{"data":{"id":"CM-08","name":"System Component Inventory","family":"CM","family_name":"Configuration Management","withdrawn":false,"description":"a. Develop and document an inventory of system components that:\n1. Accurately reflects the system;\n2. Includes all components within the system;\n3. Does not include duplicate accounting of components or components assigned to any other system;\n4. Is at the level of granularity deemed necessary for tracking and reporting; and\n5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and\nb. Review and update the system component inventory [Assignment: organization-defined frequency].","supplemental_guidance":"System components are discrete, identifiable information technology assets that include hardware, software, and firmware. Organizations may choose to implement centralized system component inventories that include components from all organizational systems. In such situations, organizations ensure that the inventories include system-specific information required for component accountability. The information necessary for effective accountability of system components includes the system name, software owners, software version numbers, hardware inventory specifications, software license information, and for networked components, the machine names and network addresses across all implemented protocols (e.g., IPv4, IPv6). Inventory specifications include date of receipt, cost, model, serial number, manufacturer, supplier information, component type, and physical location.\n\nPreventing duplicate accounting of system components addresses the lack of accountability that occurs when component ownership and system association is not known, especially in large or complex connected systems. Effective prevention of duplicate accounting of system components necessitates use of a unique identifier for each component. For software inventory, centrally managed software that is accessed via other systems is addressed as a component of the system on which it is installed and managed. Software installed on multiple organizational systems and managed at the system level is addressed for each individual system and may appear more than once in a centralized component inventory, necessitating a system association for each software instance in the centralized inventory to avoid duplicate accounting of components. Scanning systems implementing multiple network protocols (e.g., IPv4 and IPv6) can result in duplicate components being identified in different address spaces. The implementation of CM-08(07) can help to eliminate duplicate accounting of components.","enhancements":[{"id":"CM-08(01)","name":"Updates During Installation and Removal","statement":"Update the inventory of system components as part of component installations, removals, and system updates.","baselines":["moderate","high"]},{"id":"CM-08(02)","name":"Automated Maintenance","statement":"Maintain the currency, completeness, accuracy, and availability of the inventory of system components using [Assignment: organization-defined automated mechanisms].","baselines":["high"]},{"id":"CM-08(03)","name":"Automated Unauthorized Component Detection","statement":"a. Detect the presence of unauthorized hardware, software, and firmware components within the system using [Assignment: organization-defined automated mechanisms] [Assignment: organization-defined frequency]; and\nb. Take the following actions when unauthorized components are detected: [Selection (one or more): disable network access by such components; isolate the components; notify [Assignment: organization-defined personnel or roles]].","baselines":["moderate","high"]},{"id":"CM-08(04)","name":"Accountability Information","statement":"Include in the system component inventory information, a means for identifying by [Selection (one or more): name; position; role], individuals responsible and accountable for administering those components.","baselines":["high"]},{"id":"CM-08(05)","name":"No Duplicate Accounting of Components","withdrawn":true,"incorporated_into":["CM-08"]},{"id":"CM-08(06)","name":"Assessed Configurations and Approved Deviations","statement":"Include assessed component configurations and any approved deviations to current deployed configurations in the system component inventory.","baselines":[]},{"id":"CM-08(07)","name":"Centralized Repository","statement":"Provide a centralized repository for the inventory of system components.","baselines":[]},{"id":"CM-08(08)","name":"Automated Location Tracking","statement":"Support the tracking of system components by geographic location using [Assignment: organization-defined automated mechanisms].","baselines":[]},{"id":"CM-08(09)","name":"Assignment of Components to Systems","statement":"a. Assign system components to a system; and\nb. Receive an acknowledgement from [Assignment: organization-defined personnel or roles] of this assignment.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CM-08","name":"System Component Inventory","description":"a. Develop and document an inventory of system components that:\n1. Accurately reflects the system;\n2. Includes all components within the system;\n3. Does not include duplicate accounting of components or components assigned to any other system;\n4. Is at the level of granularity deemed necessary for tracking and reporting; and\n5. Includes the following information to achieve system component accountability: [Assignment: organization-defined information deemed necessary to achieve effective system component accountability]; and\nb. Review and update the system component inventory [Assignment: organization-defined frequency].","discussion":"System components are discrete, identifiable information technology assets that include hardware, software, and firmware. Organizations may choose to implement centralized system component inventories that include components from all organizational systems. In such situations, organizations ensure that the inventories include system-specific information required for component accountability. The information necessary for effective accountability of system components includes the system name, software owners, software version numbers, hardware inventory specifications, software license information, and for networked components, the machine names and network addresses across all implemented protocols (e.g., IPv4, IPv6). Inventory specifications include date of receipt, cost, model, serial number, manufacturer, supplier information, component type, and physical location.