Log sources › networkdevice:syslog
networkdevice:syslog
Inverted view: what can be detected if this is the log you have. Linux, Network Devices
53
channels
47
analytics
46
techniques
200
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
AAA or TACACS authentication failures |
DC0002 User Account Authentication | AN1340 | 1 |
AAA, RADIUS, or TACACS authentication |
DC0002 User Account Authentication | AN1267 | 1 |
ACL/Firewall rule modification or new route injection |
DC0085 Network Traffic Content | AN0015 | 1 |
Admin activity |
DC0034 Process Metadata | AN0099 | 1 |
Authentication failures or unusual community string usage in SNMP queries |
DC0085 Network Traffic Content | AN1630 | 1 |
Authentication failures, unexpected community string usage, or unauthorized SNMPv1/v2 requests |
DC0085 Network Traffic Content | AN1249 | 1 |
Boot information log showing image loaded from TFTP server instead of local storage |
DC0004 Firmware Modification | AN1603 | 1 |
CLI Command Audit |
DC0064 Command Execution | AN1084 | 1 |
CLI Command Logging |
DC0064 Command Execution | AN1044 | 1 |
CLI command audit |
DC0064 Command Execution | AN0471 | 1 |
Command Audit / Configuration Change |
DC0064 Command Execution | AN0136 | 1 |
Config change: CLI/NETCONF/SNMP – 'monitor session', 'mirror port' |
DC0078 Network Traffic Flow | AN1132 | 1 |
Config/ACL changes, line vty transport input changes, telnet/ssh/http(s) enable, image/feature module changes. |
DC0078 Network Traffic Flow | AN0845 | 1 |
Config/ACL/line vty changes, service enable (telnet/ssh/http(s)), module reloads |
DC0078 Network Traffic Flow | AN1451 | 1 |
Custom firmware or routing changes |
DC0004 Firmware Modification | AN1024 | 1 |
Detected CLI command to export key material |
DC0064 Command Execution | AN1519 | 1 |
Dynamic route changes |
DC0082 Network Connection Creation | AN0926 | 1 |
Failed and successful logins to network devices outside approved admin IP ranges |
DC0002 User Account Authentication | AN0647 | 1 |
Failed authentication requests redirected to non-standard portals |
DC0038 Application Log Content | AN1069 | 1 |
Image Upgrade / Configuration Change |
DC0004 Firmware Modification | AN0246 | 1 |
OS version query results inconsistent with expected or approved version list |
DC0059 File Metadata | AN1570 | 1 |
Privilege-level command execution |
DC0064 Command Execution | AN1457 | 1 |
Privileged login followed by destructive command sequence |
DC0002 User Account Authentication | AN0885 | 1 |
Privileged login followed by destructive format command |
DC0002 User Account Authentication | AN0830 | 1 |
SIP REGISTER, INVITE, or unusual call destination metadata |
DC0038 Application Log Content | AN0684 | 1 |
System reboot scheduled or performed |
DC0018 Host Status | AN1542 | 1 |
Unexpected reload, crashinfo, or boot message not tied to scheduled maintenance |
DC0021 OS API Execution | AN0497 | 1 |
User privilege escalation to level 15/root prior to destructive commands |
DC0002 User Account Authentication | AN0387 | 1 |
aaa privilege_exec |
DC0021 OS API Execution | AN0257 | 1 |
admin login events |
DC0002 User Account Authentication | AN0879 | 1 |
authentication & authorization |
DC0002 User Account Authentication | AN1432 | 1 |
authentication logs |
DC0002 User Account Authentication | AN1287 | 1 |
authorization/accounting logs |
DC0002 User Account Authentication | AN0399 | 1 |
cmd='show aaa*' OR 'show running-config | include password|aaa' OR 'show aaa common-criteria policy all' |
DC0064 Command Execution | AN0461 | 1 |
command audit |
DC0064 Command Execution | AN1219 | 1 |
command sequence: erase → format → reload |
DC0064 Command Execution | AN0936 | 1 |
command-exec: CLI commands containing "show clock", "show clock detail", "show timezone" executed by suspicious user/source |
DC0064 Command Execution | AN0434 | 1 |
command_exec |
DC0064 Command Execution | AN0399 | 1 |
config |
DC0061 File Modification | AN0315 | 1 |
config access, authentication logs |
DC0002 User Account Authentication | AN0296 | 1 |
config change (e.g., logging buffered, pcap buffers) |
DC0085 Network Traffic Content | AN0879 | 1 |
config push events |
DC0038 Application Log Content | AN0627 | 1 |
eventlog |
DC0064 Command Execution | AN0257 | 1 |
exec command='monitor capture' |
DC0064 Command Execution | AN0879 | 1 |
flow records |
DC0078 Network Traffic Flow | AN0427 | 1 |
login failed |
DC0002 User Account Authentication | AN1525 | 1 |
no logging buffered, no aaa new-model, disable firewall |
DC0064 Command Execution | AN0893 | 0 |
no logging host, no aaa new-model, no snmp-server, commit |
DC0018 Host Status | AN1374 | 1 |
reload command issued |
DC0064 Command Execution | AN1542 | 1 |
startup-config |
DC0061 File Modification | AN0661 | 1 |
syslog facility LOCAL7 or trap messages |
DC0064 Command Execution | AN1587 | 1 |
system boot logs |
DC0064 Command Execution | AN0661 | 1 |
username <user> privilege <level> |
DC0014 User Account Creation | AN1240 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2010-2883 | Adobe Acrobat and Reader | T1059 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2016-10033 | PHP PHPMailer | T1059.004 | Mapped |
| CVE-2016-4437 | Apache Shiro | T1059 | Mapped |
| CVE-2017-11882 | Microsoft Office | T1059 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1083 | Mapped |
| CVE-2017-5638 | Apache Struts | T1059 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1059 T1542.005 | Mapped |
| CVE-2017-9805 | Apache Struts | T1059 | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1059 | Mapped |
| CVE-2018-11776 | Apache Struts | T1059 | Mapped |
