{"data":{"id":"CM-02","name":"Baseline Configuration","family":"CM","family_name":"Configuration Management","withdrawn":false,"description":"a. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and\nb. Review and update the baseline configuration of the system:\n1. [Assignment: organization-defined frequency];\n2. When required due to [Assignment: organization-defined circumstances]; and\n3. When system components are installed or upgraded.","supplemental_guidance":"Baseline configurations for systems and system components include connectivity, operational, and communications aspects of systems. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, or changes to systems and include security and privacy control implementations, operational procedures, information about system components, network topology, and logical placement of components in the system architecture. Maintaining baseline configurations requires creating new baselines as organizational systems change over time. Baseline configurations of systems reflect the current enterprise architecture.","enhancements":[{"id":"CM-02(01)","name":"Reviews and Updates","withdrawn":true,"incorporated_into":["CM-02"]},{"id":"CM-02(02)","name":"Automation Support for Accuracy and Currency","statement":"Maintain the currency, completeness, accuracy, and availability of the baseline configuration of the system using [Assignment: organization-defined automated mechanisms].","baselines":["moderate","high"]},{"id":"CM-02(03)","name":"Retention of Previous Configurations","statement":"Retain [Assignment: organization-defined number] of previous versions of baseline configurations of the system to support rollback.","baselines":["moderate","high"]},{"id":"CM-02(04)","name":"Unauthorized Software","withdrawn":true,"incorporated_into":["CM-07(04)"]},{"id":"CM-02(05)","name":"Authorized Software","withdrawn":true,"incorporated_into":["CM-07(05)"]},{"id":"CM-02(06)","name":"Development and Test Environments","statement":"Maintain a baseline configuration for system development and test environments that is managed separately from the operational baseline configuration.","baselines":[]},{"id":"CM-02(07)","name":"Configure Systems and Components for High-risk Areas","statement":"a. Issue [Assignment: organization-defined systems or system components] with [Assignment: organization-defined configurations] to individuals traveling to locations that the organization deems to be of significant risk; and\nb. Apply the following controls to the systems or components when the individuals return from travel: [Assignment: organization-defined controls].","baselines":["moderate","high"]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CM-02","name":"Baseline Configuration","description":"a. Develop, document, and maintain under configuration control, a current baseline configuration of the system; and\nb. Review and update the baseline configuration of the system:\n1. [Assignment: organization-defined frequency];\n2. When required due to [Assignment: organization-defined circumstances]; and\n3. When system components are installed or upgraded.","discussion":"Baseline configurations for systems and system components include connectivity, operational, and communications aspects of systems. Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, or changes to systems and include security and privacy control implementations, operational procedures, information about system components, network topology, and logical placement of components in the system architecture. Maintaining baseline configurations requires creating new baselines as organizational systems change over time. Baseline configurations of systems reflect the current enterprise architecture.","related_controls":["AC-19","AU-06","CA-09","CM-01","CM-03","CM-05","CM-06","CM-08","CM-09","CP-09","CP-10","CP-12","MA-02","PL-08","PM-05","SA-08","SA-10","SA-15","SC-18"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Adds requirement to update baseline configuration document at organizationally-defined frequencies and for organizationally-defined circumstances (in addition to when changes are made) Incorporates withdrawn control CM-02(1)"}},"compliance_mappings":{"iso_27001_2022":["A.8.9"],"iso_27002_2022":["5.37","8.9","8.31"],"cobit_2019":["BAI10"],"pci_dss_v4":["1.2","1.2.1","2.1","2.2"],"nist_csf_2":["PR.PS-01"],"cis_controls_v8":["CIS 4","CIS 4.1","CIS 12","CIS 16.7"],"soc2_tsc":["CC6.1-POF7","CC6.7-POF1","CC7.1","CC7.1-POF1","CC8.1"],"finos_ccc":["CCC-C14"],"iso_42001_2023":["A.4.2","A.6.2.3"],"iec_62443":["3-3 SR 7.6"],"asd_e8":[],"nis2":["Art. 21(2)(g)"],"apra_cps_234":[],"mas_trm":["11"],"pra_op_resilience":[],"bsi_grundschutz":["NET.1.2","NET.3.1","SYS.1.1","SYS.2.1"],"anssi":["Hygiene.5","Hygiene.18","SecNumCloud.13.1"],"osfi_b13":["B-13.2.2"],"finma_circular":["IV.A(28)","IV.A(29)","IV.A(30)","IV.A(31)"],"gdpr":["Art.25(1)","Art.32(1)(b)"],"dora":["Art.7(1)","Art.9(1)"],"bio2":["5.37","8.9","8.31"],"rbi_csf":["Annex1.5"],"fisc":["FISC.O3","FISC.O13","FISC.T7","FISC.T14"],"lgpd_bcb":[],"hkma_tme1":["TME1.4.1","TME1.4.3"],"mlps_2":["8.1.9.5","8.1.10.4","8.1.10.6"],"dnb_good_practice":["DNB.3.2","DNB.10.3","DNB.10.5","DNB.13.1","DNB.13.2"],"cra":["CRA.I.2b","CRA.Info.3"],"swift_cscf":["SWIFT.2.3"],"cbb_tm":["TM-5"],"cbuae":["CR-7"],"nca_ecc":["2-3","5-1"],"qatar_nia":["OS","SD"],"sama_csf":["3.3","3.5","3.8","4.3"],"uae_ia":["T7"],"bog_cisd":["CISD-VI"],"bom_ctrm":["3.1","3.2"],"cbe_csf":["CTO-7","CTO-12"],"cbn_csf":["Part3.3"],"popia":["s19"],"sa_js2":["JS2-7.2"],"bcbs_239":["Principle 2"],"bot_cyber":["Ch2.1"],"cpmi_pfmi":["CG.PR","PFMI.P17"],"eba_ict":["3.4.4","3.5(a)"],"ecb_croe":["CROE.2.3.4"],"ffiec_is":["II.C.2","II.C.10"],"iosco_cyber":["ID-4"],"nydfs_500":["500.8"],"sebi_cscrf":["PR.IP"],"cmmc_2":["CM"],"nerc_cip":["CIP-010-4"],"nrc_73_54":["RG5.71-B-CM"],"tsa_psd":[],"ieee_1686":["5.4"],"ferc_cip":["Order 887"],"doe_c2m2":["ASSET"],"api_1164":["Sec 7"],"awia":["AWWA Sec 2"],"iaea_nss":["Sec 5.4"],"pci_pts":["K"],"fips_140":["FIPS 140-3 §7.6"],"cbest":[],"tiber_eu":[],"pci_hsm":["8"],"common_criteria":[],"isae_3402":["Clause 4","Clause 9"],"fca_sysc_13":["SYSC 13.7.1","SYSC 13.7.2"],"fda_21_cfr_11":["§11.10(f)"],"fda_cyber":["PU-2","SA-3"],"hitrust_csf":["09.a"],"iso_27799":["12.1"],"lloyds_ms":["MS8.4"],"naic_ds":["4-config","4B"],"nhs_dspt":["NDG-8.3"],"pra_ss1_23":["P3.3","P-IT.3"],"solvency_ii":["DR.266","EIOPA-ICT-4.8"],"owasp_masvs_v2":["MASVS-CODE-1","MASVS-CODE-2"],"csa_ccm_v4":["AIS-06","CCC-06","CCC-07","IVS-04","IVS-05","UEM-03","UEM-05","UEM-07"],"csa_aicm":["AIS-06","CCC-06","CCC-07","I&S-04","I&S-05","UEM-03","UEM-05","UEM-07"],"ccss_v9":[],"mica":["Art.62(5)"],"basel_sco60":["SCO60.14","SCO60.51","SCO60.65"],"bssc":["GSP-14","NOS-03"],"sec_custody_digital":["SEC-CD-08"],"dpdpa":[]},"attack_techniques":[{"id":"T1001","name":"Data Obfuscation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"A documented baseline configuration defines expected network traffic patterns and protocols, enabling detection of data obfuscation techniques that deviate from the approved communication standards established in the configuration baseline."},{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that harden credential storage—including Credential Guard enablement, LSASS protection, and restricted debug privileges—reduce the attack surface for OS credential dumping by ensuring systems are deployed in a known-secure state."},{"id":"T1008","name":"Fallback Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baseline configurations that document approved communication channels and protocols enable detection of fallback C2 channels, as traffic to undocumented endpoints or over non-baseline protocols triggers deviation alerts."},{"id":"T1021","name":"Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations define which remote services are enabled on each system type, enabling detection and blocking of unauthorized remote access methods that deviate from the documented service configuration."},{"id":"T1027","name":"Obfuscated Files or Information","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for endpoint protection—including script block logging, AMSI integration, and content inspection—establish the defensive posture needed to detect obfuscated files and information that bypass default security settings."},{"id":"T1029","name":"Scheduled Transfer","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network baseline configurations document expected data transfer schedules and volumes, enabling detection of adversary-scheduled exfiltration transfers that deviate from documented automated data movement patterns."},{"id":"T1030","name":"Data Transfer Size Limits","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that define expected data transfer volumes and DLP thresholds enable detection of adversary attempts to exfiltrate data in small increments that stay below default alert thresholds but exceed baselined norms."},{"id":"T1036","name":"Masquerading","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"A well-documented system baseline enables detection of masquerading by establishing the legitimate names, locations, and signatures of all approved executables, making it possible to identify files impersonating trusted system components."},{"id":"T1037","name":"Boot or Logon Initialization Scripts","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations document approved boot and logon initialization scripts, enabling detection of adversary-created scripts that deviate from the documented startup configuration by modifying login hooks, logon scripts, or RC files."},{"id":"T1046","name":"Network Service Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved network services and listening ports enable detection of network service discovery scans by establishing the expected network footprint against which anomalous enumeration activity is identified."},{"id":"T1047","name":"Windows Management Instrumentation","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict WMI access and define approved remote management methods enable detection of unauthorized WMI usage by establishing which systems should accept WMI connections and from which sources."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network baseline configurations documenting approved egress protocols and destinations enable detection of exfiltration over alternative protocols by flagging data transfers that use channels not included in the approved configuration."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations defining approved removable media policies—including USB device restrictions and portable storage controls—establish the standards against which physical media exfiltration attempts are detected."