Courses of Action
Use this page to search and filter courses of action.
| Value↑ | External Ref | ||
|---|---|---|---|
| Alert on downloads via wget/curl to /tmp or executable drops in web directories | |||
| Alert on hidden PowerShell spawned via Shell.Application.ShellExecute | |||
| Application Developer Guidance | ATT&CK Enterprise | ||
| Apply Ivanti EPMM patches immediately | |||
| Apply Microsoft Outlook patches for CVE-2023-23397 and CVE-2023-29324 | |||
| Apply patches to edge devices immediately | |||
| Apply SAP Security Note #3594142 | |||
| Apply Sigma rule: Script Interpreter Execution From Suspicious Folder | |||
| Apply Sigma rule: Suspicious Microsoft Office Child Process | |||
| Assess multi-cloud/hybrid architecture for continuity against physical cloud region disruption | |||
| Avoid exposing company names in SSL certificate CN/SAN | |||
| Avoid relying solely on ransom payments or insurance; prioritize backups and incident response | |||
| Block .co.com second-level domains and brand-mirroring FQDNs | |||
| Block unauthenticated public access via WAF/firewall rules | |||
| Block wscript.exe via application whitelisting | |||
| Centralize logging with sufficient retention for threat hunting | |||
| Conduct red-teaming and data-extraction testing of LLMs | |||
| Continuous configuration monitoring for unauthorised firmware and routing changes | |||
| Data Destruction Mitigation | |||
| Deploy YARA rules for ONNX detection | |||
| Detect and block ISO mounting events | |||
| Detect curl.exe use with SOCKS5/TOR (Sigma) | |||
| Detect HTTPS C2 with Base64 Parameters | |||
| Detect Office Applications Spawning LoLBins | |||
| Detect phishing kit artifacts | |||
| Detect renamed AutoIt execution (SIGMA) | |||
| Detect suspicious curl.exe downloads (SIGMA) | |||
| Detect suspicious script execution from Temp folder (SIGMA) | |||
| Detect suspicious Windows Defender exclusion additions (Sigma) | |||
| Disable browser password caching | |||
| Disable Macros | |||
| Disable unnecessary remote services and default accounts | |||
| Email filtering for cloud-shared documents | |||
| Embed rapid counter-disinformation mechanisms and synchronize intelligence sharing | |||
| Employee education on dangers of embedded QR codes in PDFs | |||
| Empower employees (training and phishing simulations) | |||
| Enable command-line process auditing for LNK execution | |||
| Enable MFA for admin accounts | |||
| Enable multi-factor authentication (MFA) | |||
| Enable two-factor authentication (2FA) | |||
| Enforce least privilege | |||
| Enforce MFA and credential hygiene | |||
| Enforce MFA for staff (especially admin/payment accounts) | |||
| Enforce PowerShell Constrained Language Mode via WDAC/AppLocker | |||
| Enforce short-lived OAuth tokens and conditional access | |||
| Enforce strict IT/OT segmentation | |||
| Enforce strong unique passwords and rotation | |||
| Exploit Protection | |||
| Harden and inventory network edge devices | |||
| Harden edge appliances and VPN gateways |