\n\nPreventing duplicate accounting of system components addresses the lack of accountability that occurs when component ownership and system association is not known, especially in large or complex connected systems. Effective prevention of duplicate accounting of system components necessitates use of a unique identifier for each component. For software inventory, centrally managed software that is accessed via other systems is addressed as a component of the system on which it is installed and managed. Software installed on multiple organizational systems and managed at the system level is addressed for each individual system and may appear more than once in a centralized component inventory, necessitating a system association for each software instance in the centralized inventory to avoid duplicate accounting of components. Scanning systems implementing multiple network protocols (e.g., IPv4 and IPv6) can result in duplicate components being identified in different address spaces. The implementation of CM-08(07) can help to eliminate duplicate accounting of components.","related_controls":["CM-02","CM-07","CM-09","CM-10","CM-11","CM-13","CP-02","CP-09","MA-02","MA-06","PE-20","PL-09","PM-05","SA-04","SA-05","SI-02","SR-04"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Adds 'Does not include duplicate accounting of components or components assigned to any other system' Discussion of accountability expanded Incorporates withdrawn control CM-08(5)"}},"compliance_mappings":{"iso_27001_2022":["A.5.9","A.8.9"],"iso_27002_2022":["5.9","5.37","8.1","8.9"],"cobit_2019":["BAI09","BAI10"],"pci_dss_v4":["11.2","12.5"],"nist_csf_2":["ID.AM-01","ID.AM-02","ID.AM-07","ID.AM-08","PR.PS-01","PR.PS-03"],"cis_controls_v8":["CIS 1","CIS 1.1","CIS 1.2","CIS 1.3","CIS 1.5","CIS 2","CIS 2.1","CIS 2.4","CIS 3.2","CIS 16.4"],"soc2_tsc":["CC6.1-POF1"],"finos_ccc":["CCC-C06"],"iso_42001_2023":["A.4.2","A.4.4"],"iec_62443":[],"asd_e8":["E8-2 ML3","E8-6 ML3"],"nis2":["Art. 21(2)(i)"],"apra_cps_234":["Para 21"],"mas_trm":[],"pra_op_resilience":["SS1/21-5.2","SS2/21-13.1"],"bsi_grundschutz":[],"anssi":["Hygiene.5","Hygiene.8","SecNumCloud.9.1"],"osfi_b13":["B-13.2.1","B-13.3.1"],"finma_circular":["IV.A(28)","IV.A(29)","IV.A(30)","IV.B.c(54)","IV.B.c(55)"],"gdpr":["Art.30(1)","Art.35(7)(a)"],"dora":["Art.8(1)","Art.8(4)","Art.28(4)"],"bio2":["5.9","5.37","8.1","8.9"],"rbi_csf":["Annex1.1","ITGRCA.9"],"fisc":["FISC.O9","FISC.O13","FISC.T7"],"lgpd_bcb":["BCB.Art.20"],"hkma_tme1":[],"mlps_2":["8.1.10.1","8.1.10.6","8.2","8.3"],"dnb_good_practice":["DNB.6.1","DNB.13.1","DNB.13.2","DNB.19.3"],"cra":["CRA.II.1","CRA.Info.3"],"swift_cscf":["SWIFT.2.7"],"cbuae":["CR-7"],"nca_ecc":["2-1","2-6"],"qatar_nia":["AM","OS"],"sama_csf":["2.1"],"uae_ia":["T4","T7"],"bog_cisd":["CISD-V"],"bom_ctrm":["2.1","3.2","3.7"],"cbe_csf":["CRM-2"],"cbn_csf":["Part3.1"],"popia":["s17"],"sa_js2":["JS2-6.1","JS2-7.2"],"bcbs_239":["Principle 2","Principle 4"],"bot_cyber":["Ch2.1"],"cpmi_pfmi":["CG.ID","PFMI.P17"],"eba_ict":["3.3.2","3.4.4","3.5(a)","3.5(b)"],"ecb_croe":["CROE.2.2.2"],"ffiec_is":["II.C.5","II.C.11","II.C.13(e)"],"hipaa_sr":["§164.310(d)(2)(iii)"],"iosco_cyber":["ID-1","ID-2","ID-4"],"nydfs_500":["500.13"],"sebi_cscrf":["ID.AM"],"cmmc_2":["CM"],"nerc_cip":["CIP-010-4"],"nrc_73_54":["RG5.71-B-CM"],"tsa_psd":[],"ieee_1686":["5.4"],"ferc_cip":[],"doe_c2m2":["ASSET"],"api_1164":[],"awia":["AWWA Sec 2"],"iaea_nss":[],"pci_pts":["K"],"fips_140":[],"cbest":["CBEST.3"],"tiber_eu":[],"pci_hsm":["2"],"common_criteria":[],"isae_3402":["Clause 9"],"fca_sysc_13":["SYSC 13.7.1","SYSC 13.7.2"],"fda_21_cfr_11":["§11.10(h)"],"fda_cyber":["524B-1","SBOM-1","SBOM-2","SBOM-3","ST-4"],"hitrust_csf":["05.c","07.a","10.e"],"iso_27799":["8.1","11.2","H.3"],"lloyds_ms":["MS1.1","MS8.4","MS9.3"],"naic_ds":["3","4-asset"],"nhs_dspt":["NDG-5.3","NDG-8.1","NDG-8.3","NDG-9.7"],"pra_ss1_23":["P1.1","P1.3","P5.5","P-IT.3"],"solvency_ii":["DR.266-DataSec","EIOPA-ICT-4.3"],"owasp_masvs_v2":["MASVS-CODE-3"],"csa_ccm_v4":["CEK-21","DCS-05","DCS-06","DCS-08","DSP-03","STA-07","UEM-04","UEM-12"],"csa_aicm":["CEK-21","DCS-05","DCS-06","DCS-08","DSP-03","MDS-02","STA-07","STA-15","UEM-04","UEM-12"],"ccss_v9":["1.02.3","1.04.5"],"mica":["Art.40(1)","Art.63(2)","Art.82(1)"],"basel_sco60":["SCO60.14","SCO60.51","SCO60.65"],"bssc":["GSP-14","NOS-03"],"sec_custody_digital":["SEC-CD-04","SEC-CD-09","SEC-CD-18"],"dpdpa":[]},"attack_techniques":[{"id":"T1046","name":"Network Service Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"A comprehensive component inventory enables security teams to distinguish legitimate network services from unauthorized ones, making adversary network service discovery efforts more detectable when scans reveal services not documented in the authoritative asset inventory."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Maintaining an inventory of approved physical media and peripheral devices enables detection of unauthorized removable media used for data exfiltration, as unregistered devices connected to inventoried systems trigger security alerts."