kevmap

Coverage › CVE-2025-0411

CVE-2025-0411 Mapped Sigma

7-Zip Mark of the Web Bypass Vulnerability

Vendor / product
7-Zip — 7-Zip
Description (CISA)
7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
Added to KEV
2025-02-06
Due date
2025-02-27
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known ransomware use
Unknown
CWE
CWE-693
CISA notes
https://www.7-zip.org/history.txt
https://nvd.nist.gov/vuln/detail/CVE-2025-0411
Elsewhere
cve.org · NVD · CISA KEV · JSON

ATT&CK techniques · CTID Mappings Explorer, ATT&CK 16.1, KEV snapshot 2025-07-28

3 mapping objects across 3 techniques. exploitation technique states how the vulnerability is exploited; primary and secondary impact state what exploitation achieves. They are different claims and are labelled as such.

TechniqueMapping typeCTID commentStatus in v19.2
T1553.005 Mark-of-the-Web Bypass exploitation technique Attackers can double-archive malicious payloads with 7-Zip to bypass Windows's Mark-of-the-Web security feature, further allowing the bypassing of Microsoft Defender SmartScreen. This allows attackers to disseminate these payloads via methods like email attachments, which would normally be subject to additional scrutiny by the service's protective measures. This flaw was patched in 7-Zip version 24.09.
ref 1
live
T1566.001 Spearphishing Attachment exploitation technique Attackers can double-archive malicious payloads with 7-Zip to bypass Windows's Mark-of-the-Web security feature, further allowing the bypassing of Microsoft Defender SmartScreen. This allows attackers to disseminate these payloads via methods like email attachments, which would normally be subject to additional scrutiny by the service's protective measures. This flaw was patched in 7-Zip version 24.09.
ref 1
live
T1588.001 Malware primary impact Attackers can double-archive malicious payloads with 7-Zip to bypass Windows's Mark-of-the-Web security feature, further allowing the bypassing of Microsoft Defender SmartScreen. This allows attackers to disseminate these payloads via methods like email attachments, which would normally be subject to additional scrutiny by the service's protective measures. This flaw was patched in 7-Zip version 24.09.
ref 1
live

Detection chain · ATT&CK Enterprise v19.2 detection strategies, analytics, log sources

T1553.005 Mark-of-the-Web Bypass exploitation technique

Sigma rules tagged attack.t1553.005 (6)

Author: frack113 · 2022-02-01 · logsource: product=windows category=ps_script · 29e1c216-6408-489d-8a06-ee9d151ef819
Adversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.
Techniques: T1553.005
Author: frack113 · 2022-02-01 · logsource: product=windows category=ps_script · 5947497f-1aa4-41dd-9693-c9848d58727d
Remove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet.
Techniques: T1553.005
Author: frack113 · 2022-02-01 · logsource: product=windows category=ps_script · 902cedee-0398-4e3a-8183-6f3a89773a96
Adversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.
Techniques: T1553.005
Author: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-03 · logsource: product=windows service=appxdeployment-server · 9a025188-6f2d-42f8-bb2f-d3a83d24a5af
Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events
Techniques: T1204.002T1553.005
Author: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-03 · logsource: product=windows category=process_creation · af5732ed-764e-489d-826d-0447c8b36242
Detects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.
Author: Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-03 · logsource: product=windows service=appxdeployment-server · e54279c7-4910-4e2c-902c-c56a25b549f6
Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions
Techniques: T1204.002T1553.005

T1566.001 Spearphishing Attachment exploitation technique

Sigma rules tagged attack.t1566.001 (24)

