kevmap

Log sources

The 261 log sources ATT&CK v19.2 analytics name, inverted: pick the log you have and see which techniques — and which actively exploited CVEs — it can reach.

Derived from x_mitre_log_source_references on 1758 analytics (4182 references). Names are MITRE's verbatim; a source appearing twice under slightly different spellings is a source problem and is left visible.

Log sourcePlatformsChannelsAnalyticsTechniquesKEV CVEs reachable
WinEventLog:SysmonIaaS, Linux, Office Suite, Windows, macOS 24435423418
macos:unifiedlogmacOS 499350348419
auditd:SYSCALLContainers, Linux, macOS 276344331418
WinEventLog:SecurityIdentity Provider, Office Suite, Windows 54284280270
NSM:FlowContainers, ESXi, Linux, Network Devices, Windows, macOS 229235131274
macos:osquerymacOS 599494140
AWS:CloudTrailContainers, IaaS, Identity Provider, SaaS, Windows 1069289119
linux:syslogLinux, Network Devices 778180138
m365:unifiedIdentity Provider, Office Suite, SaaS, Windows 86827083
WinEventLog:PowerShellOffice Suite, Windows 13656426
esxi:hostdESXi, IaaS 515453221
linux:osqueryLinux 38484742
esxi:vmkernelESXi 434746104
networkdevice:syslogLinux, Network Devices 534746200
auditd:EXECVELinux 35454421
WinEventLog:SystemWindows 20393828
esxi:shellESXi 32373647
macos:endpointsecuritymacOS 233535152
azure:signinlogsIdentity Provider, Office Suite, SaaS, Windows 34353356
fs:fsusagemacOS 30313174
Internet ScanPRE 1272714
NSM:ConnectionsIdentity Provider, Linux, Network Devices, Windows, macOS 242523141
WinEventLog:ApplicationOffice Suite, Windows 20222298
networkdevice:cliNetwork Devices 202121211
AWS:VPCFlowLogsIaaS 161616177
auditd:PATHLinux 14161612
saas:oktaIdentity Provider, SaaS 17161655
Network TrafficPRE, Windows 115152
networkdevice:configNetwork Devices 1414146
etw:Microsoft-Windows-Kernel-ProcessWindows 12121243
auditd:FILELinux 1111113
linux:SysmonLinux 5111132
m365:exchangeOffice Suite, Windows 1212116
NSM:FirewallESXi, Network Devices, Windows, macOS 1212106
azure:auditIdentity Provider, Office Suite 11101012
kubernetes:auditContainers, Linux 11111072
AWS:CloudWatchIaaS 99930
azure:activityIaaS, Identity Provider, Windows 9991
esxi:syslogESXi 99912
esxi:vpxdESXi 99911
kubernetes:apiserverContainers 10994
docker:daemonContainers 8886
docker:eventsContainers 988171
ebpf:syscallsContainers, IaaS, Linux 98817
gcp:auditIaaS, Office Suite, SaaS 111188
m365:signinlogsOffice Suite, SaaS 7982
Malware RepositoryPRE 1773
WinEventLog:Microsoft-Windows-CodeIntegrity/OperationalWindows 7773
fs:fileeventsLinux, macOS 6774
fs:fseventsmacOS 77754
Application LogPRE 1661
Application:MailLinux 66618
WinEventLog:WMIWindows 2662
auditd:CONFIG_CHANGELinux 6662
esxi:authESXi 66615
saas:googleworkspaceSaaS 7666
saas:slackSaaS 6663
Domain NamePRE 1550
containerd:EventsContainers, Linux 55524
containerd:runtimeContainers 55579
linux:cliLinux 5559
m365:messagetraceOffice Suite, Windows 5550
macos:syslogmacOS 45546
saas:authIdentity Provider, SaaS 55521
saas:salesforceSaaS 5551
saas:zoomSaaS 5554
PersonaPRE 1440
Windows:perfmonWindows 44421
auditd:PROCTITLELinux 4441
esxcli:networkESXi 4444
linux:cronLinux 2440
