<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Defensive Actions (Network)</title><link>https://cybersecuritytracker.ai/defensive-actions?cat=network</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:05:07 GMT</lastBuildDate><item><title>M1031 Network Intrusion Prevention counters T1105 Ingress Tool Transfer</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1105</link><guid isPermaLink="false">cst-defensive-M1031-T1105</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1105 Ingress Tool Transfer</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1105</link><guid isPermaLink="false">cst-defensive-M1037-T1105</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1071 Application Layer Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1071</link><guid isPermaLink="false">cst-defensive-M1031-T1071</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1071 Application Layer Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1071</link><guid isPermaLink="false">cst-defensive-M1037-T1071</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1057 Data Loss Prevention counters T1005 Data from Local System</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1057-T1005</link><guid isPermaLink="false">cst-defensive-M1057-T1005</guid><description>Data Loss Prevention (DLP) involves implementing strategies and technologies to identify, categorize, monitor, and control the movement of sensitive data within an organization. This includes protecting data formats indicative of Personally Identifiable Information (PII), intellectual property, or financial data from unauthorized access, transmission, or exfiltration. DLP solutions integrate with network, endpoint, and cloud platforms to enforce security policies and prevent accidental or malici</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1027 Obfuscated Files or Information</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1027</link><guid isPermaLink="false">cst-defensive-M1017-T1027</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1040 Behavior Prevention on Endpoint counters T1027 Obfuscated Files or Information</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1040-T1027</link><guid isPermaLink="false">cst-defensive-M1040-T1027</guid><description>Behavior Prevention on Endpoint refers to the use of technologies and strategies to detect and block potentially malicious activities by analyzing the behavior of processes, files, API calls, and other endpoint events. Rather than relying solely on known signatures, this approach leverages heuristics, machine learning, and real-time monitoring to identify anomalous patterns indicative of an attack. This mitigation can be implemented through the following measures:

Suspicious Process Behavior:

</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1027 Obfuscated Files or Information</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1027</link><guid isPermaLink="false">cst-defensive-M1047-T1027</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1049 Antivirus/Antimalware counters T1027 Obfuscated Files or Information</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1049-T1027</link><guid isPermaLink="false">cst-defensive-M1049-T1027</guid><description>Antivirus/Antimalware solutions utilize signatures, heuristics, and behavioral analysis to detect, block, and remediate malicious software, including viruses, trojans, ransomware, and spyware. These solutions continuously monitor endpoints and systems for known malicious patterns and suspicious behaviors that indicate compromise. Antivirus/Antimalware software should be deployed across all devices, with automated updates to ensure protection against the latest threats. This mitigation can be imp</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1022 Restrict File and Directory Permissions counters T1037 Boot or Logon Initialization Scripts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1022-T1037</link><guid isPermaLink="false">cst-defensive-M1022-T1037</guid><description>Restricting file and directory permissions involves setting access controls at the file system level to limit which users, groups, or processes can read, write, or execute files. By configuring permissions appropriately, organizations can reduce the attack surface for adversaries seeking to access sensitive data, plant malicious code, or tamper with system files.

Enforce Least Privilege Permissions:

- Remove unnecessary write permissions on sensitive files and directories.
- Use file ownership</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1024 Restrict Registry Permissions counters T1037 Boot or Logon Initialization Scripts</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1024-T1037</link><guid isPermaLink="false">cst-defensive-M1024-T1037</guid><description>Restricting registry permissions involves configuring access control settings for sensitive registry keys and hives to ensure that only authorized users or processes can make modifications. By limiting access, organizations can prevent unauthorized changes that adversaries might use for persistence, privilege escalation, or defense evasion. This mitigation can be implemented through the following measures:

Review and Adjust Permissions on Critical Keys

- Regularly review permissions on keys su</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1030 Network Segmentation counters T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1030-T1048-003</link><guid isPermaLink="false">cst-defensive-M1030-T1048-003</guid><description>Network segmentation involves dividing a network into smaller, isolated segments to control and limit the flow of traffic between devices, systems, and applications. By segmenting networks, organizations can reduce the attack surface, restrict lateral movement by adversaries, and protect critical assets from compromise.

