Log sources › auditd:PATH
auditd:PATH
Inverted view: what can be detected if this is the log you have. Linux
14
channels
16
analytics
16
techniques
12
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/etc/passwd or /etc/group file write |
DC0061 File Modification | AN0266 | 1 |
Creation of files with extensions .sql, .csv, .sqlite, especially in user directories |
DC0039 File Creation | AN0676 | 1 |
New .py/.js/.sh files written to ~/.local/, ~/.cache/, or /tmp/ within 5 min of package install |
DC0039 File Creation | AN0698 | 1 |
PATH |
DC0055 File Access DC0059 File Metadata |
AN0312 AN0847 AN1041 | 3 |
Read access to known backup software configuration files (e.g., /etc/rsnapshot.conf, /opt/veeam/config.ini) |
DC0055 File Access | AN0241 | 1 |
WRITE: Drop of binaries/scripts in ~/.local, /tmp, or /opt tool dirs |
DC0039 File Creation | AN1367 | 1 |
creation of .so files in non-standard directories (e.g., /tmp, /home/*) |
DC0039 File Creation | AN1209 | 1 |
file path matches exclusion directories |
DC0059 File Metadata | AN0140 | 1 |
file read |
DC0055 File Access | AN1281 | 1 |
mount target path within /proc/* |
DC0039 File Creation | AN1196 | 1 |
odification of ~/.ssh/authorized_keys or credential files |
DC0061 File Modification | AN2037 | 1 |
open: Access to sensitive log files (/var/log/auth.log, /var/log/secure, /var/log/syslog) |
DC0055 File Access | AN0706 | 1 |
write or create events on *.pth, sitecustomize.py, usercustomize.py in site-packages or dist-packages |
DC0061 File Modification | AN0713 | 1 |
write: File modifications to /etc/systemd/sleep.conf or related power configuration files |
DC0061 File Modification | AN1175 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1016.002 Wi-Fi Discovery | discovery | 0 | 0 |
| T1037 Boot or Logon Initialization Scripts | persistence, privilege escalation | 0 | 3 |
| T1083 File and Directory Discovery | discovery | 24 | 5 |
| T1087.001 Local Account | discovery | 13 | 1 |
| T1098 Account Manipulation | persistence, privilege escalation | 34 | 2 |
| T1204.005 Malicious Library | execution | 0 | 0 |
| T1213.006 Databases | collection | 0 | 0 |
| T1219 Remote Access Tools | command and control | 6 | 1 |
| T1518.002 Backup Software Discovery | discovery | 0 | 0 |
| T1546.018 Python Startup Hooks | persistence, privilege escalation | 0 | 0 |
| T1564.012 File/Path Exclusions | stealth | 0 | 0 |
| T1564.013 Bind Mounts | stealth | 0 | 0 |
| T1574.006 Dynamic Linker Hijacking | stealth, execution | 2 | 0 |
| T1653 Power Settings | persistence | 1 | 1 |
| T1654 Log Enumeration | discovery | 0 | 0 |
| T1684 Social Engineering | stealth | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2012-0767 | Adobe Flash Player | T1098 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1083 | Mapped |
| CVE-2018-4878 | Adobe Flash Player | T1219 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1083 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1083 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1098 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1037 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1083 | Stale |
| CVE-2023-27532 | Veeam Backup & Replication | T1087.001 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 T1653 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1083 | Mapped |