Log sources › Internet Scan
Internet Scan
Inverted view: what can be detected if this is the log you have. PRE
1
channels
27
analytics
27
techniques
14
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
None |
DC0104 Response Content DC0106 Response Metadata |
AN1952 AN1956 AN1957 AN1958 AN1961 AN1966 AN1968 AN1970 AN1971 AN1972 AN1976 AN1980 AN1982 AN1985 AN1986 AN1991 AN1996 AN2003 AN2006 AN2013 AN2014 AN2017 AN2019 AN2020 AN2025 AN2027 AN2028 | 27 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2013-0631 | Adobe ColdFusion | T1592 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1592 | Mapped |
| CVE-2019-0604 | Microsoft SharePoint | T1608.001 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1608.001 | Mapped |
| CVE-2023-33246 | Apache RocketMQ | T1608.001 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1588 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1608.001 | Mapped |
| CVE-2024-37085 | VMware ESXi | T1608.001 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1608.001 | Mapped |
| CVE-2025-32701 | Microsoft Windows | T1608.001 | Mapped |
| CVE-2025-32706 | Microsoft Windows | T1608.001 | Mapped |
| CVE-2025-32709 | Microsoft Windows | T1608.001 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1608.001 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1608.001 | Mapped |