Log sources › auditd:FILE
auditd:FILE
Inverted view: what can be detected if this is the log you have. Linux
11
channels
11
analytics
11
techniques
3
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/home/*/.mozilla/firefox/*/logins.json OR /home/*/.config/google-chrome/*/Login Data |
DC0055 File Access | AN0106 | 1 |
/proc/*/mem read attempt |
DC0055 File Access | AN0157 | 1 |
Creation of hidden files (.*) in sensitive directories (/etc, /var, /usr/bin) |
DC0039 File Creation | AN1385 | 1 |
File creation with name starting with '.' |
DC0039 File Creation | AN0092 | 1 |
Modification of Display Manager configuration files (/etc/gdm3/*, /etc/lightdm/*) |
DC0061 File Modification | AN1002 | 1 |
Modification or deletion of /etc/audit/audit.rules or /etc/audit/audit.conf |
DC0061 File Modification | AN0171 | 1 |
create: Creation of .zip, .gz, .bz2 files in /tmp, /var/tmp, or /home directories |
DC0039 File Creation | AN0748 | 1 |
create: Creation of archive files in /tmp, /var/tmp, or user home directories |
DC0039 File Creation | AN0832 | 1 |
create: Creation of files ending in .tar, .gz, .bz2, .zip in /tmp or /var/tmp |
DC0039 File Creation | AN1459 | 1 |
create: Creation of files with anomalous headers and entropy levels in /tmp or user directories |
DC0039 File Creation | AN1214 | 1 |
create: New file created in system binaries or temp directories |
DC0039 File Creation | AN0517 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1555.002 Securityd Memory | credential access | 0 | 0 |
| T1555.003 Credentials from Web Browsers | credential access | 8 | 0 |
| T1560 Archive Collected Data | collection | 4 | 0 |
| T1560.001 Archive via Utility | collection | 17 | 2 |
| T1560.002 Archive via Library | collection | 0 | 0 |
| T1560.003 Archive via Custom Method | collection | 0 | 0 |
| T1564 Hide Artifacts | stealth | 10 | 0 |
| T1564.001 Hidden Files and Directories | stealth | 9 | 0 |
| T1564.002 Hidden Users | stealth | 4 | 0 |
| T1570 Lateral Tool Transfer | lateral movement | 6 | 1 |
| T1685.004 Disable or Modify Linux Audit System Log | defense impairment | 1 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2021-40539 | Zoho ManageEngine | T1560.001 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1560.001 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1570 | Mapped |