{"data":{"id":"SI-03","name":"Malicious Code Protection","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"a. Implement [Selection (one or more): signature based; non-signature based] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code;\nb. Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures;\nc. Configure malicious code protection mechanisms to:\n1. Perform periodic scans of the system [Assignment: organization-defined frequency] and real-time scans of files from external sources at [Selection (one or more): endpoint; network entry and exit points] as the files are downloaded, opened, or executed in accordance with organizational policy; and\n2. [Selection (one or more): block malicious code; quarantine malicious code; take [Assignment: organization-defined action]]; and send alert to [Assignment: organization-defined personnel or roles] in response to malicious code detection; and\nd. Address the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the system.","supplemental_guidance":"System entry and exit points include firewalls, remote access servers, workstations, electronic mail servers, web servers, proxy servers, notebook computers, and mobile devices. Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code can also be encoded in various formats contained within compressed or hidden files or hidden in files using techniques such as steganography. Malicious code can be inserted into systems in a variety of ways, including by electronic mail, the world-wide web, and portable storage devices. Malicious code insertions occur through the exploitation of system vulnerabilities. A variety of technologies and methods exist to limit or eliminate the effects of malicious code.\n\nMalicious code protection mechanisms include both signature- and nonsignature-based technologies. Nonsignature-based detection mechanisms include artificial intelligence techniques that use heuristics to detect, analyze, and describe the characteristics or behavior of malicious code and to provide controls against such code for which signatures do not yet exist or for which existing signatures may not be effective. Malicious code for which active signatures do not yet exist or may be ineffective includes polymorphic malicious code (i.e., code that changes signatures when it replicates). Nonsignature-based mechanisms also include reputation-based technologies. In addition to the above technologies, pervasive configuration management, comprehensive software integrity controls, and anti-exploitation software may be effective in preventing the execution of unauthorized code. Malicious code may be present in commercial off-the-shelf software as well as custom-built software and could include logic bombs, backdoors, and other types of attacks that could affect organizational mission and business functions.\n\nIn situations where malicious code cannot be detected by detection methods or technologies, organizations rely on other types of controls, including secure coding practices, configuration management and control, trusted procurement processes, and monitoring practices to ensure that software does not perform functions other than the functions intended. Organizations may determine that, in response to the detection of malicious code, different actions may be warranted. For example, organizations can define actions in response to malicious code detection during periodic scans, the detection of malicious downloads, or the detection of maliciousness when attempting to open or execute files.","enhancements":[{"id":"SI-03(01)","name":"Central Management","withdrawn":true,"incorporated_into":["PL-09"]},{"id":"SI-03(02)","name":"Automatic Updates","withdrawn":true,"incorporated_into":["SI-03"]},{"id":"SI-03(03)","name":"Non-privileged Users","withdrawn":true,"incorporated_into":["AC-06(10)"]},{"id":"SI-03(04)","name":"Updates Only by Privileged Users","statement":"Update malicious code protection mechanisms only when directed by a privileged user.","baselines":[]},{"id":"SI-03(05)","name":"Portable Storage Devices","withdrawn":true,"incorporated_into":["MP-07"]},{"id":"SI-03(06)","name":"Testing and Verification","statement":"a. Test malicious code protection mechanisms [Assignment: organization-defined frequency] by introducing known benign code into the system; and\nb. Verify that the detection of the code and the associated incident reporting occur.","baselines":[]},{"id":"SI-03(07)","name":"Nonsignature-based Detection","withdrawn":true,"incorporated_into":["SI-03"]},{"id":"SI-03(08)","name":"Detect Unauthorized Commands","statement":"a. Detect the following unauthorized operating system commands through the kernel application programming interface on [Assignment: organization-defined system hardware components]: [Assignment: organization-defined unauthorized operating system commands]; and\nb. [Selection (one or more): issue a warning; audit the command execution; prevent the execution of the command].","baselines":[]},{"id":"SI-03(09)","name":"Authenticate Remote Commands","withdrawn":true,"incorporated_into":["AC-17(10)"]},{"id":"SI-03(10)","name":"Malicious Code Analysis","statement":"a. Employ the following tools and techniques to analyze the characteristics and behavior of malicious code: [Assignment: organization-defined tools and techniques]; and\nb. Incorporate the results from malicious code analysis into organizational incident response and flaw remediation processes.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SI-03","name":"Malicious Code Protection","description":"a. Implement [Selection (one or more): signature based; non-signature based] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code;\nb. Automatically update malicious code protection mechanisms as new releases are available in accordance with organizational configuration management policy and procedures;\nc. Configure malicious code protection mechanisms to:\n1. Perform periodic scans of the system [Assignment: organization-defined frequency] and real-time scans of files from external sources at [Selection (one or more): endpoint; network entry and exit points] as the files are downloaded, opened, or executed in accordance with organizational policy; and\n2. [Selection (one or more): block malicious code; quarantine malicious code; take [Assignment: organization-defined action]]; and send alert to [Assignment: organization-defined personnel or roles] in response to malicious code detection; and\nd. Address the receipt of false positives during malicious code detection and eradication and the resulting potential impact on the availability of the system.","discussion":"System entry and exit points include firewalls, remote access servers, workstations, electronic mail servers, web servers, proxy servers, notebook computers, and mobile devices. Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code can also be encoded in various formats contained within compressed or hidden files or hidden in files using techniques such as steganography. Malicious code can be inserted into systems in a variety of ways, including by electronic mail, the world-wide web, and portable storage devices. Malicious code insertions occur through the exploitation of system vulnerabilities. A variety of technologies and methods exist to limit or eliminate the effects of malicious code.\n\nMalicious code protection mechanisms include both signature- and nonsignature-based technologies. Nonsignature-based detection mechanisms include artificial intelligence techniques that use heuristics to detect, analyze, and describe the characteristics or behavior of malicious code and to provide controls against such code for which signatures do not yet exist or for which existing signatures may not be effective. Malicious code for which active signatures do not yet exist or may be ineffective includes polymorphic malicious code (i.e., code that changes signatures when it replicates). Nonsignature-based mechanisms also include reputation-based technologies. In addition to the above technologies, pervasive configuration management, comprehensive software integrity controls, and anti-exploitation software may be effective in preventing the execution of unauthorized code. Malicious code may be present in commercial off-the-shelf software as well as custom-built software and could include logic bombs, backdoors, and other types of attacks that could affect organizational mission and business functions.