},{"id":"T1053","name":"Scheduled Task/Job","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines document approved scheduled tasks and automation jobs, enabling detection of adversary-created persistence mechanisms by comparing active scheduled items against the documented baseline configuration."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that define approved scripting interpreters and execution policies for each system type enable detection of unauthorized script execution that deviates from the documented software baseline."},{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Maintaining current baseline configurations with defined patch levels and security hardening ensures systems are resistant to known privilege escalation exploits, as the baseline mandates vulnerability remediation standards."},{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for audit logging—including centralized forwarding, protected storage, and tamper detection—ensure that indicator removal attempts are detectable because the logging infrastructure operates according to documented standards."},{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that document approved application layer protocols and their expected endpoints enable detection of C2 communications that use legitimate protocols but deviate from the established traffic patterns."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations document authorized software deployment tools and their approved distribution scope, enabling detection when adversaries abuse deployment infrastructure to push payloads outside the baselined distribution patterns."},{"id":"T1080","name":"Taint Shared Content","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for shared content repositories—including access controls, integrity checks, and approved content types—enable detection of tainted shared content that deviates from documented repository standards."},{"id":"T1090","name":"Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that define approved proxy configurations enable detection of unauthorized proxy usage for C2 relay, as adversary-established proxy communications deviate from the documented proxy infrastructure baseline."},{"id":"T1091","name":"Replication Through Removable Media","tactics":["initial-access","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that define removable media policies and USB device restrictions enable prevention and detection of malware replication through removable media by enforcing documented hardware access standards."},{"id":"T1092","name":"Communication Through Removable Media","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict removable media access and define approved communication channels make covert communication through removable media detectable as a deviation from the documented configuration."},{"id":"T1095","name":"Non-Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines documenting approved protocols at each network layer enable detection of non-application layer protocol C2 channels, as raw socket communications or custom protocol usage deviates from the documented standard."},{"id":"T1102","name":"Web Service","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations defining approved web service endpoints and cloud platform access enable detection of C2 communications to legitimate web services that are not included in the documented configuration."},{"id":"T1104","name":"Multi-Stage Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that document approved communication stages and connection patterns enable detection of multi-stage C2 channels that introduce undocumented handshake sequences or staging infrastructure."},{"id":"T1105","name":"Ingress Tool Transfer","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that define approved file transfer mechanisms and sources enable detection of adversary tool transfers that use methods or endpoints not included in the documented configuration baseline."},{"id":"T1106","name":"Native API","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines that define approved API usage patterns and restrict unnecessary system call access enable detection of adversary use of native APIs that deviates from the documented application behavior baseline."},{"id":"T1110","name":"Brute Force","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that mandate account lockout policies, password complexity requirements, and authentication rate limiting establish the defensive parameters that resist brute force attacks against credential stores."},{"id":"T1111","name":"Multi-Factor Authentication Interception","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for MFA implementation—including approved authenticator types, token handling, and protocol standards—establish the hardened authentication posture that resists MFA interception techniques."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for email systems—including access controls, forwarding restrictions, and delegation policies—establish the standards against which unauthorized email collection activities are detected."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved automated data collection tools and their scopes enable detection of adversary automation that deviates from the documented collection patterns across monitored data repositories."},{"id":"T1127","name":"Trusted Developer Utilities Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations documenting approved development tools on each system type enable detection of trusted developer utility proxy execution on endpoints where these tools are not part of the standard software load."},{"id":"T1129","name":"Shared Modules","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved shared modules and their loading paths enable detection of unauthorized shared module loading that deviates from the documented library configuration for each system type."},{"id":"T1132","name":"Data Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines defining expected data encoding formats in communications enable detection of C2 data encoding techniques that introduce non-standard encoding patterns not present in legitimate baseline traffic."},{"id":"T1133","name":"External Remote Services","tactics":["initial-access","persistence"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that document approved external remote service endpoints and their access methods enable detection of unauthorized remote access infrastructure that deviates from the documented perimeter configuration."},{"id":"T1137","name":"Office Application Startup","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"System baselines for Office application configurations—including approved add-ins, templates, and startup items—enable detection of adversary persistence through unauthorized Office startup modifications."},{"id":"T1176","name":"Browser Extensions","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Browser baseline configurations that define approved extensions, add-on sources, and installation policies enable detection of unauthorized browser extension installations used for persistent data collection or C2."},{"id":"T1185","name":"Browser Session Hijacking","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline browser configurations that enforce secure cookie handling, session management, and extension restrictions reduce the attack surface for browser session hijacking by hardening the default browser posture."},{"id":"T1187","name":"Forced Authentication","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network baseline configurations that disable unnecessary authentication protocols like LLMNR and NBT-NS, and enforce SMB signing, reduce the attack surface for forced authentication credential harvesting."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for web browsers—including content security settings, script restrictions, and plugin limitations—establish the hardened posture that reduces the drive-by compromise attack surface."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that document approved software sources, vendor checksums, and supply chain verification procedures enable detection of compromised components that deviate from the documented software provenance standards."},{"id":"T1201","name":"Password Policy Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that standardize and document password policies across the environment limit the value of password policy discovery, as adversaries cannot identify weak password implementations when policies conform to the hardened baseline."},{"id":"T1204","name":"User Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict executable content types, enforce application whitelisting, and configure email gateway filtering reduce the likelihood of successful user execution of malicious content."},{"id":"T1205","name":"Traffic Signaling","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that document approved port usage and traffic patterns enable detection of traffic signaling techniques, as port-knocking or protocol-based activation sequences deviate from the documented network configuration."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations with current patch levels and hardened service configurations reduce the attack surface for remote service exploitation by ensuring that documented security standards are maintained across all systems."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that mandate current security tool versions and configurations ensure that defense evasion exploits targeting known vulnerabilities in security software are mitigated by the documented patching standard."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enforce credential protection mechanisms—including Credential Guard and protected process light—reduce the attack surface for credential access exploitation by hardening authentication infrastructure."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for information repositories—including access controls, data classification, and monitoring settings—establish the security standards against which unauthorized data collection activities are detected."},{"id":"T1216","name":"System Script Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved system scripts and restrict execution to known, signed scripts enable detection of system script proxy execution that leverages legitimate scripts outside the baselined configuration."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict or remove unnecessary system binaries from each system type enable detection of proxy execution through signed utilities that should not be present according to the documented software load."