Log sources › linux:procfs
linux:procfs
Inverted view: what can be detected if this is the log you have. Linux
2
channels
2
analytics
2
techniques
38
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/proc/[pid]/maps, /proc/[pid]/mem |
DC0020 Process Modification | AN1400 | 1 |
Sustained high /proc/[pid]/stat usage |
DC0018 Host Status | AN0742 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1055 Process Injection | stealth, privilege escalation | 37 | 19 |
| T1496 Resource Hijacking | impact | 13 | 19 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1496 | Mapped |
| CVE-2018-11776 | Apache Struts | T1496 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1496 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1496 | Mapped |
| CVE-2020-29574 | Sophos CyberoamOS | T1055 | Mapped |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1496 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1496 | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | T1496 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1496 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1496 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1496 | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | T1496 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1496 | Mapped |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | T1496 | Mapped |
| CVE-2023-32315 | Ignite Realtime Openfire | T1496 | Mapped |
| CVE-2023-34192 | Synacor Zimbra Collaboration Suite (ZCS) | T1055 | Mapped |
| CVE-2023-38035 | Ivanti Sentry | T1496 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1496 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1496 | Mapped |
| CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway | T1055 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1496 | Mapped |
| CVE-2024-40890 | Zyxel DSL CPE Devices | T1055 | Mapped |
| CVE-2024-40891 | Zyxel DSL CPE Devices | T1055 | Mapped |
| CVE-2024-50603 | Aviatrix Controllers | T1055 | Mapped |
| CVE-2024-56145 | Craft CMS Craft CMS | T1055 | Mapped |
| CVE-2024-58136 | Yiiframework Yii | T1055 | Mapped |
| CVE-2024-6047 | GeoVision Multiple Devices | T1055 | Mapped |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | T1055 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1055 | Mapped |
| CVE-2025-1316 | Edimax IC-7100 IP Camera | T1055 | Mapped |
| CVE-2025-21418 | Microsoft Windows | T1055 | Mapped |
| CVE-2025-21480 | Qualcomm Multiple Chipsets | T1055 | Mapped |
| CVE-2025-22224 | VMware ESXi and Workstation | T1055 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1055 | Mapped |
| CVE-2025-25181 | Advantive VeraCore | T1055 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1055 | Mapped |
| CVE-2025-31324 | SAP NetWeaver | T1055 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1496 | Mapped |