\n\nIn situations where malicious code cannot be detected by detection methods or technologies, organizations rely on other types of controls, including secure coding practices, configuration management and control, trusted procurement processes, and monitoring practices to ensure that software does not perform functions other than the functions intended. Organizations may determine that, in response to the detection of malicious code, different actions may be warranted. For example, organizations can define actions in response to malicious code detection during periodic scans, the detection of malicious downloads, or the detection of maliciousness when attempting to open or execute files.","related_controls":["AC-04","AC-19","CM-03","CM-08","IR-04","MA-03","MA-04","PL-09","RA-05","SC-07","SC-23","SC-26","SC-28","SC-44","SI-02","SI-04","SI-07","SI-08","SI-15"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Parameter adds '[Selection (one or more): signature based; non-signature based]'; another parameter adds requirement to send an alert to specified personnel Parameter selection eliminates option to send an alert to specified personnel and adds option to take specified action Discussion expanded to explain signature- and non-signature-based technologies Incorporates withdrawn controls SI-03(2) and SI-03(7)"}},"compliance_mappings":{"iso_27001_2022":["A.8.7","A.8.23"],"iso_27002_2022":["8.7","8.23"],"cobit_2019":["DSS05"],"pci_dss_v4":["5.1","5.2","5.3","6.4"],"nist_csf_2":["PR.DS-01","PR.DS-02","PR.DS-10","RS.MI-02"],"cis_controls_v8":["CIS 9","CIS 9.3","CIS 9.6","CIS 9.7","CIS 10","CIS 10.1","CIS 10.2","CIS 10.4","CIS 10.6","CIS 10.7"],"soc2_tsc":["CC6.6","CC6.6-POF2","CC6.8","CC9.2-POF13"],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":["E8-3","E8-3 ML2"],"nis2":[],"apra_cps_234":["Para 22-23"],"mas_trm":["11"],"pra_op_resilience":[],"bsi_grundschutz":["APP.1.1","OPS.1.1.4"],"anssi":["Hygiene.21","SecNumCloud.13.1"],"osfi_b13":["B-13.3.2","B-13.3.3"],"finma_circular":["IV.B.d(59)","IV.C(64)","IV.C(65)"],"gdpr":["Art.32(1)(b)"],"dora":["Art.9(4)(b)"],"bio2":["8.7","8.23"],"rbi_csf":["Annex1.13"],"fisc":["FISC.T7","FISC.T14"],"lgpd_bcb":["BCB.Art.3","LGPD.Art.46"],"hkma_tme1":["TME1.7.3","TME1.10.1"],"mlps_2":["8.1.3.3","8.1.3.4","8.1.4.5","8.1.10.5"],"dnb_good_practice":["DNB.19.1"],"cra":["CRA.I.2i"],"swift_cscf":["SWIFT.6.1"],"cbb_tm":["TM-8"],"cbuae":["CR-7"],"nca_ecc":["2-3","2-4"],"qatar_nia":["OS"],"sama_csf":["3.3"],"uae_ia":["T7"],"bog_cisd":["CISD-VI"],"cbe_csf":["CTO-7","CTO-8"],"cbn_csf":["Part3.3"],"popia":["s19"],"sa_js2":["JS2-7.2","JS2-8.4"],"bot_cyber":["Ch2.6","Ch8.2"],"cpmi_pfmi":["CG.DE","CG.PR"],"eba_ict":["3.4.4"],"ecb_croe":["CROE.2.3.4","CROE.2.4"],"ffiec_is":["II.C.12"],"hipaa_sr":["§164.308(a)(5)(ii)(B)"],"iosco_cyber":["DET-3"],"nydfs_500":["500.14"],"sebi_cscrf":["DE.DP","PR.ES"],"cmmc_2":["SI"],"nerc_cip":["CIP-007-6"],"nrc_73_54":["RG5.71-A-SI"],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":["Sec 7"],"awia":[],"iaea_nss":["Sec 5.4"],"pci_pts":[],"fips_140":["FIPS 140-3 §7.6"],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 4"],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":["PU-3"],"hitrust_csf":["09.c"],"iso_27799":["12.2"],"lloyds_ms":["MS8.10"],"naic_ds":["4-monitoring","4B"],"nhs_dspt":["NDG-9.3","NDG-9.4"],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":["TVM-02","TVM-04","UEM-09"],"csa_aicm":["TVM-02","TVM-04","UEM-09"],"ccss_v9":["1.01.3","1.05.4"],"mica":[],"basel_sco60":["SCO60.51","SCO60.64","SCO60.65"],"bssc":[],"sec_custody_digital":[],"dpdpa":["Act.8(5)","Rules.Sch1.B.7"]},"attack_techniques":[{"id":"T1001","name":"Data Obfuscation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection mechanisms deployed at network entry and exit points can inspect traffic for obfuscated command-and-control data by employing heuristic and behavioral analysis beyond signature-based detection, identifying anomalous data patterns indicative of covert channels."},{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions with memory-scanning capabilities can detect credential-dumping tools such as Mimikatz and gsecdump resident in memory, blocking the extraction of password hashes and plaintext credentials from operating system processes."},{"id":"T1005","name":"Data from Local System","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Endpoint malicious code protection can detect and quarantine data-harvesting malware—including keyloggers, spyware, and information stealers—before they can collect and stage sensitive files from local storage for exfiltration."},{"id":"T1008","name":"Fallback Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at network boundaries can identify malware beaconing patterns that attempt to establish fallback C2 channels, detecting the characteristic retry and protocol-switching behaviors even when primary channels are disrupted."},{"id":"T1025","name":"Data from Removable Media","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning of removable media upon insertion—as specified in SI-03's requirement for protection at entry points—can detect malicious collection tools designed to harvest data from USB drives, external hard disks, and other removable storage."},{"id":"T1027","name":"Obfuscated Files or Information","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Multi-engine malicious code protection employing behavioral analysis, sandboxing, and heuristic detection can identify obfuscated malware that evades signature-based methods through encoding, encryption, or packing of files and payloads."},{"id":"T1029","name":"Scheduled Transfer","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection mechanisms monitoring outbound traffic patterns can detect malware that stages data exfiltration on scheduled intervals, identifying the characteristic periodic transfer behavior as anomalous automated activity."},{"id":"T1030","name":"Data Transfer Size Limits","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions with data-loss-prevention capabilities can detect malware that breaks exfiltrated data into size-limited chunks to evade threshold-based detection, correlating multiple small transfers as a unified exfiltration campaign."},{"id":"T1036","name":"Masquerading","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with file integrity and metadata analysis can detect executables masquerading as legitimate system files by comparing file hashes, digital signatures, and behavioral profiles against known-good baselines."},{"id":"T1037","name":"Boot or Logon Initialization Scripts","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning of boot and logon initialization scripts can detect malicious code injected into startup sequences, preventing persistent backdoors from executing during system boot or user logon events."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at network boundaries can inspect C2 channel traffic for embedded exfiltration payloads, detecting malware that piggybacks data theft onto existing command-and-control communications."},{"id":"T1046","name":"Network Service Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect and block network scanning tools and scripts commonly used for service discovery, preventing adversaries from mapping network topology and identifying exploitable services."},{"id":"T1047","name":"Windows Management Instrumentation","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Endpoint malicious code protection can detect malicious use of WMI by identifying known attack tools and suspicious WMI-based execution patterns, blocking adversaries from leveraging Windows Management Instrumentation for remote code execution."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection deployed at network exit points can detect exfiltration malware that transmits stolen data over alternative protocols such as DNS, ICMP, or custom protocols not normally used for data transfer."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning at endpoint level can detect exfiltration tools that stage and copy data to physical media, and scanning removable media upon connection prevents transfer of data-harvesting malware to air-gapped systems."},{"id":"T1055","name":"Process Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Endpoint malicious code protection with runtime behavior monitoring can detect process injection techniques by identifying suspicious cross-process memory operations, API call sequences, and code execution within non-standard process contexts."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect and block malicious scripts and commands executed through interpreters by employing content inspection, script emulation, and behavioral analysis of command-line activity."},{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions with exploit-prevention capabilities—including memory protection and behavioral detection—can identify and block exploit code targeting software vulnerabilities before privilege escalation succeeds."},{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect tools designed to tamper with forensic evidence, identifying known indicator-removal utilities and suspicious file-deletion or log-manipulation behaviors as malicious activity."},{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at network boundaries with deep-packet inspection can identify C2 traffic disguised within legitimate application-layer protocols such as HTTP, HTTPS, DNS, and SMTP by detecting malicious payloads and anomalous protocol usage."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning can detect malicious payloads distributed through compromised software deployment tools, preventing adversaries from leveraging trusted distribution infrastructure for lateral movement and code execution."},{"id":"T1080","name":"Taint Shared Content","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection scanning shared network drives and collaboration platforms can detect and quarantine tainted files before other users access them, preventing lateral movement through poisoned shared content."},{"id":"T1090","name":"Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at network boundaries can detect proxy-based C2 infrastructure by identifying malware that establishes proxy connections, relay chains, or SOCKS tunnels to obscure the true origin of command-and-control traffic."},{"id":"T1091","name":"Replication Through Removable Media","tactics":["initial-access","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning of removable media at insertion—a core SI-03 requirement—directly prevents replication of malicious code through USB drives and other removable storage by detecting and quarantining self-propagating malware."