kevmap

Log sources › linux:cli

linux:cli

Inverted view: what can be detected if this is the log you have. Linux

5
channels
5
analytics
5
techniques
9
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/home/*/.bash_history DC0064 Command Execution AN1592 1
Shell history logs DC0064 Command Execution AN1065 1
Terminal Command History DC0064 Command Execution AN1441 1
cleared or truncated .bash_history DC0038 Application Log Content AN0521 1
command logging DC0064 Command Execution AN0904 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1027 Obfuscated Files or Informationstealth945
T1049 System Network Connections Discoverydiscovery91
T1056.002 GUI Input Capturecollection, credential access30
T1070 Indicator Removalstealth203
T1114.003 Email Forwarding Rulecollection60

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-2883Adobe Acrobat and Reader T1027 Mapped
CVE-2021-40449Microsoft Windows T1027 Mapped
CVE-2021-40539Zoho ManageEngine T1027 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1027 Mapped
CVE-2021-45382D-Link Multiple Routers T1070 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1027 Mapped
CVE-2022-41128Microsoft Windows T1070 Mapped
CVE-2022-41328Fortinet FortiOS T1049 Mapped
CVE-2023-1389TP-Link Archer AX21 T1070 Mapped