<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Defensive Actions (Email and M365)</title><link>https://cybersecuritytracker.ai/defensive-actions?cat=email-m365</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:05:07 GMT</lastBuildDate><item><title>M1017 User Training counters T1657 Financial Theft</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1657</link><guid isPermaLink="false">cst-defensive-M1017-T1657</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1657 Financial Theft</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1657</link><guid isPermaLink="false">cst-defensive-M1018-T1657</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1048 Exfiltration Over Alternative Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1048</link><guid isPermaLink="false">cst-defensive-M1018-T1048</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1022 Restrict File and Directory Permissions counters T1048 Exfiltration Over Alternative Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1022-T1048</link><guid isPermaLink="false">cst-defensive-M1022-T1048</guid><description>Restricting file and directory permissions involves setting access controls at the file system level to limit which users, groups, or processes can read, write, or execute files. By configuring permissions appropriately, organizations can reduce the attack surface for adversaries seeking to access sensitive data, plant malicious code, or tamper with system files.

Enforce Least Privilege Permissions:

- Remove unnecessary write permissions on sensitive files and directories.
- Use file ownership</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1030 Network Segmentation counters T1048 Exfiltration Over Alternative Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1030-T1048</link><guid isPermaLink="false">cst-defensive-M1030-T1048</guid><description>Network segmentation involves dividing a network into smaller, isolated segments to control and limit the flow of traffic between devices, systems, and applications. By segmenting networks, organizations can reduce the attack surface, restrict lateral movement by adversaries, and protect critical assets from compromise.

Effective network segmentation leverages a combination of physical boundaries, logical separation through VLANs, and access control policies enforced by network appliances like </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1048 Exfiltration Over Alternative Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1048</link><guid isPermaLink="false">cst-defensive-M1031-T1048</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1048 Exfiltration Over Alternative Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1048</link><guid isPermaLink="false">cst-defensive-M1037-T1048</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1057 Data Loss Prevention counters T1048 Exfiltration Over Alternative Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1057-T1048</link><guid isPermaLink="false">cst-defensive-M1057-T1048</guid><description>Data Loss Prevention (DLP) involves implementing strategies and technologies to identify, categorize, monitor, and control the movement of sensitive data within an organization. This includes protecting data formats indicative of Personally Identifiable Information (PII), intellectual property, or financial data from unauthorized access, transmission, or exfiltration. DLP solutions integrate with network, endpoint, and cloud platforms to enforce security policies and prevent accidental or malici</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1213.002 Sharepoint</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1213-002</link><guid isPermaLink="false">cst-defensive-M1017-T1213-002</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1213.002 Sharepoint</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1213-002</link><guid isPermaLink="false">cst-defensive-M1018-T1213-002</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1213.002 Sharepoint</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1213-002</link><guid isPermaLink="false">cst-defensive-M1047-T1213-002</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1537 Transfer Data to Cloud Account</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1537</link><guid isPermaLink="false">cst-defensive-M1018-T1537</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1537 Transfer Data to Cloud Account</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1537</link><guid isPermaLink="false">cst-defensive-M1037-T1537</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1054 Software Configuration counters T1537 Transfer Data to Cloud Account</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1054-T1537</link><guid isPermaLink="false">cst-defensive-M1054-T1537</guid><description>Software configuration refers to making security-focused adjustments to the settings of applications, middleware, databases, or other software to mitigate potential threats. These changes help reduce the attack surface, enforce best practices, and protect sensitive data. This mitigation can be implemented through the following measures:

Conduct a Security Review of Application Settings:

- Review the software documentation to identify recommended security configurations.
- Compare default setti</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1057 Data Loss Prevention counters T1537 Transfer Data to Cloud Account</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1057-T1537</link><guid isPermaLink="false">cst-defensive-M1057-T1537</guid><description>Data Loss Prevention (DLP) involves implementing strategies and technologies to identify, categorize, monitor, and control the movement of sensitive data within an organization. This includes protecting data formats indicative of Personally Identifiable Information (PII), intellectual property, or financial data from unauthorized access, transmission, or exfiltration. DLP solutions integrate with network, endpoint, and cloud platforms to enforce security policies and prevent accidental or malici</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1022 Restrict File and Directory Permissions counters T1070 Indicator Removal</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1022-T1070</link><guid isPermaLink="false">cst-defensive-M1022-T1070</guid><description>Restricting file and directory permissions involves setting access controls at the file system level to limit which users, groups, or processes can read, write, or execute files. By configuring permissions appropriately, organizations can reduce the attack surface for adversaries seeking to access sensitive data, plant malicious code, or tamper with system files.

