kevmap

Log sources › linux:syslog

linux:syslog

Inverted view: what can be detected if this is the log you have. Linux, Network Devices

77
channels
81
analytics
80
techniques
138
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/var/log/syslog DC0029 Script Execution AN0174 AN0211 AN0735 3
Accepted publickey/password for * from * port * ssh2 DC0067 Logon Session Creation AN1345 1
Application or browser logs (webview errors, plugin enumerations) indicating suspicious script evaluation or plugin loads DC0038 Application Log Content AN0499 1
Authentication attempts into finance-related servers from unusual IPs or times DC0038 Application Log Content AN1362 1
Block device write errors or unusual bootloader activity DC0046 Drive Modification AN0429 1
CLI access to 'show running-config', 'show password', or 'cat config.txt' DC0064 Command Execution AN1159 1
DNS response IPs followed by connections to non-standard calculated ports DC0085 Network Traffic Content AN0729 1
Discrepancies in _VBA_PROJECT p-code vs source code extracted with oletools/pcodedmp DC0059 File Metadata AN0035 1
Driver load events or firmware load failures for hardware devices DC0079 Driver Load AN0917 1
Error/warning logs from services indicating load spike or worker exhaustion DC0038 Application Log Content AN1166 1
Execution of modified binaries or abnormal library load sequences DC0021 OS API Execution AN1098 1
Execution of non-standard script or binary by cron DC0001 Scheduled Job Creation AN0025 1
Failed password for invalid user DC0002 User Account Authentication AN1337 1
Inbound messages from webmail services containing attachments or URLs DC0038 Application Log Content AN0321 1
Integrity mismatch warnings or malformed packets detected DC0085 Network Traffic Content AN0703 1
Kernel or daemon warnings of downgraded TLS or cryptographic settings DC0034 Process Metadata AN0996 1
Module registration or stacktrace logs indicating segmentation faults or unknown module errors DC0038 Application Log Content AN1508 1
Multiple NXDOMAIN responses and high entropy domains DC0085 Network Traffic Content AN1179 1
New HID device enumeration with type 'keyboard' followed by immediate input injection DC0042 Drive Creation AN1568 1
New Wi-Fi connection established or repeated association failures DC0082 Network Connection Creation AN1477 1
Non-standard processes negotiating SSL/TLS key exchanges DC0038 Application Log Content AN1497 1
None DC0067 Logon Session Creation
DC0082 Network Connection Creation
DC0088 Logon Session Metadata
AN0505 AN1532 AN1638 3
Out of memory killer invoked or kernel panic entries DC0018 Host Status AN0585 1
Query to suspicious domain with high entropy or low reputation DC0085 Network Traffic Content AN0110 1
Repetitive HTTP 408, 500, or 503 errors logged within short timeframe DC0038 Application Log Content AN0490 1
SPF fail OR DKIM fail OR DMARC fail OR mismatched from_domain vs return_path_domain DC0038 Application Log Content AN1203 1
SSH failed login DC0002 User Account Authentication AN1263 1
Segfaults, kernel oops, or crashes in security software processes DC0038 Application Log Content AN1634 1
Service restart with modified executable path DC0041 Service Metadata AN0610 1
Service stop or disable messages for security tools not reflected in SIEM alerts DC0018 Host Status AN0869 1
Sudo or root escalation followed by filesystem mount commands DC0064 Command Execution AN1272 1
Suspicious script or command execution targeting browser folders DC0064 Command Execution AN0038 1
System daemons initiating encrypted sessions with unexpected destinations DC0038 Application Log Content AN0401 1
Unauthorized sudo or shell access, especially leading to file changes in /var/www or /srv/http DC0032 Process Creation AN0663 1
Unexpected SQL or application log entries showing tampered or malformed data DC0085 Network Traffic Content AN0163 1
Unexpected termination of daemons or critical services not aligned with admin change tickets DC0033 Process Termination AN0046 1
Unusual kinit or klist activity DC0084 Active Directory Credential Request AN1444 1
Unusual outbound transfers from CLI tools like base64, gzip, or netcat DC0064 Command Execution AN0303 1
application or system execution logs DC0059 File Metadata AN0812 1
auditd service stopped or disabled DC0041 Service Metadata AN0171 1