m365:defenderIdentity Provider, Office Suite, Windows 44414
m365:sharepointOffice Suite, Windows 4442
EDR:fileWindows 3330
PF:LogsmacOS 33325
WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/FirewallWindows 2330
WinEventLog:TaskSchedulerWindows 2333
auditd:USER_LOGINLinux 2333
esxi:cronESXi 3332
esxi:vobdESXi 333170
esxi:vpxaESXi 33315
gcp:workspaceauditIdentity Provider, SaaS 3330
iptables:LOGLinux 23335
journald:packageLinux 3333
kubernetes:eventsContainers, Linux 3337
m365:officeOffice Suite 4330
saas:auditSaaS 3330
saas:boxSaaS 3333
CertificatePRE 1221
EDR:AMSIWindows 2220
EDR:detectionLinux, Windows 2220
EDR:huntingWindows 2220
ETW:TokenWindows 2221
Firewall Audit LogsNetwork Devices 2221
NSM:ContentESXi, Windows, macOS 3320
Okta:SystemLogIaaS, Identity Provider 2220
OpenBSM:AuditTrailmacOS 2220
WinEventLog:Microsoft-Office-AlertsWindows 2220
WinEventLog:Microsoft-Windows-Windows Defender/OperationalWindows 2226
WinEventLog:Windows DefenderWindows 2220
auditd:MMAPLinux 2220
azure:policyIdentity Provider 3322
dns:queryWindows 2220
esxi:esxupdateESXi 2220
etw:Microsoft-Windows-Win32kWindows 2220
etw:Microsoft-Windows-WinINetWindows 2220
journald:systemdLinux 2227
linux:authLinux 2221
linux:procfsLinux 22238
macos:keychainmacOS 22218
networkconfig Linux, Network Devices 2222
networkdevice:firmwareNetwork Devices 2222
networkdevice:runtimeNetwork Devices 2220
saas:accessSaaS 2220
saas:applicationSaaS 22219
saas:confluenceSaaS 3222
saas:githubSaaS 6220
saas:googledriveSaaS 2220
vpxd.logESXi 2221
ALB:HTTPLogsIaaS 111157
AWS:CloudMetricsIaaS 1110
Apple TCC LogsmacOS 1110
ApplicationLog:APIContainers 11125
ApplicationLog:CallRecordsWindows 1110
ApplicationLog:EntraIDPortalIdentity Provider 1110
ApplicationLog:IISWindows 111157
ApplicationLog:IngressContainers 111157
ApplicationLog:Intune/MDM LogsWindows 1110
ApplicationLog:MailServerLinux 1110
ApplicationLog:WebServerLinux 111157
ApplicationLogs:SQLLinux 1110
Autoruns:RegistryScanWindows 1110
CloudTrail:GetCallerIdentityIaaS 1110
CloudTrail:GetObjectIaaS 1113
CloudTrail:PutObjectIaaS 1110
CloudTrail:SigninIaaS 1110
EDR:TelemetryWindows 1110
EDR:cliWindows 1110
EDR:memoryWindows 1110
EDR:scriptblockWindows 1116
ESXiLogs:authlogESXi 1110
ESXiLogs:messagesESXi 1110
ETWWindows 1110
ETW:ProcThreadWindows 1110
GCPAuditLogs:login.googleapis.comSaaS 1110
Google Admin AuditSaaS 1110
IDS:TLSInspectionNetwork Devices 1110
M365Defender:DeviceNetworkEventsWindows 1110
Microsoft Entra ID Audit LogsIdentity Provider 1110
Microsoft Graph API LogsOffice Suite 1110
NSX:FlowLogsESXi 1110
NetFlow:FlowLinux 11143
Netfilter/iptablesLinux 1110
VPCFlowLogs:AllIaaS 1117
WIDS:AssociationLogsNetwork Devices 1110
WLANLogs:AssociationNetwork Devices 1110
WinEventLog:ADFSWindows 1110
WinEventLog:AppLockerWindows 1110
WinEventLog:CodeIntegrityWindows 1110
WinEventLog:KerberosWindows 1110
WinEventLog:Microsoft-IIS-ConfigurationWindows 1110
WinEventLog:Microsoft-Office/OutlookAddinMonitorOffice Suite 1110
WinEventLog:Microsoft-Windows-BackupWindows 1112
WinEventLog:Microsoft-Windows-COM/OperationalWindows 1110
