authentication, encryption and connection controls, which can surface anomalous cookie-based session activity on covered networks; it does not mandate instrumentation that reliably catches the post-theft import or use of a stolen web session cookie itself.
- T1550.004prevents — A.8.21 mandates identifying/implementing network-service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can block cookie theft vectors at the network layer or via enforced auth/monitoring; however, it does not address the post-auth cookie import, browser-level reuse, or MFA bypass once the cookie is obtained, leaving a substantial remainder of the technique untouched.
- T1552.001detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour detection across networks/systems/applications, which surfaces credential-file searches when they traverse monitored network paths, shares or cloud/container logs, but leaves the dominant local-filesystem slice (non-network) unreached.
- T1552.001prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, encryption, network connection controls, access restrictions, monitoring) for network services; this constrains discovery and exfiltration of credential files over networks or in cloud/container configs but leaves local filesystem searches, embedded credentials in code/backups, and non-network vectors untouched.
- T1552.004prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can prevent insecure storage or network exposure of private keys on allowed services but leaves local filesystem searches, key export from devices, and passphrase attacks on already-stored keys untouched.
- T1552.005detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection, which surfaces direct queries or SSRF attempts to the metadata API endpoint from within the instance or proxy; this is only a slice because the clause's scope is set by organisational requirements rather than mandating universal coverage of all instance-internal or non-network metadata access vectors.
- T1552.005prevents — A.8.21 requires identifying, implementing, and enforcing network/service rules plus features (authentication, authorization, network connection controls, VPN/wireless means, time/location attributes, monitoring) that can block unauthorized queries to the metadata endpoint from an instance or via SSRF, but leaves residual paths such as misconfigured allowed networks, local-instance access that bypasses external controls, or incomplete enforcement of connection rules.
- T1552.006detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and access controls that surface anomalous credential-gathering behavior on SYSVOL shares over the network; this catches the technique when it traverses monitored network paths but leaves local or non-networked enumeration of GPP XML files outside the clause's named scope.
- T1552.006prevents — A.8.21 requires identifying/implementing network-service security features (authentication, authorization, network connection controls, monitoring, access rules by time/location/means) and provider oversight; this can prevent the technique where SYSVOL exposure or GPP credential use crosses a network boundary under those controls, but leaves the core Windows-domain credential embedding and local SYSVOL access untouched.
- T1552.007detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous usage, which surfaces adversary API access to Docker/Kubernetes endpoints over the network; this is only a slice of the technique because credential gathering can also occur locally inside a compromised container without traversing monitored network services.
- T1552.007prevents — A.8.21 mandates identifying/implementing network-service security features (auth, encryption, connection controls, access rules, monitoring) and provider oversight; this directly constrains unsecured container APIs (e.g. unauthenticated Docker endpoints or overly permissive Kubernetes service-account access) on the network, but leaves residual gaps in API-level authorization, pod-level secrets, and non-network vectors inside the container environment.
- T1552.008detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication/encryption/connection controls and anomalous usage, which surfaces credential exposure in chat services when it occurs over monitored enterprise networks or SaaS endpoints, but the clause's scope is set by organizational requirements and does not mandate instrumentation of chat-message content, admin portals, or integration-tool workflows themselves.
- T1552.008prevents — A.8.21 requires identifying, implementing, and enforcing network/service rules plus features (authentication, encryption, access controls, monitoring) that can stop unsecured credential transmission in chat services when those services are treated as network services under organizational policy; it reaches only a slice because the control is scoped to network-level measures and does not govern user behavior or credential handling inside the applications themselves.
- T1553.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network management and technological controls; registry tampering and DLL search-order hijacking that enable SIP/trust-provider attacks are observable anomalies that fall inside that monitoring slice, but the control is scoped only to network services and does not address the broader class of local trust-provider tampering.
- T1553.004detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication and encryption features; these surface anomalous certificate installs or trust changes that affect TLS/SSL connections, but the clause is scoped to network services rather than host-level root-store changes or supply-chain pre-installs, leaving a genuine slice unreached.
- T1555.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication/encryption/connection controls; this can surface anomalous browser-file or process-memory access over the network (or via monitored service endpoints), but the core local file/memory reads on the endpoint are outside its network-service scope
- T1555.006detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls, which can surface anomalous API calls that retrieve secrets from cloud services (e.g. get-secret-value), but the clause is scoped only to network services and does not mandate detection of the credential-acquisition technique itself or of the privilege-escalation prerequisite.
- T1555.006prevents — A.8.21 requires identification, implementation, authentication, authorization, network controls, monitoring, and auditing of network services (including cloud APIs), which can block unauthenticated or unauthorized API calls to secrets managers; however, it does not address the core privilege-escalation path (e.g., via compromised high-priv Cloud Accounts) that enables the technique.
- T1556detects — A.8.21 explicitly requires monitoring of network service use plus regular determination/monitoring of provider security management, which can surface anomalous modifications to auth processes (especially on network-accessible services, VPNs, or provider-managed identity components) but does not mandate instrumentation that would catch local PAM/LSASS/SAM edits on endpoints.
- T1556prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network connection controls, VPNs, monitoring) for network services, which directly constrains many T1556 vectors on network-facing auth (e.g. VPN, remote desktop, cloud identity) but leaves local process modification (LSASS, PAM, SAM) untouched.
- T1556.001detects — A.8.21 explicitly requires monitoring of network service use plus consideration of authentication, encryption and connection controls, which can surface anomalous DC authentication or LSASS patching in monitored environments, but the control's scope is limited to network-level service rules and does not mandate host/process monitoring that would reliably catch the in-memory patch itself.
- T1556.003detects — A.8.21 explicitly requires monitoring of network service use plus consideration of authentication, authorization and network connection controls, which can surface anomalous PAM modifications or credential-harvesting behavior on Linux/macOS systems that rely on network services; this is only a slice because the clause scopes monitoring to network services and does not mandate host-level PAM integrity or credential-flow inspection.
- T1556.005detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization controls and audit rights over providers, which can surface anomalous setting of reversible-encryption properties or related credential-access activity on Windows AD environments; this is only a slice of the technique's full surface (e.g., local GPO edits or non-networked FGPP changes remain outside the network-service monitoring scope).
- T1556.005prevents — A.8.21 requires identification, implementation, and monitoring of security features (authentication, encryption, connection controls, authorization procedures, network rules) that can block the AD property change and the subsequent reversible-encryption path, but the clause is scoped to network services and does not reach the core Windows/AD account-policy or FGPP mechanisms that actually enable the weakness.
- T1556.006detects — A.8.21 explicitly requires monitoring of the use of network services plus determination/regular monitoring of the provider's secure management ability, which surfaces anomalous MFA modifications or bypasses when they involve network services, authentication flows, or provider-managed identity components; this is only a slice of the technique's full scope (local patching, host-file edits, policy exclusions)
- T1556.006prevents — A.8.21 requires identification, implementation, monitoring and enforcement of network-service security features (including authentication requirements, MFA-capable tech, connection controls, authorization procedures and usage rules) that can stop many classes of MFA disablement or bypass before they succeed, but leaves residual paths such as post-compromise admin abuse of legitimate policy features, local patching of MFA binaries, or fail-open configurations that the clause does not directly block.
