{"description": "Enterprise techniques used by Application Isolation and Sandboxing, ATT&CK mitigation M1048 v1.1", "name": "Application Isolation and Sandboxing (M1048)", "domain": "enterprise-attack", "versions": {"layer": "4.3", "attack": "10", "navigator": "4.5"}, "techniques": [{"score": 1, "techniqueID": "T1189", "showSubtechniques": false, "comment": "Browser sandboxes can be used to mitigate some of the impact of exploitation, but sandbox escapes may still exist.(Citation: Windows Blogs Microsoft Edge Sandbox)(Citation: Ars Technica Pwn2Own 2017 VM Escape)\n\nOther types of virtualization and application microsegmentation may also mitigate the impact of client-side exploitation. The risks of additional exploits and weaknesses in implementation may still exist for these types of systems.(Citation: Ars Technica Pwn2Own 2017 VM Escape)"}, {"score": 1, "techniqueID": "T1611", "showSubtechniques": false, "comment": "Consider utilizing seccomp, seccomp-bpf, or a similar solution that restricts certain system calls such as mount."}, {"score": 1, "techniqueID": "T1190", "showSubtechniques": false, "comment": "Application isolation will limit what other processes and system features the exploited target can access."}, {"score": 1, "techniqueID": "T1203", "showSubtechniques": false, "comment": "Browser sandboxes can be used to mitigate some of the impact of exploitation, but sandbox escapes may still exist. (Citation: Windows Blogs Microsoft Edge Sandbox) (Citation: Ars Technica Pwn2Own 2017 VM Escape)\n\nOther types of virtualization and application microsegmentation may also mitigate the impact of client-side exploitation. Risks of additional exploits and weaknesses in those systems may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)"}, {"score": 1, "techniqueID": "T1212", "showSubtechniques": false, "comment": "Make it difficult for adversaries to advance their operation through exploitation of undiscovered or unpatched vulnerabilities by using sandboxing. Other types of virtualization and application microsegmentation may also mitigate the impact of some types of exploitation. Risks of additional exploits and weaknesses in these systems may still exist.(Citation: Ars Technica Pwn2Own 2017 VM Escape)"}, {"score": 1, "techniqueID": "T1211", "showSubtechniques": false, "comment": "Make it difficult for adversaries to advance their operation through exploitation of undiscovered or unpatched vulnerabilities by using sandboxing. Other types of virtualization and application microsegmentation may also mitigate the impact of some types of exploitation. Risks of additional exploits and weaknesses in these systems may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)"}, {"score": 1, "techniqueID": "T1068", "showSubtechniques": false, "comment": "Make it difficult for adversaries to advance their operation through exploitation of undiscovered or unpatched vulnerabilities by using sandboxing. Other types of virtualization and application microsegmentation may also mitigate the impact of some types of exploitation. Risks of additional exploits and weaknesses in these systems may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)"}, {"score": 1, "techniqueID": "T1210", "showSubtechniques": false, "comment": "Make it difficult for adversaries to advance their operation through exploitation of undiscovered or unpatched vulnerabilities by using sandboxing. Other types of virtualization and application microsegmentation may also mitigate the impact of some types of exploitation. Risks of additional exploits and weaknesses in these systems may still exist. (Citation: Ars Technica Pwn2Own 2017 VM Escape)"}, {"score": 1, "techniqueID": "T1559", "showSubtechniques": true, "comment": "Ensure all COM alerts and Protected View are enabled.(Citation: Microsoft Protected View)"}, {"score": 1, "techniqueID": "T1559.001", "showSubtechniques": true, "comment": "Ensure all COM alerts and Protected View are enabled.(Citation: Microsoft Protected View)"}, {"score": 1, "techniqueID": "T1559.002", "showSubtechniques": true, "comment": "Ensure Protected View is enabled.(Citation: Microsoft Protected View)"}, {"techniqueID": "T1021", "showSubtechniques": true}, {"score": 1, "techniqueID": "T1021.003", "showSubtechniques": true, "comment": "Ensure all COM alerts and Protected View are enabled.(Citation: Microsoft Protected View)"}], "gradient": {"colors": ["#ffffff", "#66b1ff"], "minValue": 0, "maxValue": 1}, "legendItems": [{"label": "used by Application Isolation and Sandboxing", "color": "#66b1ff"}]}