},{"id":"T1219","name":"Remote Access Software","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that define approved remote access software and block unauthorized remote administration tools enable detection of adversary-installed remote access software that deviates from the documented standard."},{"id":"T1220","name":"XSL Script Processing","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict XSL script processing capabilities and disable unnecessary XML processing features reduce the attack surface for XSL-based defense evasion by enforcing documented configuration standards."},{"id":"T1221","name":"Template Injection","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for document handling—including restricted template loading sources and macro security settings—reduce the template injection attack surface by enforcing documented content security standards."},{"id":"T1482","name":"Domain Trust Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict domain trust enumeration tools and limit Active Directory query access reduce adversary domain trust discovery capabilities by enforcing documented access control standards."},{"id":"T1484","name":"Domain or Tenant Policy Modification","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for domain and tenant policies—including documented Group Policy objects and conditional access rules—enable detection of policy modifications that deviate from the approved baseline."},{"id":"T1485","name":"Data Destruction","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that include data protection standards—backup schedules, write protections, and integrity monitoring—reduce the impact of data destruction by establishing recoverable system states."},{"id":"T1486","name":"Data Encrypted for Impact","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce application whitelisting, controlled folder access, and endpoint protection configurations reduce the ransomware attack surface by establishing a hardened posture against data encryption attacks."},{"id":"T1490","name":"Inhibit System Recovery","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that protect system recovery mechanisms—including shadow copy settings, backup agent configurations, and recovery partition access—resist adversary attempts to inhibit system recovery."},{"id":"T1491","name":"Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for web servers and applications—including file integrity monitoring and content management controls—enable detection of defacement through comparison against the documented content baseline."},{"id":"T1495","name":"Firmware Corruption","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Hardware baseline configurations that include firmware version tracking, Secure Boot enforcement, and integrity monitoring enable detection and prevention of firmware corruption on systems maintained to documented standards."},{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Server baseline configurations that document approved components—including web modules, stored procedures, and transport agents—enable detection of unauthorized server software additions that deviate from the approved standard."},{"id":"T1525","name":"Implant Internal Image","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Container baseline configurations that define approved base images, registry sources, and image signing requirements enable detection of implanted images that deviate from the documented container image standards."},{"id":"T1528","name":"Steal Application Access Token","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for OAuth and API access—including approved application registrations and token scope limitations—reduce the attack surface for application access token theft by enforcing documented authorization standards."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for cloud storage—including access policies, encryption standards, and public access restrictions—establish the security posture that protects against unauthorized data collection from cloud repositories."},{"id":"T1539","name":"Steal Web Session Cookie","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Browser baseline configurations that enforce secure cookie attributes (HttpOnly, Secure, SameSite) and restrict extension access to session storage reduce the attack surface for web session cookie theft."},{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enforce Secure Boot, firmware integrity verification, and UEFI configuration standards prevent pre-OS boot manipulation by ensuring systems maintain documented boot chain security."},{"id":"T1543","name":"Create or Modify System Process","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved system processes and services enable detection of adversary-created persistent processes that do not correspond to the documented service configuration."},{"id":"T1546","name":"Event Triggered Execution","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that document approved event-triggered execution mechanisms—including WMI subscriptions, shell configurations, and accessibility features—enable detection of unauthorized persistence triggers."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for elevation control mechanisms—including UAC levels, sudo configurations, and authorization plugin settings—reduce the attack surface for privilege escalation by enforcing documented security standards."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that mandate credential storage standards—including vault usage, encryption requirements, and file permission settings—reduce the incidence of unsecured credentials by enforcing documented handling practices."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for code signing policies, trust stores, and certificate pinning standards establish the trust framework that resists adversary attempts to subvert trust controls through policy modification."},{"id":"T1554","name":"Compromise Host Software Binary","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"System baselines with documented software hashes and integrity verification enable detection of compromised host software binaries by comparing installed files against the baseline configuration's known-good state."},{"id":"T1556","name":"Modify Authentication Process","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for authentication infrastructure—including PAM modules, network device AAA, and domain controller settings—enable detection of authentication process modifications that deviate from documented standards."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that disable unnecessary name resolution protocols, enforce encrypted communications, and mandate mutual authentication reduce the adversary-in-the-middle attack surface across the documented network configuration."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for Kerberos infrastructure—including encryption type restrictions, pre-authentication enforcement, and ticket lifetime settings—harden the environment against ticket theft and forgery attacks."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict IPC mechanisms and define approved COM objects and DDE settings reduce the inter-process communication attack surface by enforcing documented application interaction standards."},{"id":"T1560","name":"Archive Collected Data","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that monitor and restrict archive utility usage enable detection of adversary data staging through archive tools that operate outside the documented automation and backup frameworks."},{"id":"T1561","name":"Disk Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enforce disk protection mechanisms—including BitLocker, volume shadow copies, and backup procedures—establish recovery capabilities that mitigate the impact of disk wipe attacks."},{"id":"T1562","name":"Impair Defenses","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that mandate specific security tool deployments, logging levels, and firewall rules establish the defensive posture whose impairment becomes detectable through baseline compliance monitoring."},{"id":"T1563","name":"Remote Service Session Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for remote service session management—including timeout settings, session recording, and reconnection policies—reduce the attack surface for remote service session hijacking."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enforce data integrity mechanisms—including checksums, digital signatures, and change detection—enable identification of data manipulation by comparing against documented integrity baselines."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for email security—including SPF, DKIM, DMARC enforcement, attachment filtering, and link scanning—establish the phishing defense posture defined by the documented email security standards."},{"id":"T1569","name":"System Services","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict service execution privileges and document approved service configurations enable detection of unauthorized service-based execution that deviates from the documented service management baseline."},{"id":"T1570","name":"Lateral Tool Transfer","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that restrict lateral file transfer mechanisms and define approved internal data movement methods enable detection of adversary tool transfers between systems outside documented channels."},{"id":"T1571","name":"Non-Standard Port","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baseline configurations that document approved port assignments enable detection of C2 communications over non-standard ports, as traffic on undocumented ports deviates from the approved network configuration."},{"id":"T1572","name":"Protocol Tunneling","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline network configurations that define approved tunneling mechanisms enable detection of unauthorized protocol tunneling, as encapsulated traffic through non-baselined channels triggers deviation alerts."},{"id":"T1573","name":"Encrypted Channel","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that document approved encryption standards and certificate authorities enable detection of adversary-established encrypted channels using non-baseline encryption implementations or unauthorized certificates."},{"id":"T1574","name":"Hijack Execution Flow","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved DLL locations, service paths, and library loading configurations enable detection of execution flow hijacking by identifying components outside the documented installation baseline."},{"id":"T1578","name":"Modify Cloud Compute Infrastructure","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Cloud baseline configurations that document approved compute resources and their configurations enable detection of unauthorized cloud infrastructure modifications that deviate from the documented cloud posture."