- T1556.007detects — A.8.21 explicitly requires monitoring of the use of network services plus determination/regular monitoring of the provider's ability to manage services securely (including via audits and third-party attestations), which surfaces anomalous authentication behavior on hybrid identity flows that traverse network services, but this is scoped only to network/provider monitoring rather than code-level or on-premises process injection/PTA-agent backdoors themselves.
- T1556.007prevents — A.8.21 requires identifying/implementing security features (authentication, encryption, connection controls), formulating rules on allowed networks/services, authentication/authorization procedures, monitoring, and provider oversight; this constrains some hybrid-identity backdooring vectors (e.g. via enforced auth requirements, monitoring of service use, or audited provider configs) but leaves the dominant on-premises compromise and DLL/config modification techniques untouched.
- T1556.008detects — A.8.21 explicitly requires monitoring of the use of network services plus determining and regularly monitoring a provider's ability to manage services securely (including via audits and attestations), which surfaces anomalous or malicious network-provider behavior on Windows; this is a genuine but minority slice of the technique's full surface (registry-based installation of a malicious DLL plus its later credential-capture use).
- T1556.008prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network connection controls, monitoring) plus rules on allowed networks/services and provider oversight; this constrains many vectors for registering malicious network provider DLLs (esp. via provider management and auth rules) but leaves open registry-based installation paths, unmonitored internal providers, and credential-manager add-ons that the clause does not directly block.
- T1556.009detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's secure management of agreed services (including right to audit and third-party attestations), which surfaces anomalous policy changes on identity-provider or IaaS network-access services; this is a genuine but minority slice of the technique's scope (e.g., it does not instrument the policy store itself or cover non-network conditional attributes).
- T1556.009prevents — A.8.21 requires formulating/implementing rules on allowed networks/services plus authentication, authorization, monitoring, and technological controls (including conditional attributes such as IP, time, location, MFA, and risk), which directly stops the adversary technique of disabling or modifying those same conditional access policies from succeeding; it is partial because the control is a governance/requirement-setting clause whose actual coverage depends on the rigor of the provider's implementation rather than mandating a universal mechanism.
- T1557detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, encryption and anomalous usage, which surfaces many (but not all) AiTM positioning behaviors such as unexpected DNS/ARP manipulation or downgrade negotiation.
- T1557prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, rules on allowed networks/services, monitoring) and provider oversight, which directly stops many protocol-abuse vectors (ARP/DNS/LLMNR poisoning, downgrade attacks, weak negotiation) that enable AiTM positioning; it leaves residual gaps such as unmonitored legacy devices, insider provider compromise, or physical-layer insertion not covered by the clause's service-provider and logical-control focus.
- T1557.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection, which surfaces LLMNR/NBT-NS/mDNS spoofing when it occurs inside the monitored scope; the remainder is the slice of implementations that set narrow monitoring scope excluding these local multicast protocols.
- T1557.001prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls), formulating rules on allowed networks/services, authentication/authorization, monitoring, and restricting access where necessary; this directly constrains LLMNR/NBT-NS/mDNS spoofing and relay on managed networks but leaves residual gaps on unmanaged segments, legacy protocols, or incomplete enforcement.
- T1557.002detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls and anomalous behaviour detection, which surfaces ARP cache poisoning in flight on covered segments; it does not mandate host-level ARP cache inspection or coverage of every possible network segment.
- T1557.002prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls), formulating rules on allowed networks/services, authentication/authorization, monitoring, and technological controls to protect access to network connections; these directly constrain ARP poisoning (stateless, unauthenticated local segment replies) on covered networks, but only where such measures are selected and enforced, leaving gaps on unmanaged segments or unencrypted legacy traffic.
- T1557.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous configurations (e.g. rogue DHCP responses), which surfaces the spoofing technique in flight on covered networks; it is only partial because the clause sets the scope by organizational requirements rather than mandating universal DHCP-specific instrumentation, leaving slices (e.g. unmonitored segments) conformant yet undetected.
- T1557.003prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls), formulating rules on allowed networks/services, authentication/authorization, monitoring, and restricting access via technological controls; this constrains rogue DHCP spoofing and malicious config delivery in some (but not all) deployment models, leaving residual exposure on unmanaged segments, wireless, or where rogue servers can still respond before legitimate ones.
- T1557.004detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and anomalous access attributes (time/location), which surfaces evil-twin Wi-Fi deception in flight or post-connection; it does not mandate wireless-specific rogue-AP detection or PNL-probe monitoring, leaving a large slice of the technique unseen.
- T1557.004prevents — A.8.21 explicitly requires rules, authentication, authorization, technological controls (including for wireless networks and VPNs), monitoring, and security features such as encryption and connection controls that directly constrain or block the rogue-AP deception and unauthorized connection that T1557.004 relies on; the remainder is that the control is a set of requirements whose actual preventive effect still depends on implementation strength and cannot stop every physical-layer evil-twin deployment.
- T1558detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization controls that can surface anomalous Kerberos ticket activity (e.g. via logs or network telemetry), but this is scoped only to allowed networks/services and does not mandate detection of ticket theft or forgery itself
- T1558prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, authorization, monitoring, VPN/wireless rules) and provider oversight, which can stop many Kerberos ticket theft/forgery vectors on the wire or at service boundaries, but leaves the dominant in-memory credential-theft and local klist abuse vectors on endpoints untouched.
- T1558.001detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization controls and anomalous behaviour detection, which surfaces golden ticket usage when it traverses monitored network paths or KDC interactions, but leaves substantial remainder for offline forgery, non-network TGS requests, or unmonitored domain-controller activity.
- T1558.002detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization controls that surface anomalous access patterns to services; this can detect silver ticket usage when it triggers observable network or auth anomalies, but the technique's offline forging and lack of KDC interaction leaves a large undetected portion
- T1558.002prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, authorization, monitoring, VPN/wireless rules) and provider oversight; these can stop silver-ticket use on covered services or networks but leave gaps for offline forging after hash theft, non-network vectors, and services outside the scoped rules.
- T1558.003detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication features and anomalous access attributes, which can surface Kerberoasting's network requests for TGS tickets or RC4-encrypted ticket traffic; this is only a slice because the control is scoped to allowed/authorized network services rather than mandating deep inspection of all Kerberos protocol exchanges or offline cracking artifacts.
- T1558.003prevents — A.8.21 mandates network rules, authentication/authorization requirements, encryption, connection controls, and monitoring that can block sniffing of TGS tickets or weak-RC4 issuance over the network, but leaves the dominant root (weak service-account passwords enabling offline brute-force of any obtained ticket) untouched.
