{"data":{"id":"SI-10","name":"Information Input Validation","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"Check the validity of the following information inputs: [Assignment: organization-defined information inputs to the system].","supplemental_guidance":"Checking the valid syntax and semantics of system inputs—including character set, length, numerical range, and acceptable values—verifies that inputs match specified definitions for format and content. For example, if the organization specifies that numerical values between 1-100 are the only acceptable inputs for a field in a given application, inputs of \"387,\"\"abc,\" or \"%K%\" are invalid inputs and are not accepted as input to the system. Valid inputs are likely to vary from field to field within a software application. Applications typically follow well-defined protocols that use structured messages (i.e., commands or queries) to communicate between software modules or system components. Structured messages can contain raw or unstructured data interspersed with metadata or control information. If software applications use attacker-supplied inputs to construct structured messages without properly encoding such messages, then the attacker could insert malicious commands or special characters that can cause the data to be interpreted as control information or metadata. Consequently, the module or component that receives the corrupted output will perform the wrong operations or otherwise interpret the data incorrectly. Prescreening inputs prior to passing them to interpreters prevents the content from being unintentionally interpreted as commands. Input validation ensures accurate and correct inputs and prevents attacks such as cross-site scripting and a variety of injection attacks.","enhancements":[{"id":"SI-10(01)","name":"Manual Override Capability","statement":"a. Provide a manual override capability for input validation of the following information inputs: [Assignment: organization-defined inputs defined in the base control (SI-10)];\nb. Restrict the use of the manual override capability to only [Assignment: organization-defined authorized individuals]; and\nc. Audit the use of the manual override capability.","baselines":[]},{"id":"SI-10(02)","name":"Review and Resolve Errors","statement":"Review and resolve input validation errors within [Assignment: organization-defined time period].","baselines":[]},{"id":"SI-10(03)","name":"Predictable Behavior","statement":"Verify that the system behaves in a predictable and documented manner when invalid inputs are received.","baselines":[]},{"id":"SI-10(04)","name":"Timing Interactions","statement":"Account for timing interactions among system components in determining appropriate responses for invalid inputs.","baselines":[]},{"id":"SI-10(05)","name":"Restrict Inputs to Trusted Sources and Approved Formats","statement":"Restrict the use of information inputs to [Assignment: organization-defined trusted sources] and/or [Assignment: organization-defined formats].","baselines":[]},{"id":"SI-10(06)","name":"Injection Prevention","statement":"Prevent untrusted data injections.","baselines":[]}],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SI-10","name":"Information Input Validation","description":"Check the validity of the following information inputs: [Assignment: organization-defined information inputs to the system].","discussion":"Checking the valid syntax and semantics of system inputs—including character set, length, numerical range, and acceptable values—verifies that inputs match specified definitions for format and content. For example, if the organization specifies that numerical values between 1-100 are the only acceptable inputs for a field in a given application, inputs of \"387,\"\"abc,\" or \"%K%\" are invalid inputs and are not accepted as input to the system. Valid inputs are likely to vary from field to field within a software application. Applications typically follow well-defined protocols that use structured messages (i.e., commands or queries) to communicate between software modules or system components. Structured messages can contain raw or unstructured data interspersed with metadata or control information. If software applications use attacker-supplied inputs to construct structured messages without properly encoding such messages, then the attacker could insert malicious commands or special characters that can cause the data to be interpreted as control information or metadata. Consequently, the module or component that receives the corrupted output will perform the wrong operations or otherwise interpret the data incorrectly. Prescreening inputs prior to passing them to interpreters prevents the content from being unintentionally interpreted as commands. Input validation ensures accurate and correct inputs and prevents attacks such as cross-site scripting and a variety of injection attacks.","related_controls":[],"baseline_low":false,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":""}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":[],"cobit_2019":["DSS06"],"pci_dss_v4":[],"nist_csf_2":["PR.DS-10"],"cis_controls_v8":[],"soc2_tsc":["CC6.6","CC6.6-POF2"],"finos_ccc":[],"iso_42001_2023":["A.7.2","A.7.4"],"iec_62443":["3-3 SR 3.5"],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":[],"pra_op_resilience":[],"bsi_grundschutz":["APP.3.1"],"anssi":["Hygiene.33","SecNumCloud.15.3"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.D(78)","IV.D(80)","IV.E(84)"],"gdpr":["Art.5(1)(d)"],"dora":["Art.9(4)(e)"],"bio2":[],"rbi_csf":["Annex1.6"],"fisc":["FISC.T5","FISC.T6","FISC.T8","FISC.T12"],"lgpd_bcb":["BCB.PIX"],"hkma_tme1":["TME1.3.2","TME1.10.1"],"mlps_2":[],"dnb_good_practice":[],"cra":["CRA.I.2f"],"swift_cscf":[],"cbb_tm":["TM-7"],"cbuae":["CR-6"],"nca_ecc":["2-14"],"sama_csf":["3.2"],"uae_ia":["T7"],"bog_cisd":["CISD-IX","CISD-SDLC"],"bom_ctrm":["3.13"],"cbe_csf":["CTO-4","CTO-5"],"cbn_csf":["Part5.2"],"popia":["s16"],"sa_js2":["JS2-SA"],"bcbs_239":["Principle 