Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

Threat-Informed Defense

Move from adversary behavior to defensive design.

Use mitigation profiles to examine control objectives, implementation priorities, validation evidence, common failure modes, and accountable ownership.

M1013

Application Developer Guidance (M1013)

Give developers actionable security requirements and patterns that reduce vulnerabilities before software reaches production. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1015

Active Directory Configuration (M1015)

Harden Active Directory so directory design, delegation, authentication, and replication do not create avoidable attack paths. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1016

Vulnerability Scanning (M1016)

Use authenticated and appropriately scoped assessment to identify known vulnerabilities, missing updates, weak configurations, and exposed services. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1017

User Training (M1017)

Prepare people to recognize, avoid, report, and respond to adversary actions relevant to their role, systems, data, and authority. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1018

User Account Management (M1018)

Manage user accounts through verified provisioning, change, review, suspension, and deprovisioning processes tied to business need. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1019

Threat Intelligence Program (M1019)

Operate a requirements-driven threat intelligence capability that turns external and internal information into decisions, priorities, detections, and defensive changes. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1020

SSL/TLS Inspection (M1020)

Inspect appropriately authorized encrypted traffic where risk, privacy, architecture, and legal requirements justify visibility into protected sessions. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1021

Restrict Web-Based Content (M1021)

Reduce exposure to malicious web content by controlling destinations, downloads, active content, browser behavior, and risky categories. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1022

Restrict File and Directory Permissions (M1022)

Apply least-privilege permissions to files and directories so unauthorized users and processes cannot read, alter, replace, or execute protected content. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1024

Restrict Registry Permissions (M1024)

Limit who and what can modify security-sensitive registry locations used for startup, services, policies, credentials, and application behavior. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1025

Privileged Process Integrity (M1025)

Protect privileged processes and security boundaries from injection, modification, debugging, credential extraction, and untrusted code. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1026

Privileged Account Management (M1026)

Control the creation, use, elevation, monitoring, and retirement of highly privileged human and machine accounts. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1027

Password Policies (M1027)

Set password and passphrase requirements that resist guessing, reuse, default credentials, and unsafe recovery practices without encouraging predictable workarounds. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1028

Operating System Configuration (M1028)

Harden operating systems through secure defaults, least functionality, protected administration, and continuously enforced configuration baselines. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1029

Remote Data Storage (M1029)

Keep recoverable or authoritative data copies in storage that is separated from the primary system and governed through independent access controls. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1030

Network Segmentation (M1030)

Divide networks and trust zones so compromise in one area does not provide unrestricted access to users, services, management paths, or critical assets. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1031

Network Intrusion Prevention (M1031)

Detect and block malicious or policy-violating network activity in line before it reaches its intended target. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1032

Multi-factor Authentication (M1032)

Require more than one independent factor for sensitive authentication so a stolen password or token alone is insufficient. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1033

Limit Software Installation (M1033)

Restrict who and what may install software so unapproved tools, packages, drivers, and persistence mechanisms are harder to introduce. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1034

Limit Hardware Installation (M1034)

Control attachment and installation of hardware that could introduce code, storage, network access, or unauthorized interfaces. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1035

Limit Access to Resource Over Network (M1035)

Reduce remote attack paths by limiting which identities, systems, zones, and protocols can reach sensitive resources. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1036

Account Use Policies (M1036)

Establish rules for when accounts may be created, shared, elevated, accessed remotely, or used for administrative work. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1037

Filter Network Traffic (M1037)

Permit only necessary network communication and inspect, block, or constrain traffic that violates approved flows and trust boundaries. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1038

Execution Prevention (M1038)

Block unapproved code, scripts, macros, binaries, and interpreters from executing in contexts where they are not required. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1039

Environment Variable Permissions (M1039)

Prevent unauthorized users and processes from changing environment variables that influence execution, search paths, libraries, credentials, or application behavior. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1040

Behavior Prevention on Endpoint (M1040)

Prevent high-risk endpoint behavior by evaluating process, script, memory, file, and system activity rather than relying only on known signatures. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1041

Encrypt Sensitive Information (M1041)

Protect sensitive information from unauthorized disclosure by applying appropriate encryption in storage, transit, processing, and backup contexts. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1042

Disable or Remove Feature or Program (M1042)

Reduce attack surface by removing or disabling software, services, interpreters, protocols, and features that are not required. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1043

Credential Access Protection (M1043)

Reduce credential theft by limiting where secrets exist, how they are stored, and which processes or administrators can retrieve them. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1044

Restrict Library Loading (M1044)

Constrain which dynamic libraries, modules, drivers, and extensions privileged or sensitive processes may load. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1045

Code Signing (M1045)

Use cryptographic signatures and trusted publishing processes to verify software origin and integrity before execution or deployment. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1046

Boot Integrity (M1046)

Protect the chain of trust from firmware through operating-system startup so unauthorized boot components are blocked or exposed. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1047

Audit (M1047)

Use independent, evidence-based assessment to determine whether security controls are designed appropriately and operating as intended. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1048

Application Isolation and Sandboxing (M1048)

Confine untrusted applications, content, and workloads so compromise has limited access to the host, identities, data, and adjacent services. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1049

Antivirus/Antimalware (M1049)

Use maintained antimalware capabilities to prevent, detect, quarantine, and investigate malicious code and known harmful artifacts. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →
M1050

Exploit Protection (M1050)

Use platform and application protections that make vulnerability exploitation less reliable or prevent common exploit behaviors. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.

Open profile →

Framework metadata remains source-controlled by MITRE.

Bare Metal Cyber profiles add original educational and defensive context. Verify current object status, relationships, and underlying references on the official ATT&CK site before using a profile for operational or attribution decisions.

MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.