},{"id":"T1092","name":"Communication Through Removable Media","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection on endpoints can detect malware designed to communicate via removable media in air-gapped environments, scanning files written to and read from USB devices for known C2 protocols and suspicious data patterns."},{"id":"T1095","name":"Non-Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network-based malicious code protection can inspect non-application-layer protocol traffic (ICMP, raw sockets, custom protocols) for embedded C2 payloads, detecting covert channels that bypass application-layer security controls."},{"id":"T1102","name":"Web Service","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect malware that uses legitimate web services (cloud storage, social media, paste sites) as C2 infrastructure by identifying suspicious API calls and data exchange patterns with these services."},{"id":"T1104","name":"Multi-Stage Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect multi-stage malware delivery by scanning downloaded payloads at each stage, blocking initial droppers, secondary loaders, and final-stage implants before they establish persistent C2 channels."},{"id":"T1105","name":"Ingress Tool Transfer","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning at network entry points and endpoints can detect and block adversary tools transferred into the environment, quarantining malicious binaries, scripts, and exploitation frameworks during download."},{"id":"T1106","name":"Native API","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Endpoint malicious code protection with behavioral monitoring can detect malicious use of native operating system APIs by identifying suspicious API call patterns characteristic of malware execution, including unusual process creation and memory manipulation sequences."},{"id":"T1111","name":"Multi-Factor Authentication Interception","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect MFA-interception malware such as credential-harvesting trojans and token-theft tools that hook into authentication processes, preventing adversaries from capturing multi-factor authentication tokens and one-time codes."},{"id":"T1129","name":"Shared Modules","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect adversary use of shared modules by scanning loaded DLLs and shared libraries for malicious code, identifying unauthorized or modified modules loaded into legitimate processes."},{"id":"T1132","name":"Data Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with traffic analysis capabilities can detect encoded C2 communications by identifying non-standard encoding schemes (Base64, XOR, custom encoding) in network traffic that deviate from legitimate protocol patterns."},{"id":"T1137","name":"Office Application Startup","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning of Office application startup locations—including templates, add-ins, and COM objects—can detect malicious code planted to execute when Office applications launch, preventing persistence through trusted productivity software."},{"id":"T1176","name":"Browser Extensions","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious browser extensions that harvest credentials, inject content, or establish persistence by scanning extension packages for known malware signatures and suspicious behavioral patterns."},{"id":"T1185","name":"Browser Session Hijacking","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Endpoint anti-malware with browser protection capabilities can detect man-in-the-browser attacks and session hijacking tools that inject into browser processes, preventing adversaries from intercepting web sessions and authentication tokens."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at web gateways and endpoints can detect and block drive-by compromise payloads—including exploit kits, malicious JavaScript, and weaponized content—before browser vulnerabilities are exploited for initial access."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions on public-facing servers can detect web shells, backdoors, and exploitation payloads uploaded through application vulnerabilities, preventing adversaries from establishing persistent access through exploited internet-facing services."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect compromised software distributed through supply chain attacks by scanning all incoming software packages, updates, and dependencies for embedded malware, trojans, and unauthorized code modifications."},{"id":"T1201","name":"Password Policy Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect reconnaissance tools and scripts used to enumerate password policies, blocking utilities commonly employed by adversaries to gather information that informs subsequent brute-force or credential-stuffing attacks."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Endpoint malicious code protection with exploit prevention can detect and block exploitation of client application vulnerabilities—in browsers, document readers, and office suites—by identifying malicious payloads targeting memory corruption and code execution flaws."},{"id":"T1204","name":"User Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning can intercept and block malicious files and links before user execution, providing a critical safety net when social engineering bypasses user awareness training and users attempt to open weaponized content."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection on networked systems can detect exploitation tools and payloads targeting remote service vulnerabilities, blocking lateral movement attempts that leverage unpatched services for remote code execution."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions with exploit detection capabilities can identify code that exploits software vulnerabilities to evade security controls, detecting exploitation attempts aimed at disabling defenses or bypassing security enforcement."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect exploitation tools targeting authentication and credential-storage vulnerabilities, blocking adversary attempts to leverage software flaws for unauthorized credential access."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware with behavioral analysis can detect malicious payloads executed through signed system binaries (LOLBins), identifying when trusted utilities like mshta, regsvr32, or rundll32 are used to proxy-execute malicious code."},{"id":"T1219","name":"Remote Access Software","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect unauthorized remote access tools—such as TeamViewer, AnyDesk, or custom RATs—installed by adversaries, distinguishing them from legitimate remote administration software through behavioral and signature analysis."},{"id":"T1221","name":"Template Injection","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning of document files can detect template injection attacks where malicious remote templates are loaded into Office documents, blocking the retrieval and execution of weaponized template payloads."},{"id":"T1485","name":"Data Destruction","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect and block destructive malware—including wipers and ransomware—before they execute data destruction routines, quarantining payloads designed to permanently delete or corrupt organizational data."},{"id":"T1486","name":"Data Encrypted for Impact","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions are a primary defense against ransomware, detecting encryption routines, known ransomware families, and suspicious mass-file-encryption behaviors to block data encryption for impact before files become inaccessible."},{"id":"T1490","name":"Inhibit System Recovery","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malware that deletes shadow copies, disables recovery services, or modifies boot configuration to inhibit system recovery, blocking these destructive actions that prevent restoration after an attack."},{"id":"T1491","name":"Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning on web servers and internal systems can detect defacement tools and web shells that modify content for visual impact, preventing adversaries from altering websites or internal portals for propaganda or disruption."},{"id":"T1525","name":"Implant Internal Image","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can scan container images and virtual machine templates for implanted backdoors and malicious code, detecting adversary modifications to internal images before they are deployed across the infrastructure."},{"id":"T1539","name":"Steal Web Session Cookie","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Endpoint anti-malware can detect cookie-stealing malware and browser-session-theft tools that extract session tokens from browser storage, preventing adversaries from hijacking authenticated web sessions."},{"id":"T1543","name":"Create or Modify System Process","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malware that creates or modifies system services and daemons for persistence, identifying suspicious service installations and unauthorized modifications to system process configurations."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect tools that abuse elevation control mechanisms—such as UAC bypass utilities—blocking malicious code designed to escalate privileges through exploitation of trust boundaries."},{"id":"T1554","name":"Compromise Host Software Binary","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with file-integrity capabilities can detect modifications to legitimate host software binaries, identifying trojaned executables where adversaries have replaced or patched system binaries to maintain persistence."