3","Principle 7"],"bot_cyber":["Ch2.5"],"ffiec_is":["II.C.17"],"hipaa_sr":["§164.312(c)(1)"],"iosco_cyber":["PROT-3","RR-3"],"sebi_cscrf":["PR.AS"],"cmmc_2":["SI"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.1"],"fda_21_cfr_11":["§11.10(f)"],"fda_cyber":["ST-3"],"hitrust_csf":["10.b"],"iso_27799":[],"lloyds_ms":["BP2.2","MS1.1","MS2.1","MS5.1","MS6.1","MS13.2"],"naic_ds":[],"nhs_dspt":[],"pra_ss1_23":["P3.2","P4.3"],"solvency_ii":["Pillar3-Reporting"],"owasp_masvs_v2":["MASVS-CODE-4","MASVS-PLATFORM-1"],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":["Art.68(1)","Art.69(1)","Art.76(1)"],"basel_sco60":["SCO60.66"],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1036","name":"Masquerading","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation checks verify that file names, process names, and metadata conform to expected patterns, detecting masquerading attempts where adversaries use deceptive naming to appear legitimate."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Validating the format, protocol compliance, and content of outbound data transfers detects exfiltration attempts that use alternative protocols with malformed or suspicious payload structures."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Input validation on command interpreters prescreens inputs to prevent content from being unintentionally interpreted as commands, blocking injection attacks that leverage scripting engines for execution."},{"id":"T1080","name":"Taint Shared Content","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Integrity validation of shared content through checksums, digital signatures, and format verification detects tainted files before they are opened by other users for lateral infection."},{"id":"T1090","name":"Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Input validation on proxy requests verifies URL syntax, header format, and request structure, detecting proxy abuse where adversaries use malformed requests to establish C2 relay channels."},{"id":"T1095","name":"Non-Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Protocol conformance validation detects non-application-layer protocol misuse by verifying that network traffic matches expected packet structures, identifying covert C2 channels using raw protocols."},{"id":"T1127","name":"Trusted Developer Utilities Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on development tool invocations verifies that tool parameters conform to expected usage patterns, detecting abuse of trusted developer utilities for proxy code execution."},{"id":"T1129","name":"Shared Modules","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Validating the integrity and origin of shared modules before loading ensures that only properly signed and vetted shared libraries are loaded, preventing execution of malicious shared objects."},{"id":"T1176","name":"Browser Extensions","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Input validation on browser extension manifests and permission requests detects malicious or overly permissive extensions before installation, blocking adversary persistence through browser compromise."},{"id":"T1187","name":"Forced Authentication","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Validating authentication request parameters detects forced authentication attempts where adversaries craft malicious resources that trigger automatic credential transmission to attacker-controlled servers."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Input validation on public-facing applications checks for SQL injection, XSS, command injection, and buffer overflow payloads, directly blocking exploitation attempts at the application boundary."},{"id":"T1197","name":"BITS Jobs","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Validating BITS job parameters, including source URLs and destination paths, detects suspicious background transfer configurations that adversaries use for persistence and payload retrieval."},{"id":"T1204","name":"User Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Input validation on user-facing content checks file types, formats, and embedded content for malicious elements, reducing the risk of users executing adversary-crafted payloads."},{"id":"T1216","name":"System Script Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on script arguments passed to system script proxies detects adversary attempts to abuse trusted script execution mechanisms for defense evasion."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating command-line arguments and parameters passed to system binaries detects abuse of trusted signed executables as proxies for executing malicious payloads."},{"id":"T1219","name":"Remote Access Software","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Input validation on remote access tool connection parameters and configurations detects unauthorized remote access software installation and usage for command and control."},{"id":"T1220","name":"XSL Script Processing","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating XSL stylesheet content for embedded scripts and executable code prevents adversaries from using XSL script processing as a proxy for executing malicious payloads."},{"id":"T1221","name":"Template Injection","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on document template references detects malicious remote template URLs injected into Office documents for payload delivery and defense evasion."