kevmap

Log sources › containerd:runtime

containerd:runtime

Inverted view: what can be detected if this is the log you have. Containers

5
channels
5
analytics
5
techniques
79
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/var/log/containers/*.log DC0032 Process Creation AN0358 1
CRI CreateContainer/StartContainer with privileged=true OR added capabilities OR host* namespaces DC0077 Container Start AN0693 1
container-level outbound traffic events DC0078 Network Traffic Flow AN1060 1
e.g., containerd, Docker events DC0091 Container Enumeration AN1422 1
file change monitoring within /etc/cron.*, /tmp, or mounted volumes DC0061 File Modification AN0261 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1036 Masqueradingstealth402
T1046 Network Service Discoverydiscovery207
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1068 Exploitation for Privilege Escalationprivilege escalation3169
T1610 Deploy Containerexecution00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2014-0546Adobe Reader and Acrobat T1068 Mapped
CVE-2019-0211Apache HTTP Server T1068 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1046 Mapped
CVE-2019-13608Citrix StoreFront Server T1046 Mapped
CVE-2020-0069MediaTek Multiple Chipsets T1068 Mapped
CVE-2020-0787Microsoft Windows T1068 Mapped
CVE-2020-1472Microsoft Netlogon T1068 Mapped
CVE-2021-21973VMware vCenter Server and Cloud Foundation T1046 Mapped
CVE-2021-22900Ivanti Pulse Connect Secure T1068 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1068 Mapped
CVE-2021-32030ASUS Routers T1068 Mapped
CVE-2021-33739Microsoft Windows T1068 Mapped
CVE-2021-36934Microsoft Windows T1068 Mapped
CVE-2021-4034Red Hat Polkit T1068 Mapped
CVE-2021-40449Microsoft Windows T1068 Mapped
CVE-2021-41379Microsoft Windows T1068 Mapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1068 Mapped
CVE-2022-21919Microsoft Windows T1068 Mapped
CVE-2022-21999Microsoft Windows T1068 Mapped
CVE-2022-22047Microsoft Windows T1068 Mapped
CVE-2022-22718Microsoft Windows T1068 Mapped
CVE-2022-22948VMware vCenter Server T1068 Mapped
CVE-2022-24521Microsoft Windows T1068 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 Mapped
CVE-2022-26904Microsoft Windows T1068 Mapped
CVE-2022-37969Microsoft Windows T1068 Mapped
CVE-2022-41033Microsoft Windows COM+ Event System Service T1068 Mapped
CVE-2022-41073Microsoft Windows T1068 Mapped
CVE-2022-41125Microsoft Windows T1068 Mapped
CVE-2022-47966Zoho ManageEngine T1068 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1068 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1068 Mapped
CVE-2023-21674Microsoft Windows T1068 Mapped
CVE-2023-26360Adobe ColdFusion T1046 Mapped
CVE-2023-28229Microsoft Windows CNG Key Isolation Service T1068 Mapped
CVE-2023-28252Microsoft Windows T1068 Mapped
CVE-2023-33538TP-Link Multiple Routers T1068 Mapped
CVE-2023-38035Ivanti Sentry T1046 Mapped
CVE-2023-38831RARLAB WinRAR T1053 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1068 Mapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) T1068 Mapped
CVE-2024-12987DrayTek Vigor Routers T1068 Mapped
CVE-2024-29059Microsoft .NET Framework T1068 Mapped
CVE-2024-30051Microsoft DWM Core Library T1068 Mapped
CVE-2024-37085VMware ESXi T1068 Mapped
CVE-2024-38080Microsoft Windows T1068 Mapped
CVE-2024-41710Mitel SIP Phones T1068 Mapped
CVE-2024-41713Mitel MiCollab T1068 Mapped
CVE-2024-4577PHP Group PHP T1053 T1068 Mapped
CVE-2024-4885Progress WhatsUp Gold T1068 Mapped
CVE-2024-49035Microsoft Partner Center T1068 Mapped
CVE-2024-53104Linux Kernel T1068 Mapped
CVE-2024-53197Linux Kernel T1068 Mapped
CVE-2024-54085AMI MegaRAC SPx T1068 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1068 Mapped
CVE-2025-0111Palo Alto Networks PAN-OS T1068 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1046 Mapped
CVE-2025-0994Trimble Cityworks T1068 Mapped
CVE-2025-1976Broadcom Brocade Fabric OS T1068 Mapped
CVE-2025-21333Microsoft Windows T1068 Mapped
CVE-2025-21334Microsoft Windows T1068 Mapped
CVE-2025-21335Microsoft Windows T1068 Mapped
CVE-2025-21391Microsoft Windows T1068 Mapped
CVE-2025-21418Microsoft Windows T1068 Mapped
CVE-2025-21590Juniper Junos OS T1068 Mapped
CVE-2025-22225VMware ESXi T1068 Mapped
CVE-2025-24085Apple Multiple Products T1068 Mapped
CVE-2025-24993Microsoft Windows T1068 Mapped
CVE-2025-25181Advantive VeraCore T1068 Mapped
CVE-2025-25257Fortinet FortiWeb T1068 Mapped
CVE-2025-30400Microsoft Windows T1068 Mapped
CVE-2025-32701Microsoft Windows T1068 Mapped
CVE-2025-32706Microsoft Windows T1068 Mapped
CVE-2025-32709Microsoft Windows T1068 Mapped
CVE-2025-32756Fortinet Multiple Products T1046 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1068 Mapped
CVE-2025-47812Wing FTP Server Wing FTP Server T1068 Mapped
CVE-2025-54309CrushFTP CrushFTP T1068 Mapped