| CVE-2018-6789 | Exim Exim | T1059 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1059 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1059.004 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1059 T1083 | Mapped |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center | T1059 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1059 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1059 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1082 | Mapped |
| CVE-2019-17558 | Apache Solr | T1059 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1059 T1083 | Mapped |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center | T1059 | Mapped |
| CVE-2020-0787 | Microsoft Windows | T1059 | Mapped |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products | T1059 | Mapped |
| CVE-2020-17530 | Apache Struts | T1059 | Mapped |
| CVE-2020-25506 | D-Link DNS-320 Device | T1059 | Mapped |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices | T1059 | Mapped |
| CVE-2020-29574 | Sophos CyberoamOS | T1059 | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1059 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1059 | Stale |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1082 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1082 | Mapped |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1059 | Mapped |
| CVE-2021-1497 | Cisco HyperFlex HX | T1059 | Mapped |
| CVE-2021-1498 | Cisco HyperFlex HX | T1059 | Mapped |
| CVE-2021-20035 | SonicWall SMA100 Appliances | T1059 | Mapped |
| CVE-2021-21972 | VMware vCenter Server | T1059 | Mapped |
| CVE-2021-22005 | VMware vCenter Server | T1059 | Mapped |
| CVE-2021-22204 | Perl Exiftool | T1059 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1059 | Mapped |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | T1059 | Mapped |
| CVE-2021-22894 | Ivanti Pulse Connect Secure | T1059 | Mapped |
| CVE-2021-22900 | Ivanti Pulse Connect Secure | T1059 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1059 | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | T1059 | Mapped |
| CVE-2021-27101 | Accellion FTA | T1059 | Mapped |
| CVE-2021-27102 | Accellion FTA | T1059 | Mapped |
| CVE-2021-27104 | Accellion FTA | T1059 | Mapped |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack | T1059 | Mapped |
| CVE-2021-3129 | Laravel Ignition | T1059 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1040 | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | T1048.003 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1059 | Mapped |
| CVE-2021-35464 | ForgeRock Access Management (AM) | T1059 | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | T1059.004 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1082 | Mapped |
| CVE-2021-41773 | Apache HTTP Server | T1059 | Mapped |
| CVE-2021-42013 | Apache HTTP Server | T1059 | Mapped |
| CVE-2021-42237 | Sitecore XP | T1059 | Mapped |
| CVE-2021-42258 | BQE BillQuick Web Suite | T1059 | Mapped |
| CVE-2021-42321 | Microsoft Exchange | T1059 | Mapped |
| CVE-2021-45046 | Apache Log4j2 | T1059 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1059 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1040 T1059 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-21971 | Microsoft Windows | T1059 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1059 T1136.001 | Mapped |
| CVE-2022-22047 | Microsoft Windows | T1059 | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | T1059 | Mapped |
| CVE-2022-22965 | VMware Spring Framework | T1059 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1059 | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | T1059 | Mapped |
| CVE-2022-24521 | Microsoft Windows | T1059 | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | T1059 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1059 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1059 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1059 | Mapped |
| CVE-2022-34713 | Microsoft Windows | T1059 | Mapped |
| CVE-2022-35405 | Zoho ManageEngine | T1059 | Mapped |
| CVE-2022-35914 | Teclib GLPI | T1059 | Mapped |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center | T1059 | Mapped |
| CVE-2022-37969 | Microsoft Windows | T1059 | Mapped |
| CVE-2022-39197 | Fortra Cobalt Strike | T1059 | Mapped |
| CVE-2022-41125 | Microsoft Windows | T1059 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1037 | Mapped |
| CVE-2022-42948 | Fortra Cobalt Strike | T1059 | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1059 | Mapped |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1059 | Mapped |
| CVE-2022-47966 | Zoho ManageEngine | T1136.001 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1059 | Mapped |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | T1059 | Mapped |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | T1059 | Mapped |
| CVE-2023-20867 | VMware Tools | T1059 | Mapped |
| CVE-2023-20887 | VMware Aria Operations for Networks | T1059 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1059 | Mapped |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | T1033 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1059 T1083 | Stale |
| CVE-2023-2533 | PaperCut NG/MF | T1059 | Mapped |
| CVE-2023-26359 | Adobe ColdFusion | T1059 | Mapped |
| CVE-2023-27350 | PaperCut MF/NG | T1059 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1059 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1059 | Mapped |
| CVE-2023-33246 | Apache RocketMQ | T1059 | Mapped |
| CVE-2023-33538 | TP-Link Multiple Routers | T1059 | Mapped |