},{"id":"T1498","name":"Network Denial of Service","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Validating incoming network packets for conformance to protocol specifications, including header validation and payload size checks, enables filtering of malformed DoS attack traffic."},{"id":"T1499","name":"Endpoint Denial of Service","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Input validation at application endpoints checks request parameters for size, format, and resource consumption patterns, blocking requests crafted to exhaust endpoint resources."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Validating cloud storage access request parameters, query formats, and authentication tokens detects unauthorized enumeration and data retrieval attempts targeting cloud-hosted information repositories and object stores."},{"id":"T1537","name":"Transfer Data to Cloud Account","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Input validation on cloud data transfer configurations detects suspicious cross-account transfer parameters that indicate adversary attempts to exfiltrate data to controlled cloud accounts."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Validating input sources and credential handling processes ensures that applications do not inadvertently expose credentials through improper input processing or error messages."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on trust control operations verifies certificate parameters, code signing attributes, and trust chain integrity, detecting attempts to subvert trust verification mechanisms."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Protocol-level input validation detects spoofed network responses, malformed authentication exchanges, and tampered protocol headers characteristic of adversary-in-the-middle attacks targeting network communications."},{"id":"T1570","name":"Lateral Tool Transfer","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Validating the content and metadata of files transferred between internal systems detects lateral tool transfer by identifying suspicious executable content in inter-system file transfers."},{"id":"T1572","name":"Protocol Tunneling","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Input validation on tunnel establishment parameters and encapsulated protocol content detects protocol tunneling attempts that embed C2 traffic within legitimate protocol wrappers."},{"id":"T1574","name":"Hijack Execution Flow","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Validating the integrity of loaded modules, libraries, and executables through path verification and signature checking detects execution flow hijacking via malicious binary substitution."},{"id":"T1599","name":"Network Boundary Bridging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on network device configuration commands detects unauthorized modifications to routing and NAT rules that could bridge network boundaries for adversary lateral movement."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Validating the format and authentication of configuration retrieval requests detects unauthorized SNMP queries and configuration dumps targeting network device data repositories."},{"id":"T1609","name":"Container Administration Command","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Input validation on container administration commands verifies command syntax and parameters against authorized operations, detecting malicious commands injected into container management interfaces."},{"id":"T1622","name":"Debugger Evasion","tactics":["defense-evasion","discovery"],"mapping_type":"mitigates","mapping_rationale":"Validating system environment parameters and debug interface requests detects adversary attempts to probe for debugger presence or evade debugging through crafted inputs."},{"id":"T1021.002","name":"SMB/Windows Admin Shares","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Input validation on SMB connection parameters and share access requests detects malformed or suspicious authentication attempts targeting Windows administrative shares for lateral movement."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Validating VNC connection parameters and authentication exchanges detects suspicious connection attempts that may indicate adversary lateral movement through compromised VNC sessions."},{"id":"T1027.010","name":"Command Obfuscation","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation that decodes and normalizes obfuscated command parameters detects adversary attempts to bypass security controls through command-line obfuscation techniques such as character substitution."},{"id":"T1036.005","name":"Match Legitimate Name or Location","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation checks that verify file names match expected naming conventions and are located in appropriate directories detect adversary attempts to masquerade malicious files as legitimate."},{"id":"T1036.008","name":"Masquerade File Type","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating file type headers against declared extensions detects masqueraded file types where adversaries disguise executable content with benign file extensions to deceive users."},{"id":"T1048.001","name":"Exfiltration Over Symmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Input validation on encrypted outbound traffic patterns detects anomalous symmetric-encrypted transfers over non-standard protocols that may indicate covert exfiltration channels."