{"data":{"id":"SC-44","name":"Detonation Chambers","family":"SC","family_name":"System and Communications Protection","withdrawn":false,"description":"Employ a detonation chamber capability within [Assignment: organization-defined system, system component, or location].","supplemental_guidance":"Detonation chambers, also known as dynamic execution environments, allow organizations to open email attachments, execute untrusted or suspicious applications, and execute Universal Resource Locator requests in the safety of an isolated environment or a virtualized sandbox. Protected and isolated execution environments provide a means of determining whether the associated attachments or applications contain malicious code. While related to the concept of deception nets, the employment of detonation chambers is not intended to maintain a long-term environment in which adversaries can operate and their actions can be observed. Rather, detonation chambers are intended to quickly identify malicious code and either reduce the likelihood that the code is propagated to user environments of operation or prevent such propagation completely.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"SC-44","name":"Detonation Chambers","description":"Employ a detonation chamber capability within [Assignment: organization-defined system, system component, or location].","discussion":"Detonation chambers, also known as dynamic execution environments, allow organizations to open email attachments, execute untrusted or suspicious applications, and execute Universal Resource Locator requests in the safety of an isolated environment or a virtualized sandbox. Protected and isolated execution environments provide a means of determining whether the associated attachments or applications contain malicious code. While related to the concept of deception nets, the employment of detonation chambers is not intended to maintain a long-term environment in which adversaries can operate and their actions can be observed. Rather, detonation chambers are intended to quickly identify malicious code and either reduce the likelihood that the code is propagated to user environments of operation or prevent such propagation completely.","related_controls":["SC-07","SC-18","SC-25","SC-26","SC-30","SC-35","SC-39","SI-03","SI-07"],"baseline_low":null,"baseline_moderate":null,"baseline_high":null,"baseline_privacy":null,"new_in_rev5":false,"changes_from_rev4":"No significant title changes from Rev 4."}},"compliance_mappings":{"iso_27001_2022":[],"iso_27002_2022":["8.7"],"cobit_2019":["DSS05"],"pci_dss_v4":["5.2"],"nist_csf_2":[],"cis_controls_v8":["CIS 10","CIS 10.7"],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["12"],"pra_op_resilience":[],"bsi_grundschutz":["APP.1.1","OPS.1.1.4"],"anssi":["Hygiene.21"],"osfi_b13":["B-13.3.2"],"finma_circular":["IV.C(64)","IV.C(65)"],"gdpr":[],"dora":[],"bio2":["8.7"],"rbi_csf":["Annex1.13"],"fisc":[],"lgpd_bcb":[],"hkma_tme1":[],"mlps_2":[],"dnb_good_practice":["DNB.19.1"],"cra":["CRA.I.2i"],"swift_cscf":[],"cbb_tm":["TM-8","TM-12"],"cbuae":["CR-3"],"qatar_nia":["CS"],"sama_csf":["3.6"],"bom_ctrm":["4.2"],"cbe_csf":["CD-1","CTO-6"],"cbn_csf":["Part3.5","Part4"],"sa_js2":["JS2-7.3","JS2-8.4"],"bot_cyber":["Ch3.1"],"ecb_croe":["CROE.2.3.5"],"ffiec_is":["II.C.9","II.C.12"],"hipaa_sr":["§164.308(a)(5)(ii)(B)"],"nydfs_500":["500.14"],"sebi_cscrf":["DE.DP","PR.NS"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":[],"tiber_eu":[],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":[],"hitrust_csf":["09.c"],"iso_27799":["12.2"],"lloyds_ms":["MS8.10"],"naic_ds":["4-monitoring"],"nhs_dspt":["NDG-9.3"],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1137","name":"Office Application Startup","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers execute suspicious Office documents in isolated environments to detect malicious startup code, macros, and add-ins before they reach user systems for persistent Office-based execution."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Sandbox detonation of suspicious content identifies client-side exploitation attempts by executing potential payloads in instrumented environments that detect exploit behavior without risking production systems."},{"id":"T1204","name":"User Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers analyze files and URLs that users might execute, identifying malicious behavior in isolated environments before content reaches users, preventing social engineering-based execution."},{"id":"T1221","name":"Template Injection","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Sandbox analysis of documents detects template injection by observing outbound requests for remote templates during detonation, identifying malicious external template URLs embedded in Office files."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers process email attachments and links in isolated sandboxes to detect phishing payloads, malicious macros, and exploitation attempts before delivery to user mailboxes."