Webserver Path Scan for ScreenConnect SetupWizard Authentication Bypass (CVE-2024-1709)

Alerts on web requests to '/SetupWizard.aspx/' that match exploitation patterns for ScreenConnect authentication bypass CVE-2024-1709.

FreeReviewedSigma · Critical · v5
Category
webserver
Author
Matt Anderson, Huntress (SigmaHQ), DRL 1.1
Published
2024-02-20
Updated
2026-07-31

What it detects

This rule matches webserver GET requests whose URI stem contains '/SetupWizard.aspx/' with any following path segment. That pattern is used to probe or trigger ScreenConnect authentication bypass exploitation associated with CVE-2024-1709. It relies on webserver request telemetry, specifically the requested URI stem, to flag suspicious request paths that target the SetupWizard endpoint.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.