Enforce Least Privilege Permissions:

- Remove unnecessary write permissions on sensitive files and directories.
- Use file ownership</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1029 Remote Data Storage counters T1070 Indicator Removal</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1029-T1070</link><guid isPermaLink="false">cst-defensive-M1029-T1070</guid><description>Remote Data Storage focuses on moving critical data, such as security logs and sensitive files, to secure, off-host locations to minimize unauthorized access, tampering, or destruction by adversaries. By leveraging remote storage solutions, organizations enhance the protection of forensic evidence, sensitive information, and monitoring data. This mitigation can be implemented through the following measures:

Centralized Log Management:

- Configure endpoints to forward security logs to a central</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1041 Encrypt Sensitive Information counters T1070 Indicator Removal</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1041-T1070</link><guid isPermaLink="false">cst-defensive-M1041-T1070</guid><description>Protect sensitive information at rest, in transit, and during processing by using strong encryption algorithms. Encryption ensures the confidentiality and integrity of data, preventing unauthorized access or tampering. This mitigation can be implemented through the following measures:

Encrypt Data at Rest:

- Use Case: Use full-disk encryption or file-level encryption to secure sensitive data stored on devices.
- Implementation: Implement BitLocker for Windows systems or FileVault for macOS dev</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1114 Email Collection</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1114</link><guid isPermaLink="false">cst-defensive-M1032-T1114</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1041 Encrypt Sensitive Information counters T1114 Email Collection</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1041-T1114</link><guid isPermaLink="false">cst-defensive-M1041-T1114</guid><description>Protect sensitive information at rest, in transit, and during processing by using strong encryption algorithms. Encryption ensures the confidentiality and integrity of data, preventing unauthorized access or tampering. This mitigation can be implemented through the following measures:

Encrypt Data at Rest:

- Use Case: Use full-disk encryption or file-level encryption to secure sensitive data stored on devices.
- Implementation: Implement BitLocker for Windows systems or FileVault for macOS dev</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1114 Email Collection</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1114</link><guid isPermaLink="false">cst-defensive-M1047-T1114</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1060 Out-of-Band Communications Channel counters T1114 Email Collection</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1060-T1114</link><guid isPermaLink="false">cst-defensive-M1060-T1114</guid><description>Establish secure out-of-band communication channels to ensure the continuity of critical communications during security incidents, data integrity attacks, or in-network communication failures. Out-of-band communication refers to using an alternative, separate communication path that is not dependent on the potentially compromised primary network infrastructure. This method can include secure messaging apps, encrypted phone lines, satellite communications, or dedicated emergency communication sys</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1114.002 Remote Email Collection</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1114-002</link><guid isPermaLink="false">cst-defensive-M1032-T1114-002</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1041 Encrypt Sensitive Information counters T1114.002 Remote Email Collection</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1041-T1114-002</link><guid isPermaLink="false">cst-defensive-M1041-T1114-002</guid><description>Protect sensitive information at rest, in transit, and during processing by using strong encryption algorithms. Encryption ensures the confidentiality and integrity of data, preventing unauthorized access or tampering. This mitigation can be implemented through the following measures:

Encrypt Data at Rest:

- Use Case: Use full-disk encryption or file-level encryption to secure sensitive data stored on devices.
- Implementation: Implement BitLocker for Windows systems or FileVault for macOS dev</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1060 Out-of-Band Communications Channel counters T1114.002 Remote Email Collection</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1060-T1114-002</link><guid isPermaLink="false">cst-defensive-M1060-T1114-002</guid><description>Establish secure out-of-band communication channels to ensure the continuity of critical communications during security incidents, data integrity attacks, or in-network communication failures. Out-of-band communication refers to using an alternative, separate communication path that is not dependent on the potentially compromised primary network infrastructure. This method can include secure messaging apps, encrypted phone lines, satellite communications, or dedicated emergency communication sys</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1029 Remote Data Storage counters T1119 Automated Collection</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1029-T1119</link><guid isPermaLink="false">cst-defensive-M1029-T1119</guid><description>Remote Data Storage focuses on moving critical data, such as security logs and sensitive files, to secure, off-host locations to minimize unauthorized access, tampering, or destruction by adversaries. By leveraging remote storage solutions, organizations enhance the protection of forensic evidence, sensitive information, and monitoring data. This mitigation can be implemented through the following measures:

Centralized Log Management:

- Configure endpoints to forward security logs to a central</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1041 Encrypt Sensitive Information counters T1119 Automated Collection</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1041-T1119</link><guid isPermaLink="false">cst-defensive-M1041-T1119</guid><description>Protect sensitive information at rest, in transit, and during processing by using strong encryption algorithms. Encryption ensures the confidentiality and integrity of data, preventing unauthorized access or tampering. This mitigation can be implemented through the following measures:

Encrypt Data at Rest:

- Use Case: Use full-disk encryption or file-level encryption to secure sensitive data stored on devices.
- Implementation: Implement BitLocker for Windows systems or FileVault for macOS dev</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1213 Data from Information Repositories</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1213</link><guid isPermaLink="false">cst-defensive-M1017-T1213</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1213 Data from Information Repositories</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1213</link><guid isPermaLink="false">cst-defensive-M1018-T1213</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1213 Data from Information Repositories</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1213</link><guid isPermaLink="false">cst-defensive-M1032-T1213</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1041 Encrypt Sensitive Information counters T1213 Data from Information Repositories</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1041-T1213</link><guid isPermaLink="false">cst-defensive-M1041-T1213</guid><description>Protect sensitive information at rest, in transit, and during processing by using strong encryption algorithms. Encryption ensures the confidentiality and integrity of data, preventing unauthorized access or tampering. This mitigation can be implemented through the following measures:

Encrypt Data at Rest:

- Use Case: Use full-disk encryption or file-level encryption to secure sensitive data stored on devices.
- Implementation: Implement BitLocker for Windows systems or FileVault for macOS dev</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1213 Data from Information Repositories</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1213</link><guid isPermaLink="false">cst-defensive-M1047-T1213</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1054 Software Configuration counters T1213 Data from Information Repositories</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1054-T1213</link><guid isPermaLink="false">cst-defensive-M1054-T1213</guid><description>Software configuration refers to making security-focused adjustments to the settings of applications, middleware, databases, or other software to mitigate potential threats. These changes help reduce the attack surface, enforce best practices, and protect sensitive data. This mitigation can be implemented through the following measures:

Conduct a Security Review of Application Settings:

- Review the software documentation to identify recommended security configurations.
- Compare default setti</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1060 Out-of-Band Communications Channel counters T1213 Data from Information Repositories</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1060-T1213</link><guid isPermaLink="false">cst-defensive-M1060-T1213</guid><description>Establish secure out-of-band communication channels to ensure the continuity of critical communications during security incidents, data integrity attacks, or in-network communication failures. Out-of-band communication refers to using an alternative, separate communication path that is not dependent on the potentially compromised primary network infrastructure. This method can include secure messaging apps, encrypted phone lines, satellite communications, or dedicated emergency communication sys</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1530 Data from Cloud Storage</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1530</link><guid isPermaLink="false">cst-defensive-M1018-T1530</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1022 Restrict File and Directory Permissions counters T1530 Data from Cloud Storage</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1022-T1530</link><guid isPermaLink="false">cst-defensive-M1022-T1530</guid><description>Restricting file and directory permissions involves setting access controls at the file system level to limit which users, groups, or processes can read, write, or execute files. By configuring permissions appropriately, organizations can reduce the attack surface for adversaries seeking to access sensitive data, plant malicious code, or tamper with system files.

Enforce Least Privilege Permissions:

- Remove unnecessary write permissions on sensitive files and directories.
- Use file ownership</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1530 Data from Cloud Storage</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1530</link><guid isPermaLink="false">cst-defensive-M1032-T1530</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1530 Data from Cloud Storage</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1530</link><guid isPermaLink="false">cst-defensive-M1037-T1530</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1041 Encrypt Sensitive Information counters T1530 Data from Cloud Storage</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1041-T1530</link><guid isPermaLink="false">cst-defensive-M1041-T1530</guid><description>Protect sensitive information at rest, in transit, and during processing by using strong encryption algorithms. Encryption ensures the confidentiality and integrity of data, preventing unauthorized access or tampering. This mitigation can be implemented through the following measures:

Encrypt Data at Rest:

- Use Case: Use full-disk encryption or file-level encryption to secure sensitive data stored on devices.
- Implementation: Implement BitLocker for Windows systems or FileVault for macOS dev</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1530 Data from Cloud Storage</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1530</link><guid isPermaLink="false">cst-defensive-M1047-T1530</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1021 Restrict Web-Based Content counters T1567 Exfiltration Over Web Service</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1021-T1567</link><guid isPermaLink="false">cst-defensive-M1021-T1567</guid><description>Restricting web-based content involves enforcing policies and technologies that limit access to potentially malicious websites, unsafe downloads, and unauthorized browser behaviors. This can include URL filtering, download restrictions, script blocking, and extension control to protect against exploitation, phishing, and malware delivery. This mitigation can be implemented through the following measures:

Deploy Web Proxy Filtering:

- Use solutions to filter web traffic based on categories, rep</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1057 Data Loss Prevention counters T1567 Exfiltration Over Web Service</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1057-T1567</link><guid isPermaLink="false">cst-defensive-M1057-T1567</guid><description>Data Loss Prevention (DLP) involves implementing strategies and technologies to identify, categorize, monitor, and control the movement of sensitive data within an organization. This includes protecting data formats indicative of Personally Identifiable Information (PII), intellectual property, or financial data from unauthorized access, transmission, or exfiltration. DLP solutions integrate with network, endpoint, and cloud platforms to enforce security policies and prevent accidental or malici</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item></channel></rss>