<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Defensive Actions (Endpoint)</title><link>https://cybersecuritytracker.ai/defensive-actions?cat=endpoint</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:05:07 GMT</lastBuildDate><item><title>M1047 Audit counters T1560.001 Archive via Utility</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1560-001</link><guid isPermaLink="false">cst-defensive-M1047-T1560-001</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1021.001 Remote Desktop Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1021-001</link><guid isPermaLink="false">cst-defensive-M1018-T1021-001</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1021.001 Remote Desktop Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1021-001</link><guid isPermaLink="false">cst-defensive-M1026-T1021-001</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1028 Operating System Configuration counters T1021.001 Remote Desktop Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1028-T1021-001</link><guid isPermaLink="false">cst-defensive-M1028-T1021-001</guid><description>Operating System Configuration involves adjusting system settings and hardening the default configurations of an operating system (OS) to mitigate adversary exploitation and prevent abuse of system functionality. Proper OS configurations address security vulnerabilities, limit attack surfaces, and ensure robust defense against a wide range of techniques. This mitigation can be implemented through the following measures: 

Disable Unused Features:

- Turn off SMBv1, LLMNR, and NetBIOS where not n</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1030 Network Segmentation counters T1021.001 Remote Desktop Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1030-T1021-001</link><guid isPermaLink="false">cst-defensive-M1030-T1021-001</guid><description>Network segmentation involves dividing a network into smaller, isolated segments to control and limit the flow of traffic between devices, systems, and applications. By segmenting networks, organizations can reduce the attack surface, restrict lateral movement by adversaries, and protect critical assets from compromise.

Effective network segmentation leverages a combination of physical boundaries, logical separation through VLANs, and access control policies enforced by network appliances like </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1021.001 Remote Desktop Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1021-001</link><guid isPermaLink="false">cst-defensive-M1032-T1021-001</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1035 Limit Access to Resource Over Network counters T1021.001 Remote Desktop Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1035-T1021-001</link><guid isPermaLink="false">cst-defensive-M1035-T1021-001</guid><description>Restrict access to network resources, such as file shares, remote systems, and services, to only those users, accounts, or systems with a legitimate business requirement. This can include employing technologies like network concentrators, RDP gateways, and zero-trust network access (ZTNA) models, alongside hardening services and protocols. This mitigation can be implemented through the following measures:

Audit and Restrict Access:

- Regularly audit permissions for file shares, network service</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1042 Disable or Remove Feature or Program counters T1021.001 Remote Desktop Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1042-T1021-001</link><guid isPermaLink="false">cst-defensive-M1042-T1021-001</guid><description>Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures: 

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or secu</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1021.001 Remote Desktop Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1021-001</link><guid isPermaLink="false">cst-defensive-M1047-T1021-001</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1059.001 PowerShell</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1059-001</link><guid isPermaLink="false">cst-defensive-M1026-T1059-001</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1038 Execution Prevention counters T1059.001 PowerShell</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1038-T1059-001</link><guid isPermaLink="false">cst-defensive-M1038-T1059-001</guid><description>Prevent the execution of unauthorized or malicious code on systems by implementing application control, script blocking, and other execution prevention mechanisms. This ensures that only trusted and authorized code is executed, reducing the risk of malware and unauthorized actions. This mitigation can be implemented through the following measures:

Application Control:

- Use Case: Use tools like AppLocker or Windows Defender Application Control (WDAC) to create whitelists of authorized applicat</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1042 Disable or Remove Feature or Program counters T1059.001 PowerShell</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1042-T1059-001</link><guid isPermaLink="false">cst-defensive-M1042-T1059-001</guid><description>Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures: 

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or secu</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1045 Code Signing counters T1059.001 PowerShell</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1045-T1059-001</link><guid isPermaLink="false">cst-defensive-M1045-T1059-001</guid><description>Code Signing is a security process that ensures the authenticity and integrity of software by digitally signing executables, scripts, and other code artifacts. It prevents untrusted or malicious code from executing by verifying the digital signatures against trusted sources. Code signing protects against tampering, impersonation, and distribution of unauthorized or malicious software, forming a critical defense against supply chain and software exploitation attacks. This mitigation can be implem</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1049 Antivirus/Antimalware counters T1059.001 PowerShell</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1049-T1059-001</link><guid isPermaLink="false">cst-defensive-M1049-T1059-001</guid><description>Antivirus/Antimalware solutions utilize signatures, heuristics, and behavioral analysis to detect, block, and remediate malicious software, including viruses, trojans, ransomware, and spyware. These solutions continuously monitor endpoints and systems for known malicious patterns and suspicious behaviors that indicate compromise. Antivirus/Antimalware software should be deployed across all devices, with automated updates to ensure protection against the latest threats. This mitigation can be imp</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1038 Execution Prevention counters T1059.003 Windows Command Shell</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1038-T1059-003</link><guid isPermaLink="false">cst-defensive-M1038-T1059-003</guid><description>Prevent the execution of unauthorized or malicious code on systems by implementing application control, script blocking, and other execution prevention mechanisms. This ensures that only trusted and authorized code is executed, reducing the risk of malware and unauthorized actions. This mitigation can be implemented through the following measures:

Application Control:

- Use Case: Use tools like AppLocker or Windows Defender Application Control (WDAC) to create whitelists of authorized applicat</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1219 Remote Access Tools</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1219</link><guid isPermaLink="false">cst-defensive-M1031-T1219</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1034 Limit Hardware Installation counters T1219 Remote Access Tools</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1034-T1219</link><guid isPermaLink="false">cst-defensive-M1034-T1219</guid><description>Prevent unauthorized users or groups from installing or using hardware, such as external drives, peripheral devices, or unapproved internal hardware components, by enforcing hardware usage policies and technical controls. This includes disabling USB ports, restricting driver installation, and implementing endpoint security tools to monitor and block unapproved devices. This mitigation can be implemented through the following measures:

Disable USB Ports and Hardware Installation Policies:

- Use</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1219 Remote Access Tools</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1219</link><guid isPermaLink="false">cst-defensive-M1037-T1219</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1038 Execution Prevention counters T1219 Remote Access Tools</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1038-T1219</link><guid isPermaLink="false">cst-defensive-M1038-T1219</guid><description>Prevent the execution of unauthorized or malicious code on systems by implementing application control, script blocking, and other execution prevention mechanisms. This ensures that only trusted and authorized code is executed, reducing the risk of malware and unauthorized actions. This mitigation can be implemented through the following measures:

Application Control:

- Use Case: Use tools like AppLocker or Windows Defender Application Control (WDAC) to create whitelists of authorized applicat</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1042 Disable or Remove Feature or Program counters T1219 Remote Access Tools</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1042-T1219</link><guid isPermaLink="false">cst-defensive-M1042-T1219</guid><description>Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures: 

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or secu</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1056 Pre-compromise counters T1588.002 Tool</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1056-T1588-002</link><guid isPermaLink="false">cst-defensive-M1056-T1588-002</guid><description>Pre-compromise mitigations involve proactive measures and defenses implemented to prevent adversaries from successfully identifying and exploiting weaknesses during the Reconnaissance and Resource Development phases of an attack. These activities focus on reducing an organization's attack surface, identify adversarial preparation efforts, and increase the difficulty for attackers to conduct successful operations. This mitigation can be implemented through the following measures:

Limit Informati</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1003.001 LSASS Memory</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1003-001</link><guid isPermaLink="false">cst-defensive-M1017-T1003-001</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1025 Privileged Process Integrity counters T1003.001 LSASS Memory</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1025-T1003-001</link><guid isPermaLink="false">cst-defensive-M1025-T1003-001</guid><description>Privileged Process Integrity focuses on defending highly privileged processes (e.g., system services, antivirus, or authentication processes) from tampering, injection, or compromise by adversaries. These processes often interact with critical components, making them prime targets for techniques like code injection, privilege escalation, and process manipulation. This mitigation can be implemented through the following measures:

Protected Process Mechanisms:

- Enable RunAsPPL on Windows system</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1003.001 LSASS Memory</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1003-001</link><guid isPermaLink="false">cst-defensive-M1026-T1003-001</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1027 Password Policies counters T1003.001 LSASS Memory</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1027-T1003-001</link><guid isPermaLink="false">cst-defensive-M1027-T1003-001</guid><description>Set and enforce secure password policies for accounts to reduce the likelihood of unauthorized access. Strong password policies include enforcing password complexity, requiring regular password changes, and preventing password reuse. This mitigation can be implemented through the following measures:

Windows Systems:

- Use Group Policy Management Console (GPMC) to configure:
    - Minimum password length (e.g., 12+ characters).
    - Password complexity requirements.
    - Password history (e.g</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1028 Operating System Configuration counters T1003.001 LSASS Memory</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1028-T1003-001</link><guid isPermaLink="false">cst-defensive-M1028-T1003-001</guid><description>Operating System Configuration involves adjusting system settings and hardening the default configurations of an operating system (OS) to mitigate adversary exploitation and prevent abuse of system functionality. Proper OS configurations address security vulnerabilities, limit attack surfaces, and ensure robust defense against a wide range of techniques. This mitigation can be implemented through the following measures: 