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect man-in-the-middle attack tools—such as Responder, Ettercap, and mitmproxy—blocking adversary interception of network communications used to harvest credentials and manipulate data in transit."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect Kerberos attack tools such as Rubeus and Impacket that forge or steal tickets, blocking the execution of utilities used for golden ticket, silver ticket, and kerberoasting attacks."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware with behavioral monitoring can detect malicious inter-process communication exploitation, identifying when COM objects or DDE channels are abused to execute arbitrary code across application boundaries."},{"id":"T1560","name":"Archive Collected Data","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect data-staging tools that archive and compress collected data for exfiltration, identifying suspicious use of archiving utilities and custom compression routines indicative of pre-exfiltration staging."},{"id":"T1561","name":"Disk Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect and block disk-wiping malware—such as Shamoon, NotPetya, and similar destructive tools—before they execute disk content or structure wipe operations that render systems inoperable."},{"id":"T1562","name":"Impair Defenses","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with self-defense capabilities can detect and resist attempts to disable or modify security tools, maintaining defensive coverage even when adversaries specifically target anti-malware mechanisms."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at email gateways and endpoints is a primary defense against phishing, scanning attachments and linked content for malware, exploit code, and weaponized documents before they reach end users."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect exfiltration malware that transmits stolen data to cloud storage services, code repositories, or other web services, identifying suspicious automated uploads to external platforms."},{"id":"T1568","name":"Dynamic Resolution","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malware employing dynamic resolution techniques—including domain generation algorithms and fast-flux DNS—by identifying characteristic resolution patterns and blocking connections to algorithmically generated domains."},{"id":"T1569","name":"System Services","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious payloads executed through system services, identifying when service control mechanisms are leveraged to launch unauthorized code with elevated privileges."},{"id":"T1570","name":"Lateral Tool Transfer","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection scanning network file transfers can detect adversary tools being moved laterally between systems, quarantining malicious binaries, scripts, and exploitation frameworks during internal transfer."},{"id":"T1571","name":"Non-Standard Port","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network-based malicious code protection can detect C2 traffic on non-standard ports by correlating protocol analysis with port usage, identifying communications where the observed protocol does not match the expected service for that port."},{"id":"T1572","name":"Protocol Tunneling","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions with network inspection capabilities can detect protocol tunneling—such as DNS tunneling or HTTP encapsulation—by identifying anomalous protocol behavior and data patterns indicative of covert channel encapsulation."},{"id":"T1573","name":"Encrypted Channel","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with TLS inspection capabilities can detect malicious encrypted C2 channels by analyzing certificate anomalies, connection patterns, and decrypted payload content for known malware indicators."},{"id":"T1574","name":"Hijack Execution Flow","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect execution-flow hijacking techniques by monitoring for suspicious DLL loads, path interception, and library injection, identifying when legitimate applications are redirected to execute malicious code."},{"id":"T1598","name":"Phishing for Information","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at email gateways can scan reconnaissance-focused phishing messages for malicious attachments and links, blocking attempts to harvest sensitive organizational information through social engineering."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions on network management systems can detect tools used to extract configuration data from network devices, blocking unauthorized SNMP queries and configuration dump utilities."},{"id":"T1611","name":"Escape to Host","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection within containerized environments can detect container escape exploits and tools, preventing malicious code from breaking out of container isolation to compromise the underlying host system."},{"id":"T1622","name":"Debugger Evasion","tactics":["defense-evasion","discovery"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware with advanced evasion detection can identify malware that employs debugger evasion techniques—such as timing checks, debug-flag queries, and environment fingerprinting—treating these anti-analysis behaviors as indicators of malicious intent."},{"id":"T1001.001","name":"Junk Data","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with traffic analysis can detect C2 communications padded with junk data by identifying statistical anomalies in packet size distributions and payload entropy that deviate from legitimate protocol patterns."},{"id":"T1001.002","name":"Steganography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions with content inspection capabilities can detect steganographic payloads hidden within image, audio, or video files by analyzing files for embedded data that does not match the expected media format structure."},{"id":"T1001.003","name":"Protocol or Service Impersonation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at network boundaries can detect C2 traffic impersonating legitimate protocols by performing deep protocol validation, identifying communications that superficially resemble standard services but contain malicious command structures."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect credential-dumping tools that target LSASS process memory—such as Mimikatz and ProcDump—blocking attempts to extract plaintext passwords, NTLM hashes, and Kerberos tickets from the LSASS address space."},{"id":"T1003.002","name":"Security Account Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect tools that extract password hashes from the SAM database by identifying known SAM-dumping utilities and suspicious registry access patterns targeting the SAM hive."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect tools targeting the NTDS.dit Active Directory database—such as ntdsutil abuse and volume shadow copy extraction—blocking attempts to harvest domain-wide credential material from domain controllers."},{"id":"T1003.004","name":"LSA Secrets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect utilities that dump LSA secrets from the Windows registry, including service account passwords, cached credentials, and other sensitive authentication material stored in the LSA secret store."},{"id":"T1003.005","name":"Cached Domain Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect tools that extract cached domain credentials (DCC2 hashes) from the Windows registry, blocking offline credential-cracking attacks against cached logon material."},{"id":"T1003.006","name":"DCSync","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect DCSync attack tools that impersonate domain controllers to request credential replication via the MS-DRSR protocol, blocking unauthorized directory replication attempts."},{"id":"T1003.007","name":"Proc Filesystem","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware on Linux systems can detect tools that read credential material from the /proc filesystem, identifying suspicious access to process memory spaces where authentication tokens and passwords may be stored."},{"id":"T1003.008","name":"/etc/passwd and /etc/shadow","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect tools targeting /etc/passwd and /etc/shadow files for credential harvesting, blocking unauthorized read access and known password-file extraction utilities on Unix and Linux systems."},{"id":"T1011.001","name":"Exfiltration Over Bluetooth","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning can detect exfiltration tools that leverage Bluetooth connections to transmit stolen data to nearby adversary-controlled devices, identifying suspicious Bluetooth data-transfer utilities and malware."},{"id":"T1021.003","name":"Distributed Component Object Model","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious use of DCOM for lateral movement by identifying known attack tools and suspicious remote DCOM instantiation patterns that deviate from normal administrative activity."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect unauthorized VNC tools and malicious remote-access agents installed to provide adversaries with graphical remote control, distinguishing them from legitimate VNC deployments."},{"id":"T1027.002","name":"Software Packing","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with unpacking and emulation capabilities can analyze packed executables to reveal hidden malicious code, defeating software packing used to evade static signature-based detection."