<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Defensive Actions (Identity)</title><link>https://cybersecuritytracker.ai/defensive-actions?cat=identity</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:05:07 GMT</lastBuildDate><item><title>M1013 Application Developer Guidance counters T1078 Valid Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1013-T1078</link><guid isPermaLink="false">cst-defensive-M1013-T1078</guid><description>Application Developer Guidance focuses on providing developers with the knowledge, tools, and best practices needed to write secure code, reduce vulnerabilities, and implement secure design principles. By integrating security throughout the software development lifecycle (SDLC), this mitigation aims to prevent the introduction of exploitable weaknesses in applications, systems, and APIs. This mitigation can be implemented through the following measures:
 
Preventing SQL Injection (Secure Coding </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1015 Active Directory Configuration counters T1078 Valid Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1015-T1078</link><guid isPermaLink="false">cst-defensive-M1015-T1078</guid><description>Implement robust Active Directory (AD) configurations using group policies to secure user accounts, control access, and minimize the attack surface. AD configurations enable centralized control over account settings, logon policies, and permissions, reducing the risk of unauthorized access and lateral movement within the network. This mitigation can be implemented through the following measures:

Account Configuration:

- Implementation: Use domain accounts instead of local accounts to leverage </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1078 Valid Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1078</link><guid isPermaLink="false">cst-defensive-M1017-T1078</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1078 Valid Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1078</link><guid isPermaLink="false">cst-defensive-M1018-T1078</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1078 Valid Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1078</link><guid isPermaLink="false">cst-defensive-M1026-T1078</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1027 Password Policies counters T1078 Valid Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1027-T1078</link><guid isPermaLink="false">cst-defensive-M1027-T1078</guid><description>Set and enforce secure password policies for accounts to reduce the likelihood of unauthorized access. Strong password policies include enforcing password complexity, requiring regular password changes, and preventing password reuse. This mitigation can be implemented through the following measures:

Windows Systems:

- Use Group Policy Management Console (GPMC) to configure:
    - Minimum password length (e.g., 12+ characters).
    - Password complexity requirements.
    - Password history (e.g</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1078 Valid Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1078</link><guid isPermaLink="false">cst-defensive-M1032-T1078</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1036 Account Use Policies counters T1078 Valid Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1036-T1078</link><guid isPermaLink="false">cst-defensive-M1036-T1078</guid><description>Account Use Policies help mitigate unauthorized access by configuring and enforcing rules that govern how and when accounts can be used. These policies include enforcing account lockout mechanisms, restricting login times, and setting inactivity timeouts. Proper configuration of these policies reduces the risk of brute-force attacks, credential theft, and unauthorized access by limiting the opportunities for malicious actors to exploit accounts. This mitigation can be implemented through the fol</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1566 Phishing</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1566</link><guid isPermaLink="false">cst-defensive-M1017-T1566</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1021 Restrict Web-Based Content counters T1566 Phishing</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1021-T1566</link><guid isPermaLink="false">cst-defensive-M1021-T1566</guid><description>Restricting web-based content involves enforcing policies and technologies that limit access to potentially malicious websites, unsafe downloads, and unauthorized browser behaviors. This can include URL filtering, download restrictions, script blocking, and extension control to protect against exploitation, phishing, and malware delivery. This mitigation can be implemented through the following measures:

Deploy Web Proxy Filtering:

- Use solutions to filter web traffic based on categories, rep</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1566 Phishing</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1566</link><guid isPermaLink="false">cst-defensive-M1031-T1566</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1566 Phishing</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1566</link><guid isPermaLink="false">cst-defensive-M1047-T1566</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1049 Antivirus/Antimalware counters T1566 Phishing</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1049-T1566</link><guid isPermaLink="false">cst-defensive-M1049-T1566</guid><description>Antivirus/Antimalware solutions utilize signatures, heuristics, and behavioral analysis to detect, block, and remediate malicious software, including viruses, trojans, ransomware, and spyware. These solutions continuously monitor endpoints and systems for known malicious patterns and suspicious behaviors that indicate compromise. Antivirus/Antimalware software should be deployed across all devices, with automated updates to ensure protection against the latest threats. This mitigation can be imp</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1054 Software Configuration counters T1566 Phishing</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1054-T1566</link><guid isPermaLink="false">cst-defensive-M1054-T1566</guid><description>Software configuration refers to making security-focused adjustments to the settings of applications, middleware, databases, or other software to mitigate potential threats. These changes help reduce the attack surface, enforce best practices, and protect sensitive data. This mitigation can be implemented through the following measures:

Conduct a Security Review of Application Settings:

- Review the software documentation to identify recommended security configurations.
- Compare default setti</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1021 Restrict Web-Based Content counters T1059 Command and Scripting Interpreter</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1021-T1059</link><guid isPermaLink="false">cst-defensive-M1021-T1059</guid><description>Restricting web-based content involves enforcing policies and technologies that limit access to potentially malicious websites, unsafe downloads, and unauthorized browser behaviors. This can include URL filtering, download restrictions, script blocking, and extension control to protect against exploitation, phishing, and malware delivery. This mitigation can be implemented through the following measures:

Deploy Web Proxy Filtering:

- Use solutions to filter web traffic based on categories, rep</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1059 Command and Scripting Interpreter</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1059</link><guid isPermaLink="false">cst-defensive-M1026-T1059</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1033 Limit Software Installation counters T1059 Command and Scripting Interpreter</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1033-T1059</link><guid isPermaLink="false">cst-defensive-M1033-T1059</guid><description>Prevent users or groups from installing unauthorized or unapproved software to reduce the risk of introducing malicious or vulnerable applications. This can be achieved through allowlists, software restriction policies, endpoint management tools, and least privilege access principles. This mitigation can be implemented through the following measures:

Application Whitelisting

- Implement Microsoft AppLocker or Windows Defender Application Control (WDAC) to create and enforce allowlists for appr</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1038 Execution Prevention counters T1059 Command and Scripting Interpreter</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1038-T1059</link><guid isPermaLink="false">cst-defensive-M1038-T1059</guid><description>Prevent the execution of unauthorized or malicious code on systems by implementing application control, script blocking, and other execution prevention mechanisms. This ensures that only trusted and authorized code is executed, reducing the risk of malware and unauthorized actions. This mitigation can be implemented through the following measures:

Application Control:

- Use Case: Use tools like AppLocker or Windows Defender Application Control (WDAC) to create whitelists of authorized applicat</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1040 Behavior Prevention on Endpoint counters T1059 Command and Scripting Interpreter</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1040-T1059</link><guid isPermaLink="false">cst-defensive-M1040-T1059</guid><description>Behavior Prevention on Endpoint refers to the use of technologies and strategies to detect and block potentially malicious activities by analyzing the behavior of processes, files, API calls, and other endpoint events. Rather than relying solely on known signatures, this approach leverages heuristics, machine learning, and real-time monitoring to identify anomalous patterns indicative of an attack. This mitigation can be implemented through the following measures:

Suspicious Process Behavior:

</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1042 Disable or Remove Feature or Program counters T1059 Command and Scripting Interpreter</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1042-T1059</link><guid isPermaLink="false">cst-defensive-M1042-T1059</guid><description>Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures: 

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or secu</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1045 Code Signing counters T1059 Command and Scripting Interpreter</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1045-T1059</link><guid isPermaLink="false">cst-defensive-M1045-T1059</guid><description>Code Signing is a security process that ensures the authenticity and integrity of software by digitally signing executables, scripts, and other code artifacts. It prevents untrusted or malicious code from executing by verifying the digital signatures against trusted sources. Code signing protects against tampering, impersonation, and distribution of unauthorized or malicious software, forming a critical defense against supply chain and software exploitation attacks. This mitigation can be implem</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1059 Command and Scripting Interpreter</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1059</link><guid isPermaLink="false">cst-defensive-M1047-T1059</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1049 Antivirus/Antimalware counters T1059 Command and Scripting Interpreter</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1049-T1059</link><guid isPermaLink="false">cst-defensive-M1049-T1059</guid><description>Antivirus/Antimalware solutions utilize signatures, heuristics, and behavioral analysis to detect, block, and remediate malicious software, including viruses, trojans, ransomware, and spyware. These solutions continuously monitor endpoints and systems for known malicious patterns and suspicious behaviors that indicate compromise. Antivirus/Antimalware software should be deployed across all devices, with automated updates to ensure protection against the latest threats. This mitigation can be imp</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1015 Active Directory Configuration counters T1078.004 Cloud Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1015-T1078-004</link><guid isPermaLink="false">cst-defensive-M1015-T1078-004</guid><description>Implement robust Active Directory (AD) configurations using group policies to secure user accounts, control access, and minimize the attack surface. AD configurations enable centralized control over account settings, logon policies, and permissions, reducing the risk of unauthorized access and lateral movement within the network. This mitigation can be implemented through the following measures:

Account Configuration:

- Implementation: Use domain accounts instead of local accounts to leverage </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1078.004 Cloud Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1078-004</link><guid isPermaLink="false">cst-defensive-M1017-T1078-004</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1078.004 Cloud Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1078-004</link><guid isPermaLink="false">cst-defensive-M1018-T1078-004</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1078.004 Cloud Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1078-004</link><guid isPermaLink="false">cst-defensive-M1026-T1078-004</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1027 Password Policies counters T1078.004 Cloud Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1027-T1078-004</link><guid isPermaLink="false">cst-defensive-M1027-T1078-004</guid><description>Set and enforce secure password policies for accounts to reduce the likelihood of unauthorized access. Strong password policies include enforcing password complexity, requiring regular password changes, and preventing password reuse. This mitigation can be implemented through the following measures:

Windows Systems:

- Use Group Policy Management Console (GPMC) to configure:
    - Minimum password length (e.g., 12+ characters).
    - Password complexity requirements.
    - Password history (e.g</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1078.004 Cloud Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1078-004</link><guid isPermaLink="false">cst-defensive-M1032-T1078-004</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1036 Account Use Policies counters T1078.004 Cloud Accounts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1036-T1078-004</link><guid isPermaLink="false">cst-defensive-M1036-T1078-004</guid><description>Account Use Policies help mitigate unauthorized access by configuring and enforcing rules that govern how and when accounts can be used. These policies include enforcing account lockout mechanisms, restricting login times, and setting inactivity timeouts. Proper configuration of these policies reduces the risk of brute-force attacks, credential theft, and unauthorized access by limiting the opportunities for malicious actors to exploit accounts. This mitigation can be implemented through the fol</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1087 Account Discovery</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1087</link><guid isPermaLink="false">cst-defensive-M1018-T1087</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1028 Operating System Configuration counters T1087 Account Discovery</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1028-T1087</link><guid isPermaLink="false">cst-defensive-M1028-T1087</guid><description>Operating System Configuration involves adjusting system settings and hardening the default configurations of an operating system (OS) to mitigate adversary exploitation and prevent abuse of system functionality. Proper OS configurations address security vulnerabilities, limit attack surfaces, and ensure robust defense against a wide range of techniques. This mitigation can be implemented through the following measures: 

Disable Unused Features:

- Turn off SMBv1, LLMNR, and NetBIOS where not n</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1098 Account Manipulation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1098</link><guid isPermaLink="false">cst-defensive-M1018-T1098</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1022 Restrict File and Directory Permissions counters T1098 Account Manipulation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1022-T1098</link><guid isPermaLink="false">cst-defensive-M1022-T1098</guid><description>Restricting file and directory permissions involves setting access controls at the file system level to limit which users, groups, or processes can read, write, or execute files. By configuring permissions appropriately, organizations can reduce the attack surface for adversaries seeking to access sensitive data, plant malicious code, or tamper with system files.

Enforce Least Privilege Permissions:

- Remove unnecessary write permissions on sensitive files and directories.
- Use file ownership</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1098 Account Manipulation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1098</link><guid isPermaLink="false">cst-defensive-M1026-T1098</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1028 Operating System Configuration counters T1098 Account Manipulation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1028-T1098</link><guid isPermaLink="false">cst-defensive-M1028-T1098</guid><description>Operating System Configuration involves adjusting system settings and hardening the default configurations of an operating system (OS) to mitigate adversary exploitation and prevent abuse of system functionality. Proper OS configurations address security vulnerabilities, limit attack surfaces, and ensure robust defense against a wide range of techniques. This mitigation can be implemented through the following measures: 

Disable Unused Features:

- Turn off SMBv1, LLMNR, and NetBIOS where not n</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1030 Network Segmentation counters T1098 Account Manipulation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1030-T1098</link><guid isPermaLink="false">cst-defensive-M1030-T1098</guid><description>Network segmentation involves dividing a network into smaller, isolated segments to control and limit the flow of traffic between devices, systems, and applications. By segmenting networks, organizations can reduce the attack surface, restrict lateral movement by adversaries, and protect critical assets from compromise.