},{"id":"T1053","name":"Scheduled Task/Job","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Component inventory tracking identifies authorized scheduled tasks and jobs across the enterprise, enabling detection of adversary-created persistence mechanisms that do not correspond to documented, approved automation entries."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"An accurate software inventory documents which scripting interpreters are legitimately installed on each system, enabling detection and blocking of unauthorized scripting engines that adversaries deploy for command execution."},{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Maintaining a current inventory of installed software versions and patch levels enables rapid identification of systems vulnerable to privilege escalation exploits, prioritising remediation before adversaries can leverage known vulnerabilities."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Inventory of authorized software deployment tools and their legitimate distribution scope enables detection of adversary abuse when deployment infrastructure is used to push malicious payloads to systems outside normal distribution patterns."},{"id":"T1091","name":"Replication Through Removable Media","tactics":["initial-access","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Tracking hardware component inventory, including removable media readers and USB ports, enables enforcement of media controls and detection of unauthorized device connections used for malware propagation via removable media."},{"id":"T1092","name":"Communication Through Removable Media","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Component inventory of systems with removable media capabilities identifies potential targets for covert communication channels, enabling targeted monitoring and port restriction on inventoried systems in sensitive environments."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"A comprehensive data repository inventory enables detection of automated collection activities by establishing baselines for normal access patterns across inventoried information stores, revealing anomalous bulk data access."},{"id":"T1127","name":"Trusted Developer Utilities Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software inventory that tracks developer utilities on each endpoint enables detection of unauthorized use of trusted development tools for proxy execution, flagging when inventoried build tools execute outside approved development contexts."},{"id":"T1133","name":"External Remote Services","tactics":["initial-access","persistence"],"mapping_type":"mitigates","mapping_rationale":"Maintaining an inventory of authorized external remote service access points enables detection of unauthorized VPN endpoints, remote desktop gateways, or other remote access services that adversaries establish for persistent access."},{"id":"T1137","name":"Office Application Startup","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Office application inventory tracking enables detection of unauthorized startup modifications by documenting legitimate Office add-ins and templates, revealing adversary-installed persistence mechanisms that deviate from the approved configuration."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"An accurate inventory of internet-facing client applications and their versions enables targeted patching and browser hardening to reduce drive-by compromise exposure across the documented attack surface."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Component inventory of all public-facing applications provides the foundation for vulnerability management and attack surface reduction, ensuring every internet-exposed service is documented, monitored, and included in patching cycles."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Maintaining a comprehensive inventory of hardware and software components, including vendor and provenance information, enables verification of supply chain integrity and detection of unauthorized or tampered components entering the environment."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Inventory of client applications and their versions across all endpoints enables rapid identification and remediation of systems running software vulnerable to client-side exploitation, reducing the available attack surface."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"A current inventory of all network-accessible services and their patch levels enables prioritised remediation of exploitable remote services, reducing the attack surface available for lateral movement through vulnerability exploitation."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Component inventory tracking of security tool versions and configurations enables detection of systems running outdated or vulnerable defensive software that adversaries could exploit to achieve defense evasion."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Maintaining an inventory of authentication infrastructure components and their patch levels enables rapid identification and remediation of systems vulnerable to credential access exploits, reducing adversary opportunities for credential harvesting."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"An inventory of information repositories—including wikis, document management systems, and collaboration platforms—enables access monitoring and data protection controls across all documented data stores."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software inventory documenting which system binaries are present on each endpoint enables detection of proxy execution attempts using utilities that should not be installed on specific system types according to the authoritative inventory."