kevmap

Log sources › networkdevice:syslog

networkdevice:syslog

Inverted view: what can be detected if this is the log you have. Linux, Network Devices

53
channels
47
analytics
46
techniques
200
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
AAA or TACACS authentication failures DC0002 User Account Authentication AN1340 1
AAA, RADIUS, or TACACS authentication DC0002 User Account Authentication AN1267 1
ACL/Firewall rule modification or new route injection DC0085 Network Traffic Content AN0015 1
Admin activity DC0034 Process Metadata AN0099 1
Authentication failures or unusual community string usage in SNMP queries DC0085 Network Traffic Content AN1630 1
Authentication failures, unexpected community string usage, or unauthorized SNMPv1/v2 requests DC0085 Network Traffic Content AN1249 1
Boot information log showing image loaded from TFTP server instead of local storage DC0004 Firmware Modification AN1603 1
CLI Command Audit DC0064 Command Execution AN1084 1
CLI Command Logging DC0064 Command Execution AN1044 1
CLI command audit DC0064 Command Execution AN0471 1
Command Audit / Configuration Change DC0064 Command Execution AN0136 1
Config change: CLI/NETCONF/SNMP – 'monitor session', 'mirror port' DC0078 Network Traffic Flow AN1132 1
Config/ACL changes, line vty transport input changes, telnet/ssh/http(s) enable, image/feature module changes. DC0078 Network Traffic Flow AN0845 1
Config/ACL/line vty changes, service enable (telnet/ssh/http(s)), module reloads DC0078 Network Traffic Flow AN1451 1
Custom firmware or routing changes DC0004 Firmware Modification AN1024 1
Detected CLI command to export key material DC0064 Command Execution AN1519 1
Dynamic route changes DC0082 Network Connection Creation AN0926 1
Failed and successful logins to network devices outside approved admin IP ranges DC0002 User Account Authentication AN0647 1
Failed authentication requests redirected to non-standard portals DC0038 Application Log Content AN1069 1
Image Upgrade / Configuration Change DC0004 Firmware Modification AN0246 1
OS version query results inconsistent with expected or approved version list DC0059 File Metadata AN1570 1
Privilege-level command execution DC0064 Command Execution AN1457 1
Privileged login followed by destructive command sequence DC0002 User Account Authentication AN0885 1
Privileged login followed by destructive format command DC0002 User Account Authentication AN0830 1
SIP REGISTER, INVITE, or unusual call destination metadata DC0038 Application Log Content AN0684 1
System reboot scheduled or performed DC0018 Host Status AN1542 1
Unexpected reload, crashinfo, or boot message not tied to scheduled maintenance DC0021 OS API Execution AN0497 1
User privilege escalation to level 15/root prior to destructive commands DC0002 User Account Authentication AN0387 1
aaa privilege_exec DC0021 OS API Execution AN0257 1
admin login events DC0002 User Account Authentication AN0879 1
authentication & authorization DC0002 User Account Authentication AN1432 1
authentication logs DC0002 User Account Authentication AN1287 1
authorization/accounting logs DC0002 User Account Authentication AN0399 1
cmd='show aaa*' OR 'show running-config | include password|aaa' OR 'show aaa common-criteria policy all' DC0064 Command Execution AN0461 1
command audit DC0064 Command Execution AN1219 1
command sequence: erase → format → reload DC0064 Command Execution AN0936 1
command-exec: CLI commands containing "show clock", "show clock detail", "show timezone" executed by suspicious user/source DC0064 Command Execution AN0434 1
command_exec DC0064 Command Execution AN0399 1
config DC0061 File Modification AN0315 1
config access, authentication logs DC0002 User Account Authentication AN0296 1
config change (e.g., logging buffered, pcap buffers) DC0085 Network Traffic Content AN0879 1
config push events DC0038 Application Log Content AN0627 1
eventlog DC0064 Command Execution AN0257 1
exec command='monitor capture' DC0064 Command Execution AN0879 1
flow records DC0078 Network Traffic Flow AN0427 1
login failed DC0002 User Account Authentication AN1525 1
no logging buffered, no aaa new-model, disable firewall DC0064 Command Execution AN0893 0
no logging host, no aaa new-model, no snmp-server, commit DC0018 Host Status AN1374 1
reload command issued DC0064 Command Execution AN1542 1
startup-config DC0061 File Modification AN0661 1
syslog facility LOCAL7 or trap messages DC0064 Command Execution AN1587 1
system boot logs DC0064 Command Execution AN0661 1
username <user> privilege <level> DC0014 User Account Creation AN1240 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1018 Remote System Discoverydiscovery172
T1020.001 Traffic Duplicationexfiltration00
T1033 System Owner/User Discoverydiscovery302
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation03
T1037.004 RC Scriptspersistence, privilege escalation00
T1040 Network Sniffingcredential access, discovery92
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocolexfiltration91
T1056.001 Keyloggingcollection, credential access31
T1057 Process Discoverydiscovery80
T1059 Command and Scripting Interpreterexecution95170
T1059.004 Unix Shellexecution1814
T1059.008 Network Device CLIexecution00
T1070.003 Clear Command Historystealth90
T1070.007 Clear Network Connection History and Configurationsstealth00
T1070.010 Relocate Malwarestealth00
T1072 Software Deployment Toolsexecution, lateral movement40
T1078.001 Default Accountsstealth, persistence, privilege escalation, initial access40
T1082 System Information Discoverydiscovery337
T1083 File and Directory Discoverydiscovery245
T1090.002 External Proxycommand and control20
T1090.003 Multi-hop Proxycommand and control30
T1110.001 Password Guessingcredential access30
T1110.002 Password Crackingcredential access10
T1110.003 Password Sprayingcredential access00
T1110.004 Credential Stuffingcredential access00
T1124 System Time Discoverydiscovery30
T1136.001 Local Accountpersistence182
T1201 Password Policy Discoverydiscovery60
T1205 Traffic Signalingstealth, persistence, command and control00
T1205.001 Port Knockingstealth, persistence, command and control00
T1490 Inhibit System Recoveryimpact272
T1529 System Shutdown/Rebootimpact80
T1542.004 ROMMONkitstealth, persistence00
T1542.005 TFTP Bootstealth, persistence01
T1552.004 Private Keyscredential access71
T1557.004 Evil Twincredential access, collection00
T1561 Disk Wipeimpact00
T1561.001 Disk Content Wipeimpact10
T1561.002 Disk Structure Wipeimpact10
T1566.004 Spearphishing Voiceinitial access00
T1599 Network Boundary Bridgingdefense impairment00
T1601.002 Downgrade System Imagedefense impairment00
T1602 Data from Configuration Repositorycollection01
T1602.001 SNMP (MIB Dump)collection00
T1602.002 Network Device Configuration Dumpcollection00
T1685 Disable or Modify Toolsdefense impairment1640

