kevmap

Coverage › CVE-2024-53704

CVE-2024-53704 Mapped Sigma

SonicWall SonicOS SSLVPN Improper Authentication Vulnerability

Vendor / product
SonicWall — SonicOS
Description (CISA)
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
Added to KEV
2025-02-18
Due date
2025-03-11
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known ransomware use
Known
CWE
CWE-287
CISA notes
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003
https://nvd.nist.gov/vuln/detail/CVE-2024-53704
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

5 mapping objects across 5 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.

TechniqueMapping typeCTID commentStatus in v19.2
T1199 Trusted Relationship exploitation technique Due to improper session cookie validation in SonicOS, an attacker can hiijack an active session without any credentials.
ref 1
live
T1212 Exploitation for Credential Access exploitation technique Due to improper session cookie validation in SonicOS, an attacker can hiijack an active session without any credentials.
ref 1
live
T1021.001 Remote Desktop Protocol secondary impact Due to improper session cookie validation in SonicOS, an attacker can hiijack an active session without any credentials.
ref 1
live
T1078.004 Cloud Accounts primary impact Due to improper session cookie validation in SonicOS, an attacker can hiijack an active session without any credentials.
ref 1
live
T1083 File and Directory Discovery primary impact Due to improper session cookie validation in SonicOS, an attacker can hiijack an active session without any credentials.
ref 1
live

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

T1021.001 Remote Desktop Protocol secondary impact

Sigma rules tagged attack.t1021.001 (16)

Author: pH-T (Nextron Systems), @Kostastsale, TheDFIRReport · 2022-02-12 (modified 2025-11-22) · logsource: product=windows category=process_creation · 0d5675be-bc88-4172-86d3-1e96a4476536
Detects the execution of "reg.exe" for enabling/disabling the RDP service on the host by tampering with the 'CurrentControlSet\Control\Terminal Server' values
Techniques: T1021.001T1112
Author: Josh Brower @DefensiveDepth · 2020-08-22 (modified 2024-03-13) · logsource: product=zeek service=rdp · 1fc0809e-06bf-4de3-ad52-25e5263b7623
Detects connections from routable IPs to an RDP listener. Which is indicative of a publicly-accessible RDP service.
Techniques: T1021.001
Author: Florian Roth (Nextron Systems) · 2022-02-25 (modified 2022-09-09) · logsource: product=windows category=process_creation · 2f974656-6d83-4059-bbdf-68ac5403422f
Detects process execution patterns found in intrusions related to the Hermetic Wiper malware attacks against Ukraine in February 2022
Techniques: T1021.001
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-10-12 (modified 2024-03-05) · logsource: product=windows category=process_creation · 327f48c1-a6db-4eb8-875a-f6981f1b0183
Detects port forwarding activity via SSH.exe
Author: Florian Roth (Nextron Systems) · 2021-01-19 (modified 2022-10-09) · logsource: product=windows category=process_creation · 48a61b29-389f-4032-b317-b30de6b95314
Detects suspicious Plink tunnel port forwarding to a local port
Techniques: T1572T1021.001
Author: Daniel Koifman (KoifSec), Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-15 · logsource: product=windows category=process_creation · 4b8f6d3a-9c5e-4f2a-a7d8-6b9c3e5f2a8d
Detects enabling or disabling of Remote Desktop Protocol (RDP) using alternate methods such as WMIC or PowerShell. In PowerShell one-liner commands, the "SetAllowTSConnections" method of the "Win32_TerminalServiceSetting" class may be used to enable or disable RDP. In WMIC, the "rdtoggle" alias or "Win32_TerminalServiceSetting" class may be used for the same purpose.
Techniques: T1021.001T1047
Author: Thomas Patzke · 2019-01-28 (modified 2022-10-09) · logsource: product=windows service=security · 51e33403-2a37-4d66-a574-1fda1782cc31
RDP login with localhost source address may be a tunnelled login
Techniques: T1021.001
Author: Marco Pedrinazzi (@pedrinazziM) · 2026-01-06 · logsource: product=opencanary category=application · 598290cf-5932-45cd-9123-be1e05ab4f2e
Detects instances where an RDP service on an OpenCanary node has had a connection attempt.
Techniques: T1133T1021.001
Author: Samir Bousseaden · 2019-02-16 (modified 2022-09-02) · logsource: product=windows service=security · 5bed80b6-b3e8-428e-a3ae-d3c757589e41
Detects svchost hosting RDP termsvcs communicating with the loopback address
Author: Samir Bousseaden · 2019-02-16 (modified 2024-03-12) · logsource: product=windows category=network_connection · 5f699bc5-5446-4a4a-a0b7-5ef2885a3eb4
Detects svchost hosting RDP termsvcs communicating with the loopback address and on TCP port 3389
Techniques: T1572T1021.001
Author: Pushkarev Dmitry · 2020-06-27 (modified 2021-11-27) · logsource: product=windows service=security · 8e5c03fa-b7f0-11ea-b242-07e0576828d9
This event is generated when an authenticated user who is not allowed to log on remotely attempts to connect to this computer through Remote Desktop. Often, this event can be generated by attackers when searching for available windows servers in the network.
Techniques: T1021.001
Author: frack113 · 2022-01-07 (modified 2024-06-04) · logsource: product=windows category=process_creation · 954f0af7-62dd-418f-b3df-a84bc2c7a774
Detects the usage of "mstsc.exe" with the "/v" flag to initiate a connection to a remote server. Adversaries may use valid accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
Techniques: T1021.001
Author: Florian Roth (Nextron Systems) · 2022-04-29 (modified 2022-07-14) · logsource: product=windows category=network_connection · b1e5da3b-ca8e-4adf-915c-9921f3d85481
Detects svchost hosting RDP termsvcs communicating to target systems on TCP port 80 or 443
Techniques: T1572T1021.001
Author: Markus Neis · 2019-05-15 (modified 2024-02-09) · logsource: product=windows category=network_connection · ed74fe75-7594-4b4b-ae38-e38e3fd2eb23
Detects Non-Standard tools initiating a connection over port 3389 indicating possible lateral movement. An initial baseline is required before using this utility to exclude third party RDP tooling that you might use.
Techniques: T1021.001
Author: Florian Roth (Nextron Systems) · 2018-03-17 (modified 2023-05-16) · logsource: product=windows category=process_creation · f72aa3e8-49f9-4c7d-bd74-f8ab84ff9bbb
Detects a suspicious RDP session redirect using tscon.exe
Techniques: T1563.002T1021.001