},{"id":"T1221","name":"Template Injection","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Inventory of document templates and their approved sources enables detection of template injection attacks, as modified templates that reference unauthorized remote locations can be identified through comparison against the documented template inventory."},{"id":"T1495","name":"Firmware Corruption","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Hardware component inventory with firmware version tracking enables targeted integrity monitoring and rapid detection of firmware corruption across all documented network and system infrastructure."},{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Server software component inventory enables detection of unauthorized additions such as web shells, transport agents, or IIS modules by comparing installed components against the documented approved server software baseline."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"An inventory of cloud storage resources and their sensitivity classifications enables monitoring and access control enforcement across all documented cloud data stores, detecting unauthorized access to inventoried storage objects."},{"id":"T1542","name":"Pre-OS Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Hardware inventory that tracks firmware versions and boot configurations enables detection of pre-OS boot modifications by establishing baselines for comparison during integrity verification of inventoried boot-chain components."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting authorized elevation control mechanisms and their configurations enables detection of abuse when adversaries modify or misuse privilege escalation controls on inventoried systems."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software inventory tracking code signing certificates and trust configurations enables detection of trust control subversion when adversaries modify signing policies or inject unauthorized certificates on inventoried systems."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network component inventory of switches, routers, and access points enables detection of adversary-in-the-middle infrastructure by identifying unauthorized network devices or configuration changes that facilitate traffic interception."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Inventory of applications with IPC capabilities enables monitoring of inter-process communication channels, detecting adversary abuse of COM objects, DDE, or other IPC mechanisms on inventoried systems."},{"id":"T1563","name":"Remote Service Session Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Maintaining an inventory of remote access services and their authorized users enables detection of session hijacking by identifying unauthorized session resumptions on inventoried remote service endpoints."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Component inventory with documented data integrity baselines enables detection of data manipulation by providing authoritative references for comparison against potentially tampered data on inventoried systems."},{"id":"T1574","name":"Hijack Execution Flow","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Software inventory documenting approved installation paths, DLL locations, and service configurations enables detection of execution flow hijacking through comparison against documented component locations."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Network device inventory with firmware version tracking enables detection of unauthorized system image modifications by establishing authoritative baselines for all inventoried network infrastructure firmware."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"An inventory of network management infrastructure and configuration repositories enables access monitoring and detection of unauthorized configuration data collection from inventoried management systems."},{"id":"T1622","name":"Debugger Evasion","tactics":["defense-evasion","discovery"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting approved debugging tools and analysis environments enables detection of adversary evasion techniques that probe for debuggers, as inventoried systems can be correlated with expected debug tool presence."},{"id":"T1011.001","name":"Exfiltration Over Bluetooth","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Hardware inventory tracking Bluetooth-capable devices enables enforcement of wireless restrictions and detection of unauthorized Bluetooth exfiltration from inventoried systems with documented wireless capabilities."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network infrastructure inventory enables detection of unauthorized traffic duplication by documenting legitimate port mirroring and SPAN configurations, revealing adversary-installed taps on inventoried network devices."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Inventory of systems with RDP enabled and their authorized users enables detection of unauthorized remote desktop connections, flagging lateral movement attempts to inventoried endpoints that should not be receiving RDP traffic."},{"id":"T1021.003","name":"Distributed Component Object Model","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting DCOM-enabled systems enables detection of unauthorized distributed COM usage for lateral movement, as DCOM activity on systems not inventoried for this capability triggers security alerts."},{"id":"T1021.004","name":"SSH","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"An inventory of SSH-enabled systems and authorized key pairs enables detection of unauthorized SSH connections, identifying lateral movement attempts that target inventoried systems using undocumented credentials."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Inventory of systems with VNC capabilities enables detection of unauthorized remote access, as VNC connections to or from systems not documented for VNC usage indicate potential lateral movement."