},{"id":"T1598","name":"Phishing for Information","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for email security and user awareness—including external sender warnings, link protection, and attachment scanning—establish defenses against phishing for information reconnaissance."},{"id":"T1599","name":"Network Boundary Bridging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that document approved routing configurations and boundary controls enable detection of network boundary bridging attempts that deviate from the documented network segmentation architecture."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Network device baselines with documented firmware versions and integrity hashes enable detection of system image modifications by comparing running configurations against the approved firmware baseline."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for network management infrastructure—including SNMP communities, access controls, and management plane restrictions—protect configuration repositories from unauthorized collection."},{"id":"T1612","name":"Build Image on Host","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Container baseline configurations that restrict image build capabilities and define approved build processes enable detection of adversary attempts to build malicious images on compromised hosts."},{"id":"T1622","name":"Debugger Evasion","tactics":["defense-evasion","discovery"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved debugging tools and their deployment scope enable detection of debugger evasion techniques on systems where debug tools are not part of the documented configuration."},{"id":"T1647","name":"Plist File Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"macOS system baselines that document approved plist configurations enable detection of unauthorized property list modifications by comparing runtime settings against the documented configuration baseline."},{"id":"T1653","name":"Power Settings","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved power management settings enable detection of adversary modifications to power configurations used for maintaining persistence across sleep and shutdown cycles."},{"id":"T1001.001","name":"Junk Data","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines defining expected packet structures enable detection of junk data injection in C2 communications, as padding or garbage bytes in network traffic deviate from documented protocol standards."},{"id":"T1001.002","name":"Steganography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for content inspection and network monitoring enable detection of steganographic C2 communications by establishing the expected media transfer patterns against which hidden data channels are identified."},{"id":"T1001.003","name":"Protocol or Service Impersonation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines documenting approved protocols and their expected behavior enable detection of protocol impersonation, as C2 traffic masquerading as legitimate services exhibits characteristics inconsistent with the baselined standard."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enable Credential Guard, restrict SeDebugPrivilege, and configure LSASS as a protected process directly harden systems against LSASS memory credential dumping techniques."},{"id":"T1003.002","name":"Security Account Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict local administrator accounts and enforce SAM database protections reduce the attack surface for Security Account Manager credential extraction on endpoints."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for domain controllers—including restricted replication permissions and ntdsutil access controls—harden the NTDS.dit credential store against unauthorized extraction."},{"id":"T1003.004","name":"LSA Secrets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict access to LSA registry keys and enforce credential isolation mechanisms protect LSA secrets from extraction by adversaries with local administrative access."},{"id":"T1003.005","name":"Cached Domain Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that limit cached credential counts and enforce credential caching restrictions reduce the volume of cached domain credentials available for offline extraction."},{"id":"T1003.006","name":"DCSync","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict directory replication permissions to authorized domain controllers prevent DCSync attacks by ensuring only the documented replication topology is permitted."},{"id":"T1003.007","name":"Proc Filesystem","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines for Linux that restrict /proc access and enforce process isolation protect credential material in process memory from extraction through the proc filesystem."},{"id":"T1003.008","name":"/etc/passwd and /etc/shadow","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enforce restrictive permissions on /etc/passwd and /etc/shadow and mandate PAM-based authentication hardening protect Linux credential files from unauthorized access."},{"id":"T1011.001","name":"Exfiltration Over Bluetooth","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"System baselines that define Bluetooth policies—including approved device pairings and transfer restrictions—enable detection and prevention of data exfiltration over Bluetooth channels."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that document approved SPAN and port mirroring configurations enable detection of unauthorized traffic duplication by identifying mirroring setups that deviate from the documented standard."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that define which systems have RDP enabled, approved source networks, and NLA requirements enable detection of unauthorized remote desktop connections deviating from the documented standard."},{"id":"T1021.002","name":"SMB/Windows Admin Shares","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict administrative share access and define approved SMB configurations enable detection of unauthorized lateral movement via Windows admin shares."},{"id":"T1021.003","name":"Distributed Component Object Model","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict DCOM permissions and document approved DCOM activation settings enable detection of unauthorized distributed COM usage for lateral movement."},{"id":"T1021.004","name":"SSH","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"System baselines that define approved SSH configurations, authorized key locations, and permitted source hosts enable detection of unauthorized SSH connections that deviate from the documented access baseline."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict VNC deployment to authorized systems and define approved connection sources enable detection of unauthorized VNC-based lateral movement."},{"id":"T1021.006","name":"Windows Remote Management","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved WinRM configurations and restrict remote management access enable detection of unauthorized Windows Remote Management connections."},{"id":"T1036.001","name":"Invalid Code Signature","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enforce code signing requirements and document approved certificate authorities enable detection of binaries with invalid code signatures that deviate from the documented trust standards."},{"id":"T1036.003","name":"Rename System Utilities","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting the expected names and locations of system utilities enable detection of renamed system tools, as executables matching baseline tool functionality but with unexpected names trigger alerts."},{"id":"T1036.005","name":"Match Legitimate Name or Location","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that document approved file names and installation locations for all software enable detection of masquerading attempts where malicious files match legitimate names but reside in non-baseline paths."},{"id":"T1036.007","name":"Double File Extension","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that define approved file naming conventions and extension handling enable detection of double file extension attacks, as files with unexpected extension patterns deviate from the documented standard."},{"id":"T1037.002","name":"Login Hook","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS system baselines that document approved login hooks enable detection of unauthorized login hook modifications used for persistence, as adversary-created hooks deviate from the documented startup configuration."},{"id":"T1037.003","name":"Network Logon Script","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for network logon scripts—including approved script locations and contents—enable detection of unauthorized logon script modifications used for persistence and privilege escalation."},{"id":"T1037.004","name":"RC Scripts","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved RC script configurations enable detection of unauthorized modifications to initialization scripts used for persistence on Linux systems."},{"id":"T1037.005","name":"Startup Items","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS baseline configurations that document approved startup items enable detection of unauthorized additions to the startup sequence used for persistence and privilege escalation."},{"id":"T1048.001","name":"Exfiltration Over Symmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network baselines defining approved encrypted protocols and their destinations enable detection of exfiltration over symmetric encrypted non-C2 channels that deviate from the documented communication standards."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Baseline network configurations documenting approved asymmetric encryption usage enable detection of data exfiltration through encrypted alternative protocols not included in the approved baseline."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that define approved unencrypted protocols and their usage contexts enable detection of data exfiltration over cleartext channels that deviate from documented communication patterns."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"System baselines that define USB device policies and approved removable media enable detection and prevention of USB-based data exfiltration through enforcement of documented hardware access controls."},{"id":"T1053.002","name":"At","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations documenting approved 'at' jobs enable detection of unauthorized task creation, as adversary-scheduled jobs deviate from the documented automation baseline for each system type."