Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family SC

SC-44Detonation Chambers

Employ a detonation chamber capability within {{ insert: param, sc-44_odp }}.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (0)

ATT&CK techniques this control mitigates (22)

Weaknesses this control addresses (6)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-94Improper Control of Generation of Code ('Code Injection')6,628Dynamically generated code can be produced and executed inside the isolated chamber, preventing host compromise from code-injection payloads.
CWE-434Unrestricted Upload of File with Dangerous Type4,869Dangerous file uploads can be detonated in the chamber to determine malice before any production write or execution occurs.
CWE-502Deserialization of Untrusted Data3,125Untrusted serialized data can be deserialized and observed inside the chamber, blocking gadget-chain exploitation outside the sandbox.
CWE-829Inclusion of Functionality from Untrusted Control Sphere254Isolated execution prevents functionality from an untrusted sphere from affecting the real environment, allowing safe behavioral inspection.
CWE-506Embedded Malicious Code80Detonation chambers directly detect and analyze embedded malicious code by executing it in isolation before it reaches production systems.
CWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')61Externally controlled class or code selection can be resolved and invoked inside the chamber, surfacing unsafe reflection without system impact.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2026-349382.010.00.0005good
CVE-2025-59689 KEV3.66.10.0601good
CVE-2025-526430.94.70.0002good

Other controls in family SC

SC-1 SC-10 SC-11 SC-12 SC-13 SC-14 SC-15 SC-16 SC-17 SC-18 SC-19 SC-2 SC-20 SC-21 SC-22 SC-23 SC-24 SC-25 SC-26 SC-27 SC-28 SC-29 SC-3 SC-30 SC-31 SC-32 SC-33 SC-34 SC-35 SC-36 SC-37 SC-38 SC-39 SC-4 SC-40 SC-41 SC-42 SC-43 SC-45 SC-46 SC-47 SC-48 SC-49 SC-5 SC-50 SC-51 SC-6 SC-7 SC-8 SC-9