Effective network segmentation leverages a combination of physical boundaries, logical separation through VLANs, and access control policies enforced by network appliances like </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1048-003</link><guid isPermaLink="false">cst-defensive-M1031-T1048-003</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1048-003</link><guid isPermaLink="false">cst-defensive-M1037-T1048-003</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1057 Data Loss Prevention counters T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1057-T1048-003</link><guid isPermaLink="false">cst-defensive-M1057-T1048-003</guid><description>Data Loss Prevention (DLP) involves implementing strategies and technologies to identify, categorize, monitor, and control the movement of sensitive data within an organization. This includes protecting data formats indicative of Personally Identifiable Information (PII), intellectual property, or financial data from unauthorized access, transmission, or exfiltration. DLP solutions integrate with network, endpoint, and cloud platforms to enforce security policies and prevent accidental or malici</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1038 Execution Prevention counters T1059.004 Unix Shell</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1038-T1059-004</link><guid isPermaLink="false">cst-defensive-M1038-T1059-004</guid><description>Prevent the execution of unauthorized or malicious code on systems by implementing application control, script blocking, and other execution prevention mechanisms. This ensures that only trusted and authorized code is executed, reducing the risk of malware and unauthorized actions. This mitigation can be implemented through the following measures:

Application Control:

- Use Case: Use tools like AppLocker or Windows Defender Application Control (WDAC) to create whitelists of authorized applicat</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1071.001 Web Protocols</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1071-001</link><guid isPermaLink="false">cst-defensive-M1031-T1071-001</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1071.001 Web Protocols</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1071-001</link><guid isPermaLink="false">cst-defensive-M1037-T1071-001</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1071.002 File Transfer Protocols</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1071-002</link><guid isPermaLink="false">cst-defensive-M1031-T1071-002</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1071.002 File Transfer Protocols</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1071-002</link><guid isPermaLink="false">cst-defensive-M1037-T1071-002</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1020 SSL/TLS Inspection counters T1090 Proxy</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1020-T1090</link><guid isPermaLink="false">cst-defensive-M1020-T1090</guid><description>SSL/TLS inspection involves decrypting encrypted network traffic to examine its content for signs of malicious activity. This capability is crucial for detecting threats that use encryption to evade detection, such as phishing, malware, or data exfiltration. After inspection, the traffic is re-encrypted and forwarded to its destination. This mitigation can be implemented through the following measures:

Deploy SSL/TLS Inspection Appliances:

- Implement SSL/TLS inspection solutions to decrypt an</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1090 Proxy</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1090</link><guid isPermaLink="false">cst-defensive-M1031-T1090</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1037 Filter Network Traffic counters T1090 Proxy</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1037-T1090</link><guid isPermaLink="false">cst-defensive-M1037-T1090</guid><description>Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures:

Ingress Traffic Filtering:

- Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1090.001 Internal Proxy</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1090-001</link><guid isPermaLink="false">cst-defensive-M1031-T1090-001</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1495 Firmware Corruption</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1495</link><guid isPermaLink="false">cst-defensive-M1026-T1495</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1046 Boot Integrity counters T1495 Firmware Corruption</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1046-T1495</link><guid isPermaLink="false">cst-defensive-M1046-T1495</guid><description>Boot Integrity ensures that a system starts securely by verifying the integrity of its boot process, operating system, and associated components. This mitigation focuses on leveraging secure boot mechanisms, hardware-rooted trust, and runtime integrity checks to prevent tampering during the boot sequence. It is designed to thwart adversaries attempting to modify system firmware, bootloaders, or critical OS components. This mitigation can be implemented through the following measures:

Implementa</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1051 Update Software counters T1495 Firmware Corruption</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1051-T1495</link><guid isPermaLink="false">cst-defensive-M1051-T1495</guid><description>Software updates ensure systems are protected against known vulnerabilities by applying patches and upgrades provided by vendors. Regular updates reduce the attack surface and prevent adversaries from exploiting known security gaps. This includes patching operating systems, applications, drivers, and firmware. This mitigation can be implemented through the following measures:

Regular Operating System Updates

- Implementation: Apply the latest Windows security updates monthly using WSUS (Window</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1505 Server Software Component</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1505</link><guid isPermaLink="false">cst-defensive-M1018-T1505</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1024 Restrict Registry Permissions counters T1505 Server Software Component</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1024-T1505</link><guid isPermaLink="false">cst-defensive-M1024-T1505</guid><description>Restricting registry permissions involves configuring access control settings for sensitive registry keys and hives to ensure that only authorized users or processes can make modifications. By limiting access, organizations can prevent unauthorized changes that adversaries might use for persistence, privilege escalation, or defense evasion. This mitigation can be implemented through the following measures:

