kevmap

Log sources › macos:syslog

macos:syslog

Inverted view: what can be detected if this is the log you have. macOS

4
channels
5
analytics
5
techniques
46
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/var/log/system.log DC0064 Command Execution AN0734 1
DYLD_INSERT_LIBRARIES anomalies DC0016 Module Load AN1401 1
system.log DC0064 Command Execution AN0173 AN0210 2
system.log, asl.log DC0029 Script Execution AN1082 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1055 Process Injectionstealth, privilege escalation3719
T1059.004 Unix Shellexecution1814
T1059.005 Visual Basicexecution290
T1059.006 Pythonexecution130
T1059.007 JavaScriptexecution2914

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2013-3346Adobe Reader and Acrobat T1059.007 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2015-5119Adobe Flash Player T1059.007 Mapped
CVE-2016-10033PHP PHPMailer T1059.004 Mapped
CVE-2018-4990Adobe Acrobat and Reader T1059.007 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1059.004 Mapped
CVE-2020-29574Sophos CyberoamOS T1055 Mapped
CVE-2021-21148Google Chromium V8 T1059.007 Mapped
CVE-2021-21166Google Chromium T1059.007 Mapped
CVE-2021-21206Google Chromium Blink T1059.007 Mapped
CVE-2021-30554Google Chromium WebGL T1059.007 Mapped
CVE-2021-36380Sunhillo SureLine T1059.004 Mapped
CVE-2021-37975Google Chromium V8 T1059.007 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-22963VMware Tanzu Spring Cloud T1059.007 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1059.007 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1059.007 Mapped
CVE-2023-26360Adobe ColdFusion T1059.007 Mapped
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) T1055 Mapped
CVE-2023-38831RARLAB WinRAR T1059.004 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1059.004 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1059.004 Mapped
CVE-2023-46604Apache ActiveMQ T1059.004 Mapped
CVE-2023-5631Roundcube Webmail T1059.007 Mapped
CVE-2023-6548Citrix NetScaler ADC and NetScaler Gateway T1055 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1059.004 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1059.004 Mapped
CVE-2024-40890Zyxel DSL CPE Devices T1055 Mapped
CVE-2024-40891Zyxel DSL CPE Devices T1055 Mapped
CVE-2024-50603Aviatrix Controllers T1055 Mapped
CVE-2024-56145Craft CMS Craft CMS T1055 Mapped
CVE-2024-58136Yiiframework Yii T1055 Mapped
CVE-2024-6047GeoVision Multiple Devices T1055 Mapped
CVE-2025-0108Palo Alto Networks PAN-OS T1055 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1055 Mapped
CVE-2025-1316Edimax IC-7100 IP Camera T1055 Mapped
CVE-2025-21418Microsoft Windows T1055 Mapped
CVE-2025-21480Qualcomm Multiple Chipsets T1055 Mapped
CVE-2025-22224VMware ESXi and Workstation T1055 Mapped
CVE-2025-24993Microsoft Windows T1055 Mapped
CVE-2025-25181Advantive VeraCore T1055 Mapped
CVE-2025-25257Fortinet FortiWeb T1055 T1059.004 Mapped
CVE-2025-31324SAP NetWeaver T1055 Mapped
CVE-2025-34028Commvault Command Center T1059.007 Mapped