- T1558.004detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization controls and network connection monitoring, which can surface anomalous AS-REQ/AS-REP traffic or enumeration of pre-auth-disabled accounts over the network; this is genuine but only a slice because the technique's core (cracking the harvested AS-REP offline) occurs locally after exfiltration and is invisible to network-service monitoring.
- T1558.004prevents — A.8.21 requires identification, implementation, and enforcement of network service security features (authentication, encryption, connection controls, authorization procedures, monitoring) that can mandate and enforce Kerberos pre-authentication plus stronger algorithms, blocking the unauthenticated AS-REP that enables offline cracking; this is a genuine but minority slice of the technique (the remainder being non-network-service vectors such as direct LDAP enumeration of accounts or local misconfigurations).
- T1558.005detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization controls that surface anomalous Kerberos ticket use or access to ccache locations, but this is scoped by organizational requirements rather than mandating coverage of all ccache theft indicators on Linux/macOS.
- T1558.005prevents — A.8.21 requires identification, implementation, and monitoring of network service security features (authentication, encryption, connection controls, access rules, monitoring) that can stop ccache theft on the wire or via restricted network access, but leaves local filesystem theft of /tmp files or in-memory extraction untouched.
- T1561recovers — A.8.21 requires backup, monitoring, and recovery-enabling network/service controls that restore availability after a disk-wipe event, matching the event-lane recovers verb; mostly because the control addresses network services broadly but leaves some on-device or unmonitored wipe artifacts as named remainder.
- T1561.002recovers — A.8.21 requires backup and recovery-oriented network service rules plus monitoring of usage and provider attestations that can enable restoration of wiped boot structures via secure network-based recovery mechanisms (e.g. from protected images), matching the event-lane recovers verb; mostly because the control is scoped to network services rather than mandating full system restore capability for all platforms and non-network vectors.
- T1563detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and anomalous-access attributes, which surfaces session hijacking in flight on covered remote services; the remainder is implementation-dependent scope that may omit certain services, protocols or telemetry depth.
- T1563prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, authorization, monitoring, VPN/wireless means, time/location attributes) and provider oversight, which stops many hijacking vectors on remote sessions (e.g. telnet/SSH/RDP) but leaves residual paths such as post-auth in-memory hijacking or unmonitored provider-side sessions.
- T1563.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection, which surfaces SSH session hijacking when it occurs on monitored connections; the remainder is sessions outside the organisation's defined monitoring scope or on unmanaged third-party networks.
- T1563.001prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, authorization, monitoring, VPN/wireless means) and rules that can stop SSH session hijacking vectors such as weak agent access or unauthenticated socket exposure, but leaves residual cases (e.g., root-level compromise of an already-active session or implementation gaps in provider controls).
- T1563.002detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces RDP session hijacking when it occurs within monitored scope, but the clause sets that scope by business requirements rather than mandating universal RDP-session instrumentation.
- T1563.002prevents — A.8.21 requires identification, implementation, and monitoring of network service security features (authentication, authorization, connection controls, VPN/wireless means, time/location attributes, monitoring) that can stop unauthorized RDP session takeover in many configurations, but leaves residual paths such as local hijacking with System privileges or unmonitored internal RDP use.
- T1564.006detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous attributes (time/location), which surfaces some virtualization-based hiding (e.g. mismatched IPs/hostnames from bridged VMs or rogue ESXi VMs) but leaves the core in-guest artifact hiding and non-networked VM execution entirely unreached.
- T1564.006prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, network connection controls, rules on allowed networks/services, monitoring of use) for network services, which can prevent some virtualization-based hiding (e.g. via network rules, VPN mandates, or monitored connections) but leaves most of the technique (local VM creation, shared folders, sandbox config, ESXi rogue VMs) untouched.
- T1565.002detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, encryption and anomalous-behaviour monitoring, which surfaces some instances of in-transit data manipulation on covered networks but leaves the bulk (e.g., process-to-process manipulation, non-monitored links, or sophisticated encrypted tampering) unreached.
- T1565.002prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, monitoring, usage rules) and provider oversight that can stop interception-and-alteration on covered network paths; this is genuine but only a slice because the control is scoped to service-provider agreements and allowed networks, leaves in-transit manipulation between processes or on unmanaged links untouched, and does not guarantee integrity mechanisms for every transmission mechanism the adversary could target.
- T1566detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces many phishing delivery vectors (e.g. anomalous email, malicious links/attachments traversing the network) but does not address non-network social-engineering aspects, phone-based phishing, or purely client-side execution after delivery.
- T1566prevents — A.8.21 requires rules, authentication, authorization, monitoring, and technical controls (e.g. encryption, connection controls, VPN) for network services that can block delivery or execution vectors of some phishing (email filtering, link blocking, MFA on SaaS), but leaves the social-engineering core, non-network vectors (phone, social media), and user-click execution untouched.
- T1566.001detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and anomaly-oriented network connection controls, which surfaces spearphishing attachment attempts that traverse monitored network paths or email gateways; it does not address the social-engineering or attachment-opening steps that occur outside those monitored boundaries.
- T1566.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization rules and anomalous-access controls, which can surface spearphishing-link delivery or the subsequent malicious network activity (e.g. connection to obfuscated phishing domains or consent-phishing OAuth endpoints); it does not directly inspect email content or user clicks, leaving the social-engineering delivery vector largely unreached.
- T1566.002prevents — A.8.21 mandates rules, authentication, authorization, monitoring, and network controls (including VPNs, connection rules, and access restrictions) that can block many malicious links and downstream network interactions, but leaves the initial social-engineering email delivery, user click decision, and non-network vectors (e.g., consent phishing, device-code phishing, email-reader exploits) untouched.
- T1566.003detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, authorization, and anomalous access attributes, which surfaces spearphishing messages arriving via third-party services that traverse or touch monitored enterprise networks or endpoints.
- T1566.003prevents — A.8.21 requires rules, authentication, authorization, monitoring, and security features (including for third-party network services) that can block or constrain many delivery vectors for spearphishing-via-service (e.g. restricting allowed services, enforcing MFA on personal webmail, or monitoring anomalous use), but cannot stop the adversary from creating fake accounts and sending messages on services the organization does not control or that users still access.
- T1567detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication/authorization/network connection controls, which surfaces anomalous exfiltration over web services when it deviates from allowed patterns, but the clause sets scope by organizational rules rather than mandating universal detection of covert use of legitimate channels.
- T1567prevents — A.8.21 requires identifying/implementing network service security features (auth, encryption, connection controls, usage rules, monitoring) and ensuring providers do the same, which can block unauthorized exfiltration channels over web services when those rules and controls are applied to block or tightly constrain them; however, it is a governance-and-requirements clause whose effect depends on what the organization actually chooses to allow, leaving many legitimate web services (and their pre-existing firewall rules) untouched.
- T1567.001detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication, authorization, and connection controls that surface anomalous or unauthorized outbound use of APIs such as those of code repositories; this is genuine detection coverage for the technique, but remains partial because the clause sets requirements rather than mandating specific detection depth or coverage of all exfiltration vectors (e.g., encrypted HTTPS to popular services can still blend with legitimate traffic).