Disable Unused Features:

- Turn off SMBv1, LLMNR, and NetBIOS where not n</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1040 Behavior Prevention on Endpoint counters T1003.001 LSASS Memory</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1040-T1003-001</link><guid isPermaLink="false">cst-defensive-M1040-T1003-001</guid><description>Behavior Prevention on Endpoint refers to the use of technologies and strategies to detect and block potentially malicious activities by analyzing the behavior of processes, files, API calls, and other endpoint events. Rather than relying solely on known signatures, this approach leverages heuristics, machine learning, and real-time monitoring to identify anomalous patterns indicative of an attack. This mitigation can be implemented through the following measures:

Suspicious Process Behavior:

</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1043 Credential Access Protection counters T1003.001 LSASS Memory</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1043-T1003-001</link><guid isPermaLink="false">cst-defensive-M1043-T1003-001</guid><description>Credential Access Protection focuses on implementing measures to prevent adversaries from obtaining credentials, such as passwords, hashes, tokens, or keys, that could be used for unauthorized access. This involves restricting access to credential storage mechanisms, hardening configurations to block credential dumping methods, and using monitoring tools to detect suspicious credential-related activity. This mitigation can be implemented through the following measures:

Restrict Access to Creden</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1021.002 SMB/Windows Admin Shares</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1021-002</link><guid isPermaLink="false">cst-defensive-M1026-T1021-002</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1027 Password Policies counters T1021.002 SMB/Windows Admin Shares</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1027-T1021-002</link><guid isPermaLink="false">cst-defensive-M1027-T1021-002</guid><description>Set and enforce secure password policies for accounts to reduce the likelihood of unauthorized access. Strong password policies include enforcing password complexity, requiring regular password changes, and preventing password reuse. This mitigation can be implemented through the following measures:

Windows Systems:

- Use Group Policy Management Console (GPMC) to configure:
    - Minimum password length (e.g., 12+ characters).
    - Password complexity requirements.
    - Password history (e.g</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1035 Limit Access to Resource Over Network counters T1021.002 SMB/Windows Admin Shares</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1035-T1021-002</link><guid isPermaLink="false">cst-defensive-M1035-T1021-002</guid><description>Restrict access to network resources, such as file shares, remote systems, and services, to only those users, accounts, or systems with a legitimate business requirement. This can include employing technologies like network concentrators, RDP gateways, and zero-trust network access (ZTNA) models, alongside hardening services and protocols. This mitigation can be implemented through the following measures:

Audit and Restrict Access:

- Regularly audit permissions for file shares, network service</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1021.002 SMB/Windows Admin Shares</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1021-002</link><guid isPermaLink="false">cst-defensive-M1037-T1021-002</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1040 Behavior Prevention on Endpoint counters T1027.010 Command Obfuscation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1040-T1027-010</link><guid isPermaLink="false">cst-defensive-M1040-T1027-010</guid><description>Behavior Prevention on Endpoint refers to the use of technologies and strategies to detect and block potentially malicious activities by analyzing the behavior of processes, files, API calls, and other endpoint events. Rather than relying solely on known signatures, this approach leverages heuristics, machine learning, and real-time monitoring to identify anomalous patterns indicative of an attack. This mitigation can be implemented through the following measures:

Suspicious Process Behavior:

</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1049 Antivirus/Antimalware counters T1027.010 Command Obfuscation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1049-T1027-010</link><guid isPermaLink="false">cst-defensive-M1049-T1027-010</guid><description>Antivirus/Antimalware solutions utilize signatures, heuristics, and behavioral analysis to detect, block, and remediate malicious software, including viruses, trojans, ransomware, and spyware. These solutions continuously monitor endpoints and systems for known malicious patterns and suspicious behaviors that indicate compromise. Antivirus/Antimalware software should be deployed across all devices, with automated updates to ensure protection against the latest threats. This mitigation can be imp</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1030 Data Transfer Size Limits</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1030</link><guid isPermaLink="false">cst-defensive-M1031-T1030</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1047 Windows Management Instrumentation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1047</link><guid isPermaLink="false">cst-defensive-M1018-T1047</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1047 Windows Management Instrumentation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1047</link><guid isPermaLink="false">cst-defensive-M1026-T1047</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1038 Execution Prevention counters T1047 Windows Management Instrumentation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1038-T1047</link><guid isPermaLink="false">cst-defensive-M1038-T1047</guid><description>Prevent the execution of unauthorized or malicious code on systems by implementing application control, script blocking, and other execution prevention mechanisms. This ensures that only trusted and authorized code is executed, reducing the risk of malware and unauthorized actions. This mitigation can be implemented through the following measures:

Application Control:

- Use Case: Use tools like AppLocker or Windows Defender Application Control (WDAC) to create whitelists of authorized applicat</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1040 Behavior Prevention on Endpoint counters T1047 Windows Management Instrumentation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1040-T1047</link><guid isPermaLink="false">cst-defensive-M1040-T1047</guid><description>Behavior Prevention on Endpoint refers to the use of technologies and strategies to detect and block potentially malicious activities by analyzing the behavior of processes, files, API calls, and other endpoint events. Rather than relying solely on known signatures, this approach leverages heuristics, machine learning, and real-time monitoring to identify anomalous patterns indicative of an attack. This mitigation can be implemented through the following measures:

Suspicious Process Behavior:

</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1078.002 Domain Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1078-002</link><guid isPermaLink="false">cst-defensive-M1017-T1078-002</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1078.002 Domain Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1078-002</link><guid isPermaLink="false">cst-defensive-M1018-T1078-002</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1078.002 Domain Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1078-002</link><guid isPermaLink="false">cst-defensive-M1026-T1078-002</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1027 Password Policies counters T1078.002 Domain Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1027-T1078-002</link><guid isPermaLink="false">cst-defensive-M1027-T1078-002</guid><description>Set and enforce secure password policies for accounts to reduce the likelihood of unauthorized access. Strong password policies include enforcing password complexity, requiring regular password changes, and preventing password reuse. This mitigation can be implemented through the following measures:

Windows Systems:

- Use Group Policy Management Console (GPMC) to configure:
    - Minimum password length (e.g., 12+ characters).
    - Password complexity requirements.
    - Password history (e.g</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1078.002 Domain Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1078-002</link><guid isPermaLink="false">cst-defensive-M1032-T1078-002</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1028 Operating System Configuration counters T1087.002 Domain Account</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1028-T1087-002</link><guid isPermaLink="false">cst-defensive-M1028-T1087-002</guid><description>Operating System Configuration involves adjusting system settings and hardening the default configurations of an operating system (OS) to mitigate adversary exploitation and prevent abuse of system functionality. Proper OS configurations address security vulnerabilities, limit attack surfaces, and ensure robust defense against a wide range of techniques. This mitigation can be implemented through the following measures: 

Disable Unused Features:

- Turn off SMBv1, LLMNR, and NetBIOS where not n</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1028 Operating System Configuration counters T1135 Network Share Discovery</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1028-T1135</link><guid isPermaLink="false">cst-defensive-M1028-T1135</guid><description>Operating System Configuration involves adjusting system settings and hardening the default configurations of an operating system (OS) to mitigate adversary exploitation and prevent abuse of system functionality. Proper OS configurations address security vulnerabilities, limit attack surfaces, and ensure robust defense against a wide range of techniques. This mitigation can be implemented through the following measures: 

Disable Unused Features:

- Turn off SMBv1, LLMNR, and NetBIOS where not n</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1030 Network Segmentation counters T1482 Domain Trust Discovery</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1030-T1482</link><guid isPermaLink="false">cst-defensive-M1030-T1482</guid><description>Network segmentation involves dividing a network into smaller, isolated segments to control and limit the flow of traffic between devices, systems, and applications. By segmenting networks, organizations can reduce the attack surface, restrict lateral movement by adversaries, and protect critical assets from compromise.

Effective network segmentation leverages a combination of physical boundaries, logical separation through VLANs, and access control policies enforced by network appliances like </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1482 Domain Trust Discovery</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1482</link><guid isPermaLink="false">cst-defensive-M1047-T1482</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1015 Active Directory Configuration counters T1558 Steal or Forge Kerberos Tickets</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1015-T1558</link><guid isPermaLink="false">cst-defensive-M1015-T1558</guid><description>Implement robust Active Directory (AD) configurations using group policies to secure user accounts, control access, and minimize the attack surface. AD configurations enable centralized control over account settings, logon policies, and permissions, reducing the risk of unauthorized access and lateral movement within the network. This mitigation can be implemented through the following measures:

Account Configuration:

- Implementation: Use domain accounts instead of local accounts to leverage </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1558 Steal or Forge Kerberos Tickets</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1558</link><guid isPermaLink="false">cst-defensive-M1026-T1558</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item></channel></rss>