<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>SonicWall Firewall - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/sonicwall-firewall/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 24 Aug 2026 21:46:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/sonicwall-firewall/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Detection of Anomalous SonicWall Remote Access Logins</title><link>https://feed.craftedsignal.io/briefs/2026-08-sonicwall-remote-access-anomalies/</link><pubDate>Mon, 24 Aug 2026 21:46:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-sonicwall-remote-access-anomalies/</guid><description>This detection logic identifies potentially unauthorized remote or administrative VPN access by monitoring for successful login combinations of user, source IP, and appliance not observed in the previous 14 days.</description><content:encoded><![CDATA[<p>This brief outlines a detection capability designed to identify anomalous remote access behavior on SonicWall firewalls. By leveraging a 14-day history window, the logic flags successful logins by administrators or remote users from source IP addresses that have not been previously associated with that specific user account on a particular appliance.</p>
<p>This detection is critical for identifying potential credential stuffing, account takeover (ATO), or the use of compromised administrative credentials to gain initial access to the network. As SonicWall appliances are frequent targets for credential-based attacks, distinguishing legitimate travel or ISP address rotations from adversary activity is a key challenge for security operations. The detection focuses on authentication events including administrator logins (codes 235, 236) and remote-user/SSL VPN logins (codes 237, 238, 1080).</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of compromised accounts via VPN or administrative portals allows threat actors to establish persistent access, perform internal reconnaissance, and deploy secondary payloads such as ransomware or data exfiltration tools. Failure to identify these anomalies increases the dwell time of attackers who utilize valid credentials to bypass traditional boundary defenses.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the provided detection logic to flag first-seen user/source/appliance combinations for SonicWall environments.</li>
<li>Establish a baseline for managed service provider (MSP) source IPs to minimize false positives in the 'new-terms' logic.</li>
<li>Integrate MFA status checks into the triage workflow for all alerts generated by this rule; prioritize alerts where MFA failed or was absent.</li>
<li>Review logs for concurrent suspicious activity including internal scanning, configuration changes, or unusual data transfer volumes from the tunnel address assigned to the newly identified user/IP pair.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>identity-and-access-audit</category><category>initial-access</category><category>network-security</category></item></channel></rss>