kevmap

Log sources › linux:Sysmon

linux:Sysmon

Inverted view: what can be detected if this is the log you have. Linux

5
channels
11
analytics
11
techniques
32
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
EventCode=1 DC0032 Process Creation AN0120 AN0620 AN0847 AN1562 AN1613 AN1631 6
EventCode=3, 22 DC0082 Network Connection Creation AN0238 AN1161 2
EventCode=7 DC0016 Module Load AN0473 1
New files in /tmp, /var/tmp, $HOME/.cache, executed within TimeWindow after browser HTTP fetch DC0039 File Creation AN0499 1
process creation events linked to container namespaces executing host-level binaries DC0032 Process Creation AN0613 1

Techniques detectable from this source

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-0188Adobe Reader and Acrobat T1189 Mapped
CVE-2010-1297Adobe Flash Player T1189 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 Mapped
CVE-2015-8651Adobe Flash Player T1189 Mapped
CVE-2016-1019Adobe Flash Player T1189 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2021-44515Zoho Desktop Central T1087 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1213 Mapped
CVE-2022-41082Microsoft Exchange Server T1087 Mapped
CVE-2023-27532Veeam Backup & Replication T1087 T1087.001 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1213 Mapped
CVE-2023-43770Roundcube Webmail T1189 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-38112Microsoft Windows T1189 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-5274Google Chromium V8 T1189 Mapped
CVE-2025-22224VMware ESXi and Workstation T1611 Mapped
CVE-2025-22225VMware ESXi T1611 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1611 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-5419Google Chromium V8 T1189 Mapped
CVE-2025-6554Google Chromium V8 T1189 Mapped
CVE-2025-6558Google Chromium T1189 Mapped