All 16 rules on the technique page →

T1078.004 Cloud Accounts primary impact

Sigma rules tagged attack.t1078.004 (41)

Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik' · 2022-06-02 · logsource: product=azure service=auditlogs · 0055ad1f-be85-4798-83cf-a6da17c993b3
Detects when a configuration change is made to an applications URI. URIs for domain names that no longer exist (dangling URIs), not using HTTPS, wildcards at the end of the domain, URIs that are no unique to that app, or URIs that point to domains you do not control should be investigated.
Techniques: T1528T1078.004
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-09 · logsource: product=azure service=auditlogs · 039a7469-0296-4450-84c0-f6966b16dc6d
Detects when a PIM elevation is approved or denied. Outside of normal operations should be investigated.
Techniques: T1078.004
Author: Austin Songer @austinsonger · 2021-11-26 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 09438caa-07b1-4870-8405-1dbafe3dad95
Detects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could allow an attacker access to Azure subscriptions in your environment.
Techniques: T1078.004
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-10 · logsource: product=azure service=auditlogs · 0b4b72e3-4c53-4d5b-b198-2c58cfef39a9
Detects when a user that doesn't have permissions to invite a guest user attempts to invite one.
Techniques: T1078.004
Author: Michael Epping, '@mepples21' · 2022-06-28 · logsource: product=azure service=auditlogs · 11c767ae-500b-423b-bae3-b234450736ed
Monitor and alert for users added to device admin roles.
Techniques: T1078.004
Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik' · 2022-06-02 · logsource: product=azure service=auditlogs · 1b45b0d1-773f-4f23-aedc-814b759563b1
Detects when a configuration change is made to an applications AppID URI.
Techniques: T1552T1078.004
Author: MikeDuddington, '@dudders1' · 2022-07-28 · logsource: product=azure service=signinlogs · 28870ae4-6a13-4616-bd1a-235a7fad7458
Detect failed authentications from countries you do not operate out of.
Techniques: T1078.004T1110
Author: MikeDuddington, '@dudders1' · 2022-07-27 · logsource: product=azure service=signinlogs · 28eea407-28d7-4e42-b0be-575d5ba60b2c
Detect when users are authenticating without MFA being required.
Techniques: T1078.004T1556.006
Author: Romain Gaillard (@romain-gaillard) · 2024-07-29 · logsource: product=github service=audit · 2f575940-d85e-4ddc-af13-17dad6f1a0ef
Detects when changes are made to the SSH certificate configuration of the organization.
Techniques: T1078.004
AWS Console Login Monitoring mediumexperimental
Author: Ivan Saakov · 2025-10-19 · logsource: product=aws service=cloudtrail · 313e72de-0c0d-4d65-8c95-87f4d546eceb
Detects AWS console logins from countries and IP addresses that are not recognized as legitimate for the organization. This alert can help identify potential unauthorized access attempts from unusual locations, which may indicate compromised credentials or malicious activity.
Techniques: T1078.004
Author: YochanaHenderson, '@Yochana-H' · 2022-08-03 · logsource: product=azure service=auditlogs · 340ee172-4b67-4fb4-832f-f961bdc1f3aa
Detect when a user has reset their password in Azure AD
Techniques: T1078.004
Author: Tom Kluter · 2026-04-28 · logsource: product=gcp service=google_workspace.login · 38360161-76c4-4283-842e-efcf997dafc8
Detects Google Workspace login activity that's classified as suspicious by Google.
Techniques: T1078.004
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-06 · logsource: product=azure service=auditlogs · 49a268a4-72f4-4e38-8a7b-885be690c5b5
Detects when a user is added to a privileged role.
Techniques: T1078.004
Author: Yochana Henderson, '@Yochana-H' · 2022-06-17 · logsource: product=azure service=signinlogs · 4afac85c-224a-4dd7-b1af-8da40e1c60bd
Detects when an account is disabled or blocked for sign in but tried to log in
Techniques: T1078.004
Author: Michael Epping, '@mepples21' · 2022-06-28 (modified 2022-10-05) · logsource: product=azure service=signinlogs · 4d136857-6a1a-432a-82fc-5dd497ee5e7c
Monitor and alert for Sign-ins by unknown devices from non-Trusted locations.
