Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1037
MITRE ATT&CK Mitigation

M1037: Filter Network Traffic

ShareXLinkedInRedditHN

Employ network appliances and endpoint software to filter ingress, egress, and lateral network traffic. This includes protocol-based filtering, enforcing firewall rules, and blocking or restricting traffic based on predefined conditions to limit adversary movement and data exfiltration. This mitigation can be implemented through the following measures: Ingress Traffic Filtering: - Use Case: Configure network firewalls to allow traffic only from authorized IP addresses to public-facing servers. - Implementation: Limit SSH (port 22) and RDP (port 3389) traffic to specific IP ranges. Egress Traffic Filtering: - Use Case: Use firewalls or endpoint security software to block unauthorized outbound traffic to prevent data exfiltration and command-and-control (C2) communications. - Implementation: Block outbound traffic to known malicious IPs or regions where communication is unexpected. Protocol-Based Filtering: - Use Case: Restrict the use of specific protocols that are commonly abused by adversaries, such as SMB, RPC, or Telnet, based on business needs. - Implementation: Disable SMBv1 on endpoints to prevent exploits like EternalBlue. Network Segmentation: - Use Case: Create network segments for critical systems and restrict communication between segments unless explicitly authorized. - Implementation: Implement VLANs to isolate IoT devices or guest networks from core business systems. Application Layer Filtering: - Use Case: Use proxy servers or Web Application Firewalls (WAFs) to inspect and block malicious HTTP/S traffic. - Implementation: Configure a WAF to block SQL injection attempts or other web application exploitation techniques.

▪Techniques addressed (49)

T1205.001Port KnockingT1557Adversary-in-the-MiddleT1572Protocol TunnelingT1499.003Application Exhaustion FloodT1190Exploit Public-Facing ApplicationT1557.003DHCP SpoofingT1498.002Reflection AmplificationT1218System Binary Proxy ExecutionT1071.004DNST1090.003Multi-hop ProxyT1197BITS JobsT1205Traffic SignalingT1048.001Exfiltration Over Symmetric Encrypted Non-C2 ProtocolT1071.003Mail ProtocolsT1021.005VNCT1498Network Denial of ServiceT1218.012VerclsidT1499.002Service Exhaustion FloodT1499Endpoint Denial of ServiceT1570Lateral Tool TransferT1552Unsecured CredentialsT1499.004Application or System ExploitationT1071.002File Transfer ProtocolsT1048Exfiltration Over Alternative ProtocolT1219Remote Access ToolsT1187Forced AuthenticationT1205.002Socket FiltersT1498.001Direct Network FloodT1602.002Network Device Configuration DumpT1105Ingress Tool TransferT1219.002Remote Desktop SoftwareT1095Non-Application Layer ProtocolT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1071.005Publish/Subscribe ProtocolsT1090ProxyT1499.001OS Exhaustion FloodT1537Transfer Data to Cloud AccountT1602Data from Configuration RepositoryT1599Network Boundary BridgingT1021.002SMB/Windows Admin SharesT1557.002ARP Cache PoisoningT1530Data from Cloud StorageT1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolT1071.001Web ProtocolsT1602.001SNMP (MIB Dump)T1071Application Layer ProtocolT1599.001Network Address Translation TraversalT1557.001Name Resolution Poisoning and SMB RelayT1552.005Cloud Instance Metadata API

▪Reference

M1037on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.