},{"id":"T1598","name":"Phishing for Information","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Sandbox analysis of suspected phishing content identifies credential harvesting pages and reconnaissance mechanisms by detonating suspicious links and attachments in isolated environments."},{"id":"T1137.001","name":"Office Template Macros","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Detonation chamber analysis of Office documents detects malicious template macros by executing documents in instrumented sandboxes that observe macro behavior, VBA code execution, and external callbacks."},{"id":"T1137.002","name":"Office Test","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Sandbox detonation of Office files detects Office Test registry persistence by observing document behavior in isolated environments that monitor for registry modifications and DLL loading patterns."},{"id":"T1137.003","name":"Outlook Forms","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers detect malicious Outlook forms by executing suspected payloads in isolated environments that observe form rendering behavior, script execution, and command invocation."},{"id":"T1137.004","name":"Outlook Home Page","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Sandbox analysis detects malicious Outlook Home Page modifications by observing document and email behavior in isolated environments that monitor for HTML rendering and embedded script execution."},{"id":"T1137.005","name":"Outlook Rules","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers detect malicious Outlook rules by analyzing email messages in sandboxed environments that observe automatic rule creation, forwarding, and executable invocation patterns."},{"id":"T1137.006","name":"Add-ins","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Sandbox detonation of Office documents detects malicious add-in loading by observing DLL and COM add-in registration behavior during document execution in isolated analysis environments."},{"id":"T1204.001","name":"Malicious Link","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers follow and analyze URLs from suspicious messages in isolated browser environments, detecting credential phishing pages, drive-by downloads, and exploitation kits before user access."},{"id":"T1204.002","name":"Malicious File","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Sandbox detonation of suspicious files executes potential payloads in instrumented environments, identifying malicious executables, scripts, and Office macros through behavioral analysis before user exposure."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers analyze container and VM images in isolated environments to detect malicious payloads, backdoors, and embedded malware before deployment to production infrastructure."},{"id":"T1564.009","name":"Resource Forking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Sandbox analysis of macOS files detects hidden payloads in resource forks by examining alternate data stream content during detonation in instrumented analysis environments."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers execute spearphishing attachments in isolated sandboxes that observe process creation, network callbacks, file system changes, and exploitation behavior to detect targeted malicious attachments."},{"id":"T1566.002","name":"Spearphishing Link","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Sandbox environments follow spearphishing links in isolated browsers, detecting credential harvesting forms, exploitation kits, and malicious redirects before targeted links reach intended victims."},{"id":"T1566.003","name":"Spearphishing via Service","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers analyze content delivered through social media, messaging, and other services in sandboxed environments, detecting service-based phishing payloads before user interaction."},{"id":"T1598.001","name":"Spearphishing Service","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Sandbox analysis of suspected phishing messages from social media and messaging services detects reconnaissance-focused credential harvesting and information gathering attempts in isolated environments."},{"id":"T1598.002","name":"Spearphishing Attachment","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Detonation chambers analyze suspicious attachments in isolated environments to detect reconnaissance-oriented payloads that attempt to harvest system information, credentials, or user data for targeting."},{"id":"T1598.003","name":"Spearphishing Link","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Sandbox environments follow suspicious reconnaissance links in isolated browsers, detecting information-harvesting pages that collect user credentials, system details, or organizational intelligence."}],"metadata":{"last_reviewed":"2026-02-19","review_notes":"","mapping_status":"complete"},"function":"preventative","used_by_patterns":[]}}