Techniques: T1078.004

All 41 rules on the technique page →

T1083 File and Directory Discovery primary impact

Sigma rules tagged attack.t1083 (24)

Author: Daniil Yugoslavskiy, oscd.community · 2020-10-19 (modified 2022-11-25) · logsource: product=macos category=process_creation · 089dbdf6-b960-4bcc-90e3-ffc3480c20f6
Detects usage of system utilities to discover files and directories
Techniques: T1083
Author: Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.) · 2024-09-02 · logsource: product=linux category=process_creation · 093d68c7-762a-42f4-9f46-95e79142571a
Detects the use of the "nice" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
Techniques: T1083
Author: frack113 · 2022-03-17 · logsource: product=windows category=ps_script · 162e69a7-7981-4344-84a9-0f1c9a217a52
Detects technique used by MAZE ransomware to enumerate directories using Powershell
Techniques: T1083
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-10-18 (modified 2023-02-04) · logsource: product=windows category=process_creation · 38646daa-e78f-4ace-9de0-55547b2d30da
Detects the execution of the PUA/Recon tool Seatbelt via PE information of command line parameters
Techniques: T1526T1087T1083
Author: The DFIR Report · 2025-02-21 · logsource: product=windows category=process_creation · 3b4e950b-a3ea-44d3-877e-432071990709
Detects the execution of Notepad to open a file that has the string "password" which may indicate unauthorized access to credentials or suspicious activity.
Techniques: T1083
Author: Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), oscd.community, Jonhnathan Ribeiro · 2019-01-16 (modified 2025-10-18) · logsource: product=windows category=process_creation · 41d40bff-377a-43e2-8e1b-2e543069e079
Detects WannaCry ransomware activity
PUA - TruffleHog Execution mediumexperimental
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-09-24 · logsource: product=windows category=process_creation · 44030449-b0df-4c94-aae1-502359ab28ee
Detects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.
Techniques: T1083T1552.001
Author: Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.) · 2024-09-02 · logsource: product=linux category=process_creation · 4b09c71e-4269-4111-9cdd-107d8867f0cc
Detects the use of the "flock" command to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
Techniques: T1083
Author: Li Ling, Andy Parkidomo, Robert Rakowski, Blake Hartstein (Bloomberg L.P.) · 2024-09-02 · logsource: product=linux category=process_creation · 6adfbf8f-52be-4444-9bac-81b539624146
Detects the use of the find command to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or exploitation attempt.
Techniques: T1083
Author: Nasreddine Bencherchali (Nextron Systems), Luc Génaux · 2022-12-28 (modified 2026-06-05) · logsource: product=linux category=process_creation · 7ab8f73a-fcff-428b-84aa-6a5ff7877dea
Detects the use of "vim" and it's siblings commands to execute a shell or proxy commands. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
Techniques: T1059T1083
Author: frack113 · 2022-09-16 · logsource: product=windows category=ps_script · 7d416556-6502-45b2-9bad-9d2f05f38997
Detect adversaries enumerate sensitive files
Techniques: T1083
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-12-28 · logsource: product=linux category=process_creation · 8344c0e5-5783-47cc-9cf9-a0f7fd03e6cf
Detects usage of "find" binary in a suspicious manner to perform discovery
Techniques: T1083
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-12-28 · logsource: product=macos category=process_creation · 85de3a19-b675-4a51-bfc6-b11a5186c971
Detects usage of "find" binary in a suspicious manner to perform discovery
Techniques: T1083
Author: James Ahearn · 2019-06-08 (modified 2022-10-05) · logsource: category=webserver · 953d460b-f810-420a-97a2-cfca4c98e602
Detects source code enumeration that use GET requests by keyword searches in URL strings
Techniques: T1083
Author: Austin Clark · 2019-08-12 (modified 2023-01-04) · logsource: product=cisco service=aaa · 9705a6a1-6db6-4a16-a987-15b7151e299b
Find information about network devices that is not stored in config files