},{"id":"T1053.003","name":"Cron","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved cron configurations enable detection of adversary-created cron jobs that do not correspond to the documented automation baseline on Linux systems."},{"id":"T1053.005","name":"Scheduled Task","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for Windows scheduled tasks enable detection of unauthorized task creation by comparing active tasks against the documented task baseline for each system role."},{"id":"T1059.001","name":"PowerShell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines that define PowerShell execution policies, language mode restrictions, and logging requirements establish the hardened configuration that limits unauthorized PowerShell-based attack execution."},{"id":"T1059.002","name":"AppleScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"macOS baselines that restrict AppleScript execution contexts and define approved automation workflows enable detection of unauthorized AppleScript usage that deviates from the documented configuration."},{"id":"T1059.003","name":"Windows Command Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict Windows Command Shell access through AppLocker or WDAC policies and define approved command usage patterns establish standards against which unauthorized shell execution is detected."},{"id":"T1059.004","name":"Unix Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines for Linux/macOS that define approved shell usage, restricted shell configurations, and logging requirements enable detection of unauthorized Unix shell execution patterns."},{"id":"T1059.005","name":"Visual Basic","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict VBScript execution through Group Policy and application control establish the standard against which unauthorized Visual Basic script execution is detected and blocked."},{"id":"T1059.006","name":"Python","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved Python installations and their permitted usage contexts enable detection of unauthorized Python execution on endpoints where the interpreter is not part of the documented software load."},{"id":"T1059.007","name":"JavaScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that define approved JavaScript runtime environments and restrict script execution outside browsers enable detection of unauthorized JavaScript-based attack execution."},{"id":"T1059.008","name":"Network Device CLI","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Network device baselines that define approved CLI access methods, authorized management sources, and command authorization levels establish standards that restrict unauthorized network device command execution."},{"id":"T1059.010","name":"AutoHotKey & AutoIT","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved automation tools enable detection of unauthorized AutoHotKey or AutoIT usage, as these utilities on systems outside the documented baseline indicate adversary tooling."},{"id":"T1059.011","name":"Lua","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that track approved scripting environments enable detection of unauthorized Lua interpreter usage on systems where this runtime is not part of the documented software standard."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline audit configurations that mandate centralized log forwarding and protected local storage ensure that Windows event log clearing is detectable because the baseline logging infrastructure preserves evidence."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines for Linux and macOS that enforce syslog forwarding and immutable log configurations ensure that local log clearing does not eliminate evidence preserved by the baseline logging architecture."},{"id":"T1070.003","name":"Clear Command History","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enable persistent command history logging and restrict history file modification ensure that command history clearing is both prevented and detectable through baseline compliance monitoring."},{"id":"T1070.007","name":"Clear Network Connection History and Configurations","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that mandate connection logging and centralized network event forwarding ensure that adversary attempts to clear network connection history are detectable through preserved baseline audit data."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline email configurations that enforce message journaling and archive retention ensure that mailbox data clearing does not eliminate evidence preserved by the documented email retention standards."},{"id":"T1070.009","name":"Clear Persistence","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document all approved persistence mechanisms enable detection of persistence clearing activities, as removal of baselined configurations triggers change detection alerts."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines defining approved web protocols, proxy configurations, and allowed destinations enable detection of web protocol C2 traffic that deviates from documented HTTP/HTTPS communication patterns."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline network configurations documenting approved file transfer protocols and their endpoints enable detection of FTP/SFTP-based C2 that uses channels not included in the approved standard."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines defining approved mail relay configurations enable detection of mail protocol C2 communications that bypass the documented email infrastructure or use unauthorized SMTP connections."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline DNS configurations documenting approved resolvers and query patterns enable detection of DNS-based C2 channels that generate query volumes or patterns inconsistent with documented DNS usage."},{"id":"T1090.001","name":"Internal Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that document approved internal proxy infrastructure enable detection of unauthorized internal proxies established by adversaries for C2 relay within the network perimeter."},{"id":"T1090.002","name":"External Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations documenting approved external proxy endpoints enable detection of adversary-established external proxy connections that bypass the documented egress proxy infrastructure."},{"id":"T1098.004","name":"SSH Authorized Keys","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved SSH authorized keys and their distribution enable detection of unauthorized key additions that deviate from the documented key management baseline."},{"id":"T1102.001","name":"Dead Drop Resolver","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that define approved web service endpoints enable detection of dead drop resolver C2 patterns that query web services not included in the documented configuration."},{"id":"T1102.002","name":"Bidirectional Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines documenting approved cloud service communications enable detection of bidirectional C2 through web services that are not part of the documented application baseline."},{"id":"T1102.003","name":"One-Way Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations defining approved outbound web service connections enable detection of one-way C2 communication to web services outside the documented configuration standard."},{"id":"T1110.001","name":"Password Guessing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations mandating account lockout thresholds, authentication rate limiting, and monitoring establish the defensive standards that detect and resist online password guessing attacks."},{"id":"T1110.002","name":"Password Cracking","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce strong password hashing algorithms and salt requirements increase the computational cost of offline password cracking against credential dumps obtained from baselined systems."},{"id":"T1110.003","name":"Password Spraying","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that mandate MFA, lockout policies, and adaptive authentication controls establish the layered defenses that resist password spraying attacks across the documented environment."},{"id":"T1110.004","name":"Credential Stuffing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce unique password requirements and credential screening against breach databases mitigate credential stuffing by ensuring baselined accounts do not accept compromised passwords."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for email server access—including approved client protocols, conditional access policies, and delegation restrictions—enable detection of unauthorized remote email collection deviating from documented standards."},{"id":"T1127.001","name":"MSBuild","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved MSBuild installations enable detection of MSBuild proxy execution on endpoints where the build tool is not part of the documented software configuration."},{"id":"T1127.002","name":"ClickOnce","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations tracking ClickOnce deployment settings enable detection of unauthorized application deployment through this mechanism on systems outside the documented development baseline."},{"id":"T1132.001","name":"Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines defining expected encoding formats in application communications enable detection of standard encoding used for C2 data that introduces base64 or URL encoding inconsistent with documented patterns."},{"id":"T1132.002","name":"Non-Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline network configurations documenting expected data formats enable detection of non-standard encoding in C2 communications that use custom encoding schemes not present in legitimate baseline traffic."},{"id":"T1134.005","name":"SID-History Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline Active Directory configurations that restrict SID-History modification permissions and monitor for SID changes enable detection of SID-History injection attempts that deviate from the documented identity baseline."},{"id":"T1137.001","name":"Office Template Macros","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Baseline Office configurations that document approved templates and their locations enable detection of unauthorized Office template macros that deviate from the documented template management standard."