M1013Give developers actionable security requirements and patterns that reduce vulnerabilities before software reaches production. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1015Harden Active Directory so directory design, delegation, authentication, and replication do not create avoidable attack paths. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1016Use authenticated and appropriately scoped assessment to identify known vulnerabilities, missing updates, weak configurations, and exposed services. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1017Prepare people to recognize, avoid, report, and respond to adversary actions relevant to their role, systems, data, and authority. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1018Manage user accounts through verified provisioning, change, review, suspension, and deprovisioning processes tied to business need. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1019Operate a requirements-driven threat intelligence capability that turns external and internal information into decisions, priorities, detections, and defensive changes. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1020Inspect appropriately authorized encrypted traffic where risk, privacy, architecture, and legal requirements justify visibility into protected sessions. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1021Reduce exposure to malicious web content by controlling destinations, downloads, active content, browser behavior, and risky categories. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1022Apply least-privilege permissions to files and directories so unauthorized users and processes cannot read, alter, replace, or execute protected content. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1024Limit who and what can modify security-sensitive registry locations used for startup, services, policies, credentials, and application behavior. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1025Protect privileged processes and security boundaries from injection, modification, debugging, credential extraction, and untrusted code. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1026Control the creation, use, elevation, monitoring, and retirement of highly privileged human and machine accounts. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1027Set password and passphrase requirements that resist guessing, reuse, default credentials, and unsafe recovery practices without encouraging predictable workarounds. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1028Harden operating systems through secure defaults, least functionality, protected administration, and continuously enforced configuration baselines. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1029Keep recoverable or authoritative data copies in storage that is separated from the primary system and governed through independent access controls. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1030Divide networks and trust zones so compromise in one area does not provide unrestricted access to users, services, management paths, or critical assets. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1031Detect and block malicious or policy-violating network activity in line before it reaches its intended target. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1032Require more than one independent factor for sensitive authentication so a stolen password or token alone is insufficient. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1033Restrict who and what may install software so unapproved tools, packages, drivers, and persistence mechanisms are harder to introduce. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1034Control attachment and installation of hardware that could introduce code, storage, network access, or unauthorized interfaces. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1035Reduce remote attack paths by limiting which identities, systems, zones, and protocols can reach sensitive resources. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1036Establish rules for when accounts may be created, shared, elevated, accessed remotely, or used for administrative work. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1037Permit only necessary network communication and inspect, block, or constrain traffic that violates approved flows and trust boundaries. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1038Block unapproved code, scripts, macros, binaries, and interpreters from executing in contexts where they are not required. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1039Prevent unauthorized users and processes from changing environment variables that influence execution, search paths, libraries, credentials, or application behavior. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1040Prevent high-risk endpoint behavior by evaluating process, script, memory, file, and system activity rather than relying only on known signatures. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1041Protect sensitive information from unauthorized disclosure by applying appropriate encryption in storage, transit, processing, and backup contexts. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1042Reduce attack surface by removing or disabling software, services, interpreters, protocols, and features that are not required. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1043Reduce credential theft by limiting where secrets exist, how they are stored, and which processes or administrators can retrieve them. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1044Constrain which dynamic libraries, modules, drivers, and extensions privileged or sensitive processes may load. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1045Use cryptographic signatures and trusted publishing processes to verify software origin and integrity before execution or deployment. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1046Protect the chain of trust from firmware through operating-system startup so unauthorized boot components are blocked or exposed. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1047Use independent, evidence-based assessment to determine whether security controls are designed appropriately and operating as intended. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1048Confine untrusted applications, content, and workloads so compromise has limited access to the host, identities, data, and adjacent services. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1049Use maintained antimalware capabilities to prevent, detect, quarantine, and investigate malicious code and known harmful artifacts. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1050Use platform and application protections that make vulnerability exploitation less reliable or prevent common exploit behaviors. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1051Reduce exploitable exposure by applying verified software, firmware, package, dependency, and platform updates within risk-based timelines. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1052Use operating-system elevation boundaries and prompts to separate ordinary user activity from administrative actions and reduce silent privilege use. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1053Maintain recoverable copies of critical data and configurations that remain available after deletion, corruption, ransomware, or operational failure. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1054Configure applications and services to minimize unnecessary features, unsafe defaults, excessive privileges, and exposed administrative functions. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1055Represent a deliberate decision not to apply a direct preventive treatment to a specific adversary behavior while governing the remaining risk. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1056Reduce the information, exposure, trust, and infrastructure opportunities an adversary can exploit before obtaining access. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1057Identify and constrain unauthorized movement, disclosure, or handling of sensitive information across endpoints, networks, applications, and cloud services. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →M1060Maintain a communications path independent of potentially compromised production identity, messaging, and network services. This original Bare Metal Cyber profile explains implementation, validation, evidence, failure modes, ownership, and responsible use with ATT&CK.
Open profile →