Skip to content

cis_7_10 — Only approved VM extensions are installed

Summary

Severity: Medium · Pillar: Workload · Chain role: AMPLIFIER

Description

VM extensions execute code with elevated privileges on the host. Unapproved extensions can be used for persistence, privilege escalation, or command execution.

Mapping

Framework Control / Reference
NIST 800-53 CM-7
NIST 800-207
CIS Azure 7.10
MITRE ATT&CK Technique T1059
MITRE ATT&CK Tactic Execution
Zero-Trust Tenet
Framework tags cis-azure-2.0, nist-800-53

Source

Rule defined at policies/azure/cis/vms/cis_7_10.rego.

View on GitHub