},{"id":"T1137.002","name":"Office Test","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved Office Test registry entries enable detection of unauthorized Office Test persistence mechanisms on endpoints where this feature should not be configured."},{"id":"T1137.003","name":"Outlook Forms","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for Outlook that restrict form regions and define approved form sources enable detection of unauthorized Outlook Forms persistence that deviates from the documented email client standard."},{"id":"T1137.004","name":"Outlook Home Page","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict Outlook Home Page settings enable detection of adversary persistence through unauthorized home page URL modifications in Outlook folder configurations."},{"id":"T1137.005","name":"Outlook Rules","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Baseline email client configurations documenting approved Outlook rules enable detection of adversary-created mail forwarding or processing rules that deviate from the documented rule baseline."},{"id":"T1137.006","name":"Add-ins","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved Office add-ins and their sources enable detection of unauthorized add-in installations used for persistence that deviate from the documented application baseline."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Hardware baseline configurations with documented component provenance and integrity checksums enable detection of compromised hardware supply chain components that deviate from the approved vendor and configuration standards."},{"id":"T1204.001","name":"Malicious Link","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for URL filtering, browser security, and link scanning establish the protective standards that reduce the likelihood of users successfully executing malicious links."},{"id":"T1204.002","name":"Malicious File","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce application whitelisting and file type restrictions establish the configuration standards that prevent user execution of malicious files not included in the approved software baseline."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Container and VM baselines that define approved image sources and signing requirements prevent user execution of malicious container or virtual machine images that deviate from documented standards."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for Confluence access controls and monitoring establish the security standards against which unauthorized data collection from wiki environments is detected."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"System baselines for SharePoint security—including access policies, DLP controls, and audit logging—establish standards that enable detection of unauthorized document collection from baselined sites."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for messaging applications—including access controls, data retention policies, and integration restrictions—enable detection of unauthorized data collection from communication platforms."},{"id":"T1216.001","name":"PubPrn","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved PubPrn script usage and restrict its execution enable detection of proxy execution through this legitimate script outside the documented administrative context."},{"id":"T1216.002","name":"SyncAppvPublishingServer","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict SyncAppvPublishingServer execution to approved contexts enable detection of unauthorized proxy execution through this App-V utility outside the documented baseline."},{"id":"T1218.001","name":"Compiled HTML File","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict CHM file handling and define approved help file sources enable detection of compiled HTML file proxy execution that deviates from the documented content standard."},{"id":"T1218.002","name":"Control Panel","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict Control Panel item loading to approved CPL files enable detection of adversary use of custom control panel items for defense evasion."},{"id":"T1218.003","name":"CMSTP","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict CMSTP execution and define approved connection profiles enable detection of CMSTP-based proxy execution that deviates from the documented configuration management baseline."},{"id":"T1218.004","name":"InstallUtil","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict InstallUtil usage to approved deployment contexts enable detection of unauthorized .NET installation utility proxy execution outside the documented standard."},{"id":"T1218.005","name":"Mshta","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict Mshta execution and HTA file handling enable detection of HTML Application proxy execution that deviates from the documented application execution baseline."},{"id":"T1218.007","name":"Msiexec","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that define approved MSI package sources and restrict Msiexec usage enable detection of unauthorized installer-based proxy execution outside the documented software deployment standard."},{"id":"T1218.008","name":"Odbcconf","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict Odbcconf usage to approved database configuration contexts enable detection of proxy execution through this ODBC utility outside the documented administrative baseline."},{"id":"T1218.009","name":"Regsvcs/Regasm","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict Regsvcs and Regasm execution to approved .NET deployment contexts enable detection of unauthorized COM component registration used for defense evasion."},{"id":"T1218.012","name":"Verclsid","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that define approved Verclsid usage enable detection of unauthorized COM object verification abuse for proxy execution on endpoints outside the documented administrative context."},{"id":"T1218.013","name":"Mavinject","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict Mavinject execution enable detection of DLL injection through this legitimate tool on systems where application virtualization is not part of the documented standard."},{"id":"T1218.014","name":"MMC","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that define approved MMC snap-ins and restrict console execution enable detection of unauthorized management console proxy execution that deviates from the documented administration baseline."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations documenting approved Electron applications enable detection of unauthorized Electron-based proxy execution, as undocumented Electron apps on baselined systems indicate potential defense evasion."},{"id":"T1491.001","name":"Internal Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for internal web applications with documented content baselines enable rapid detection of internal defacement through automated comparison against the approved content standard."},{"id":"T1491.002","name":"External Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"System baselines for external-facing web content enable rapid detection of external defacement by comparing live content against the documented baseline and triggering alerts on unauthorized modifications."},{"id":"T1505.001","name":"SQL Stored Procedures","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Database server baselines documenting approved stored procedures enable detection of adversary-installed SQL procedures that deviate from the documented database component configuration."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Mail server baselines documenting approved transport agents enable detection of unauthorized agent installations used for persistent email interception outside the documented server configuration."},{"id":"T1505.003","name":"Web Shell","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Web server baselines documenting approved content and modules enable detection of web shell installations by comparing deployed files against the documented web application baseline."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"IIS server baselines documenting approved modules and handlers enable detection of malicious IIS component installations that deviate from the documented web server configuration standard."},{"id":"T1505.005","name":"Terminal Services DLL","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for Terminal Services documenting approved DLLs enable detection of unauthorized Terminal Services DLL persistence that deviates from the documented RDS configuration."},{"id":"T1542.003","name":"Bootkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce Secure Boot and document approved boot configurations enable detection of bootkit installations by verifying boot integrity against the documented baseline."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network device baselines documenting approved ROMMON versions enable detection of ROMMONkit installations by comparing runtime bootstrap monitor versions against the documented standard."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for network devices documenting approved boot sources and methods enable detection of TFTP boot manipulation by identifying boot processes that deviate from the documented standard."},{"id":"T1543.001","name":"Launch Agent","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS system baselines documenting approved Launch Agents enable detection of unauthorized agent installations used for persistence that deviate from the documented startup configuration."},{"id":"T1543.002","name":"Systemd Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Linux system baselines documenting approved systemd services enable detection of unauthorized service creation used for persistence that deviates from the documented service baseline."},{"id":"T1543.003","name":"Windows Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Windows system baselines documenting approved services enable detection of unauthorized Windows service creation that deviates from the documented service configuration standard."},{"id":"T1543.004","name":"Launch Daemon","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS baselines documenting approved Launch Daemons enable detection of unauthorized daemon installations used for root-level persistence that deviate from the documented startup standard."},{"id":"T1546.002","name":"Screensaver","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved screensaver configurations enable detection of unauthorized screensaver modifications used for persistence by comparing settings against the documented display baseline."},{"id":"T1546.003","name":"Windows Management Instrumentation Event Subscription","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations documenting approved WMI event subscriptions enable detection of adversary-created WMI persistence mechanisms that deviate from the documented event subscription baseline."