- T1567.001prevents — A.8.21 requires formulating/implementing rules on allowed networks/services, authentication, authorization, monitoring, and security features (e.g. encryption, connection controls, VPNs) that can block unauthorized exfiltration to external code repo APIs when enforced; it does not guarantee prevention for all cases (e.g. approved services, insider misuse, or unmonitored egress).
- T1567.002detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, and anomalous usage patterns, which can surface exfiltration over allowed cloud-storage channels but only where those fall inside the scoped monitoring and rules (remainder: covert use of already-permitted services or unmonitored attributes).
- T1567.002prevents — A.8.21 requires identifying, implementing, and monitoring security measures (including authentication, authorization, network connection controls, allowed services, VPN/wireless means, time/location attributes, and usage monitoring) for network services; this can block unauthorized exfiltration to cloud storage when it violates those rules, but leaves open the common case where the service is already authorized/used for legitimate purposes (providing the cover the technique relies on).
- T1567.003detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous outbound use of text-storage domains, but the clause's scope is set by organizational requirements rather than mandating universal coverage of all exfil channels or post-encryption payloads.
- T1567.003prevents — A.8.21 requires rules, authentication, authorization, network controls, monitoring, and service-provider measures that can block or detect outbound access to unapproved text-storage sites (via allowed-network lists, VPN enforcement, connection rules, or provider monitoring), but leaves open many implementation gaps such as approved web access, encrypted channels, or insider use of permitted services.
- T1567.004detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication, authorization, and network connection controls that surface anomalous or unauthorized outbound HTTPS posts to webhook endpoints, but this is scoped by what the organization chooses to monitor and does not guarantee detection of blended SaaS traffic or manual posts that mimic legitimate service behavior.
- T1567.004prevents — A.8.21 requires identifying/implementing network service security features (auth, encryption, connection controls, access rules, monitoring) and provider oversight, which can block unauthorized webhook setup or outbound exfil over HTTPS to unapproved SaaS endpoints; however, it is a governance/requirement-setting control whose coverage depends on the rigor of implementation and leaves many adversary-chosen webhook endpoints (common SaaS, manual posts, blended traffic) as a slice rather than the bulk with a bounded remainder.
- T1568detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, and anomalous patterns, which surfaces dynamic C2 resolution behaviors when they trigger observable network artifacts; this is a genuine but minority slice because the control is scoped to allowed/authorized services rather than broadly instrumenting all resolution algorithms or fallback channels.
- T1568prevents — A.8.21 mandates identification, implementation, and monitoring of network service security features (authentication, encryption, connection controls, access rules, monitoring) that can stop many dynamic C2 resolution techniques at the network boundary; it does not reach the malware's internal algorithm or pre-compromise calculation of parameters.
- T1568.001detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, and anomalous patterns, which can surface fast-flux C2 traffic via DNS TTL, rapid IP churn or connection anomalies; this is only a slice because the clause leaves scope and depth of monitoring to the organization and does not mandate the specific DNS-layer telemetry needed to reliably catch fast flux.
- T1568.002detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, and anomalous patterns, which surfaces DGA-driven C2 beaconing as observable network behavior; it does not mandate the specific analytics or telemetry depth needed to reliably distinguish DGA from legitimate dynamic domains.
- T1568.003detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization and connection controls that surface anomalous DNS-derived C2 traffic when it deviates from allowed networks, ports, or patterns, but this is scoped by organizational rules rather than mandating specific detection of the calculation mechanic itself.
- T1569detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network-connection controls that surface anomalous or unauthorized service interactions, which can detect abuse of system services when it traverses the network; this is only a slice of T1569 (local abuse and many non-network daemons remain unseen).
- T1569.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and network connection controls, which can surface remote abuse of the service control manager via tools such as PsExec or sc.exe over the network; local-only abuse on a compromised endpoint lies outside the network-service scope, leaving a genuine slice rather than a bounded remainder.
- T1569.003detects — A.8.21 explicitly requires monitoring of the use of network services plus network management/technological controls that surface anomalous or unauthorized service execution, which can detect systemctl abuse when it traverses or is observed at the network layer; this is only a slice of the Linux-local technique (most invocations are not network-visible).
- T1570detects — A.8.21 explicitly requires monitoring of network service use plus authentication, authorization, connection controls and anomalous-behaviour monitoring, which surfaces many (but not all) lateral file-transfer techniques that traverse monitored networks or services.
- T1570prevents — A.8.21 mandates identifying/implementing network service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can block many file-transfer vectors (e.g. unauthorized SMB/RDP/scp/ftp sessions or unencrypted shares) but leaves open transfers that satisfy the rules (e.g. via allowed authenticated protocols, VPNs, or synced web services), so only a slice of the technique is stopped.
- T1571detects — A.8.21 explicitly requires monitoring of network service use plus identification and enforcement of allowed networks/services, authentication, authorization, connection controls and technical parameters, which surfaces anomalous protocol/port pairings as deviations from the approved baseline.
- T1571prevents — A.8.21 requires identifying, implementing, and monitoring network service security features (including authentication, connection controls, rules on allowed networks/services, and monitoring use), which can block non-standard port usage in allowed services but leaves residual cases such as adversary-modified victim configs or unmonitored protocols.
- T1572detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls, authentication, encryption and anomalous usage patterns, which surfaces tunneling (especially when it deviates from allowed services, authz, time/location attributes or expected protocols) but leaves many stealthy or policy-conformant tunnels (e.g. approved VPNs, DoH inside permitted HTTPS, or traffic that blends without triggering the chosen monitoring scope) undetected.
- T1572prevents — A.8.21 requires identifying, implementing, and monitoring network service security features (authentication, encryption, connection controls, usage rules, monitoring) that can stop many tunneling vectors (e.g. blocking unauthorized SSH/VPN/DoH tunnels or non-compliant encapsulation), but leaves residual cases where allowed services or legitimate-looking tunnels are still abused.
- T1573detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, encryption technology and anomalous parameters, which surfaces encrypted C2 channels when they deviate from allowed baselines or patterns, but only for monitored/allowed services and not inherent to all T1573 implementations (e.g. custom malware keys on unmonitored endpoints).
- T1573prevents — A.8.21 requires identifying, implementing, and enforcing specific security features (authentication, encryption, connection controls, access rules, monitoring) for allowed network services, which directly constrains many insecure C2 channel implementations but leaves residual cases (e.g., malware using strong but key-embedded encryption on permitted services or unmonitored custom channels).
- T1573.002detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces C2 traffic that relies on asymmetric crypto for concealment; this is genuine detection but only a slice (scope is set by organisational requirements, not universal instrumentation of all asymmetric flows or protocol anomalies).
- T1574.001detects — A.8.21 explicitly requires monitoring of network service use plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces many DLL-abuse indicators (e.g. anomalous process loading, remote shares, unexpected network connections) but leaves large slices (purely local sideloading, phantom hijacks without network artefacts) outside its mandated scope.