},{"id":"T1027.007","name":"Dynamic API Resolution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware with behavioral analysis can detect malware using dynamic API resolution—resolving Windows API functions at runtime via hash lookups—by monitoring suspicious GetProcAddress patterns and API call obfuscation techniques."},{"id":"T1027.008","name":"Stripped Payloads","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with heuristic analysis can detect stripped payloads where debug symbols and metadata have been removed, employing behavioral and entropy-based analysis to identify malicious binaries despite the absence of identifying strings."},{"id":"T1027.009","name":"Embedded Payloads","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning can detect executables containing embedded payloads—such as encrypted shellcode or secondary malware hidden within carrier files—by analyzing binary structure for concealed executable content."},{"id":"T1027.010","name":"Command Obfuscation","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with command-line analysis can detect obfuscated commands using techniques like string concatenation, environment variable substitution, and encoding to evade static detection of malicious script content."},{"id":"T1027.012","name":"LNK Icon Smuggling","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning can detect LNK files with smuggled icons that point to remote resources, identifying shortcut files designed to retrieve malicious payloads when their icons are rendered by Windows Explorer."},{"id":"T1027.013","name":"Encrypted/Encoded File","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Encrypted or encoded malware payloads are designed to evade signature-based detection; anti-malware solutions employing behavioral analysis, sandboxing, and heuristic evaluation provide alternative detection methods that can identify these obfuscated threats."},{"id":"T1027.014","name":"Polymorphic Code","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Polymorphic malware mutates its code with each propagation to evade signature detection; anti-malware employing behavioral analysis, emulation, and machine-learning classifiers can identify the underlying malicious behavior despite constant code transformation."},{"id":"T1036.003","name":"Rename System Utilities","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect renamed system utilities by comparing file hashes and metadata against known-good system binaries, identifying executables that have been renamed to avoid allowlisting or blend with legitimate tools."},{"id":"T1036.005","name":"Match Legitimate Name or Location","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect malware placed in legitimate directories or named to match trusted executables by performing file-hash verification and behavioral analysis that identifies mismatches between expected and actual file behavior."},{"id":"T1036.008","name":"Masquerade File Type","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect files with misleading extensions—such as executables disguised as documents—by analyzing actual file content and magic bytes rather than relying solely on file extension classification."},{"id":"T1037.002","name":"Login Hook","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning can detect malicious macOS login hooks by monitoring the LoginHook configuration and scanning referenced scripts for malicious code that executes at user login."},{"id":"T1037.003","name":"Network Logon Script","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious network logon scripts planted in SYSVOL or NETLOGON shares, scanning script content for malicious payloads that execute across multiple systems during domain authentication."},{"id":"T1037.004","name":"RC Scripts","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning of system initialization scripts can detect malicious code injected into RC scripts on Unix and Linux systems, preventing persistent backdoors from executing during system boot."},{"id":"T1037.005","name":"Startup Items","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious macOS startup items by scanning LaunchDaemons and LaunchAgents plists and their referenced executables for embedded malware or unauthorized persistent payloads."},{"id":"T1048.001","name":"Exfiltration Over Symmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware at network boundaries can detect exfiltration over symmetric-encrypted non-C2 protocols by identifying suspicious encrypted connections on unusual ports or to unexpected destinations not associated with normal business operations."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect exfiltration over asymmetric-encrypted non-C2 channels by analyzing outbound connection patterns for anomalous TLS/SSH sessions transferring data to unrecognized external endpoints."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware at network exit points can detect plaintext exfiltration over non-C2 protocols—such as FTP, DNS, or raw sockets—by inspecting outbound traffic for data patterns indicative of unauthorized bulk data transfer."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection scanning USB devices upon connection can detect exfiltration tools and staged data being copied to USB drives, preventing data theft through removable media at the endpoint level."},{"id":"T1055.001","name":"Dynamic-link Library Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware with runtime behavior monitoring can detect DLL injection attacks by identifying suspicious calls to CreateRemoteThread, LoadLibrary injection into foreign processes, and unauthorized DLL loading patterns."},{"id":"T1055.002","name":"Portable Executable Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect portable executable injection by monitoring for suspicious VirtualAllocEx and WriteProcessMemory calls that write executable code into remote process memory spaces."},{"id":"T1055.003","name":"Thread Execution Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware with behavioral detection can identify thread execution hijacking by monitoring for SuspendThread/SetThreadContext/ResumeThread call sequences that redirect legitimate thread execution to malicious code."},{"id":"T1055.004","name":"Asynchronous Procedure Call","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect asynchronous procedure call injection by identifying QueueUserAPC calls targeting threads in remote processes, a technique used to execute malicious code within a target process context."},{"id":"T1055.005","name":"Thread Local Storage","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect thread local storage injection by monitoring for manipulation of TLS callback mechanisms to execute malicious code during DLL loading sequences."},{"id":"T1055.008","name":"Ptrace System Calls","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection on Linux systems can detect ptrace-based process injection by monitoring for suspicious ptrace system calls that attach to running processes to inject and execute arbitrary code."},{"id":"T1055.009","name":"Proc Memory","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect injection via /proc/[pid]/mem by monitoring for suspicious writes to process memory through the proc filesystem, a technique used on Linux to inject code without ptrace."},{"id":"T1055.011","name":"Extra Window Memory Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect extra window memory injection by identifying suspicious manipulation of window memory structures (SetWindowLong/SetWindowLongPtr) to store and execute shellcode."},{"id":"T1055.012","name":"Process Hollowing","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware with behavioral analysis can detect process hollowing by identifying the characteristic pattern of creating a suspended process, unmapping its memory, writing malicious code to the hollowed space, and resuming execution."},{"id":"T1055.013","name":"Process Doppelgänging","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect process doppelganging by monitoring for suspicious NTFS transaction API usage (CreateFileTransacted) combined with process creation, a technique that abuses transactional NTFS to evade detection."},{"id":"T1055.014","name":"VDSO Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware on Linux can detect VDSO hijacking by monitoring for suspicious manipulation of the virtual dynamic shared object memory region, which adversaries may abuse to redirect system call execution."},{"id":"T1055.015","name":"ListPlanting","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect ListPlanting attacks by monitoring for suspicious manipulation of SysListView32 controls, where adversaries inject shellcode via list-view message handlers in target processes."},{"id":"T1056.002","name":"GUI Input Capture","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect fake GUI input-capture overlays—such as phishing dialog boxes mimicking system authentication prompts—by identifying unauthorized window creation and credential-harvesting behaviors."},{"id":"T1059.001","name":"PowerShell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with script-analysis capabilities can detect malicious PowerShell scripts through content inspection, AMSI integration, and behavioral monitoring of encoded commands, download cradles, and obfuscated execution patterns."},{"id":"T1059.002","name":"AppleScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware on macOS can detect malicious AppleScript execution by scanning script content for suspicious commands including system event manipulation, application scripting abuse, and osascript-based payload delivery."