},{"id":"T1021.006","name":"Windows Remote Management","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Tracking systems with Windows Remote Management enabled in the component inventory enables detection of unauthorized WinRM usage for lateral movement across inventoried infrastructure."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Hardware inventory tracking USB ports and removable media capabilities enables enforcement of device restrictions and detection of USB exfiltration attempts on inventoried systems with documented peripheral access."},{"id":"T1053.002","name":"At","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting authorized 'at' jobs enables detection of adversary-scheduled tasks by comparing active jobs against the approved automation baseline for each inventoried system."},{"id":"T1053.005","name":"Scheduled Task","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Inventory of authorized scheduled tasks across all Windows systems enables detection of adversary-created persistence mechanisms, as unauthorized tasks on inventoried endpoints are flagged through baseline comparison."},{"id":"T1059.001","name":"PowerShell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Software inventory tracking PowerShell installation and configuration across endpoints enables detection of unauthorized PowerShell execution on systems where the interpreter should not be installed or is restricted by policy."},{"id":"T1059.005","name":"Visual Basic","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting Visual Basic runtime presence enables detection of VBScript-based attacks on systems where VB execution is not required, as the inventory identifies endpoints where the scripting engine should be removed."},{"id":"T1059.007","name":"JavaScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Tracking JavaScript runtime engines in the software inventory enables detection of unauthorized JavaScript execution outside browser contexts, particularly on server systems where standalone JS runtimes are not documented."},{"id":"T1059.010","name":"AutoHotKey & AutoIT","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Software inventory documenting AutoHotKey and AutoIT installations enables detection of unauthorized automation tool deployment, as these utilities on systems not inventoried for their use indicate potential adversary tooling."},{"id":"T1098.004","name":"SSH Authorized Keys","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Inventory of authorized SSH key pairs and their distribution across systems enables detection of unauthorized SSH authorized keys modifications, revealing adversary persistence through undocumented key deployments."},{"id":"T1127.001","name":"MSBuild","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software inventory tracking MSBuild installations enables detection of proxy execution through MSBuild on systems where development tools are not documented, flagging defense evasion attempts using unregistered build utilities."},{"id":"T1127.002","name":"ClickOnce","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting ClickOnce deployment capabilities enables detection of unauthorized application deployment through this mechanism on systems where ClickOnce is not required for business operations."},{"id":"T1137.001","name":"Office Template Macros","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Inventory of approved Office templates and their authorized locations enables detection of malicious template macros by identifying modifications to documented template files or new templates in inventoried directories."},{"id":"T1195.003","name":"Compromise Hardware Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Hardware component inventory with provenance tracking enables detection of compromised supply chain components by documenting approved vendors, serial numbers, and hardware checksums for all inventoried physical assets."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Inventory of Confluence instances and their data classification enables monitoring and access control enforcement across all documented wiki deployments, detecting unauthorized data collection from inventoried knowledge bases."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"An inventory of SharePoint sites and their sensitivity levels enables monitoring and DLP enforcement across all documented collaboration platforms, detecting unauthorized bulk data extraction from inventoried document libraries."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Inventory of approved messaging applications enables detection of unauthorized data collection from communication platforms, as access to inventoried messaging systems can be monitored against documented user baselines."},{"id":"T1218.003","name":"CMSTP","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software inventory documenting CMSTP presence on endpoints enables detection of unauthorized use of this trusted binary for defense evasion on systems where the Connection Manager is not required."},{"id":"T1218.004","name":"InstallUtil","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Component inventory tracking InstallUtil deployment enables detection of proxy execution attempts on systems where this .NET installation utility is not documented as required for business operations."},{"id":"T1218.005","name":"Mshta","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Inventory of systems with Mshta present enables detection of HTML Application proxy execution, as Mshta usage on endpoints not documented for HTA processing indicates potential defense evasion activity."