Review and Adjust Permissions on Critical Keys

- Regularly review permissions on keys su</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1505 Server Software Component</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1505</link><guid isPermaLink="false">cst-defensive-M1026-T1505</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1042 Disable or Remove Feature or Program counters T1505 Server Software Component</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1042-T1505</link><guid isPermaLink="false">cst-defensive-M1042-T1505</guid><description>Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures: 

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or secu</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1045 Code Signing counters T1505 Server Software Component</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1045-T1505</link><guid isPermaLink="false">cst-defensive-M1045-T1505</guid><description>Code Signing is a security process that ensures the authenticity and integrity of software by digitally signing executables, scripts, and other code artifacts. It prevents untrusted or malicious code from executing by verifying the digital signatures against trusted sources. Code signing protects against tampering, impersonation, and distribution of unauthorized or malicious software, forming a critical defense against supply chain and software exploitation attacks. This mitigation can be implem</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1046 Boot Integrity counters T1505 Server Software Component</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1046-T1505</link><guid isPermaLink="false">cst-defensive-M1046-T1505</guid><description>Boot Integrity ensures that a system starts securely by verifying the integrity of its boot process, operating system, and associated components. This mitigation focuses on leveraging secure boot mechanisms, hardware-rooted trust, and runtime integrity checks to prevent tampering during the boot sequence. It is designed to thwart adversaries attempting to modify system firmware, bootloaders, or critical OS components. This mitigation can be implemented through the following measures:

Implementa</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1505 Server Software Component</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1505</link><guid isPermaLink="false">cst-defensive-M1047-T1505</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1018 User Account Management counters T1505.003 Web Shell</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1018-T1505-003</link><guid isPermaLink="false">cst-defensive-M1018-T1505-003</guid><description>User Account Management involves implementing and enforcing policies for the lifecycle of user accounts, including creation, modification, and deactivation. Proper account management reduces the attack surface by limiting unauthorized access, managing account privileges, and ensuring accounts are used according to organizational policies. This mitigation can be implemented through the following measures:

Enforcing the Principle of Least Privilege

- Implementation: Assign users only the minimum</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1042 Disable or Remove Feature or Program counters T1505.003 Web Shell</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1042-T1505-003</link><guid isPermaLink="false">cst-defensive-M1042-T1505-003</guid><description>Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures: 

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or secu</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1026 Privileged Account Management counters T1542.005 TFTP Boot</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1026-T1542-005</link><guid isPermaLink="false">cst-defensive-M1026-T1542-005</guid><description>Privileged Account Management focuses on implementing policies, controls, and tools to securely manage privileged accounts (e.g., SYSTEM, root, or administrative accounts). This includes restricting access, limiting the scope of permissions, monitoring privileged account usage, and ensuring accountability through logging and auditing.This mitigation can be implemented through the following measures:

Account Permissions and Roles:

- Implement RBAC and least privilege principles to allocate perm</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1028 Operating System Configuration counters T1542.005 TFTP Boot</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1028-T1542-005</link><guid isPermaLink="false">cst-defensive-M1028-T1542-005</guid><description>Operating System Configuration involves adjusting system settings and hardening the default configurations of an operating system (OS) to mitigate adversary exploitation and prevent abuse of system functionality. Proper OS configurations address security vulnerabilities, limit attack surfaces, and ensure robust defense against a wide range of techniques. This mitigation can be implemented through the following measures: 

Disable Unused Features:

- Turn off SMBv1, LLMNR, and NetBIOS where not n</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1542.005 TFTP Boot</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1542-005</link><guid isPermaLink="false">cst-defensive-M1031-T1542-005</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1035 Limit Access to Resource Over Network counters T1542.005 TFTP Boot</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1035-T1542-005</link><guid isPermaLink="false">cst-defensive-M1035-T1542-005</guid><description>Restrict access to network resources, such as file shares, remote systems, and services, to only those users, accounts, or systems with a legitimate business requirement. This can include employing technologies like network concentrators, RDP gateways, and zero-trust network access (ZTNA) models, alongside hardening services and protocols. This mitigation can be implemented through the following measures:

Audit and Restrict Access:

- Regularly audit permissions for file shares, network service</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1046 Boot Integrity counters T1542.005 TFTP Boot</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1046-T1542-005</link><guid isPermaLink="false">cst-defensive-M1046-T1542-005</guid><description>Boot Integrity ensures that a system starts securely by verifying the integrity of its boot process, operating system, and associated components. This mitigation focuses on leveraging secure boot mechanisms, hardware-rooted trust, and runtime integrity checks to prevent tampering during the boot sequence. It is designed to thwart adversaries attempting to modify system firmware, bootloaders, or critical OS components. This mitigation can be implemented through the following measures:

Implementa</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1542.005 TFTP Boot</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1542-005</link><guid isPermaLink="false">cst-defensive-M1047-T1542-005</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1022 Restrict File and Directory Permissions counters T1552.004 Private Keys</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1022-T1552-004</link><guid isPermaLink="false">cst-defensive-M1022-T1552-004</guid><description>Restricting file and directory permissions involves setting access controls at the file system level to limit which users, groups, or processes can read, write, or execute files. By configuring permissions appropriately, organizations can reduce the attack surface for adversaries seeking to access sensitive data, plant malicious code, or tamper with system files.

Enforce Least Privilege Permissions:

- Remove unnecessary write permissions on sensitive files and directories.
- Use file ownership</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1027 Password Policies counters T1552.004 Private Keys</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1027-T1552-004</link><guid isPermaLink="false">cst-defensive-M1027-T1552-004</guid><description>Set and enforce secure password policies for accounts to reduce the likelihood of unauthorized access. Strong password policies include enforcing password complexity, requiring regular password changes, and preventing password reuse. This mitigation can be implemented through the following measures:

Windows Systems:

- Use Group Policy Management Console (GPMC) to configure:
    - Minimum password length (e.g., 12+ characters).
    - Password complexity requirements.
    - Password history (e.g</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1041 Encrypt Sensitive Information counters T1552.004 Private Keys</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1041-T1552-004</link><guid isPermaLink="false">cst-defensive-M1041-T1552-004</guid><description>Protect sensitive information at rest, in transit, and during processing by using strong encryption algorithms. Encryption ensures the confidentiality and integrity of data, preventing unauthorized access or tampering. This mitigation can be implemented through the following measures:

Encrypt Data at Rest:

- Use Case: Use full-disk encryption or file-level encryption to secure sensitive data stored on devices.
- Implementation: Implement BitLocker for Windows systems or FileVault for macOS dev</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1047 Audit counters T1552.004 Private Keys</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1047-T1552-004</link><guid isPermaLink="false">cst-defensive-M1047-T1552-004</guid><description>Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1017 User Training counters T1557 Adversary-in-the-Middle</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1017-T1557</link><guid isPermaLink="false">cst-defensive-M1017-T1557</guid><description>User Training involves educating employees and contractors on recognizing, reporting, and preventing cyber threats that rely on human interaction, such as phishing, social engineering, and other manipulative techniques. Comprehensive training programs create a human firewall by empowering users to be an active component of the organization's cybersecurity defenses. This mitigation can be implemented through the following measures:

Create Comprehensive Training Programs:

- Design training modul</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1030 Network Segmentation counters T1557 Adversary-in-the-Middle</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1030-T1557</link><guid isPermaLink="false">cst-defensive-M1030-T1557</guid><description>Network segmentation involves dividing a network into smaller, isolated segments to control and limit the flow of traffic between devices, systems, and applications. By segmenting networks, organizations can reduce the attack surface, restrict lateral movement by adversaries, and protect critical assets from compromise.

Effective network segmentation leverages a combination of physical boundaries, logical separation through VLANs, and access control policies enforced by network appliances like </description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1031 Network Intrusion Prevention counters T1557 Adversary-in-the-Middle</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1031-T1557</link><guid isPermaLink="false">cst-defensive-M1031-T1557</guid><description>Use intrusion detection signatures to block traffic at network boundaries.</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item><item><title>M1035 Limit Access to Resource Over Network counters T1557 Adversary-in-the-Middle</title><link>https://cybersecuritytracker.ai/defensive-actions?entry=M1035-T1557</link><guid isPermaLink="false">cst-defensive-M1035-T1557</guid><description>Restrict access to network resources, such as file shares, remote systems, and services, to only those users, accounts, or systems with a legitimate business requirement. This can include employing technologies like network concentrators, RDP gateways, and zero-trust network access (ZTNA) models, alongside hardening services and protocols. This mitigation can be implemented through the following measures:

Audit and Restrict Access:

- Regularly audit permissions for file shares, network service</description><pubDate>Sun, 26 Jul 2026 22:05:07 GMT</pubDate></item></channel></rss>