- T1574.004detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this surfaces dylib-hijack execution when it produces observable network activity or anomalies, but the technique is local filesystem/loader behaviour that can succeed with no network involvement and is explicitly noted to evade security products, so only a minority slice is detected.
- T1574.005detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this can surface installer hijacking when it involves network-borne payloads, anomalous writes to %TEMP%, or network-based privilege-escalation indicators, but the core local filesystem permission weakness and most in-process installer behavior sit outside network-service monitoring scope.
- T1574.007detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which surfaces PATH hijacking when it triggers observable network or process anomalies but does not guarantee detection of the environment-variable modification or library-load step itself.
- T1574.007prevents — A.8.21 requires formulating/implementing rules on allowed networks/services, authentication, authorization, network management controls, access means (e.g. VPN), user attributes, monitoring, and security features like authentication/encryption/connection controls; this constrains some PATH hijacking vectors (e.g. via network service rules, authz for executables, or monitored connections) but leaves the core local env-var modification and search-order abuse untouched on Linux/macOS/Windows.
- T1574.008detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which can surface search-order hijacking when it triggers observable network or process anomalies, but the control's scope is limited to network-service usage and does not guarantee detection of the local filesystem placement or execution itself.
- T1574.008prevents — A.8.21 requires rules, authentication, authorization, network management controls, and monitoring that can constrain how and where network services are invoked and loaded, which prevents some but not all search-order hijacking vectors (especially local non-networked program execution on Windows).
- T1574.009detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications, which can surface path-interception artifacts (e.g. unexpected executables in search paths or anomalous process creation) when they involve networked service paths, but the control's scope is limited to network services and does not broadly instrument the local Windows filesystem/registry checks needed for the bulk of this technique.
- T1574.009prevents — A.8.21 requires rules, authentication, authorization, network management controls, and monitoring that can constrain how and where unquoted service/shortcut paths are registered and executed on managed networks, but does not reach the root cause of unquoted paths in local Windows registry or file-system references.
- T1574.010detects — A.8.21 explicitly requires monitoring of the use of network services plus network management/technological controls that surface anomalous access or connection attempts, which can detect some but not most instances of a Windows service binary being replaced via weak file permissions (a local, non-network technique on a narrow platform).
- T1578detects — A.8.21 explicitly requires monitoring of network service use plus regular determination/monitoring of the provider's secure management ability and right-to-audit, which can surface anomalous compute-infrastructure changes in IaaS network contexts, but this is scoped only to network services and does not broadly instrument the full range of cloud compute modifications (e.g. offline snapshots or non-networked instance changes).
- T1578.002detects — A.8.21 explicitly requires monitoring of the use of network services plus determining/regularly monitoring a provider's ability to manage services securely (including via audits and attestations), which can surface anomalous creation of cloud instances as a network-service event; this is genuine but only a slice because the control is scoped to network services rather than all compute-instance or cloud-management-plane activity.
- T1578.003detects — A.8.21 explicitly requires monitoring the use of network services plus determining/regularly monitoring a provider's ability to manage services securely, which can surface anomalous instance deletions (especially via provider audit rights or third-party attestations) but only for network-visible or provider-managed slices, not the full technique on IaaS platforms.
- T1578.005detects — A.8.21 explicitly requires monitoring the provider's ability to manage services securely plus monitoring of network service use, which can surface anomalous quota/policy/region changes as suspicious activity; this is genuine but only a slice because the control is scoped to network services rather than all cloud compute configuration surfaces.
- T1578.005prevents — A.8.21 requires identification, implementation, monitoring, authentication, authorization, network management controls, and rules that can constrain quota/policy/region modifications in cloud network services, but only reaches a slice of the IaaS technique (network-facing aspects) rather than the bulk of compute configuration changes.
- T1580detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; this surfaces many IaaS discovery calls (especially API-driven enumeration) when they cross monitored boundaries, but leaves a large slice (local CLI use, non-networked tools, or discovery inside an already-authorised session) outside the clause's defined scope.
- T1580prevents — A.8.21 requires formulating and implementing rules on allowed networks/services, authentication, authorization, network management controls, monitoring, and security features such as authentication/encryption/connection controls; these directly constrain the authenticated-enumeration path that is the dominant means of T1580 (preventing discovery via compromised keys or unauthorized API/CLI calls), but leave the unauthenticated/wordlist-scanning slice untouched.
- T1584.001prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls), formulating rules on allowed networks/services, authentication/authorization, monitoring, and auditing providers, which constrains several hijacking vectors (weak auth, renewal gaps, unmanaged DNS entries, unmonitored subdomains) but leaves social engineering, cloud compromises, and deprovisioned resource gaps outside its direct scope.
- T1584.008prevents — A.8.21 requires identifying, implementing, and monitoring security measures (authentication, authorization, network controls, VPNs, monitoring) for network services and providers, which directly constrains compromise of third-party/edge network devices used in targeting; partial because it governs the organization's own use and providers under contract, not all Internet-facing third-party devices an adversary might target globally.
- T1586.002prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can block credential-theft vectors (phishing, brute-force, reused creds) used to compromise email accounts, but leaves social-engineering, insider-payment, and pre-compromise reconnaissance untouched.
- T1586.003prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, authorization, network controls, VPNs, monitoring) for network services including cloud accounts, which directly constrains several compromise vectors such as password spraying, weak auth, and unauthorized access; it does not address phishing for credentials, purchasing creds, or reconnaissance, leaving a substantial remainder.
- T1589.001prevents — A.8.21 mandates network/service authentication, authorization, MFA-capable tech, monitoring, and provider oversight that stop many credential-gathering vectors (phishing for creds, cookie theft on monitored networks, weak provider MFA, unauthorized network access); it leaves personal-account reuse, dark-web purchases, and pre-existing leaks untouched.
- T1590.004prevents — A.8.21 mandates rules, authentication, authorization, network management controls, monitoring, and security features (e.g. encryption, connection controls) that constrain how and by whom network services can be accessed, thereby preventing many forms of active scanning or exposed-data collection of internal topology while leaving external/public topology discovery (via open websites, DNS, etc.) untouched.
- T1595detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface probing or anomalous access attempts, but this is scoped only to allowed/authorized services and does not broadly instrument or detect arbitrary external active scanning of unexposed infrastructure.
- T1595prevents — A.8.21 requires rules, authentication, authorization, network management controls, monitoring, and security features (e.g. connection controls, encryption) that can block many classes of active scanning probes from succeeding or being useful, but leaves open-ended reconnaissance via allowed/necessary services, unauthenticated ICMP, and pre-compromise external probing that the control does not reach.
- T1595.001detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface scanning activity (e.g. anomalous probes, connection attempts, or banner grabs) when it occurs against the organization's allocated IP blocks.
