Coverage › CVE-2022-1388
CVE-2022-1388 Mapped Sigma
F5 BIG-IP Missing Authentication Vulnerability
- Vendor / product
- F5 — BIG-IP
- Description (CISA)
- F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
- Added to KEV
- 2022-05-10
- Due date
- 2022-05-31
- Required action
- Apply updates per vendor instructions.
- Known ransomware use
- Known
- CWE
- CWE-306
- CISA notes
- https://nvd.nist.gov/vuln/detail/CVE-2022-1388
- Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28
1 mapping object across 1 technique. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.
| Technique | Mapping type | CTID comment | Status in v19.2 |
|---|---|---|---|
| T1548 Abuse Elevation Control Mechanism | exploitation technique | This CVE is an authentication bypass vulnerability. Unauthenticated users with network access can execute arbitrary commands. ref 1 |
live |
Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources
T1548 Abuse Elevation Control Mechanism exploitation technique
- DET0345 Detection Strategy for Abuse Elevation Control Mechanism (T1548)
AN0975 WindowsCorrelate registry modifications (e.g., UAC bypass registry keys), unusual parent-child process relationships (e.g., control.exe spawning cmd.exe), and unsigned elevated process executions with non-standard tokens or elevation flags.Tunable:
ElevatedProcessPathParentProcessNameTimeWindowAN0976 LinuxMonitor audit logs for setuid/setgid bit changes, executions where UID ≠ EUID (indicative of sudo or privilege escalation), and high-integrity binaries launched by unprivileged users.Tunable:WatchedDirectoriesUserContextTimeWindowAN0977 macOSDetect execution of/usr/libexec/security_authtrampolineor use of AuthorizationExecuteWithPrivileges API, and monitor process lineage for unusual launches of GUI apps with escalated privileges.Tunable:WatchedBinariesExecutionParentAN0978 Identity ProviderMonitor for unexpected privilege elevation operations via SAML assertion manipulation, role injection, or changes to identity mappings that result in access escalation.Tunable:AuthorizedRoleMappingsTimeWindowAN0979 IaaSDetect sudden privilege escalations such as IAM role changes, user-assigned privilege boundaries, or elevation via assumed roles beyond normal behavior.Tunable:PermittedRoleTransitionsCrossAccountBoundary
Sigma rules tagged attack.t1548 (24)
Author: Sittikorn S, Teoderick Contreras
· 2022-01-20 (modified 2022-12-31) · logsource: product=linux category=file_event · 00eee2a5-fdb0-4746-a21d-e43fbdea5681
Detects the creation of doas.conf file in linux host platform.
Author: Sittikorn S, Teoderick Contreras
· 2022-01-20 · logsource: product=linux category=process_creation · 067d8238-7127-451c-a9ec-fa78045b618b
Detects the doas tool execution in linux host platform. This utility tool allow standard users to perform tasks as root, the same way sudo does.
Author: Omkar Gudhate
· 2020-09-27 (modified 2023-09-28) · logsource: product=windows category=registry_set · 07743f65-7ec9-404a-a519-913db7118a8d
Detects changes to 'HKCU\Software\Classes\Folder\shell\open\command\DelegateExecute'
Author: Corissa Koopmans, '@corissalea'
· 2022-07-18 · logsource: product=azure service=auditlogs · 0922467f-db53-4348-b7bf-dee8d0d348c6
Monitor and alert on conditional access changes.
Author: Florent Labouyrie
· 2021-04-30 (modified 2022-10-09) · logsource: product=windows category=process_access · 174afcfa-6e40-4ae9-af64-496546389294
Detects when a process tries to access the memory of svchost to potentially dump credentials.
Author: Corissa Koopmans, '@corissalea'
· 2022-07-19 · logsource: product=azure service=auditlogs · 26e7c5e2-6545-481e-b7e6-050143459635
Monitor and alert on conditional access changes where non approved actor removed CA Policy.
Author: Milad Cheraghi
· 2026-04-28 · logsource: product=linux category=process_creation · 33b3cfb1-574e-44b9-b527-fbf9303b9d7b
Detects attempts of an attacker to enable core dumps for set-user-ID (SUID) processes by modifying the system file /proc/sys/fs/suid_dumpable, typically by setting its value to 1 or 2.
Enabling this feature allows memory dumps (core dumps) of SUID processes, which usually run with elevated privileges.
These dumps may contain sensitive information such as passwords, cryptographic keys or other secrets.
CVE-2025-5054: Information leak via core dumps from SUID binaries using apport.
CVE-2025-4598: Information disclosure in systemd-coredump due to insecure handling of SUID process memory dumps.
Author: Luc Génaux
· 2026-01-24 · logsource: product=linux category=process_creation · 3a716279-c18c-4488-83be-f9ececbfb9fc
Detects the use of the 'setcap' utility to set the 'setgid' capability (cap_setgid) on a binary file.
This capability allows a non privileged process to make arbitrary manipulations of group IDs (GIDs), including setting its current GID to a value that would otherwise be restricted (i.e. GID 0, the root group).
This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
Author: Corissa Koopmans, '@corissalea'
· 2022-07-19 (modified 2024-05-28) · logsource: product=azure service=auditlogs · 50a3c7aa-ec29-44a4-92c1-fce229eef6fc
Monitor and alert on conditional access changes. Is Initiated by (actor) approved to make changes? Review Modified Properties and compare "old" vs "new" value.
Author: Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner'
· 2022-08-04 · logsource: product=azure service=auditlogs · 665e2d43-70dc-4ccc-9d27-026c9dd7ed9c
Monitor and alert on group membership removal of groups that have CA policy modification access
Author: Elastic, @SBousseaden
· 2022-04-27 (modified 2024-08-13) · logsource: product=windows service=security · 749c9f5e-b353-4b90-a9c1-05243357ca4b
Detects a suspicious local successful logon event where the Logon Package is Kerberos, the remote address is set to localhost, and the target user SID is the built-in local Administrator account.
This may indicate an attempt to leverage a Kerberos relay attack variant that can be used to elevate privilege locally from a domain joined limited user to local System privileges.
Author: Bryan Lim
· 2024-01-12 · logsource: product=gcp service=gcp.audit · 76737c19-66ee-4c07-b65a-a03301d1573d
Detects the deployment of workloads that are deployed by using the break-glass flag to override Binary Authorization controls.
Author: Florian Roth (Nextron Systems)
· 2021-05-27 (modified 2022-10-09) · logsource: product=windows category=process_creation · 883835a7-df45-43e4-bf1d-4268768afda4
Detects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe
Author: Austin Songer @austinsonger
· 2021-07-24 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · 905d389b-b853-46d0-9d3d-dea0d3a3cd49
Identifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.
Author: Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner'
· 2022-08-04 · logsource: product=azure service=auditlogs · 91c95675-1f27-46d0-bead-d1ae96b97cd3
Monitor and alert on group membership additions of groups that have CA policy modification access