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Validating outbound connection parameters for asymmetric-encrypted protocol conformance detects exfiltration attempts that use non-standard encrypted channels outside normal communication patterns."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Input validation on unencrypted outbound data transfers detects plaintext exfiltration over alternative protocols by identifying data payloads that exceed normal content patterns."},{"id":"T1059.001","name":"PowerShell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Input validation on PowerShell command parameters through Constrained Language Mode and script block logging detects malicious script content before execution by the PowerShell engine."},{"id":"T1059.002","name":"AppleScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Validating AppleScript command inputs and inter-application communication parameters detects malicious automation attempts that leverage Apple's scripting framework for code execution."},{"id":"T1059.003","name":"Windows Command Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Windows Command Shell parameters detects command injection attempts and suspicious command chains that indicate adversary abuse of cmd.exe for execution."},{"id":"T1059.004","name":"Unix Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Validating Unix shell command inputs through restricted shell configurations and parameter checking detects adversary attempts to execute malicious commands through bash, sh, or zsh."},{"id":"T1059.005","name":"Visual Basic","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Input validation on VBScript and Visual Basic macro content detects malicious code patterns before execution, blocking adversary payloads delivered through Office documents or script files."},{"id":"T1059.006","name":"Python","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Validating Python script inputs and module import parameters detects adversary attempts to execute malicious Python code through command-line invocation or embedded interpreters."},{"id":"T1059.007","name":"JavaScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Input validation on JavaScript execution contexts, including script source validation and CSP enforcement, detects malicious JavaScript execution through browsers or host-based runtimes."},{"id":"T1059.008","name":"Network Device CLI","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Validating network device CLI command inputs against authorized command sets and parameter ranges detects adversary attempts to execute unauthorized configuration changes on network infrastructure."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Input validation on DNS query parameters, including domain name format and query type validation, detects DNS tunneling where adversaries encode C2 data in DNS requests and responses."},{"id":"T1090.003","name":"Multi-hop Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Validating proxy connection chains and intermediate hop parameters detects multi-hop proxy configurations that adversaries use to obscure the origin of C2 communications."},{"id":"T1127.002","name":"ClickOnce","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on ClickOnce deployment manifests and application parameters detects adversary abuse of the ClickOnce deployment mechanism for executing malicious payloads."},{"id":"T1204.002","name":"Malicious File","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Input validation on opened files checks content structure, embedded macros, and executable elements, detecting malicious files before user execution enables adversary code delivery."},{"id":"T1216.001","name":"PubPrn","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating PubPrn.vbs script parameters detects adversary abuse of this signed script for remote scriptlet execution, as legitimate usage follows predictable parameter patterns."},{"id":"T1218.001","name":"Compiled HTML File","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on compiled HTML (.chm) file content detects embedded malicious scripts and ActiveX controls that adversaries use for proxy execution through the HTML Help system."},{"id":"T1218.002","name":"Control Panel","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating Control Panel item (.cpl) file parameters and content integrity detects adversary abuse of the Control Panel interface for DLL proxy execution."},{"id":"T1218.003","name":"CMSTP","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on CMSTP.exe .inf file parameters detects malicious connection manager profiles that adversaries craft to bypass application control through trusted binary execution."},{"id":"T1218.004","name":"InstallUtil","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating InstallUtil.exe parameters and assembly content detects adversary abuse of the .NET installation utility for executing code within trusted process contexts."},{"id":"T1218.005","name":"Mshta","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Mshta.exe parameters detects adversary-crafted HTA files containing malicious VBScript or JavaScript that would execute within the trusted HTML application host."},{"id":"T1218.008","name":"Odbcconf","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating Odbcconf.exe parameters and response file content detects adversary abuse of the ODBC configuration utility for DLL registration and proxy execution."},{"id":"T1218.009","name":"Regsvcs/Regasm","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Regsvcs.exe and Regasm.exe parameters detects adversary abuse of .NET COM registration utilities for executing malicious assemblies within trusted process contexts."