Possible Check Point Management Application Token Authentication as Administrator (via checkpoint)

PremiumReviewedSigma · Medium · v1
Product
checkpoint
Service
audit
Author
HuntRule
Published
2026-05-11
Updated
2026-08-28

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects Check Point management audit records showing an authentication performed with an application token that results in system_admin access. Rapid7 tied this pattern to exploitation of the CVE-2026-16232 SmartConsole authentication bypass where forged SSO tickets granted administrative sessions. Administrative logon using an application token rather than interactive credentials is a strong indicator of the bypass being exploited.

Related detections9 linkedT1550.001 — drag to rearrange
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious Device Registration Following OAuth Token Theft
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious Entra Agent Service Principal Sign-In With PowerShell User Agent via Sign-In Logs
Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
Possible Check Point SmartConsole Token Redemption Endpoint Access (via proxy)
Possible Check Point Management Application Token Authentication as Administrator (via checkpoint)
Pivot detection · T1550.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.