auth.log / secure.log DC0067 Logon Session Creation AN1081 1
auth.log or custom tool logs DC0055 File Access AN0293 1
authentication and authorization events during environmental validation phase DC0002 User Account Authentication AN1552 1
authentication success after file access DC0067 Logon Session Creation AN0857 1
boot logs DC0029 Script Execution AN0658 1
browser/office crash, segfault, abnormal termination DC0038 Application Log Content AN0798 1
cron activity DC0064 Command Execution AN0014 1
curl|wget|python .*http DC0085 Network Traffic Content AN0148 1
dmesg or syslog for module loads DC0079 Driver Load AN0688 1
iptables or nftables rule changes DC0051 Firewall Rule Modification AN0887 0
kernel messages related to cryptographic operations, module loading, and filesystem access patterns DC0055 File Access AN1306 1
kernel|systemd messages indicating 'segmentation fault'|'core dumped'|'service terminated unexpectedly' for sshd, smbd, vsftpd, mysqld, httpd, etc. DC0038 Application Log Content AN0328 1
kmod DC0016 Module Load AN1062 1
milter configuration updated, transport rule initialized, unexpected script execution DC0038 Application Log Content AN0473 1
mount/umount or file copy logs DC0054 Drive Access AN1146 1
network DC0082 Network Connection Creation AN1016 AN1584 2
opened document|clicked link|segfault|abnormal termination|sandbox DC0038 Application Log Content AN1315 1
postfix/smtpd DC0082 Network Connection Creation AN1310 1
processes binding to non-standard ports or sshd configured on unexpected port DC0038 Application Log Content AN0634 1
rename DC0061 File Modification AN0356 1
service stopped messages DC0041 Service Metadata AN0062 1
sshd logs DC0064 Command Execution AN1026 1
sshd sessions with unusual port forwarding parameters DC0038 Application Log Content AN1484 1
sshd: Accepted password/publickey DC0067 Logon Session Creation AN0751 1
sshd[pid]: Failed password DC0002 User Account Authentication AN1522 1
sssd / sudo logs DC0088 Logon Session Metadata AN0591 1
sudo chage|grep pam_pwquality|cat /etc/login.defs DC0064 Command Execution AN0456 1
sudo execution of ffmpeg/gst-launch/v4l2-ctl by non-standard user DC0064 Command Execution AN0569 1
sudo or service accounts invoking loaders with suspicious env vars DC0034 Process Metadata AN0053 1
sudo or su access prior to content change DC0010 User Account Modification AN0230 1
sudo/date/timedatectl execution by non-standard users DC0002 User Account Authentication AN0431 1
suspicious DHCP lease assignment with unexpected DNS or gateway DC0038 Application Log Content AN1291 1
syscalls (open, read, ioctl) on /dev/input or /proc/*/fd/* DC0035 Process Access AN0688 1
system daemons initiating TLS sessions outside expected services DC0038 Application Log Content AN0760 1
system is powering down DC0018 Host Status AN1539 1
systemctl start/enable with uncommon binary paths DC0060 Service Creation AN0779 1
usb * new|thunderbolt|pci .* added|block.*: new .* device DC0038 Application Log Content AN0186 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1011.001 Exfiltration Over Bluetoothexfiltration00
T1014 Rootkitstealth10
T1016.001 Internet Connection Discoverydiscovery00
T1018 Remote System Discoverydiscovery172
T1021 Remote Serviceslateral movement114
T1021.004 SSHlateral movement52
T1021.005 VNClateral movement10
T1036 Masqueradingstealth402
T1036.003 Rename Legitimate Utilitiesstealth270
T1036.006 Space after Filenamestealth10
T1037.004 RC Scriptspersistence, privilege escalation00
T1039 Data from Network Shared Drivecollection20
T1059.004 Unix Shellexecution1814
T1059.005 Visual Basicexecution290
T1059.006 Pythonexecution130
T1059.007 JavaScriptexecution2914
T1069.002 Domain Groupsdiscovery150
T1078.002 Domain Accountsstealth, persistence, privilege escalation, initial access70
T1110.001 Password Guessingcredential access30
T1110.002 Password Crackingcredential access10
T1110.003 Password Sprayingcredential access00
T1110.004 Credential Stuffingcredential access00
T1111 Multi-Factor Authentication Interceptioncredential access00
T1114 Email Collectioncollection43
T1124 System Time Discoverydiscovery30
T1125 Video Capturecollection10
T1129 Shared Modulesexecution20
T1132 Data Encodingcommand and control00
T1189 Drive-by Compromiseinitial access321
T1199 Trusted Relationshipinitial access21
T1200 Hardware Additionsinitial access30