| CVE-2023-34192 | Synacor Zimbra Collaboration Suite (ZCS) | T1059 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1059 T1082 | Mapped |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) | T1059 | Mapped |
| CVE-2023-36845 | Juniper Junos OS | T1059 | Mapped |
| CVE-2023-36846 | Juniper Junos OS | T1059 | Mapped |
| CVE-2023-36847 | Juniper Junos OS | T1059 | Mapped |
| CVE-2023-36851 | Juniper Junos OS | T1059 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1490 | Stale |
| CVE-2023-38035 | Ivanti Sentry | T1018 T1059 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1059.004 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1059.004 | Mapped |
| CVE-2023-40044 | Progress WS_FTP Server | T1059 | Mapped |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security | T1059 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1059 T1082 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1059.004 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | T1059.004 | Mapped |
| CVE-2023-48365 | Qlik Sense | T1059 | Mapped |
| CVE-2023-48788 | Fortinet FortiClient EMS | T1059 | Mapped |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | T1059 | Mapped |
| CVE-2024-11182 | MDaemon Email Server | T1059 | Mapped |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | T1059 | Mapped |
| CVE-2024-12987 | DrayTek Vigor Routers | T1059 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 T1059 | Mapped |
| CVE-2024-20399 | Cisco NX-OS | T1059 | Mapped |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) | T1059 | Mapped |
| CVE-2024-21413 | Microsoft Office Outlook | T1059 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1059 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1082 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1059.004 | Mapped |
| CVE-2024-26169 | Microsoft Windows | T1059 | Mapped |
| CVE-2024-27198 | JetBrains TeamCity | T1059 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1059.004 | Mapped |
| CVE-2024-29059 | Microsoft .NET Framework | T1059 | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | T1059 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1059 | Mapped |
| CVE-2024-41710 | Mitel SIP Phones | T1059 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1059 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1033 T1059 | Mapped |
| CVE-2024-4671 | Google Chromium | T1059 | Mapped |
| CVE-2024-4761 | Google Chromium V8 | T1059 | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1059 | Mapped |
| CVE-2024-4885 | Progress WhatsUp Gold | T1059 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1059 | Mapped |
| CVE-2024-50603 | Aviatrix Controllers | T1059 | Mapped |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1059 | Mapped |
| CVE-2024-53104 | Linux Kernel | T1059 | Mapped |
| CVE-2024-53197 | Linux Kernel | T1059 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1083 | Mapped |
| CVE-2024-56145 | Craft CMS Craft CMS | T1059 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1059 T1552.004 | Mapped |
| CVE-2024-57968 | Advantive VeraCore | T1059 | Mapped |
| CVE-2024-58136 | Yiiframework Yii | T1059 | Mapped |
| CVE-2024-6047 | GeoVision Multiple Devices | T1059 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1018 | Mapped |
| CVE-2025-0994 | Trimble Cityworks | T1059 | Mapped |
| CVE-2025-1976 | Broadcom Brocade Fabric OS | T1059 | Mapped |
| CVE-2025-20281 | Cisco Identity Services Engine | T1059 | Mapped |
| CVE-2025-20337 | Cisco Identity Services Engine | T1059 | Mapped |
| CVE-2025-21391 | Microsoft Windows | T1490 | Mapped |
| CVE-2025-21590 | Juniper Junos OS | T1059 | Mapped |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1059 | Mapped |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | T1059 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1059 | Mapped |
| CVE-2025-24085 | Apple Multiple Products | T1059 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1059 | Mapped |
| CVE-2025-24985 | Microsoft Windows | T1059 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1059.004 | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | T1059 | Mapped |
| CVE-2025-30397 | Microsoft Windows | T1059 | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | T1059 | Mapped |
| CVE-2025-31161 | CrushFTP CrushFTP | T1059 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1059 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1059 | Stale |
| CVE-2025-31324 | SAP NetWeaver | T1059 T1602 | Mapped |
| CVE-2025-32433 | Erlang Erlang/OTP | T1059 | Mapped |
| CVE-2025-3248 | Langflow Langflow | T1059 | Mapped |
| CVE-2025-32701 | Microsoft Windows | T1059 | Mapped |
| CVE-2025-32706 | Microsoft Windows | T1059 | Mapped |
| CVE-2025-32709 | Microsoft Windows | T1059 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1059 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1056.001 T1059 | Mapped |
| CVE-2025-35939 | Craft CMS Craft CMS | T1059 | Mapped |
| CVE-2025-3928 | Commvault Web Server | T1059 | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | T1059 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1059 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1059 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1059 | Mapped |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) | T1059 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1059 | Mapped |
| CVE-2025-47812 | Wing FTP Server Wing FTP Server | T1059 | Mapped |
| CVE-2025-53770 | Microsoft SharePoint | T1059 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | T1059 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1059 | Mapped |