Author: Florian Roth (Nextron Systems) · 2019-10-24 (modified 2021-11-27) · logsource: product=windows category=process_creation · 023394c4-29d5-46ab-92b8-6a534c6f447b
Detects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation
Author: Syed Hasan (@syedhasan009) · 2021-05-29 (modified 2023-11-09) · logsource: product=windows service=security · 0248a7bc-8a9a-4cd8-a57e-3ae8e073a073
Detects the mount of an ISO image on an endpoint
Techniques: T1566.001
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-01-23 (modified 2025-10-29) · logsource: product=windows category=file_event · 0e29e3a7-1ad8-40aa-b691-9f82ecd33d66
Detects the creation of a new office macro files on the system via an application (browser, mail client). This can help identify potential malicious activity, such as the download of macro-enabled documents that could be used for exploitation.
Techniques: T1566.001
Author: Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems) · 2019-06-26 (modified 2025-05-30) · logsource: product=windows category=process_creation · 1cdd9a09-06c9-4769-99ff-626e2b3991b8
Detects suspicious use of an .exe extension after a non-executable file extension like .pdf.exe, a set of spaces or underlines to cloak the executable file in spear phishing campaigns
Techniques: T1566.001
Author: Sreeman · 2020-03-13 (modified 2022-04-14) · logsource: product=windows category=process_creation · 24de4f3b-804c-4165-b442-5a06a2302c7e
The .SettingContent-ms file type was introduced in Windows 10 and allows a user to create "shortcuts" to various Windows 10 setting pages. These files are simply XML and contain paths to various Windows 10 settings binaries.
Techniques: T1204T1566.001
Author: Antonlovesdnb, Trent Liffick (@tliffick) · 2020-02-19 (modified 2023-06-21) · logsource: product=windows category=registry_event · 295a59c1-7b79-4b47-a930-df12c15fc9c2
Alerts on trust record modification within the registry, indicating usage of macros
Techniques: T1566.001
Author: @sam0x90 · 2022-07-30 · logsource: product=windows category=file_event · 2f9356ae-bf43-41b8-b858-4496d83b2acb
Detects the creation of a ISO file in the Outlook temp folder or in the Appdata temp folder. Typical of Qakbot TTP from end-July 2022.
Techniques: T1566.001
Author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber) · 2026-01-27 · logsource: product=m365 service=audit · 3569aefd-e535-4391-8c18-24bd01a21eaf
Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder. It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.
Techniques: T1566.001T1566.002
Author: Florian Roth (Nextron Systems) · 2022-02-11 · logsource: product=windows category=file_event · 4358e5a5-7542-4dcb-b9f3-87667371839b
Detects the creation of recent element file that points to an .ISO, .IMG, .VHD or .VHDX file as often used in phishing attacks. This can be a false positive on server systems but on workstations users should rarely mount .iso or .img files.
Techniques: T1566.001
Author: Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems) · 2020-04-01 (modified 2023-04-12) · logsource: product=windows category=process_creation · 52cad028-0ff0-4854-8f67-d25dfcbc78b4
Detects a suspicious child process of a Microsoft HTML Help (HH.exe)
Author: Joseph Kamau · 2025-12-05 · logsource: product=windows category=process_creation · 538c5851-8c03-4724-8ec4-623bc7aadaea
Detects web browser process opening an HTML file from a user's Downloads folder. This behavior is could be associated with phishing attacks where threat actors send HTML attachments to users. When a user opens such an attachment, it can lead to the execution of malicious scripts or the download of malware. During investigation, analyze the HTML file for embedded scripts or links, check for any subsequent downloads or process executions, and investigate the source of the email or message containing the attachment.
Techniques: T1598.002T1566.001
Author: Florian Roth (Nextron Systems) · 2022-05-09 · logsource: product=windows service=security · 571498c8-908e-40b4-910b-d2369159a3da
Detects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.
Techniques: T1027T1566.001
Author: Florian Roth (Nextron Systems) · 2017-11-23 (modified 2021-11-27) · logsource: product=windows category=process_creation · 678eb5f4-8597-4be6-8be7-905e4234b53a
Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
CVE tags: CVE-2017-11882
Author: Florian Roth (Nextron Systems) · 2018-02-22 (modified 2021-11-27) · logsource: product=windows category=process_creation · 864403a1-36c9-40a2-a982-4c9a45f7d833
Detects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
CVE tags: CVE-2017-0261
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-01-23 (modified 2026-01-09) · logsource: product=windows category=file_event · 91174a41-dc8f-401b-be89-7bfc140612a0
Detects the creation of a new office macro files on the systems
Techniques: T1566.001

All 24 rules on the technique page →

T1588.001 Malware primary impact

Sigma rules tagged attack.t1588.001 (1)

Author: Florian Roth (Nextron Systems) · 2017-03-01 · logsource: product=linux service=clamav · 36aa86ca-fd9d-4456-814e-d3b1b8e1e0bb
Detects relevant ClamAV messages
Techniques: T1588.001