},{"id":"T1218.008","name":"Odbcconf","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software inventory documenting Odbcconf installations enables detection of unauthorized proxy execution through this ODBC configuration utility on systems where database connectivity tools are not required."},{"id":"T1218.009","name":"Regsvcs/Regasm","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Component inventory tracking .NET registration tools enables detection of Regsvcs/Regasm proxy execution on systems where .NET COM component registration is not documented as an operational requirement."},{"id":"T1218.012","name":"Verclsid","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Inventory of systems with Verclsid present enables detection of unauthorized COM object verification abuse for proxy execution, flagging usage on endpoints where this utility is not operationally documented."},{"id":"T1218.013","name":"Mavinject","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software inventory documenting Mavinject presence enables detection of process injection via this legitimate Microsoft tool on systems where application virtualization is not documented as required."},{"id":"T1218.014","name":"MMC","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Component inventory tracking MMC installation enables detection of unauthorized management console usage for proxy execution, as MMC snap-in loading on non-administrative systems indicates potential defense evasion."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Inventory of approved Electron applications enables detection of unauthorized Electron-based proxy execution, as undocumented Electron apps on inventoried systems indicate potential adversary tooling or defense evasion."},{"id":"T1505.001","name":"SQL Stored Procedures","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Database server inventory enables monitoring of SQL stored procedures against documented baselines, detecting adversary-installed persistent procedures that do not appear in the approved server component inventory."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Mail server component inventory documents legitimate transport agents, enabling detection of unauthorized agent installations that adversaries use for persistent email interception and data collection."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Web server inventory documenting approved IIS modules and components enables detection of malicious IIS module installations by comparing active components against the authoritative server software inventory."},{"id":"T1542.001","name":"System Firmware","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Hardware inventory with firmware version tracking enables detection of unauthorized system firmware modifications by comparing UEFI/BIOS versions against documented baselines for each inventoried platform."},{"id":"T1542.003","name":"Bootkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Component inventory tracking boot configuration for all systems enables detection of bootkit modifications by establishing documented boot chain baselines against which runtime integrity measurements are verified."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network device inventory with ROMMON version tracking enables detection of ROMMONkit installations by comparing bootstrap monitor versions against documented baselines for each inventoried router and switch."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Inventory of network devices and their boot configurations documents which devices use TFTP boot, enabling targeted hardening and monitoring to prevent unauthorized boot image substitution on inventoried infrastructure."},{"id":"T1546.002","name":"Screensaver","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting screensaver configurations enables detection of unauthorized screensaver modifications used for persistence, as changes to inventoried display settings trigger baseline deviation alerts."},{"id":"T1546.006","name":"LC_LOAD_DYLIB Addition","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Software inventory tracking Mach-O binary dependencies enables detection of LC_LOAD_DYLIB additions to inventoried macOS applications, revealing adversary persistence through injected dynamic library load commands."},{"id":"T1546.014","name":"Emond","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting emond daemon configuration enables detection of unauthorized Event Monitor rules on inventoried macOS systems, flagging adversary persistence through undocumented emond rules."},{"id":"T1547.007","name":"Re-opened Applications","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Inventory of macOS application persistence configurations enables detection of unauthorized additions to re-opened application lists, identifying adversary persistence mechanisms on inventoried systems."},{"id":"T1548.004","name":"Elevated Execution with Prompt","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting authorization configurations enables detection of elevated execution prompt abuse, as modifications to inventoried privilege escalation settings trigger baseline deviation alerts."},{"id":"T1548.006","name":"TCC Manipulation","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Software inventory tracking TCC database states enables detection of unauthorized privacy framework manipulation on inventoried macOS systems, revealing adversary attempts to grant themselves undocumented permissions."},{"id":"T1553.006","name":"Code Signing Policy Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Inventory of code signing policies across all systems enables detection of unauthorized policy modifications that weaken signature verification requirements on inventoried endpoints."