Log sources › linux:osquery
linux:osquery
Inverted view: what can be detected if this is the log you have. Linux
38
channels
48
analytics
47
techniques
42
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/proc/*/maps access |
DC0055 File Access | AN1494 | 1 |
Detection of bitwise operations or custom encryption functions in memory traces |
DC0020 Process Modification | AN1214 | 1 |
Execution of binary resolved from $PATH not located in /usr/bin or /bin |
DC0032 Process Creation | AN0010 | 1 |
Filesystem modifications to trusted paths |
DC0059 File Metadata | AN0984 | 1 |
Listing of /etc/passwd and /etc/shadow metadata |
DC0013 User Account Metadata | AN1078 | 1 |
New or modified kernel object files (.ko) within /lib/modules directory |
DC0061 File Modification | AN1243 | 1 |
None |
DC0055 File Access | AN1532 | 1 |
Process State |
DC0035 Process Access | AN0096 | 1 |
Process execution with LD_PRELOAD or modified library path |
DC0032 Process Creation | AN0610 | 1 |
Process linked with libcrypto.so making external connections |
DC0016 Module Load | AN0401 | 1 |
Processes linked with libssl or crypto libraries making outbound connections |
DC0032 Process Creation | AN0760 | 1 |
Processes linked with libssl/libcrypto performing network activity |
DC0016 Module Load | AN1497 | 1 |
Read headers and detect MIME type mismatch |
DC0059 File Metadata | AN0631 | 1 |
Write or modify .desktop file in XDG autostart path |
DC0059 File Metadata | AN1096 | 1 |
child process invoking dynamic linker post-ptrace |
DC0032 Process Creation | AN1241 | 1 |
crontab, systemd_timers |
DC0001 Scheduled Job Creation | AN0259 | 1 |
elf_info, hash, yara_matches |
DC0059 File Metadata | AN0600 | 1 |
event-based |
DC0059 File Metadata | AN0014 AN1463 | 2 |
execution of known firewall binaries |
DC0032 Process Creation | AN0407 | 1 |
family=AF_PACKET or protocol raw; process name not in allowlist. |
DC0082 Network Connection Creation | AN0463 | 1 |
file_events |
DC0001 Scheduled Job Creation DC0039 File Creation DC0059 File Metadata DC0061 File Modification |
AN0312 AN0356 AN0541 AN0645 AN0873 AN1062 AN1529 AN1627 | 8 |
file_events.path |
DC0059 File Metadata | AN0974 | 1 |
hardware_events |
DC0054 Drive Access | AN1354 | 1 |
hash, elf_info, file_metadata |
DC0059 File Metadata | AN0056 | 1 |
newly registered unit file with ExecStart pointing to unknown binary |
DC0060 Service Creation | AN0701 | 1 |
process environment variables containing LD_PRELOAD |
DC0034 Process Metadata | AN1209 | 1 |
process execution events for permission modification utilities with command-line analysis |
DC0032 Process Creation | AN0998 | 1 |
process listening or connecting on non-standard ports |
DC0032 Process Creation | AN0634 | 1 |
process metadata mismatch between /proc and runtime attributes |
DC0034 Process Metadata | AN1196 | 1 |
process_events |
DC0032 Process Creation DC0035 Process Access |
AN1306 AN1310 AN1418 | 3 |
process_events.command_line |
DC0064 Command Execution | AN1395 | 1 |
processes modifying environment variables related to history logging |
DC0032 Process Creation | AN1555 | 1 |
scheduled/real-time |
DC0041 Service Metadata | AN0325 | 1 |
select: path LIKE '/dev/video%' |
DC0034 Process Metadata | AN0569 | 1 |
socat, ssh, or nc processes opening unexpected ports |
DC0032 Process Creation | AN1484 | 1 |
socket_events |
DC0078 Network Traffic Flow | AN1081 | 1 |
state=attached/debugged |
DC0034 Process Metadata | AN0579 | 1 |
unexpected termination of syslog or rsyslog processes |
DC0033 Process Termination | AN0668 | 0 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2016-10033 | PHP PHPMailer | T1059.004 | Mapped |
| CVE-2016-1010 | Adobe Flash Player and AIR | T1574 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1574 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1059.004 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1114 | Mapped |
| CVE-2020-5735 | Amcrest Cameras and Network Video Recorder (NVR) | T1574 | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | T1059.004 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1573.001 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1573.001 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1573.001 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1574 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-3038 | Google Chromium Network Service | T1574 | Mapped |
| CVE-2022-41073 | Microsoft Windows | T1574 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1037 T1574 | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | T1574 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1036.005 | Mapped |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | T1574 | Mapped |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | T1574 | Mapped |
| CVE-2023-38035 | Ivanti Sentry | T1571 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1053 T1059.004 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1059.004 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1059.004 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | T1059.004 | Mapped |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | T1574 | Mapped |
| CVE-2023-5217 | Google Chromium libvpx | T1574 | Mapped |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway | T1574 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1574 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-21762 | Fortinet FortiOS | T1574 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1059.004 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1059.004 T1114 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1114 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1053 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1059.004 | Mapped |
| CVE-2025-27363 | FreeType FreeType | T1574 | Mapped |