kevmap

Log sources › fs:fsevents

fs:fsevents

Inverted view: what can be detected if this is the log you have. macOS

7
channels
7
analytics
7
techniques
54
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Create in /Users/*/Downloads or /private/var/folders/* with quarantine attribute DC0039 File Creation AN0180 1
Directory events (kFSEventStreamEventFlagItemCreated) DC0039 File Creation AN1300 1
Extensions DC0061 File Modification AN1063 1
create/write/rename under user-writable paths DC0061 File Modification AN0799 1
file system events indicating access to system configuration files and environmental information sources DC0055 File Access AN1307 1
file system events indicating permission or attribute changes DC0059 File Metadata AN0836 1
file system events indicating permission, ownership, or extended attribute changes on critical paths. File system modification events with kFSEventStreamEventFlagItemChangeOwner, kFSEventStreamEventFlagItemXattrMod flags DC0061 File Modification AN0999 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1014 Rootkitstealth10
T1080 Taint Shared Contentlateral movement00
T1203 Exploitation for Client Executionexecution3543
T1204.001 Malicious Linkexecution411
T1222 File and Directory Permissions Modificationdefense impairment21
T1222.002 Linux and Mac Permissionsdefense impairment40
T1480.001 Environmental Keyingstealth00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2012-0767Adobe Flash Player T1204.001 Mapped
CVE-2015-5119Adobe Flash Player T1203 T1204.001 Mapped
CVE-2018-4939Adobe ColdFusion T1203 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1204.001 Mapped
CVE-2021-21148Google Chromium V8 T1203 Mapped
CVE-2021-21166Google Chromium T1203 Mapped
CVE-2021-21206Google Chromium Blink T1203 Mapped
CVE-2021-27059Microsoft Office T1203 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1203 Mapped
CVE-2021-30554Google Chromium WebGL T1203 Mapped
CVE-2021-37975Google Chromium V8 T1203 Mapped
CVE-2021-39144XStream XStream T1203 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-21971Microsoft Windows T1204.001 Mapped
CVE-2022-22960VMware Multiple Products T1222 Mapped
CVE-2022-23748Audinate Dante Discovery T1203 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1204.001 Mapped
CVE-2022-3038Google Chromium Network Service T1204.001 Mapped
CVE-2022-3075Google Chromium Mojo T1204.001 Mapped
CVE-2022-41128Microsoft Windows T1203 Mapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server T1203 Mapped
CVE-2023-2136Google Chromium Skia T1204.001 Mapped
CVE-2023-21608Adobe Acrobat and Reader T1203 Mapped
CVE-2023-23397Microsoft Office T1203 Mapped
CVE-2023-26369Adobe Acrobat and Reader T1203 Mapped
CVE-2023-34048VMware vCenter Server T1203 Mapped
CVE-2023-36844Juniper Junos OS T1203 Mapped
CVE-2023-47565QNAP VioStor NVR T1203 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1203 Mapped
CVE-2023-5217Google Chromium libvpx T1204.001 Mapped
CVE-2023-5631Roundcube Webmail T1204.001 Mapped
CVE-2024-11120GeoVision Multiple Devices T1203 Mapped
CVE-2024-26169Microsoft Windows T1203 Mapped
CVE-2024-38112Microsoft Windows T1204.001 Mapped
CVE-2024-45195Apache OFBiz T1203 Mapped
CVE-2024-5274Google Chromium V8 T1203 Mapped
CVE-2025-24016Wazuh Wazuh Server T1203 Mapped
CVE-2025-24993Microsoft Windows T1203 Mapped
CVE-2025-27038Qualcomm Multiple Chipsets T1203 Mapped
CVE-2025-2783Google Chromium Mojo T1203 Mapped
CVE-2025-30397Microsoft Windows T1203 Mapped
CVE-2025-30406Gladinet CentreStack T1203 Mapped
CVE-2025-31200Apple Multiple Products T1203 Stale
CVE-2025-31201Apple Multiple Products T1203 Stale
CVE-2025-3248Langflow Langflow T1203 Mapped
CVE-2025-3935ConnectWise ScreenConnect T1203 Mapped
CVE-2025-42999SAP NetWeaver T1203 Mapped
CVE-2025-43200Apple Multiple Products T1203 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1203 Mapped
CVE-2025-5419Google Chromium V8 T1203 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1203 Mapped
CVE-2025-6554Google Chromium V8 T1203 Mapped
CVE-2025-6558Google Chromium T1203 Mapped