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2010-2883Adobe Acrobat and Reader T1059 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2016-10033PHP PHPMailer T1059.004 Mapped
CVE-2016-4437Apache Shiro T1059 Mapped
CVE-2017-11882Microsoft Office T1059 Mapped
CVE-2017-12637SAP NetWeaver T1083 Mapped
CVE-2017-5638Apache Struts T1059 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1059 T1542.005 Mapped
CVE-2017-9805Apache Struts T1059 Mapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1059 Mapped
CVE-2018-11776Apache Struts T1059 Mapped
CVE-2018-6789Exim Exim T1059 Mapped
CVE-2018-7600Drupal Drupal Core T1059 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1059.004 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1059 T1083 Mapped
CVE-2019-11580Atlassian Crowd and Crowd Data Center T1059 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1059 Mapped
CVE-2019-13608Citrix StoreFront Server T1059 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1082 Mapped
CVE-2019-17558Apache Solr T1059 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1059 T1083 Mapped
CVE-2019-3398Atlassian Confluence Server and Data Center T1059 Mapped
CVE-2020-0787Microsoft Windows T1059 Mapped
CVE-2020-15505Ivanti MobileIron Multiple Products T1059 Mapped
CVE-2020-17530Apache Struts T1059 Mapped
CVE-2020-25506D-Link DNS-320 Device T1059 Mapped
CVE-2020-29557D-Link DIR-825 R1 Devices T1059 Mapped
CVE-2020-29574Sophos CyberoamOS T1059 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1059 Mapped
CVE-2020-5902F5 BIG-IP T1059 Stale
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1082 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1082 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1059 Mapped
CVE-2021-1497Cisco HyperFlex HX T1059 Mapped
CVE-2021-1498Cisco HyperFlex HX T1059 Mapped
CVE-2021-20035SonicWall SMA100 Appliances T1059 Mapped
CVE-2021-21972VMware vCenter Server T1059 Mapped
CVE-2021-22005VMware vCenter Server T1059 Mapped
CVE-2021-22204Perl Exiftool T1059 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1059 Mapped
CVE-2021-22893Ivanti Pulse Connect Secure T1059 Mapped
CVE-2021-22894Ivanti Pulse Connect Secure T1059 Mapped
CVE-2021-22900Ivanti Pulse Connect Secure T1059 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1059 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1059 Mapped
CVE-2021-27101Accellion FTA T1059 Mapped
CVE-2021-27102Accellion FTA T1059 Mapped
CVE-2021-27104Accellion FTA T1059 Mapped
CVE-2021-31166Microsoft HTTP Protocol Stack T1059 Mapped
CVE-2021-3129Laravel Ignition T1059 Mapped
CVE-2021-32030ASUS Routers T1040 Mapped
CVE-2021-34473Microsoft Exchange Server T1048.003 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1059 Mapped
CVE-2021-35464ForgeRock Access Management (AM) T1059 Mapped
CVE-2021-36380Sunhillo SureLine T1059.004 Mapped
CVE-2021-40449Microsoft Windows T1082 Mapped
CVE-2021-41773Apache HTTP Server T1059 Mapped
CVE-2021-42013Apache HTTP Server T1059 Mapped
CVE-2021-42237Sitecore XP T1059 Mapped
CVE-2021-42258BQE BillQuick Web Suite T1059 Mapped
CVE-2021-42321Microsoft Exchange T1059 Mapped
CVE-2021-45046Apache Log4j2 T1059 Mapped
CVE-2021-45382D-Link Multiple Routers T1059 Mapped
CVE-2022-1040Sophos Firewall T1040 T1059 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-21971Microsoft Windows T1059 Mapped
CVE-2022-21999Microsoft Windows T1059 T1136.001 Mapped
CVE-2022-22047Microsoft Windows T1059 Mapped
CVE-2022-22947VMware Spring Cloud Gateway T1059 Mapped
CVE-2022-22965VMware Spring Framework T1059 Mapped
CVE-2022-23131Zabbix Frontend T1059 Mapped
