NIST 800-53 r5 · Controls catalogue · Family SC
SC-44Detonation Chambers
Employ a detonation chamber capability within {{ insert: param, sc-44_odp }}.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (22)
- T1137 Office Application Startup Persistence
- T1137.001 Office Template Macros Persistence
- T1137.002 Office Test Persistence
- T1137.003 Outlook Forms Persistence
- T1137.004 Outlook Home Page Persistence
- T1137.005 Outlook Rules Persistence
- T1137.006 Add-ins Persistence
- T1203 Exploitation for Client Execution Execution
- T1204 User Execution Execution
- T1204.001 Malicious Link Execution
- T1204.002 Malicious File Execution
- T1204.003 Malicious Image Execution
- T1221 Template Injection Stealth
- T1564.009 Resource Forking Stealth
- T1566 Phishing Initial Access
- T1566.001 Spearphishing Attachment Initial Access
- T1566.002 Spearphishing Link Initial Access
- T1566.003 Spearphishing via Service Initial Access
- T1598 Phishing for Information Reconnaissance
- T1598.001 Spearphishing Service Reconnaissance
- T1598.002 Spearphishing Attachment Reconnaissance
- T1598.003 Spearphishing Link Reconnaissance
Weaknesses this control addresses (6)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-94 | Improper Control of Generation of Code ('Code Injection') | 7,300+ | Dynamically generated code can be produced and executed inside the isolated chamber, preventing host compromise from code-injection payloads. |
CWE-434 | Unrestricted Upload of File with Dangerous Type | 5,100+ | Dangerous file uploads can be detonated in the chamber to determine malice before any production write or execution occurs. |
CWE-502 | Deserialization of Untrusted Data | 3,600+ | Untrusted serialized data can be deserialized and observed inside the chamber, blocking gadget-chain exploitation outside the sandbox. |
CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | 300+ | Isolated execution prevents functionality from an untrusted sphere from affecting the real environment, allowing safe behavioral inspection. |
CWE-506 | Embedded Malicious Code | 99 | Detonation chambers directly detect and analyze embedded malicious code by executing it in isolation before it reaches production systems. |
CWE-470 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') | 94 | Externally controlled class or code selection can be resolved and invoked inside the chamber, surfacing unsafe reflection without system impact. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2024-3094 UPD | 10.0 | 10.0 | 0.8597 | good |
CVE-2025-59374 KEV | 9.9 | 9.8 | 0.0117 | good |
CVE-2026-8398 KEV UPD | 9.9 | 9.8 | 0.0146 | good |
CVE-2026-48027 KEV UPD | 9.9 | 9.8 | 0.0185 | good |
CVE-2026-45321 KEV UPD | 9.4 | 9.6 | 0.0234 | good |
CVE-2026-33634 KEV | 9.2 | 8.8 | 0.5916 | good |
CVE-2025-30066 KEV UPD | 8.8 | 8.6 | 0.6979 | good |
CVE-2025-30154 KEV UPD | 8.8 | 8.6 | 0.0239 | good |
CVE-2024-4978 KEV UPD | 8.6 | 8.4 | 0.2694 | good |
CVE-2025-54313 KEV UPD | 8.1 | 7.5 | 0.0415 | good |
CVE-2026-46412 | 7.4 | 10.0 | 0.0042 | good |
CVE-2026-18072 | 7.4 | 9.8 | 0.0059 | good |
CVE-2026-66747 | 7.4 | 9.8 | 0.0058 | good |
CVE-2026-31976 | 7.3 | 9.8 | 0.0050 | good |
CVE-2026-34424 | 7.3 | 9.8 | 0.0055 | good |
CVE-2026-6443 | 7.3 | 9.8 | 0.0050 | good |
CVE-2026-44484 UPD | 7.3 | 9.8 | 0.0039 | good |
CVE-2026-73532 | 7.3 | 9.8 | 0.0046 | good |
CVE-2026-73533 | 7.3 | 9.8 | 0.0045 | good |
CVE-2026-77649 | 7.3 | 9.8 | 0.0043 | good |
CVE-2026-77650 | 7.3 | 9.8 | 0.0043 | good |
CVE-2026-77651 | 7.3 | 9.8 | 0.0043 | good |
CVE-2025-32965 UPD | 7.0 | 9.3 | 0.0090 | good |
CVE-2025-59039 UPD | 7.0 | 9.3 | 0.0033 | good |
CVE-2017-20201 UPD | 7.0 | 9.3 | 0.0049 | good |