- T1595.001prevents — A.8.21 requires rules, authentication, authorization, network connection controls, monitoring, and security features (e.g. network connection controls) that can block or limit many forms of external scanning of the organization's IP blocks, but leaves residual exposure from public-facing services, allowed networks, and pre-compromise reconnaissance that cannot be fully prevented by these measures.
- T1595.002detects — A.8.21 explicitly requires monitoring the use of network services plus network management and technological controls that surface anomalous scanning activity (e.g. via server banners, listening ports, or other network artifacts), but the clause's scope is set by organizational requirements rather than mandating universal coverage of all possible pre-attack vulnerability scans, leaving a genuine slice uncovered.
- T1595.002prevents — A.8.21 requires rules, authentication, authorization, network management controls, monitoring, and security features (e.g. connection controls, encryption) that can block or limit many forms of external vulnerability scanning, but leaves open-ended scanning of allowed services, public banners/ports, and reconnaissance that does not violate the formulated rules.
- T1595.003detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems, which surfaces wordlist-driven probing as it occurs; the remainder is pre-authentication reconnaissance against unmonitored external surfaces or non-network vectors that fall outside the clause's scoped requirements.
- T1595.003prevents — A.8.21 requires rules, authentication, authorization, network connection controls, monitoring, and security features (e.g. encryption, access restrictions) that can block many forms of unauthenticated wordlist-driven probing and enumeration from succeeding, but leaves open slices such as public content, allowed discovery paths, and pre-authentication reconnaissance that the technique can still complete.
- T1599detects — A.8.21 explicitly requires monitoring of the use of network services plus determining/regularly monitoring a provider's ability to manage services securely (including via audits and attestations), which surfaces anomalous boundary-device behavior or reconfiguration on covered networks; this is a genuine but minority slice of the technique because the clause sets scope by organizational requirements rather than mandating universal device-level instrumentation, leaving most compromise vectors (especially on unmanaged or internal segmentation devices) unreached.
- T1599prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, authorization, network management rules) for network services and boundary devices, which directly constrains the ability of perimeter routers/firewalls to be reconfigured into bridges; this is genuine but partial because the clause is a requirements-and-monitoring control whose effect depends on the provider's implementation rigor and does not itself stop a sufficiently privileged compromise of the device.
- T1599.001detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls and anomalous behaviour detection, which surfaces malicious NAT modifications on monitored boundary devices; partial because the clause sets scope by organisational requirements rather than mandating universal deep packet or configuration monitoring, leaving gaps on unmonitored devices or custom NAT implementations.
- T1599.001prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, network connection controls, authorization procedures, monitoring of network services) that can block unauthorized NAT modifications on boundary devices when the provider or organization enforces them, but leaves the prerequisite device compromise (T1599.001's entry point) and custom firmware cases unaddressed.
- T1600detects — A.8.21 explicitly requires monitoring of network service use plus regular determination/monitoring of provider ability to manage services securely (including via audits and third-party attestations), which can surface anomalous weakening of encryption on network devices; this is a genuine but minority slice of the technique (e.g., post-compromise behavioral indicators) rather than a broad or dedicated detection mechanism.
- T1601.001prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls), formulating rules on allowed networks/services, authentication/authorization, management controls, access means (e.g. VPN), attributes like time/location, and monitoring; this constrains several vectors for delivering/modifying a patched image (e.g. via TFTP/FTP/SCP, console, or unauthorized access) but leaves memory/debug/bootloader methods and many device-specific internals untouched.
- T1602detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, authorization, network connection controls and other access-protection features; this surfaces anomalous or unauthorized access to configuration repositories exposed over the network, but only for the network-service slice of T1602 and without mandating detection of the data-collection act itself.
- T1602prevents — A.8.21 requires identifying/implementing network service security features (auth, encryption, connection controls, access rules, monitoring) and provider oversight, which can block many exposure paths to config repositories on network devices but leaves residual vectors such as misconfigured internal management systems, unmonitored protocols, or post-auth access.
- T1602.001detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection, which surfaces SNMP queries against the MIB on covered networks; it is partial because the clause sets scope by organisational requirements rather than mandating universal SNMP/MIB instrumentation, leaving gaps where monitoring is not required or does not reach the specific query pattern.
- T1602.001prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can block unauthenticated or unauthorized SNMP queries to the MIB on covered services; it leaves residual exposure on unmanaged devices, legacy SNMPv1/2c, or where rules are not fully enforced.
- T1602.002detects — A.8.21 explicitly requires monitoring of the use of network services plus determining/regularly monitoring the provider's secure management ability, which surfaces anomalous access or export of configuration files via management protocols; this is a genuine but minority slice of the technique (only the network-service/provider slice, not device-local inspection or non-monitored paths).
- T1602.002prevents — A.8.21 requires identifying, implementing, and enforcing rules plus technical controls (authentication, authorization, network connection controls, encryption, access restrictions, monitoring) that directly stop many of the management-protocol and access-vector abuses used to dump configs, but leaves a remainder for unmonitored or misconfigured internal paths and does not reach every possible dump vector on the device itself.
- T1606prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, authorization procedures, monitoring, and rules on allowed access methods including VPNs), which can block many forgery vectors that rely on weak network exposure or insufficient auth; however, it does not reach the dominant slice of forging via stolen secrets, privileged APIs (AssumeRole), or local cryptographic material on the adversary's own host.
- T1606.001detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and anomalous-access attributes, which surfaces forged-cookie usage against web apps once the cookie is presented; this is a genuine but minority slice of the technique (forging itself is invisible, and many forgeries target non-network SaaS without triggering network-service monitoring).
- T1606.001prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls), formulating rules on allowed networks/services, authentication requirements, authorization procedures, monitoring, and access attributes, which can block forged-cookie access to those services when enforced; however, it is a governance/requirement-setting control whose coverage depends on the provider's and organization's implementation rigor, leaving residual gaps in cookie-generation logic, secret handling, or non-networked SaaS use.
- T1606.002prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, authorization procedures, monitoring) and provider oversight, which can prevent some SAML-forgery vectors when the IdP is treated as a network service, but leaves the dominant certificate-compromise and federation-trust vectors untouched.
- T1609detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization/network connection controls that surface abuse of remote container management services (e.g. Docker daemon, Kubernetes API, kubelet) when they traverse monitored networks; this is genuine detection coverage for the network-borne slice of T1609 but leaves local/containerd-only or non-networked execution outside scope.
- T1609prevents — A.8.21 requires identifying/implementing network-service security features (authentication, authorization, network connection controls, monitoring, VPN/wireless means) and formulating rules on allowed networks/services, which can prevent some abuse vectors (e.g. unauthenticated remote Docker/K8s API access over networks) but leaves the bulk of the technique (local containerd/kubelet abuse, sufficient-permissions exec after auth, entrypoint specification) untouched.
- T1610detects — A.8.21 explicitly requires monitoring of the use of network services plus network management/technological controls that surface anomalous deployments or access (e.g. via authentication, authorization, time/location attributes, or connection rules), which can detect many but not all T1610 instances (especially those using benign images or non-network vectors).
