Log sources › fs:fsevents
fs:fsevents
Inverted view: what can be detected if this is the log you have. macOS
7
channels
7
analytics
7
techniques
54
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Create in /Users/*/Downloads or /private/var/folders/* with quarantine attribute |
DC0039 File Creation | AN0180 | 1 |
Directory events (kFSEventStreamEventFlagItemCreated) |
DC0039 File Creation | AN1300 | 1 |
Extensions |
DC0061 File Modification | AN1063 | 1 |
create/write/rename under user-writable paths |
DC0061 File Modification | AN0799 | 1 |
file system events indicating access to system configuration files and environmental information sources |
DC0055 File Access | AN1307 | 1 |
file system events indicating permission or attribute changes |
DC0059 File Metadata | AN0836 | 1 |
file system events indicating permission, ownership, or extended attribute changes on critical paths. File system modification events with kFSEventStreamEventFlagItemChangeOwner, kFSEventStreamEventFlagItemXattrMod flags |
DC0061 File Modification | AN0999 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1014 Rootkit | stealth | 1 | 0 |
| T1080 Taint Shared Content | lateral movement | 0 | 0 |
| T1203 Exploitation for Client Execution | execution | 35 | 43 |
| T1204.001 Malicious Link | execution | 4 | 11 |
| T1222 File and Directory Permissions Modification | defense impairment | 2 | 1 |
| T1222.002 Linux and Mac Permissions | defense impairment | 4 | 0 |
| T1480.001 Environmental Keying | stealth | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2012-0767 | Adobe Flash Player | T1204.001 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1203 T1204.001 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1203 | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1204.001 | Mapped |
| CVE-2021-21148 | Google Chromium V8 | T1203 | Mapped |
| CVE-2021-21166 | Google Chromium | T1203 | Mapped |
| CVE-2021-21206 | Google Chromium Blink | T1203 | Mapped |
| CVE-2021-27059 | Microsoft Office | T1203 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1203 | Mapped |
| CVE-2021-30554 | Google Chromium WebGL | T1203 | Mapped |
| CVE-2021-37975 | Google Chromium V8 | T1203 | Mapped |
| CVE-2021-39144 | XStream XStream | T1203 | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-20703 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-21971 | Microsoft Windows | T1204.001 | Mapped |
| CVE-2022-22960 | VMware Multiple Products | T1222 | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | T1203 | Mapped |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) | T1204.001 | Mapped |
| CVE-2022-3038 | Google Chromium Network Service | T1204.001 | Mapped |
| CVE-2022-3075 | Google Chromium Mojo | T1204.001 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1203 | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1203 | Mapped |
| CVE-2023-2136 | Google Chromium Skia | T1204.001 | Mapped |
| CVE-2023-21608 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-23397 | Microsoft Office | T1203 | Mapped |
| CVE-2023-26369 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-34048 | VMware vCenter Server | T1203 | Mapped |
| CVE-2023-36844 | Juniper Junos OS | T1203 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1203 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1203 | Mapped |
| CVE-2023-5217 | Google Chromium libvpx | T1204.001 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1204.001 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1203 | Mapped |
| CVE-2024-26169 | Microsoft Windows | T1203 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1204.001 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1203 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1203 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1203 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1203 | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | T1203 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1203 | Mapped |
| CVE-2025-30397 | Microsoft Windows | T1203 | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | T1203 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-3248 | Langflow Langflow | T1203 | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | T1203 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1203 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1203 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1203 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1203 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | T1203 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1203 | Mapped |
| CVE-2025-6558 | Google Chromium | T1203 | Mapped |