kevmap

Log sources › AWS:CloudWatch

AWS:CloudWatch

Inverted view: what can be detected if this is the log you have. IaaS

9
channels
9
analytics
9
techniques
30
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Elevated 5xx response rates in application logs or gateway layer DC0038 Application Log Content AN1168 1
NetworkOut spike beyond baseline DC0018 Host Status AN0972 1
Repeated crash pattern within container or instance logs DC0038 Application Log Content AN0853 1
StatusCheckFailed or StatusCheckFailed_System for burstable instances (t2/t3) DC0018 Host Status AN0587 1
Sudden spike in network output without a corresponding inbound request ratio DC0018 Host Status AN1143 1
Sustained EC2 CPU usage above normal baseline DC0018 Host Status AN0744 1
Sustained spike in CPU usage on EC2 instance with web service role DC0018 Host Status AN0492 1
Unusual CPU burst or metric anomalies DC0018 Host Status AN1493 1
unexpected IAM user or role assuming privileges for instance/snapshot operations DC0070 Cloud Service Metadata AN0861 1

Techniques detectable from this source

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2015-3043Adobe Flash Player T1499.004 Mapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1496 Mapped
CVE-2018-11776Apache Struts T1496 Mapped
CVE-2018-7600Drupal Drupal Core T1496 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1496 Mapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1499 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1496 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1496 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1496 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1496 T1499 Mapped
CVE-2021-44228Apache Log4j2 T1496 Mapped
CVE-2021-45382D-Link Multiple Routers T1499.002 Mapped
CVE-2022-26258D-Link DIR-820L T1499.002 Mapped
CVE-2022-29303SolarView Compact T1496 Mapped
CVE-2022-29464WSO2 Multiple Products T1496 Mapped
CVE-2023-1389TP-Link Archer AX21 T1496 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1499 Mapped
CVE-2023-22527Atlassian Confluence Data Center and Server T1496 Mapped
CVE-2023-32315Ignite Realtime Openfire T1496 Mapped
CVE-2023-38035Ivanti Sentry T1496 Mapped
CVE-2023-44487IETF HTTP/2 T1499 Mapped
CVE-2023-47565QNAP VioStor NVR T1496 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1496 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1499 Mapped
CVE-2024-23692Rejetto HTTP File Server T1496 Mapped
CVE-2024-45195Apache OFBiz T1498.001 Mapped
CVE-2024-54085AMI MegaRAC SPx T1499 Mapped
CVE-2025-27363FreeType FreeType T1499.004 Mapped
CVE-2025-42599Qualitia Active! Mail T1499 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1496 Mapped