kevmap

Log sources › auditd:USER_LOGIN

auditd:USER_LOGIN

Inverted view: what can be detected if this is the log you have. Linux

2
channels
3
analytics
3
techniques
3
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
USER_AUTH DC0002 User Account Authentication AN1276 1
USER_LOGIN DC0088 Logon Session Metadata AN1138 AN1284 2

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1078.001 Default Accountsstealth, persistence, privilege escalation, initial access40
T1078.003 Local Accountsstealth, persistence, privilege escalation, initial access51
T1110 Brute Forcecredential access252

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2020-0688Microsoft Exchange Server T1110 Mapped
CVE-2020-1472Microsoft Netlogon T1110 Mapped
CVE-2021-44168Fortinet FortiOS T1078.003 Mapped