All 24 rules on the technique page →

T1199 Trusted Relationship exploitation technique

Sigma rules tagged attack.t1199 (2)

Author: zendannyy · 2026-04-28 · logsource: product=okta service=okta · fe04b26b-0ac4-45d7-9404-4b9f16a440a9
Detects Okta session impersonation grant event where a user is granted the ability to impersonate another user's session. This event type "user.session.impersonation.grant" signifies that someone has been given temporary access to act on behalf of another user account. Threat actors may abuse this functionality to escalate privileges, access sensitive resources, or perform unauthorized actions while appearing to be the impersonated user. Legitimate use cases are typically limited to Okta support scenarios or authorized administrative troubleshooting.
Techniques: T1484.002T1199
Author: austinsonger · 2021-08-19 (modified 2022-10-09) · logsource: product=m365 service=threat_management · ff246f56-7f24-402a-baca-b86540e3925c
Detects when a Security Compliance Center reported a user who exceeded sending limits of the service policies and because of this has been restricted from sending email.
Techniques: T1199

T1212 Exploitation for Credential Access exploitation technique

Sigma rules tagged attack.t1212 (5)

Author: Florian Roth (Nextron Systems) · 2020-07-03 (modified 2021-11-27) · logsource: product=linux service=guacamole · 1edd77db-0669-4fef-9598-165bda82826d
Detects suspicious session with two users present
Techniques: T1212
GALLIUM IOCs hightest
Author: Tim Burrell · 2020-02-07 (modified 2024-11-23) · logsource: product=windows category=process_creation · 440a56bf-7873-4439-940a-1c8a671073c2
Detects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.
Techniques: T1212T1071
Audit CVE Event criticaltest
Author: Florian Roth (Nextron Systems), Zach Mathis · 2020-01-15 (modified 2022-10-22) · logsource: product=windows service=application · 48d91a3a-2363-43ba-a456-ca71ac3da5c2
Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
Author: Elastic (idea), Tobias Michalski (Nextron Systems) · 2022-05-04 (modified 2023-02-09) · logsource: product=windows category=process_creation · bb76d96b-821c-47cf-944b-7ce377864492
Detects a privilege elevation attempt by coercing NTLM authentication on the Printer Spooler service
Techniques: T1212
Author: Florian Roth (Nextron Systems) · 2017-02-10 (modified 2024-01-16) · logsource: product=windows service=security · f7644214-0eb0-4ace-9455-331ec4c09253
Detects failed Kerberos TGT issue operation. This can be a sign of manipulations of TGT messages by an attacker.
Techniques: T1212