},{"id":"T1059.003","name":"Windows Command Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious Windows command shell usage by analyzing cmd.exe command-line arguments for encoded payloads, suspicious batch file content, and command patterns associated with known attack frameworks."},{"id":"T1059.004","name":"Unix Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware on Unix and Linux systems can detect malicious shell scripts by scanning bash, sh, and zsh script content for reverse shells, download-and-execute patterns, and known exploitation payloads."},{"id":"T1059.005","name":"Visual Basic","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious Visual Basic scripts and macros by scanning VBS/VBA content for suspicious API calls, obfuscation patterns, and payload-delivery techniques commonly used in initial-access campaigns."},{"id":"T1059.006","name":"Python","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect malicious Python script execution by identifying suspicious Python-based attack tools, encoded payloads, and known exploitation frameworks written in Python running on endpoints."},{"id":"T1059.007","name":"JavaScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious JavaScript execution by scanning for obfuscated JS payloads, suspicious eval() chains, and known attack patterns in both browser and server-side JavaScript contexts."},{"id":"T1059.008","name":"Network Device CLI","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions on network infrastructure can detect malicious commands executed through network device CLIs by identifying suspicious configuration changes and known exploitation command sequences."},{"id":"T1059.010","name":"AutoHotKey & AutoIT","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious AutoHotKey and AutoIT scripts by scanning compiled executables and script content for automation-based attack patterns, keylogging routines, and GUI manipulation used in credential theft."},{"id":"T1059.011","name":"Lua","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious Lua scripts by scanning for suspicious Lua-based payloads that may be embedded within legitimate applications or used as standalone attack scripts for code execution."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect tools designed to clear Windows Event Logs by identifying known log-wiping utilities and suspicious calls to wevtutil or the Event Log API that attempt to destroy forensic evidence."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware on Unix and macOS systems can detect tools and scripts that clear system logs (/var/log, syslog, auth.log), blocking attempts to eliminate forensic evidence of adversary activity."},{"id":"T1070.003","name":"Clear Command History","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect utilities that clear command history files (.bash_history, .zsh_history, PSReadLine) to cover adversary tracks, identifying suspicious file-truncation and history-manipulation behaviors."},{"id":"T1070.007","name":"Clear Network Connection History and Configurations","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect tools that clear network connection history and saved configurations—including WiFi profiles, ARP caches, and DNS resolver caches—used by adversaries to remove evidence of lateral movement."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect tools that delete or manipulate mailbox data to cover tracks, identifying suspicious Exchange or mail-client operations that bulk-delete emails containing evidence of compromise."},{"id":"T1070.009","name":"Clear Persistence","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect adversary tools that remove their own persistence mechanisms post-operation, identifying the characteristic pattern of persistence artifact cleanup as an indicator of a completed attack lifecycle."},{"id":"T1070.010","name":"Relocate Malware","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with behavioral tracking can detect malware that relocates itself to different directories or renames its files to evade detection, identifying suspicious file-movement patterns and self-modification behaviors."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware at network boundaries can detect C2 traffic over HTTP/HTTPS by analyzing web request patterns, identifying beaconing behavior, suspicious User-Agent strings, and anomalous data volumes in web protocol traffic."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect C2 communications over file transfer protocols (FTP, FTPS, TFTP) by scanning transferred content for embedded commands and identifying anomalous file-transfer sessions to unknown destinations."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware at email gateways can detect C2 communications disguised as mail traffic by analyzing SMTP/IMAP/POP3 sessions for embedded command structures and unusual mail-exchange patterns with adversary infrastructure."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with DNS inspection capabilities can detect DNS-based C2 channels by analyzing query patterns for high-entropy subdomain names, anomalous query volumes, and TXT record abuse characteristic of DNS tunneling."},{"id":"T1090.001","name":"Internal Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect internal proxy tools—such as SOCKS proxies and port forwarders—deployed by adversaries within the network to relay C2 traffic, identifying unauthorized proxy software and suspicious connection-relaying behavior."},{"id":"T1090.002","name":"External Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at network boundaries can detect connections to external proxy infrastructure used to anonymize C2 traffic, identifying adversary-controlled proxy servers and suspicious connection-chaining patterns."},{"id":"T1098.004","name":"SSH Authorized Keys","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect tools that plant unauthorized SSH authorized keys for persistent remote access, identifying modifications to authorized_keys files as potential backdoor installation."},{"id":"T1102.001","name":"Dead Drop Resolver","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malware using dead drop resolvers on legitimate web services to retrieve C2 addresses, identifying suspicious API calls to social media, paste sites, and cloud platforms used for address resolution."},{"id":"T1102.002","name":"Bidirectional Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect malware maintaining bidirectional C2 through web services by identifying suspicious persistent connections and data-exchange patterns with cloud storage, collaboration platforms, or social media APIs."},{"id":"T1102.003","name":"One-Way Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malware using one-way web service communications for command retrieval by identifying periodic polling of paste sites, cloud storage, or social media for encoded instructions."},{"id":"T1132.001","name":"Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware with traffic inspection can detect C2 data encoded with standard schemes (Base64, Base32, URL encoding) by identifying encoded payloads within protocol fields that should contain plaintext data."},{"id":"T1132.002","name":"Non-Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect C2 communications using non-standard or custom encoding by performing entropy analysis and pattern matching on network traffic to identify data that deviates from expected protocol formats."},{"id":"T1137.001","name":"Office Template Macros","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning of Office template directories can detect malicious macros planted in global templates (Normal.dotm, Personal.xlsb), preventing persistence through code that executes every time Office applications open documents."},{"id":"T1204.001","name":"Malicious Link","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at email gateways and web proxies can scan and block malicious URLs before users click them, providing automated protection against social engineering that lures users to weaponized websites."},{"id":"T1204.002","name":"Malicious File","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning intercepts malicious files before user execution, detecting weaponized documents, trojanized installers, and malicious executables distributed through email attachments, downloads, or file shares."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can scan container images and virtual machine images for embedded malware before deployment, detecting backdoors and malicious code in images distributed through compromised or untrusted registries."},{"id":"T1218.001","name":"Compiled HTML File","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious payloads executed through compiled HTML help files (CHM) by scanning .chm content for embedded scripts, ActiveX controls, and exploitation techniques that abuse the HTML Help engine."},{"id":"T1218.002","name":"Control Panel","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious .cpl files loaded through the Control Panel by scanning control panel items for embedded exploitation code and suspicious DLL payloads."},{"id":"T1218.003","name":"CMSTP","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious code executed through CMSTP.exe by scanning INF files for embedded payloads and monitoring for suspicious CMSTP invocations that bypass application whitelisting."},{"id":"T1218.004","name":"InstallUtil","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious .NET assemblies executed through InstallUtil.exe by scanning managed binaries for embedded exploitation code in installer class methods."