},{"id":"T1546.004","name":"Unix Shell Configuration Modification","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines for shell configuration files—including .bashrc, .zshrc, and .profile—enable detection of unauthorized modifications used for persistence by comparing against the documented baseline."},{"id":"T1546.006","name":"LC_LOAD_DYLIB Addition","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS system baselines that document approved Mach-O binary dependencies enable detection of LC_LOAD_DYLIB additions that inject unauthorized dynamic libraries into baselined applications."},{"id":"T1546.010","name":"AppInit DLLs","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Windows baselines that document approved AppInit DLL configurations enable detection of unauthorized DLL injection through the AppInit_DLLs registry key that deviates from the documented standard."},{"id":"T1546.013","name":"PowerShell Profile","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved PowerShell profile configurations enable detection of unauthorized profile modifications used for persistence that deviate from the documented scripting baseline."},{"id":"T1546.014","name":"Emond","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS baselines documenting approved emond rules enable detection of unauthorized Event Monitor daemon persistence mechanisms that deviate from the documented system event configuration."},{"id":"T1547.003","name":"Time Providers","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Windows baselines that document approved time provider DLLs enable detection of unauthorized time provider registrations used for persistence that deviate from the documented time synchronization baseline."},{"id":"T1547.007","name":"Re-opened Applications","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS baselines documenting approved re-opened application lists enable detection of unauthorized additions to the application resume list used for persistence on baselined systems."},{"id":"T1547.008","name":"LSASS Driver","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines that document approved LSASS drivers and enforce driver signing enable detection of unauthorized LSASS driver loading used for persistence and credential interception."},{"id":"T1547.013","name":"XDG Autostart Entries","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Linux baselines documenting approved XDG autostart entries enable detection of unauthorized desktop login persistence mechanisms that deviate from the documented autostart configuration."},{"id":"T1548.002","name":"Bypass User Account Control","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for UAC—including prompt behavior, auto-elevation settings, and integrity levels—establish the hardened standard that resists UAC bypass techniques on baselined systems."},{"id":"T1548.003","name":"Sudo and Sudo Caching","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved sudoers configurations and sudo caching policies enable detection of unauthorized sudo configuration changes used for privilege escalation."},{"id":"T1548.004","name":"Elevated Execution with Prompt","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS baselines that document approved authorization plugin configurations enable detection of elevated execution prompt abuse that deviates from the documented privilege escalation baseline."},{"id":"T1548.006","name":"TCC Manipulation","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS system baselines that document approved TCC database states enable detection of unauthorized privacy framework manipulation that deviates from the documented transparency and consent baseline."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for OAuth and API access documenting approved token scopes and lifetimes enable detection of stolen application access tokens used outside the documented authorization context."},{"id":"T1550.003","name":"Pass the Ticket","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline Kerberos configurations documenting approved encryption types and ticket lifetimes enable detection of pass-the-ticket attacks that use tickets with characteristics inconsistent with the documented standard."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce credential storage standards and prohibit plaintext credential storage in files reduce the attack surface for credential discovery in file system locations."},{"id":"T1552.002","name":"Credentials in Registry","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict credential storage in registry locations and enforce vault-based credential management reduce the incidence of registry-stored credentials available for adversary harvesting."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that mandate private key storage in hardware security modules or encrypted keystores and restrict file system key storage reduce the exposure of private keys to credential access attacks."},{"id":"T1552.006","name":"Group Policy Preferences","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that disable Group Policy Preferences password storage and mandate removal of existing GPP credentials eliminate this credential exposure vector from the documented environment."},{"id":"T1553.001","name":"Gatekeeper Bypass","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"macOS baselines that enforce Gatekeeper settings and document approved application sources establish the trust framework that resists Gatekeeper bypass attempts on systems maintained to the documented standard."},{"id":"T1553.003","name":"SIP and Trust Provider Hijacking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved SIP and trust provider configurations enable detection of unauthorized modifications to the Windows trust validation infrastructure that deviate from the documented standard."},{"id":"T1553.005","name":"Mark-of-the-Web Bypass","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enforce Mark-of-the-Web processing and restrict bypass mechanisms establish the content trust posture that resists MOTW bypass techniques on baselined systems."},{"id":"T1553.006","name":"Code Signing Policy Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved code signing policies enable detection of unauthorized policy modifications that weaken signature verification requirements on baselined endpoints."},{"id":"T1555.004","name":"Windows Credential Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enforce Windows Credential Manager access controls and restrict credential exposure reduce the attack surface for credential harvesting from the Windows credential vault."},{"id":"T1555.005","name":"Password Managers","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that mandate approved password manager deployments and their security configurations establish the credential management standards that resist password manager exploitation on baselined systems."},{"id":"T1556.004","name":"Network Device Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network device baselines that document approved AAA configurations enable detection of unauthorized authentication process modifications on routers and switches that deviate from the documented standard."},{"id":"T1556.008","name":"Network Provider DLL","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved Network Provider DLLs enable detection of unauthorized network provider registrations used for credential interception that deviate from the documented configuration."},{"id":"T1557.001","name":"LLMNR/NBT-NS Poisoning and SMB Relay","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that disable LLMNR and NBT-NS and enforce SMB signing eliminate the protocol weaknesses exploited for LLMNR/NBT-NS poisoning and SMB relay attacks on baselined network segments."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline network configurations that enforce dynamic ARP inspection and port security on managed switches reduce the ARP cache poisoning attack surface across the documented network infrastructure."},{"id":"T1557.003","name":"DHCP Spoofing","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that enforce DHCP snooping and document approved DHCP server configurations prevent DHCP spoofing by ensuring only baselined servers can respond to address requests."},{"id":"T1557.004","name":"Evil Twin","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline wireless configurations that enforce WPA3, certificate-based authentication, and rogue AP detection reduce the evil twin attack surface across the documented wireless infrastructure."},{"id":"T1558.001","name":"Golden Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that mandate regular KRBTGT password rotation and restrict domain controller access reduce the golden ticket attack surface by limiting adversary access to the long-term authentication secret."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce strong service account passwords and AES-only Kerberos encryption reduce the silver ticket attack surface by making service key material harder to obtain and exploit."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations mandating strong passwords for service accounts and restricting SPN assignment reduce Kerberoasting effectiveness by ensuring extracted tickets resist offline password cracking."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce Kerberos pre-authentication for all accounts eliminate the AS-REP roasting attack surface by ensuring no baselined accounts respond to unauthenticated AS requests."},{"id":"T1559.001","name":"Component Object Model","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that restrict COM object registration and define approved COM interfaces enable detection of unauthorized COM-based execution that deviates from the documented application baseline."},{"id":"T1559.002","name":"Dynamic Data Exchange","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines that disable DDE in Office applications and restrict inter-application data exchange reduce the Dynamic Data Exchange attack surface on baselined endpoints."},{"id":"T1560.001","name":"Archive via Utility","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that monitor archive utility usage and define approved compression tools enable detection of unauthorized data staging through archiving utilities outside the documented automation framework."},{"id":"T1561.001","name":"Disk Content Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce disk protection mechanisms and maintain documented recovery procedures ensure that disk content wipe attacks can be mitigated through restoration to the baselined system state."