kevmap

Log sources › docker:daemon

docker:daemon

Inverted view: what can be detected if this is the log you have. Containers

8
channels
8
analytics
8
techniques
6
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
ExecCreate + usermod or useradd DC0014 User Account Creation AN1080 1
container create/start with privileged flag or host volume mount DC0072 Container Creation AN0612 1
container file operations DC0040 File Deletion AN0523 1
container_create,container_start DC0038 Application Log Content AN0693 1
docker build or POST /build API request DC0015 Image Creation AN1261 1
docker build or docker commit commands followed by docker push to internal registry DC0015 Image Creation AN0946 1
docker exec or docker run with unexpected command/entrypoint DC0064 Command Execution AN0177 1
docker ps, docker inspect, or docker images commands DC0091 Container Enumeration AN1352 1

Techniques detectable from this source

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-45382D-Link Multiple Routers T1070 Mapped
CVE-2022-41128Microsoft Windows T1070 Mapped
CVE-2023-1389TP-Link Archer AX21 T1070 Mapped
CVE-2025-22224VMware ESXi and Workstation T1611 Mapped
CVE-2025-22225VMware ESXi T1611 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1611 Mapped