},{"id":"T1218.005","name":"Mshta","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious HTA files and scripts executed through mshta.exe by scanning HTML Application content for embedded VBScript, JScript, and PowerShell payloads."},{"id":"T1218.008","name":"Odbcconf","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious payloads loaded through odbcconf.exe by scanning response files and DLL arguments for exploitation code abusing the ODBC driver configuration utility."},{"id":"T1218.009","name":"Regsvcs/Regasm","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious .NET assemblies executed through Regsvcs/Regasm by scanning COM-registered binaries for embedded exploitation code in ComRegisterFunction methods."},{"id":"T1218.012","name":"Verclsid","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious COM objects validated through verclsid.exe by scanning referenced DLLs and CLSIDs for known malicious payloads executed during COM class verification."},{"id":"T1218.013","name":"Mavinject","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect DLL injection via mavinject.exe by monitoring for suspicious invocations of the Windows component used to inject DLLs into running processes under the guise of legitimate Microsoft functionality."},{"id":"T1218.014","name":"MMC","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious MMC snap-in files (.msc) that abuse the Microsoft Management Console to execute embedded scripts and payloads through trusted system management interfaces."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious code execution through Electron applications by scanning application packages for modified JavaScript, embedded payloads, and suspicious Node.js code within Electron-based software."},{"id":"T1491.001","name":"Internal Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection on internal systems can detect defacement tools and malware that modify internal web applications, portals, or shared resources for visual impact or intimidation."},{"id":"T1491.002","name":"External Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning on public-facing web servers can detect web shells and defacement scripts that modify external website content, preventing adversaries from altering public-facing pages for propaganda or disruption."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious IIS modules and handlers installed for web server persistence by scanning IIS components for unauthorized native and managed code modules added to the request pipeline."},{"id":"T1543.002","name":"Systemd Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious systemd service unit files by scanning service definitions for suspicious ExecStart commands, unauthorized binary paths, and persistence mechanisms disguised as legitimate system services."},{"id":"T1546.002","name":"Screensaver","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious screensaver files (.scr) installed for persistence by scanning screensaver executables for embedded malware that executes when the system enters screensaver mode."},{"id":"T1546.003","name":"Windows Management Instrumentation Event Subscription","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious WMI event subscriptions by scanning WMI permanent event consumers for suspicious scripts and commands that execute automatically in response to system events."},{"id":"T1546.004","name":"Unix Shell Configuration Modification","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious modifications to Unix shell configuration files (.bashrc, .profile, .zshrc) that establish persistence by executing adversary code at every shell session initialization."},{"id":"T1546.006","name":"LC_LOAD_DYLIB Addition","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware on macOS can detect malicious LC_LOAD_DYLIB additions to Mach-O binaries, identifying unauthorized dynamic library loading directives inserted to achieve code execution when legitimate applications launch."},{"id":"T1546.013","name":"PowerShell Profile","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious PowerShell profile modifications that execute adversary code at every PowerShell session startup, scanning profile scripts for embedded backdoors and download cradles."},{"id":"T1546.014","name":"Emond","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware on macOS can detect malicious emond rules and scripts by scanning the Event Monitor daemon configuration for unauthorized rules that trigger malicious code execution in response to system events."},{"id":"T1546.016","name":"Installer Packages","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious installer packages (.pkg, .msi) containing embedded backdoors and post-install scripts by scanning package contents for malicious payloads that execute during software installation."},{"id":"T1547.002","name":"Authentication Package","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious authentication packages by scanning DLLs registered in the LSA authentication package registry key, identifying unauthorized code that loads into the LSASS process at system startup."},{"id":"T1547.005","name":"Security Support Provider","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious Security Support Providers by scanning SSP/AP DLLs registered with LSA, blocking unauthorized code that intercepts authentication credentials during logon."},{"id":"T1547.006","name":"Kernel Modules and Extensions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious kernel modules and extensions by scanning loadable kernel modules (LKMs) and kexts for rootkit code, unauthorized system-call hooking, and kernel-level persistence mechanisms."},{"id":"T1547.007","name":"Re-opened Applications","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection on macOS can detect malicious applications configured to re-open at login, scanning applications in the re-opened items list for malware that persists through the login persistence mechanism."},{"id":"T1547.008","name":"LSASS Driver","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious LSASS driver DLLs loaded through the LSA driver registry key, identifying unauthorized code that achieves persistence and credential access by loading into the LSASS process."},{"id":"T1547.009","name":"Shortcut Modification","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect modified shortcut files (.lnk) that have been altered to point to malicious payloads, identifying shortcut modifications that redirect execution to adversary-controlled code at user login."},{"id":"T1547.013","name":"XDG Autostart Entries","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious XDG autostart entries on Linux desktop environments by scanning .desktop files in autostart directories for unauthorized executables configured to run at user login."},{"id":"T1548.004","name":"Elevated Execution with Prompt","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection on macOS can detect malware that triggers elevated execution prompts to trick users into granting administrator privileges, identifying unauthorized applications requesting elevation through AuthorizationExecuteWithPrivileges."},{"id":"T1548.006","name":"TCC Manipulation","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect tools that manipulate macOS Transparency, Consent, and Control (TCC) databases to grant unauthorized permissions, blocking attempts to bypass privacy protections through TCC.db modification."},{"id":"T1553.003","name":"SIP and Trust Provider Hijacking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect SIP and trust provider hijacking by monitoring for modifications to Subject Interface Package DLLs and trust provider registry entries, blocking attempts to subvert code-signing verification."},{"id":"T1557.001","name":"LLMNR/NBT-NS Poisoning and SMB Relay","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect LLMNR/NBT-NS poisoning tools such as Responder by identifying their characteristic broadcast poisoning behavior and SMB relay attack components on the local network."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect ARP cache poisoning tools by identifying known ARP spoofing utilities and suspicious gratuitous ARP packet generation indicative of man-in-the-middle positioning."},{"id":"T1557.003","name":"DHCP Spoofing","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect DHCP spoofing tools by identifying rogue DHCP server software and suspicious lease-offer behavior designed to redirect network traffic through adversary-controlled systems."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect silver ticket forgery tools by identifying Kerberos ticket manipulation utilities that create forged service tickets, blocking the use of crafted tickets for unauthorized service access."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect kerberoasting tools—such as Invoke-Kerberoast and Rubeus kerberoast—that request service tickets for offline password cracking, identifying the characteristic TGS request patterns and extraction utilities."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect AS-REP roasting tools that target accounts without Kerberos pre-authentication, identifying utilities that request and extract AS-REP messages for offline credential cracking."},{"id":"T1559.001","name":"Component Object Model","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious COM object abuse by scanning for suspicious COM instantiation patterns, identifying when adversaries leverage Component Object Model interfaces to execute arbitrary code across application boundaries."