kevmap

Log sources › auditd:CONFIG_CHANGE

auditd:CONFIG_CHANGE

Inverted view: what can be detected if this is the log you have. Linux

6
channels
6
analytics
6
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/etc/fstab, /etc/systemd/* DC0040 File Deletion AN0934 1
/var/log/audit/audit.log DC0012 Scheduled Job Modification AN0325 1
chmod or chown of hook files indicating privilege escalation or execution permission change DC0059 File Metadata AN0713 1
creation or modification of systemd services DC0060 Service Creation AN0200 1
delete: Modification of systemd unit files or config for security agents DC0041 Service Metadata AN1370 1
udev rule reload or trigger command executed DC0064 Command Execution AN1056 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1036.004 Masquerade Task or Servicestealth30
T1490 Inhibit System Recoveryimpact272
T1546.017 Udev Rulespersistence, privilege escalation00
T1546.018 Python Startup Hookspersistence, privilege escalation00
T1569.003 Systemctlexecution00
T1685 Disable or Modify Toolsdefense impairment1640

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2023-36884Microsoft Windows T1490 Stale
CVE-2025-21391Microsoft Windows T1490 Mapped