+Filter Network Traffic

Filter Network Traffic

Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures: Ingress Traffic Filtering: - Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers. - Implementation: Limit SSH (port 22) and RDP (port 3389) traffic to specific IP ranges. Egress Traffic Filtering: - Use Case: Use firewalls or endpoint security software to block unauthorized outbound traffic to prevent data exfiltration and command-and-control (C2) communications. - Implementation: Block outbound traffic to known malicious IPs or regions where communication is unexpected. Protocol-Based Filtering: - Use Case: Restrict the use of specific protocols that are commonly abused by adversaries, such as SMB, RPC, or Telnet, based on business needs. - Implementation: Disable SMBv1 on endpoints to prevent exploits like EternalBlue. Network Segmentation: - Use Case: Create network segments for critical systems and restrict communication between segments unless explicitly authorized. - Implementation: Implement VLANs to isolate IoT devices or guest networks from core business systems. Application Layer Filtering: - Use Case: Use proxy servers or Web Application Firewalls (WAFs) to inspect and block malicious HTTP/S traffic. - Implementation: Configure a WAF to block SQL injection attempts or other web application exploitation techniques.

1. Overview

Summary Standard

1.1 References

1.2 Identified Requirements

1.3 Related Regulations

2. Identified Requirements

Requirements
Source Requirement

3. Related Regulations

Regulations
Source Regulation

Linked Issues

Issuelinks
Linktype Issue
is related to Mitigations
blocks Port Knocking
blocks Adversary-in-the-Middle
blocks Protocol Tunneling
blocks Application Exhaustion Flood
blocks Exploit Public-Facing Application
blocks DHCP Spoofing
blocks Reflection Amplification
blocks System Binary Proxy Execution
blocks DNS
blocks Multi-hop Proxy
blocks BITS Jobs
blocks Traffic Signaling
blocks Exfiltration Over Symmetric Encrypted Non-C2 Protocol
blocks Mail Protocols
blocks VNC
blocks Network Denial of Service
blocks Verclsid
blocks Service Exhaustion Flood
blocks Endpoint Denial of Service
blocks Lateral Tool Transfer
blocks Unsecured Credentials
blocks Application or System Exploitation
blocks File Transfer Protocols
blocks Exfiltration Over Alternative Protocol
blocks Remote Access Tools
blocks Forced Authentication
blocks Socket Filters
blocks Direct Network Flood
blocks Network Device Configuration Dump
blocks Ingress Tool Transfer
blocks Remote Desktop Software
blocks Non-Application Layer Protocol
blocks Exfiltration Over Unencrypted Non-C2 Protocol
blocks Publish/Subscribe Protocols
blocks Proxy
blocks OS Exhaustion Flood
blocks Transfer Data to Cloud Account
blocks Data from Configuration Repository
blocks Network Boundary Bridging
blocks SMB/Windows Admin Shares
blocks ARP Cache Poisoning
blocks Data from Cloud Storage
blocks Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
blocks Web Protocols
blocks SNMP (MIB Dump)
blocks Application Layer Protocol
blocks Network Address Translation Traversal
blocks Name Resolution Poisoning and SMB Relay
blocks Cloud Instance Metadata API
  • MITREATTACK -

    © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. https://attack.mitre.org/

    Terms of Use

    LICENSE

    The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

    "© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation."

    DISCLAIMERS

    MITRE does not claim ATT&CK enumerates all possibilities for the types of actions and behaviors documented as part of its adversary model and framework of techniques. Using the information contained within ATT&CK to address or cover full categories of techniques will not guarantee full defensive coverage as there may be undisclosed techniques or variations on existing techniques not documented by ATT&CK.

    ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

    See our FAQ for more information on how to use and represent the ATT&CK name.

Impressum German English