Effective network segmentation leverages a combination of physical boundaries, logical separation through VLANs, and access control policies enforced by network appliances like </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1098 Account Manipulation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1098</link><guid isPermaLink="false">cst-defensive-M1032-T1098</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1042 Disable or Remove Feature or Program counters T1098 Account Manipulation</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1042-T1098</link><guid isPermaLink="false">cst-defensive-M1042-T1098</guid><description>Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures: 

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or secu</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1110 Brute Force</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1110</link><guid isPermaLink="false">cst-defensive-M1018-T1110</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1027 Password Policies counters T1110 Brute Force</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1027-T1110</link><guid isPermaLink="false">cst-defensive-M1027-T1110</guid><description>Set and enforce secure password policies for accounts to reduce the likelihood of unauthorized access. Strong password policies include enforcing password complexity, requiring regular password changes, and preventing password reuse. This mitigation can be implemented through the following measures:

Windows Systems:

- Use Group Policy Management Console (GPMC) to configure:
    - Minimum password length (e.g., 12+ characters).
    - Password complexity requirements.
    - Password history (e.g</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1110 Brute Force</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1110</link><guid isPermaLink="false">cst-defensive-M1032-T1110</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1036 Account Use Policies counters T1110 Brute Force</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1036-T1110</link><guid isPermaLink="false">cst-defensive-M1036-T1110</guid><description>Account Use Policies help mitigate unauthorized access by configuring and enforcing rules that govern how and when accounts can be used. These policies include enforcing account lockout mechanisms, restricting login times, and setting inactivity timeouts. Proper configuration of these policies reduces the risk of brute-force attacks, credential theft, and unauthorized access by limiting the opportunities for malicious actors to exploit accounts. This mitigation can be implemented through the fol</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1136 Create Account</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1136</link><guid isPermaLink="false">cst-defensive-M1026-T1136</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1028 Operating System Configuration counters T1136 Create Account</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1028-T1136</link><guid isPermaLink="false">cst-defensive-M1028-T1136</guid><description>Operating System Configuration involves adjusting system settings and hardening the default configurations of an operating system (OS) to mitigate adversary exploitation and prevent abuse of system functionality. Proper OS configurations address security vulnerabilities, limit attack surfaces, and ensure robust defense against a wide range of techniques. This mitigation can be implemented through the following measures: 

Disable Unused Features:

- Turn off SMBv1, LLMNR, and NetBIOS where not n</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1030 Network Segmentation counters T1136 Create Account</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1030-T1136</link><guid isPermaLink="false">cst-defensive-M1030-T1136</guid><description>Network segmentation involves dividing a network into smaller, isolated segments to control and limit the flow of traffic between devices, systems, and applications. By segmenting networks, organizations can reduce the attack surface, restrict lateral movement by adversaries, and protect critical assets from compromise.

Effective network segmentation leverages a combination of physical boundaries, logical separation through VLANs, and access control policies enforced by network appliances like </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1032 Multi-factor Authentication counters T1136 Create Account</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1032-T1136</link><guid isPermaLink="false">cst-defensive-M1032-T1136</guid><description>Multi-Factor Authentication (MFA) enhances security by requiring users to provide at least two forms of verification to prove their identity before granting access. These factors typically include:

- *Something you know*: Passwords, PINs.
- *Something you have*: Physical tokens, smartphone authenticator apps.
- *Something you are*: Biometric data such as fingerprints, facial recognition, or retinal scans.

Implementing MFA across all critical systems and services ensures robust protection again</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1189 Drive-by Compromise</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1189</link><guid isPermaLink="false">cst-defensive-M1017-T1189</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1021 Restrict Web-Based Content counters T1189 Drive-by Compromise</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1021-T1189</link><guid isPermaLink="false">cst-defensive-M1021-T1189</guid><description>Restricting web-based content involves enforcing policies and technologies that limit access to potentially malicious websites, unsafe downloads, and unauthorized browser behaviors. This can include URL filtering, download restrictions, script blocking, and extension control to protect against exploitation, phishing, and malware delivery. This mitigation can be implemented through the following measures:

Deploy Web Proxy Filtering:

- Use solutions to filter web traffic based on categories, rep</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1048 Application Isolation and Sandboxing counters T1189 Drive-by Compromise</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1048-T1189</link><guid isPermaLink="false">cst-defensive-M1048-T1189</guid><description>Application Isolation and Sandboxing refers to the technique of restricting the execution of code to a controlled and isolated environment (e.g., a virtual environment, container, or sandbox). This method prevents potentially malicious code from affecting the rest of the system or network by limiting access to sensitive resources and critical operations. The goal is to contain threats and minimize their impact. This mitigation can be implemented through the following measures:

Browser Sandboxin</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item></channel></rss>