T1201 Password Policy Discoverydiscovery60
T1203 Exploitation for Client Executionexecution3543
T1204 User Executionexecution102
T1210 Exploitation of Remote Serviceslateral movement154
T1211 Exploitation for Stealthstealth41
T1217 Browser Information Discoverydiscovery41
T1480 Execution Guardrailsstealth00
T1480.001 Environmental Keyingstealth00
T1489 Service Stopimpact201
T1491 Defacementimpact00
T1491.001 Internal Defacementimpact40
T1499 Endpoint Denial of Serviceimpact37
T1499.002 Service Exhaustion Floodimpact02
T1499.003 Application Exhaustion Floodimpact00
T1505 Server Software Componentpersistence12
T1505.002 Transport Agentpersistence30
T1529 System Shutdown/Rebootimpact80
T1534 Internal Spearphishinglateral movement00
T1542.002 Component Firmwarestealth, persistence00
T1542.003 Bootkitstealth, persistence10
T1546 Event Triggered Executionprivilege escalation, persistence100
T1552 Unsecured Credentialscredential access134
T1552.001 Credentials In Filescredential access243
T1557.003 DHCP Spoofingcredential access, collection10
T1558 Steal or Forge Kerberos Ticketscredential access63
T1564.005 Hidden File Systemstealth00
T1564.007 VBA Stompingstealth00
T1565 Data Manipulationimpact32
T1565.002 Transmitted Data Manipulationimpact20
T1565.003 Runtime Data Manipulationimpact00
T1566.003 Spearphishing via Serviceinitial access00
T1568 Dynamic Resolutioncommand and control20
T1568.002 Domain Generation Algorithmscommand and control20
T1568.003 DNS Calculationcommand and control00
T1569 System Servicesexecution40
T1571 Non-Standard Portcommand and control51
T1572 Protocol Tunnelingcommand and control240
T1573 Encrypted Channelcommand and control60
T1573.001 Symmetric Cryptographycommand and control03
T1573.002 Asymmetric Cryptographycommand and control00
T1574 Hijack Execution Flowstealth, execution816
T1657 Financial Theftimpact00
T1668 Exclusive Controlpersistence00
T1669 Wi-Fi Networksinitial access00
T1674 Input Injectionexecution00
T1684.002 Email Spoofingstealth00
T1685.003 Modify or Spoof Tool UIdefense impairment00
T1685.004 Disable or Modify Linux Audit System Logdefense impairment10
T1689 Downgrade Attackdefense impairment10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-0188Adobe Reader and Acrobat T1189 Mapped
CVE-2010-1297Adobe Flash Player T1189 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2013-3346Adobe Reader and Acrobat T1059.007 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 Mapped
CVE-2015-5119Adobe Flash Player T1059.007 T1203 Mapped
CVE-2015-8651Adobe Flash Player T1189 Mapped
CVE-2016-10033PHP PHPMailer T1059.004 Mapped
CVE-2016-1010Adobe Flash Player and AIR T1574 Mapped
CVE-2016-1019Adobe Flash Player T1189 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1574 Mapped
CVE-2018-4939Adobe ColdFusion T1203 Mapped
CVE-2018-4990Adobe Acrobat and Reader T1059.007 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1059.004 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1552.001 Mapped
CVE-2020-0688Microsoft Exchange Server T1114 Mapped
CVE-2020-1472Microsoft Netlogon T1021 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1217 Mapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1499 T1574 Mapped
CVE-2020-5902F5 BIG-IP T1552 Stale
CVE-2021-21148Google Chromium V8 T1059.007 T1203 Mapped
CVE-2021-21166Google Chromium T1059.007 T1203 Mapped
CVE-2021-21206Google Chromium Blink T1059.007 T1203 Mapped
CVE-2021-27059Microsoft Office T1203 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1203 Mapped
CVE-2021-30554Google Chromium WebGL T1059.007 T1203 Mapped
CVE-2021-31207Microsoft Exchange Server T1565 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1499 Mapped
CVE-2021-36380Sunhillo SureLine T1059.004 Mapped
CVE-2021-37975Google Chromium V8 T1059.007 T1203 Mapped
CVE-2021-39144XStream XStream T1203 Mapped
CVE-2021-40449Microsoft Windows T1573.001 Mapped
CVE-2021-40539Zoho ManageEngine T1573.001 Mapped
CVE-2021-41773Apache HTTP Server T1210 Mapped
CVE-2021-42013Apache HTTP Server T1210 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1573.001 Mapped
CVE-2021-45382D-Link Multiple Routers T1499.002 Mapped
CVE-2022-1040Sophos Firewall T1574 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-21999Microsoft Windows T1211 Mapped
CVE-2022-22963VMware Tanzu Spring Cloud T1059.007 Mapped