- T1610prevents — A.8.21 mandates rules, authentication, authorization, network connection controls, monitoring, and security features (e.g. encryption, access restrictions) for network services that can block many deployment vectors (e.g. unsecured Kubernetes APIs, unauthenticated dashboards, or network-exposed Docker APIs), but leaves open slices such as local/privileged container deployment from already-authenticated hosts, malicious images pulled via allowed channels, or in-node workloads like DaemonSets.
- T1611detects — A.8.21 explicitly requires monitoring of the use of network services plus network management and technological controls that surface anomalous access or connection attempts, which can detect some container/host escape techniques that involve network activity or privilege-escalating system calls observable at the network layer, but most escape vectors (bind mounts, privileged containers, docker.sock abuse, kernel module loads) have no necessary network footprint and fall outside the clause's scope.
- T1611prevents — A.8.21 requires identifying/implementing network-service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight; this constrains several escape vectors that rely on weak network-exposed management sockets, untrusted network access to privileged containers, or lateral movement post-escape, but leaves the bulk of configuration, kernel, and hypervisor-level escape techniques (bind mounts, privileged containers, unshare/keyctl, VM escapes) untouched.
- T1612detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication, authorization, and network connection controls; these surface anomalous build requests (Docker API over the network) or suspicious pulls in monitored environments, but the technique can also be performed locally without network activity and the clause sets scope by organizational requirements rather than mandating universal coverage of all build activity.
- T1620detects — A.8.21 explicitly requires monitoring of network service use plus network connection controls, which can surface anomalous in-memory loading when it traverses or originates from a network vector, but the technique is primarily a local memory-resident execution method with no inherent network dependency, leaving the bulk of fileless/in-memory cases outside the clause's scope.
- T1621detects — A.8.21 explicitly requires monitoring of network service use plus authentication/authorization rules and anomaly-enabling features (time/location/attributes), which surfaces repeated login attempts that generate MFA fatigue requests, but does not guarantee detection of the subtler single-request or SSPR-abuse variants and is scoped only to network-visible activity.
- T1621prevents — A.8.21 requires identification, implementation, and monitoring of network service security features (including authentication, authorization, MFA-enforcing tech parameters, access rules, and monitoring for abuse), which can block automated MFA request generation and fatigue bombing at the network/service level for covered providers and connections, but leaves residual paths such as direct application abuse, non-network vectors, or unenforced MFA configurations.
- T1648detects — A.8.21 explicitly requires monitoring of the use of network services plus anomalous-behaviour monitoring of networks/systems/applications; serverless execution in cloud/SaaS environments is observable via invocation logs, event triggers and network calls, but the clause's scope is set by organisational requirements rather than mandating universal coverage of all serverless platforms or stealthy in-process abuse, leaving a genuine slice uncovered.
- T1649detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls, which can surface anomalous certificate-based authentication attempts or forged-certificate usage on monitored networks, but does not address theft from local stores, CA compromise, or non-network certificate forgery.
- T1649prevents — A.8.21 mandates identifying/implementing network-service security features (authentication, encryption, connection controls, access rules, monitoring) and provider oversight, which can block certificate theft or forgery vectors that rely on insecure network access or weak auth to CAs, but leaves the bulk of the technique (local store theft, enrollment abuse, CA key compromise, misconfigurations) untouched.
- T1651detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls, which can surface abuse of cloud management services (a form of network service) when it deviates from allowed patterns, but the control is scoped to network services rather than the full breadth of VM agent-based command execution or delegated admin abuse.
- T1659detects — A.8.21 explicitly requires monitoring of network service use plus consideration of network connection controls, authentication, encryption and anomalous traffic patterns that would surface ISP-level or upstream content injection in monitored channels; it does not mandate detection of every injection vector or every platform.
- T1659prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, connection controls, network rules, and provider oversight) that directly constrain upstream channel compromise and content injection from the middle/side, but leaves residual risk in ISP-level lawful-interception scenarios and incomplete provider enforcement.
- T1665detects — A.8.21 explicitly requires monitoring of network service use plus identification and regular monitoring of provider security measures, which surfaces anomalous traffic patterns or filtering consistent with T1665's evasion tactics; this is only a slice because the control is scoped to approved/allowed services and provider oversight rather than universal detection of all adversary hiding techniques (e.g. domain masking or conditional redirects).
- T1665prevents — A.8.21 mandates identification, implementation, and monitoring of network security features (authentication, encryption, connection controls, access rules, VPN usage, monitoring) that can stop many forms of traffic manipulation and infrastructure hiding from succeeding, but leaves open adversary techniques that use trusted services, domain masking, or conditional redirects before detection thresholds are met.
- T1667detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization and anomaly-oriented network controls that can surface anomalous inbound email volume or signup patterns at the mail gateway or network boundary; this is genuine detection coverage for the flooding technique but only a slice, as the control does not mandate mailbox-level or end-user client monitoring and many bombing vectors (e.g. direct SMTP from external bots) sit outside the scoped network-service monitoring an implementer may choose.
- T1669detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of authentication, encryption, connection controls and anomalous access attributes (time, location, means such as Wi-Fi/VPN), which surfaces adversary Wi-Fi connection attempts or bridges when they fall inside the monitored scope; it does not guarantee detection of all proximity-based or dual-homed bridging attempts outside that scope.
- T1669prevents — A.8.21 directly requires formulating and implementing rules plus technical controls (authentication, authorization, network connection controls, VPN/wireless means, time/location attributes, monitoring) that stop unauthorized Wi-Fi connections, covering the bulk of the technique while leaving a bounded remainder (physical proximity exploits of open networks or dual-homed bridges).
- T1671detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and anomalous-access attributes, which surfaces malicious OAuth consent and persistent token usage in SaaS environments; it does not mandate detection of the creation/co-opting step itself or of all integration abuse outside monitored network boundaries.
- T1671prevents — A.8.21 requires identification, implementation, authentication, authorization, monitoring, and rules for network services (including VPNs and access attributes), which constrains some OAuth/SaaS integration abuse vectors in cloud environments but leaves the bulk of the technique (consent grants, service principals, token persistence, and exfiltration) untouched as it is not a network-service mechanism.
- T1675prevents — A.8.21 requires identifying/implementing network service security features (authentication, authorization, connection controls, monitoring, VPN/wireless means, time/location attributes) and rules that can block or constrain abuse of ESXi administration services and guest command APIs when treated as network services, but leaves residual paths such as already-authenticated management channels, internal hypervisor APIs, or non-network vectors on the ESXi platform.
- T1677prevents — A.8.21 requires rules, authentication, authorization, network controls, and monitoring for network services (including those used by CI/CD pipelines), which can block several poisoning vectors such as unauthorized direct/indirect modifications or untrusted public PRs; however, it does not address code-level injection into referenced files, trusted inputs, or self-hosted runner execution inside the build.