},{"id":"T1559.002","name":"Dynamic Data Exchange","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malicious DDE exploitation in Office documents by scanning for embedded DDE field codes that execute external commands, blocking document-based code execution through Dynamic Data Exchange."},{"id":"T1560.001","name":"Archive via Utility","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect adversary use of archiving utilities (7-Zip, WinRAR, tar) for data staging by identifying suspicious invocations that archive sensitive directories or create encrypted archives for exfiltration."},{"id":"T1561.001","name":"Disk Content Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect disk content wipe malware that overwrites file system data, blocking destructive payloads—such as those using raw disk writes—before they render stored data irrecoverable."},{"id":"T1561.002","name":"Disk Structure Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect disk structure wipe attacks that target master boot records, partition tables, and GUID partition tables, blocking malware that destroys disk structures to render systems completely unbootable."},{"id":"T1562.001","name":"Disable or Modify Tools","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with tamper-resistant self-defense mechanisms can detect and resist adversary attempts to disable, uninstall, or modify security tools, maintaining endpoint protection even under active attack."},{"id":"T1562.002","name":"Disable Windows Event Logging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect tools and techniques used to disable Windows Event Logging—including auditpol manipulation, service stopping, and registry modification—preventing adversaries from blinding monitoring capabilities."},{"id":"T1562.004","name":"Disable or Modify System Firewall","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect tools that disable or modify host firewalls by identifying suspicious netsh, iptables, or firewall-management commands that weaken network-level defenses."},{"id":"T1562.006","name":"Indicator Blocking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware with tamper protection can detect and prevent indicator-blocking techniques—such as ETW patching, AMSI bypasses, and Event Tracing manipulation—that adversaries use to prevent security telemetry collection."},{"id":"T1562.011","name":"Spoof Security Alerting","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect malware that spoofs security alerts or generates false notifications to create confusion, identifying unauthorized processes that mimic security tool interfaces or suppress legitimate warnings."},{"id":"T1564.004","name":"NTFS File Attributes","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malware hidden in NTFS alternate data streams by scanning ADS content for executable code, identifying a Windows-specific hiding technique that conceals malicious payloads within legitimate file metadata."},{"id":"T1564.008","name":"Email Hiding Rules","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect tools that create email hiding rules in Exchange or Outlook to conceal adversary communications, identifying suspicious mail-rule creation that auto-deletes or moves security notifications."},{"id":"T1564.009","name":"Resource Forking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware on macOS can detect malicious code hidden in resource forks—the legacy dual-fork file structure—identifying payloads concealed in the resource fork that evade file-scanning tools examining only the data fork."},{"id":"T1564.012","name":"File/Path Exclusions","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect adversary abuse of file-path exclusions in security tools, identifying malware deliberately placed in excluded directories or attempts to modify exclusion lists to create safe havens."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware at email gateways and endpoints scans spearphishing attachments—including weaponized documents, executables, and archives—for malicious content, detonating suspicious files in sandboxes to detect zero-day exploits."},{"id":"T1566.002","name":"Spearphishing Link","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection at email gateways can analyze URLs in spearphishing links, blocking access to known malicious domains, phishing pages, and exploit kit landing pages embedded in targeted email messages."},{"id":"T1566.003","name":"Spearphishing via Service","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware scanning extends to messages received through collaboration services (Slack, Teams, social media), detecting malicious files and links delivered through non-email communication channels."},{"id":"T1568.002","name":"Domain Generation Algorithms","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can identify malware using domain generation algorithms by detecting characteristic DGA resolver code patterns and blocking connections to algorithmically generated domains that lack legitimate DNS registrations."},{"id":"T1569.002","name":"Service Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect malicious binaries executed through the Windows Service Control Manager by scanning service executables for malware signatures and identifying suspicious service creation events."},{"id":"T1573.001","name":"Symmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection with TLS termination capabilities can inspect C2 traffic encrypted with symmetric cryptography, identifying malicious payloads within decrypted sessions that use AES, ChaCha20, or other symmetric algorithms."},{"id":"T1573.002","name":"Asymmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware at network boundaries with TLS inspection can analyze C2 channels using asymmetric cryptography (RSA, ECDHE key exchange), detecting malicious traffic through certificate analysis and decrypted content inspection."},{"id":"T1574.001","name":"DLL Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect DLL search-order hijacking by identifying malicious DLLs placed in application directories that override legitimate system libraries, blocking unauthorized code loaded through predictable search paths."},{"id":"T1574.004","name":"Dylib Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware on macOS can detect dylib hijacking by identifying malicious dynamic libraries placed to intercept application dylib loading, blocking unauthorized code execution through macOS library search-path abuse."},{"id":"T1574.007","name":"Path Interception by PATH Environment Variable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect path interception via PATH environment variable manipulation by identifying malicious executables placed in directories that appear earlier in the PATH than their legitimate counterparts."},{"id":"T1574.008","name":"Path Interception by Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect search-order hijacking by identifying malicious executables or libraries placed in locations where they are loaded before their legitimate counterparts due to predictable search-order behavior."},{"id":"T1574.009","name":"Path Interception by Unquoted Path","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect path interception through unquoted service paths by identifying malicious executables placed at path segments that Windows evaluates before reaching the intended service binary."},{"id":"T1574.013","name":"KernelCallbackTable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware can detect KernelCallbackTable hijacking by monitoring for suspicious modifications to the PEB's KernelCallbackTable pointer, identifying adversary attempts to redirect kernel callbacks to malicious code."},{"id":"T1574.014","name":"AppDomainManager","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can detect AppDomainManager hijacking by identifying unauthorized .NET configuration files or assemblies that redirect the CLR to load adversary-controlled code into managed application domains."},{"id":"T1598.001","name":"Spearphishing Service","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware at email and messaging gateways can scan phishing-for-information messages delivered through third-party services, blocking malicious attachments and links used for reconnaissance-stage social engineering."},{"id":"T1598.002","name":"Spearphishing Attachment","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection can scan attachments in reconnaissance-focused spearphishing emails for malicious content, blocking weaponized documents designed to harvest sensitive information or establish tracking callbacks."},{"id":"T1598.003","name":"Spearphishing Link","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware at email gateways can analyze URLs in reconnaissance spearphishing links, blocking access to credential-harvesting pages and tracking pixels used to gather information about targeted individuals."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Malicious code protection on network management platforms can detect SNMP exploitation tools and unauthorized MIB-dumping utilities, blocking attempts to extract device configurations through SNMP query abuse."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Anti-malware solutions can detect tools that dump network device configurations through management protocols, blocking unauthorized extraction of running and startup configurations containing sensitive infrastructure data."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.DS-01, PR.DS-02, PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":["SP-001","SP-002","SP-011","SP-015","SP-016","SP-023","SP-024","SP-025","SP-026","SP-027","SP-028","SP-030","SP-048"]}}