WinEventLog:Microsoft-Windows-Kernel-BootWindows 1112
WinEventLog:Microsoft-Windows-SMBClient/SecurityWindows 1110
WinEventLog:Microsoft-Windows-Security-Mitigations/KernelModeWindows 1110
WinEventLog:Microsoft-Windows-Shell-CoreWindows 1111
WinEventLog:Microsoft-Windows-TCPIPWindows 1110
WinEventLog:Microsoft-Windows-VSSWindows 1113
WinEventLog:Microsoft-Windows-WLAN-AutoConfigWindows 1110
WinEventLog:Microsoft-Windows-Windows Camera Frame Server/OperationalWindows 1110
WinEventLog:WinRMWindows 1110
WinEventLog:iisWindows 1110
Windows Firewall LogWindows 1111
apache:access_logLinux 1110
auditd:AUTHLinux 1110
auditd:DAEMONLinux 1110
auditd:FSLinux 1110
auditd:file-eventsLinux 1110
auditd:memprotectLinux 1110
azure:adOffice Suite 1113
azure:vmguestIaaS 1110
azure:vpcflowIaaS 1110
cni:netflowContainers 1113
container:cniContainers 11119
container:proxyContainers 1110
containers:osqueryContainers 1110
desktop:file_managerLinux 1110
docker:apiContainers 1110
docker:registryContainers 1110
docker:runtimeContainers 2210
docker:statsContainers 1110
ebpf:tracepointsLinux 1110
esxi:vobESXi 1110
esxis:vmkernelESXi 11146
etw:Microsoft-Antimalware-Scan-InterfaceWindows 1110
etw:Microsoft-Windows-Directory-Services-SAMWindows 1110
etw:Microsoft-Windows-DotNETRuntimeWindows 1110
etw:Microsoft-Windows-Kernel-BaseWindows 1110
etw:Microsoft-Windows-Kernel-FileWindows 1110
etw:Microsoft-Windows-Kernel-StorageWindows 1110
etw:Microsoft-Windows-NDIS-PacketCaptureWindows 1110
etw:Microsoft-Windows-RPCWindows 1110
etw:Microsoft-Windows-Security-AuditingWindows 1110
firmware:integrity Windows 1110
firmware:runtimeNetwork Devices 1110
fs:filesystemmacOS 1110
fs:launchdaemonsmacOS 2110
fs:plistmacOS 1110
fs:plist_monitoringmacOS 1110
fs:quarantinemacOS 1110
fwupd:logsLinux 1110
gatekeeper/quarantine databasemacOS 1110
gcp:configIaaS 1110
gcp:iamIdentity Provider 1110
gcp:vpcflowIaaS 1112
journald:ApplicationLinux 1112
kubernetes:orchestratorContainers 1110
linus:syslogLinux 1110
linux:fimESXi 1110
linux:shellLinux 1110
linuxsyslogLinux 1115
m365:auditIdentity Provider 1110
m365:dirsyncWindows 1110
m365:mailboxauditOffice Suite 1110
m365:oauthOffice Suite 1110
m365:purviewOffice Suite, Windows 2211
m365:teamsOffice Suite 1110
macos:MDMmacOS 1110
macos:authmacOS 1111
macos:cronmacOS 1110
macos:fseventsmacOS 1110
macos:jamfmacOS 1110
macos:launchdmacOS 1110
network:authNetwork Devices 1110
networkdevice:FirewallNetwork Devices 3110
networkdevice:FlowNetwork Devices 1110
networkdevice:IDSNetwork Devices 1115
networkdevice:auditNetwork Devices 1110
networkdevice:controlplaneNetwork Devices 111157
prometheus:metricsContainers 11119
saas-app:authSaaS 1110
saas:PRMetadataSaaS 1110
saas:RepoEventsSaaS 1110
saas:SnowflakeSaaS 1110
saas:adminapiSaaS 1110
saas:apiSaaS 1110
saas:appsscriptSaaS 1110
saas:collaborationSaaS 1116
saas:emailOffice Suite 1110
saas:financeSaaS 1110
saas:integrationSaaS 1110
sar:networkLinux 1110
snmp:accessNetwork Devices 1110
snmp:statusNetwork Devices 1110
snmp:syslogNetwork Devices 11135
snmp:trapNetwork Devices 1111
systemd:unitContainers 1110
windows:osqueryWindows 1110
wineventlog:dhcpWindows 1110