CVE-2022-23748Audinate Dante Discovery T1203 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1059.007 Mapped
CVE-2022-26138Atlassian Confluence T1552.001 Mapped
CVE-2022-26258D-Link DIR-820L T1499.002 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 Mapped
CVE-2022-29303SolarView Compact T1505 Mapped
CVE-2022-3038Google Chromium Network Service T1574 Mapped
CVE-2022-41073Microsoft Windows T1574 Mapped
CVE-2022-41128Microsoft Windows T1203 Mapped
CVE-2022-41328Fortinet FortiOS T1574 Mapped
CVE-2022-42475Fortinet FortiOS T1574 Mapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server T1203 Mapped
CVE-2023-0669Fortra GoAnywhere MFT T1210 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1499 Mapped
CVE-2023-21608Adobe Acrobat and Reader T1203 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1059.007 Mapped
CVE-2023-23397Microsoft Office T1203 Mapped
CVE-2023-26360Adobe ColdFusion T1059.007 Mapped
CVE-2023-26369Adobe Acrobat and Reader T1203 Mapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN T1574 Mapped
CVE-2023-28252Microsoft Windows T1021 Mapped
CVE-2023-34048VMware vCenter Server T1203 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1574 Mapped
CVE-2023-36844Juniper Junos OS T1203 Mapped
CVE-2023-36884Microsoft Windows T1489 Stale
CVE-2023-38035Ivanti Sentry T1018 T1571 Mapped
CVE-2023-38831RARLAB WinRAR T1059.004 T1204 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1021.004 T1059.004 Mapped
CVE-2023-43770Roundcube Webmail T1189 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1059.004 Mapped
CVE-2023-44487IETF HTTP/2 T1499 Mapped
CVE-2023-46604Apache ActiveMQ T1059.004 Mapped
CVE-2023-47565QNAP VioStor NVR T1203 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1552 Mapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway T1574 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1203 Mapped
CVE-2023-5217Google Chromium libvpx T1574 Mapped
CVE-2023-5631Roundcube Webmail T1059.007 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1499 T1574 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 T1574 Mapped
CVE-2024-11120GeoVision Multiple Devices T1203 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1558 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1558 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1558 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1552 Mapped
CVE-2024-21762Fortinet FortiOS T1574 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1552 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1059.004 Mapped
CVE-2024-26169Microsoft Windows T1203 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1059.004 T1114 Mapped
CVE-2024-38112Microsoft Windows T1189 Mapped
CVE-2024-42009Roundcube Webmail T1114 Mapped
CVE-2024-45195Apache OFBiz T1203 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-5274Google Chromium V8 T1189 T1203 Mapped
CVE-2024-53704SonicWall SonicOS T1199 Mapped
CVE-2024-54085AMI MegaRAC SPx T1210 T1499 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1021 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1552.001 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1018 Mapped
CVE-2025-24016Wazuh Wazuh Server T1203 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-24993Microsoft Windows T1203 T1204 T1565 Mapped
CVE-2025-25257Fortinet FortiWeb T1059.004 Mapped
CVE-2025-27038Qualcomm Multiple Chipsets T1203 Mapped
CVE-2025-27363FreeType FreeType T1574 Mapped
CVE-2025-2783Google Chromium Mojo T1203 Mapped
CVE-2025-30397Microsoft Windows T1203 Mapped
CVE-2025-30406Gladinet CentreStack T1203 Mapped
CVE-2025-31200Apple Multiple Products T1203 Stale
CVE-2025-31201Apple Multiple Products T1203 Stale
CVE-2025-32433Erlang Erlang/OTP T1021.004 Mapped
CVE-2025-3248Langflow Langflow T1203 Mapped
CVE-2025-34028Commvault Command Center T1059.007 Mapped
CVE-2025-3935ConnectWise ScreenConnect T1203 Mapped
CVE-2025-42599Qualitia Active! Mail T1499 Mapped
CVE-2025-42999SAP NetWeaver T1203 Mapped
CVE-2025-43200Apple Multiple Products T1203 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1203 Mapped
CVE-2025-49706Microsoft SharePoint T1505 Mapped
CVE-2025-5419Google Chromium V8 T1189 T1203 Mapped
CVE-2025-54309CrushFTP CrushFTP T1021 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1203 Mapped
CVE-2025-6554Google Chromium V8 T1189 T1203 Mapped
CVE-2025-6558Google Chromium T1189 T1203 Mapped