},{"id":"T1218.010","name":"Regsvr32","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating Regsvr32.exe parameters, including remote scriptlet URLs, detects adversary use of the COM object registration utility for downloading and executing malicious code."},{"id":"T1218.011","name":"Rundll32","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Rundll32.exe command-line parameters detects adversary abuse of the DLL execution utility for running malicious payloads through a trusted Windows binary."},{"id":"T1218.012","name":"Verclsid","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating Verclsid.exe parameters detects adversary abuse of the COM object verification utility for executing arbitrary DLLs through trusted process invocation."},{"id":"T1218.013","name":"Mavinject","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Mavinject.exe parameters detects adversary abuse of this Microsoft utility for injecting DLLs into running processes for code execution."},{"id":"T1218.014","name":"MMC","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating MMC snap-in parameters and .msc file content detects adversary abuse of the Microsoft Management Console for executing malicious payloads through trusted management interfaces."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Electron application parameters detects adversary abuse of Electron-based applications for proxy execution of malicious JavaScript within trusted application contexts."},{"id":"T1498.001","name":"Direct Network Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Validating incoming traffic volume and packet construction patterns enables detection and filtering of direct network flood attacks that exceed legitimate traffic baselines."},{"id":"T1498.002","name":"Reflection Amplification","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Input validation on DNS, NTP, and SSDP response traffic detects amplified reflection attacks by identifying response volumes that exceed legitimate request-response ratios."},{"id":"T1499.001","name":"OS Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Validating connection request parameters at the OS level, including SYN rate and connection state, detects resource exhaustion attempts targeting operating system network stack resources."},{"id":"T1499.002","name":"Service Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Input validation on service request parameters identifies malformed or excessive requests designed to exhaust service-level resources such as worker threads and connection pools."},{"id":"T1499.003","name":"Application Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Validating application-layer request parameters for size, format, and computational complexity detects resource exhaustion payloads that target computationally expensive application functions through carefully crafted input values."},{"id":"T1499.004","name":"Application or System Exploitation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Input validation and sanitization prevent exploitation of application vulnerabilities that adversaries target for denial-of-service through malformed inputs causing crashes or resource exhaustion."},{"id":"T1546.002","name":"Screensaver","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Validating screensaver file references and parameters detects adversary modification of screensaver settings to execute malicious binaries when the screensaver activates."},{"id":"T1546.006","name":"LC_LOAD_DYLIB Addition","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Mach-O binary LC_LOAD_DYLIB headers detects the addition of unauthorized dynamic library load commands that adversaries use for persistent code injection on macOS."},{"id":"T1546.008","name":"Accessibility Features","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Validating accessibility feature binary integrity and registration parameters detects adversary replacement of accessibility utilities like sethc.exe with malicious executables for persistence."},{"id":"T1546.009","name":"AppCert DLLs","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Input validation on AppCert DLL registry entries detects adversary registration of malicious DLLs that load into processes invoking CreateProcess API calls."},{"id":"T1546.010","name":"AppInit DLLs","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Validating AppInit DLL registry entries and DLL content detects adversary registration of malicious DLLs that automatically load into every user-mode process linked to User32.dll."},{"id":"T1547.004","name":"Winlogon Helper DLL","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Winlogon registry values detects adversary modification of Notify, Userinit, or Shell keys that load malicious DLLs during the Windows logon process."},{"id":"T1547.006","name":"Kernel Modules and Extensions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Validating kernel module signatures and parameters before loading detects adversary attempts to install unauthorized kernel modules or extensions for persistent privileged access."},{"id":"T1548.006","name":"TCC Manipulation","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Input validation on TCC database modification requests and entitlement declarations detects adversary attempts to manipulate macOS Transparency, Consent, and Control protections."},{"id":"T1552.005","name":"Cloud Instance Metadata API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Validating cloud instance metadata API request parameters and implementing IMDSv2 token requirements prevent adversary exploitation of metadata endpoints for credential harvesting."