- T1684.002detects — A.8.21 explicitly requires monitoring of the use of network services plus authentication/authorization procedures and network connection controls; these surface spoofed emails that fail DMARC/SPF/DKIM checks or violate allowed-network rules, but the clause is scoped to network-service governance rather than mandating email-specific detection mechanisms, leaving a large slice of header forgery undetected.
- T1684.002prevents — A.8.21 explicitly requires identification and implementation of network-service security features (authentication, encryption, connection controls, authorization procedures, monitoring) plus rules on allowed networks/services; this directly mandates the DMARC/SPF/DKIM configurations and enforcement policies whose absence or weakness the technique exploits, but leaves residual vectors such as internal Direct Send abuse and imperfect policy enforcement.
- T1685.001detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's ability to manage services securely, which surfaces anomalous tampering with EventLog (a core detection data source) when that tampering traverses or is visible from network services; this is a genuine but minority slice of the technique's local/registry/auditpol vectors on Windows endpoints.
- T1685.002detects — A.8.21 explicitly requires monitoring the use of network services plus determining/regularly monitoring the provider's ability to manage services securely (including via audits and attestations); this surfaces tampering with cloud logging integrations when they sit inside the monitored network-service scope, but the clause's scope is set by the implementer and does not mandate coverage of every logging-modification vector (especially non-network SaaS/identity-provider license or mailbox changes).
- T1685.002prevents — A.8.21 requires formulating/implementing rules on allowed networks/services, authentication, authorization, monitoring of network service use, and security features (auth/encryption/connection controls) that can constrain the permissions and access paths an adversary would need to reach and disable/modify cloud logging integrations.
- T1685.004detects — A.8.21 explicitly requires monitoring of the use of network services plus consideration of network connection controls and anomalous behaviour detection, which surfaces tampering with auditd when it affects network-related events or rules, but does not broadly instrument or guarantee detection of all kernel-level audit modifications (e.g. direct hooking or non-network rules).
- T1686detects — A.8.21 explicitly requires monitoring of network service use plus identification and regular monitoring of the provider's ability to manage services securely, which surfaces anomalous firewall changes on monitored networks or via provider attestations/audits, but does not mandate host-based detection of local tampering across all platforms or behaviors in the technique.
- T1686prevents — A.8.21 requires formulating/implementing rules on allowed networks/services, authentication, authorization, network management/technological controls (incl. connection controls), and monitoring; these directly constrain the adversary behaviors of tampering with or adding firewall rules to open paths, but only for network-level enforcement and where the provider or rules cover the specific modification vectors (e.g., does not block all local privilege-based tampering on every platform).
- T1686.001detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's secure management of agreed services (including via audits and attestations), which surfaces anomalous firewall changes in IaaS environments as a detectable deviation; this is only a slice because the clause's scope is set by what the organization requires/monitors rather than mandating universal detection of every possible modification technique.
- T1686.001prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, network connection controls, rules on allowed networks/services, authorization procedures, and monitoring) for network services, which directly constrains the ability to introduce or modify permissive firewall rules in cloud environments, but only for services under the organization's managed agreements and does not cover all adversary permission paths or unmonitored provider configurations.
- T1686.002detects — A.8.21 explicitly requires monitoring of network service use plus regular determination/monitoring of provider ability to manage services securely (including via audits and attestations), which surfaces anomalous firewall rule changes or disabled mechanisms on managed network devices as a detectable deviation; this is only a slice because the control is scoped to allowed/authorized services and provider-managed infrastructure rather than all possible device-level or host-network manipulations.
- T1686.002prevents — A.8.21 requires identifying, implementing, and monitoring security features (authentication, encryption, network connection controls, rules on allowed networks/services, authorization, and monitoring of use) that directly constrain the network configurations adversaries target in T1686.002; this stops many instances at the policy and configuration level, but leaves a slice where the adversary has already obtained privileged access to the device (via valid accounts or exploits) and can alter rules in place.
- T1686.003detects — A.8.21 explicitly requires monitoring of the use of network services plus regular determination/monitoring of the provider's secure management of agreed services, which surfaces anomalous firewall changes or rule modifications on monitored networks; this is only a slice because the clause scopes monitoring to business/security requirements and does not mandate host-level detection of local Windows firewall tampering itself.
- T1689prevents — A.8.21 requires identifying/implementing network service security features (authentication, encryption, connection controls, technical parameters for secured connections, usage rules restricting access) and monitoring provider compliance, which directly stops many protocol/network downgrades (e.g. HTTPS to HTTP, weak ciphers) but leaves non-network downgrade vectors (PowerShell version, boot manager) untouched.
Prevented OWASP Web Top 10 (2025) risks (13)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01mitigates — A.8.21's network-level authentication, authorization procedures, access rules, monitoring, and connection controls (e.g. VPN) limit blast radius or block some paths for realized access-control failures like path traversal or CSRF, but do not address the core authorization-decision defects (IDOR, missing function-level checks) inside applications.
- A01prevents — A.8.21 explicitly requires formulating and implementing rules plus technological controls for authentication, authorization procedures, network access restrictions, and monitoring, which squarely prevents the authorization-decision slice of A01 (missing checks, incorrect enforcement) while leaving path traversal, CSRF, and IDOR in non-network contexts untouched.
- A02mitigates — A.8.21's network-service rules, authentication/authorization requirements, connection controls, monitoring and explicit security features (authn, encryption, access restriction) bound the blast radius or block some exploitation paths of a realized misconfiguration, but do not address the core weakness of weak defaults or incomplete hardening itself.
- A02prevents — A.8.21 mandates identifying, requiring and monitoring specific security features (authentication, authorization, network connection controls, encryption, access rules) from providers and formulating rules that directly close many misconfiguration vectors in network services, but leaves residual exposure in non-network defaults, application-layer settings, incomplete hardening of unrelated components, and implementation gaps.
- A04mitigates — A.8.21 requires identifying/implementing network-service security features (explicitly including encryption and connection controls) and rules covering their use, which bounds the blast radius or observability of realized crypto failures for data in transit over those networks without removing the underlying absent/weak/misused crypto.
- A05mitigates — A.8.21's network boundary, authentication, authorization, connection controls, encryption and monitoring can bound the blast radius or block outbound payoff for some injection shapes (e.g. OS command, SSRF, certain C2), but the weakness itself (unneutralized input reaching an interpreter) remains realized for dominant members such as SQLi and reflected XSS.
- A07mitigates — A.8.21's authentication/authorization rules, monitoring, encryption, and access controls for network services limit the blast radius or consequence of realized authentication failures (e.g. via VPN, connection controls, or session attributes) but do not address the core identity-verification, credential-stuffing, or session-management defects named in A07.
- A07prevents — A.8.21 explicitly requires authentication requirements, authorization procedures, network connection controls, and monitoring for network services, which directly blocks many authentication bypass, brute-force, credential stuffing, and session hijacking vectors when those services are network-facing; however, it is silent on application-layer specifics such as password reset flows, weak credential storage, or session token implementation details that dominate the OWASP category.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.