kevmap

Log sources › container:cni

container:cni

Inverted view: what can be detected if this is the log you have. Containers

1
channels
1
analytics
1
techniques
19
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Outbound network traffic to mining proxies DC0078 Network Traffic Flow AN0745 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1496 Resource Hijackingimpact1319

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1496 Mapped
CVE-2018-11776Apache Struts T1496 Mapped
CVE-2018-7600Drupal Drupal Core T1496 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1496 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1496 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1496 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1496 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1496 Mapped
CVE-2021-44228Apache Log4j2 T1496 Mapped
CVE-2022-29303SolarView Compact T1496 Mapped
CVE-2022-29464WSO2 Multiple Products T1496 Mapped
CVE-2023-1389TP-Link Archer AX21 T1496 Mapped
CVE-2023-22527Atlassian Confluence Data Center and Server T1496 Mapped
CVE-2023-32315Ignite Realtime Openfire T1496 Mapped
CVE-2023-38035Ivanti Sentry T1496 Mapped
CVE-2023-47565QNAP VioStor NVR T1496 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1496 Mapped
CVE-2024-23692Rejetto HTTP File Server T1496 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1496 Mapped