},{"id":"T1553.001","name":"Gatekeeper Bypass","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Gatekeeper quarantine attributes and code signing verification detects adversary attempts to bypass macOS Gatekeeper through modified quarantine flags."},{"id":"T1553.003","name":"SIP and Trust Provider Hijacking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating SIP and trust provider DLL integrity and registration parameters detects adversary attempts to hijack Windows code signing verification through malicious trust provider substitution."},{"id":"T1553.005","name":"Mark-of-the-Web Bypass","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Mark-of-the-Web zone identifier attributes detects adversary techniques for removing or modifying MOTW flags to bypass security warnings on downloaded files."},{"id":"T1557.001","name":"LLMNR/NBT-NS Poisoning and SMB Relay","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Validating name resolution responses and SMB authentication exchanges detects LLMNR/NBT-NS poisoning attempts through response format anomalies and unexpected authentication redirections."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Input validation on ARP responses, including source MAC consistency checking, detects ARP cache poisoning attempts that redirect traffic through adversary-controlled network positions."},{"id":"T1557.003","name":"DHCP Spoofing","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Validating DHCP response parameters against known server configurations detects rogue DHCP servers attempting to redirect network traffic through adversary-controlled gateways via spoofed responses."},{"id":"T1564.003","name":"Hidden Window","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on window creation parameters and visibility flags detects adversary use of hidden windows to conceal malicious process execution from user observation."},{"id":"T1564.006","name":"Run Virtual Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Validating virtual machine and hypervisor deployment parameters detects adversary attempts to run malicious workloads within virtual instances to evade host-based security monitoring."},{"id":"T1564.009","name":"Resource Forking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on macOS resource fork content detects adversary attempts to hide malicious payloads within resource fork alternate data streams that bypass standard file inspection."},{"id":"T1574.001","name":"DLL Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Input validation on DLL load paths verifies that requested libraries resolve to expected locations, detecting DLL search order hijacking through path manipulation or planted binaries."},{"id":"T1574.006","name":"Dynamic Linker Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Validating dynamic linker environment variables such as LD_PRELOAD and DYLD_INSERT_LIBRARIES and verifying loaded library paths against expected values detects adversary hijacking of the dynamic linking process."},{"id":"T1574.007","name":"Path Interception by PATH Environment Variable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Input validation on PATH environment variable contents detects adversary insertion of malicious directory entries that redirect executable resolution to attacker-controlled binaries."},{"id":"T1574.008","name":"Path Interception by Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Validating executable search order resolution against expected application paths detects adversary placement of malicious binaries in directories that take search precedence."},{"id":"T1574.009","name":"Path Interception by Unquoted Path","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Input validation on Windows service executable paths detects unquoted path vulnerabilities where adversaries place executables at intermediate path locations to intercept service startup."},{"id":"T1574.012","name":"COR_PROFILER","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Validating COR_PROFILER environment variable values and referenced DLL integrity detects adversary registration of malicious .NET profiler DLLs for execution flow hijacking."},{"id":"T1574.013","name":"KernelCallbackTable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Input validation on KernelCallbackTable function pointer values detects adversary modification of this process environment block structure for callback-based code execution hijacking."},{"id":"T1574.014","name":"AppDomainManager","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Validating AppDomainManager configuration entries and referenced assembly integrity detects adversary specification of malicious domain managers for .NET application execution hijacking."},{"id":"T1599.001","name":"Network Address Translation Traversal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Input validation on NAT rule configurations detects unauthorized NAT traversal modifications that adversaries use to bridge network boundaries and access isolated segments."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Validating SNMP request parameters, community strings, and query scope detects unauthorized MIB dumps targeting network device configurations and operational data."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Input validation on configuration retrieval requests verifies request authenticity and scope, detecting unauthorized attempts to dump complete network device configurations."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base. 2026-10-03: baselines LMH to -MH, from NIST SP 800-53B Release 5.2.0.","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-002","SP-005","SP-012","SP-013","SP-023","SP-027","SP-028","SP-030","SP-041","SP-045","SP-047","SP-048","SP-049","SP-050","SP-051","SP-053","SP-054"]}}