},{"id":"T1561.002","name":"Disk Structure Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that protect boot sectors and partition tables through firmware-level write protection and documented recovery images enable restoration after disk structure wipe attacks."},{"id":"T1562.001","name":"Disable or Modify Tools","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that mandate specific security tool deployments and configurations enable detection of tool disablement or modification, as changes to baselined security software trigger compliance alerts."},{"id":"T1562.002","name":"Disable Windows Event Logging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline audit configurations that mandate Windows event logging levels and forwarding enable detection of logging disablement by monitoring compliance with the documented audit baseline."},{"id":"T1562.003","name":"Impair Command History Logging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce persistent command history logging and protect history files enable detection of attempts to impair command history that deviate from the documented logging standard."},{"id":"T1562.004","name":"Disable or Modify System Firewall","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline firewall configurations documenting approved rules and default deny policies enable detection of unauthorized firewall modifications by comparing active rules against the documented standard."},{"id":"T1562.006","name":"Indicator Blocking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that mandate specific security sensor deployments and alert configurations enable detection of indicator blocking through compliance monitoring against the documented defensive baseline."},{"id":"T1562.010","name":"Downgrade Attack","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that enforce minimum protocol versions and disable legacy cryptographic standards prevent downgrade attacks by ensuring that baselined systems refuse weak protocol negotiations."},{"id":"T1563.001","name":"SSH Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce SSH session management settings—including key-based authentication, session recording, and idle timeouts—reduce the SSH hijacking attack surface on baselined systems."},{"id":"T1563.002","name":"RDP Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Baseline RDP configurations that enforce NLA, session timeouts, and restricted reconnection policies reduce the RDP session hijacking attack surface on systems maintained to the documented standard."},{"id":"T1564.006","name":"Run Virtual Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System baselines that restrict virtualization capabilities and document approved hypervisor usage enable detection of unauthorized virtual machine instances running on baselined endpoints for defense evasion."},{"id":"T1564.007","name":"VBA Stomping","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline Office configurations that enforce macro security settings enable detection of VBA stomping by comparing macro compilation states against the documented macro management standard."},{"id":"T1564.009","name":"Resource Forking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"macOS system baselines that document approved resource fork usage enable detection of adversary data hiding through macOS resource forks that deviates from the documented file system baseline."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Baseline data integrity configurations that enforce checksums and change detection on critical data stores enable identification of stored data manipulation by comparing against the documented integrity baseline."},{"id":"T1565.002","name":"Transmitted Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network baselines that mandate transmission integrity protections enable detection of in-transit data manipulation by verifying that transmitted data maintains the integrity standards documented in the baseline."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline email security configurations that enforce attachment filtering, sandboxing, and type restrictions establish the defensive standard that blocks spearphishing attachments at the documented gateway."},{"id":"T1566.002","name":"Spearphishing Link","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations for URL filtering and email link scanning establish the protective standards that detect and block spearphishing links before they reach users on baselined systems."},{"id":"T1569.002","name":"Service Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved Windows services and their execution configurations enable detection of unauthorized service execution that deviates from the documented service management baseline."},{"id":"T1573.001","name":"Symmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network baselines documenting approved symmetric encryption standards enable detection of adversary-established C2 channels using encryption implementations inconsistent with the documented cryptographic baseline."},{"id":"T1573.002","name":"Asymmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations documenting approved asymmetric encryption and PKI standards enable detection of C2 channels using unauthorized certificates or key exchange mechanisms outside the documented standard."},{"id":"T1574.001","name":"DLL Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved DLL locations and search order configurations enable detection of DLL search order hijacking by identifying unauthorized libraries in baselined search paths."},{"id":"T1574.004","name":"Dylib Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"macOS baselines documenting approved dylib paths and dependencies enable detection of dylib hijacking through unauthorized library placement in documented search directories."},{"id":"T1574.005","name":"Executable Installer File Permissions Weakness","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce installer file permissions and document approved installation paths enable detection of executable installer exploitation through weak permissions on baselined installations."},{"id":"T1574.007","name":"Path Interception by PATH Environment Variable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations documenting approved PATH environment variables enable detection of path interception attacks that introduce unauthorized directories into the documented execution search order."},{"id":"T1574.008","name":"Path Interception by Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines documenting approved binary and library locations enable detection of search order hijacking by identifying executables planted in documented search paths to intercept execution flow."},{"id":"T1574.009","name":"Path Interception by Unquoted Path","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline service configurations that enforce quoted paths for all services eliminate the unquoted path exploitation vector by ensuring that documented service paths do not contain exploitable spaces."},{"id":"T1574.010","name":"Services File Permissions Weakness","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System baselines that enforce restrictive permissions on service executable files enable detection of service binary replacement through compliance monitoring against the documented file permission standard."},{"id":"T1574.013","name":"KernelCallbackTable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations documenting approved KernelCallbackTable usage enable detection of unauthorized callback table modifications used for execution flow hijacking on baselined Windows systems."},{"id":"T1578.001","name":"Create Snapshot","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Cloud baselines documenting approved snapshot policies and retention schedules enable detection of unauthorized snapshot creation that deviates from the documented cloud infrastructure management standard."},{"id":"T1578.002","name":"Create Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline cloud configurations documenting approved instance types and deployment patterns enable detection of unauthorized instance creation that deviates from the documented cloud infrastructure baseline."},{"id":"T1578.003","name":"Delete Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Cloud baselines that document approved instance lifecycle policies enable detection of unauthorized instance deletion used to destroy forensic evidence, as deletions outside the documented standard trigger alerts."},{"id":"T1598.002","name":"Spearphishing Attachment","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Baseline email security configurations—including attachment scanning, sender verification, and external sender warnings—establish protections against reconnaissance phishing attachments designed to harvest information."},{"id":"T1598.003","name":"Spearphishing Link","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"System baselines for URL filtering and email link protection establish the defensive standard that detects and blocks reconnaissance phishing links designed to collect sensitive information from targeted users."},{"id":"T1599.001","name":"Network Address Translation Traversal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Network baselines documenting approved NAT configurations and routing policies enable detection of unauthorized NAT traversal attempts that bypass the documented network boundary architecture."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Network device baselines documenting approved firmware versions and their cryptographic hashes enable detection of unauthorized image patches that deviate from the documented firmware management standard."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Baseline configurations that document approved minimum firmware versions for all network devices enable detection of system image downgrades below the documented security baseline."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Baseline SNMP configurations documenting approved communities, access controls, and management sources restrict unauthorized MIB data collection by enforcing the documented management access standard."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Network device baselines that define approved management access methods and source restrictions prevent unauthorized configuration dumps by enforcing the documented management plane security standard."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-008","SP-011","SP-012","SP-015","SP-017","SP-023","SP-025","SP-026","SP-028","SP-029","SP-030","SP-036","SP-037","SP-038","SP-041","SP-045","SP-046","SP-047","SP-049","SP-051","SP-053","SP-054"]}}