},{"id":"T1556.009","name":"Conditional Access Policies","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Inventory of conditional access policy configurations enables detection of unauthorized modifications to authentication requirements, as changes to inventoried policies trigger security alerts for review."},{"id":"T1557.001","name":"LLMNR/NBT-NS Poisoning and SMB Relay","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network infrastructure inventory enables detection of LLMNR/NBT-NS poisoning by documenting legitimate name resolution services, revealing unauthorized protocol responses from non-inventoried sources."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Component inventory of network infrastructure enables detection of ARP cache poisoning by establishing documented MAC-to-IP address mappings for inventoried devices, revealing spoofed ARP responses."},{"id":"T1557.003","name":"DHCP Spoofing","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network device inventory documenting authorized DHCP servers enables detection of rogue DHCP responses from non-inventoried sources, preventing adversary network manipulation through DHCP spoofing."},{"id":"T1559.002","name":"Dynamic Data Exchange","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Software inventory documenting DDE-capable applications enables monitoring of Dynamic Data Exchange usage, detecting adversary exploitation of DDE on systems where this inter-process communication is not operationally required."},{"id":"T1563.001","name":"SSH Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Inventory of SSH-enabled systems and active sessions enables detection of SSH hijacking by correlating session activity against documented user-to-system assignments in the component inventory."},{"id":"T1563.002","name":"RDP Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Component inventory tracking RDP-enabled systems and their authorized users enables detection of RDP session hijacking by identifying unauthorized session reconnections on inventoried endpoints."},{"id":"T1564.006","name":"Run Virtual Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"System inventory tracking enables detection of unauthorized virtual machine instances running on inventoried endpoints, revealing adversary use of lightweight VMs to evade host-based detection tools."},{"id":"T1564.007","name":"VBA Stomping","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Software inventory documenting Office macro configurations enables detection of VBA stomping by comparing compiled macro code against documented source, revealing discrepancies on inventoried systems."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Component inventory with documented data integrity baselines enables detection of stored data manipulation by providing authoritative reference states for critical data on inventoried systems."},{"id":"T1565.002","name":"Transmitted Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Network infrastructure inventory enables detection of transmitted data manipulation by documenting legitimate data flows and their integrity protection mechanisms across inventoried communication paths."},{"id":"T1574.004","name":"Dylib Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Software inventory documenting dylib locations and dependencies for inventoried macOS applications enables detection of dylib hijacking by identifying unauthorized library files in documented search paths."},{"id":"T1574.007","name":"Path Interception by PATH Environment Variable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting PATH environment variables across systems enables detection of path interception attacks by identifying unauthorized executables placed in inventoried PATH directories."},{"id":"T1574.008","name":"Path Interception by Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Software inventory tracking application search order configurations enables detection of search order hijacking by identifying unauthorized executables in documented DLL and binary search paths."},{"id":"T1574.009","name":"Path Interception by Unquoted Path","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting service executable paths enables detection of unquoted path exploitation by identifying services with spaces in their file paths that lack proper quoting in the documented configuration."},{"id":"T1593.003","name":"Code Repositories","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Maintaining an inventory of organisational code repositories—including public, private, and archived repositories—enables detection of information leakage through exposed source code and identification of repositories requiring access controls."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Network device inventory with firmware version tracking enables detection of unauthorized image patches by comparing running firmware against documented, cryptographically verified baselines for each inventoried device."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting approved firmware versions for all network devices enables detection of image downgrades, as running versions below documented baselines trigger security alerts for investigation."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Inventory of SNMP-enabled devices and their management configurations enables monitoring of MIB access patterns, detecting unauthorized SNMP queries against inventoried network infrastructure."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Component inventory documenting network device management access enables detection of unauthorized configuration dumps by monitoring access patterns against the documented management baseline for inventoried infrastructure."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":["SP-001","SP-002","SP-015","SP-017","SP-026","SP-029","SP-030","SP-038","SP-040","SP-044","SP-046","SP-047","SP-049","SP-050","SP-051","SP-053","SP-054"]}}