CVE-2022-23748Audinate Dante Discovery T1059 Mapped
CVE-2022-24521Microsoft Windows T1059 Mapped
CVE-2022-26258D-Link DIR-820L T1059 Mapped
CVE-2022-26500Veeam Backup & Replication T1059 Mapped
CVE-2022-26501Veeam Backup & Replication T1059 Mapped
CVE-2022-29303SolarView Compact T1059 Mapped
CVE-2022-34713Microsoft Windows T1059 Mapped
CVE-2022-35405Zoho ManageEngine T1059 Mapped
CVE-2022-35914Teclib GLPI T1059 Mapped
CVE-2022-36804Atlassian Bitbucket Server and Data Center T1059 Mapped
CVE-2022-37969Microsoft Windows T1059 Mapped
CVE-2022-39197Fortra Cobalt Strike T1059 Mapped
CVE-2022-41125Microsoft Windows T1059 Mapped
CVE-2022-41328Fortinet FortiOS T1037 Mapped
CVE-2022-42948Fortra Cobalt Strike T1059 Mapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server T1059 Mapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) Server T1059 Mapped
CVE-2022-47966Zoho ManageEngine T1136.001 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1059 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1059 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1059 Mapped
CVE-2023-20867VMware Tools T1059 Mapped
CVE-2023-20887VMware Aria Operations for Networks T1059 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1059 Mapped
CVE-2023-22518Atlassian Confluence Data Center and Server T1033 Mapped
CVE-2023-22952SugarCRM Multiple Products T1059 T1083 Stale
CVE-2023-2533PaperCut NG/MF T1059 Mapped
CVE-2023-26359Adobe ColdFusion T1059 Mapped
CVE-2023-27350PaperCut MF/NG T1059 Mapped
CVE-2023-28252Microsoft Windows T1059 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1059 Mapped
CVE-2023-33246Apache RocketMQ T1059 Mapped
CVE-2023-33538TP-Link Multiple Routers T1059 Mapped
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) T1059 Mapped
CVE-2023-34362Progress MOVEit Transfer T1059 T1082 Mapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) T1059 Mapped
CVE-2023-36845Juniper Junos OS T1059 Mapped
CVE-2023-36846Juniper Junos OS T1059 Mapped
CVE-2023-36847Juniper Junos OS T1059 Mapped
CVE-2023-36851Juniper Junos OS T1059 Mapped
CVE-2023-36884Microsoft Windows T1490 Stale
CVE-2023-38035Ivanti Sentry T1018 T1059 Mapped
CVE-2023-38831RARLAB WinRAR T1059.004 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1059.004 Mapped
CVE-2023-40044Progress WS_FTP Server T1059 Mapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security T1059 Mapped
CVE-2023-43770Roundcube Webmail T1059 T1082 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1059.004 Mapped
CVE-2023-46604Apache ActiveMQ T1059.004 Mapped
CVE-2023-48365Qlik Sense T1059 Mapped
CVE-2023-48788Fortinet FortiClient EMS T1059 Mapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcel T1059 Mapped
CVE-2024-11182MDaemon Email Server T1059 Mapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) T1059 Mapped
CVE-2024-12987DrayTek Vigor Routers T1059 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 T1059 Mapped
CVE-2024-20399Cisco NX-OS T1059 Mapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) T1059 Mapped
CVE-2024-21413Microsoft Office Outlook T1059 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1059 Mapped
CVE-2024-23692Rejetto HTTP File Server T1082 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1059.004 Mapped
CVE-2024-26169Microsoft Windows T1059 Mapped
CVE-2024-27198JetBrains TeamCity T1059 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1059.004 Mapped
CVE-2024-29059Microsoft .NET Framework T1059 Mapped
CVE-2024-34102Adobe Commerce and Magento Open Source T1059 Mapped
CVE-2024-38475Apache HTTP Server T1059 Mapped
CVE-2024-41710Mitel SIP Phones T1059 Mapped
CVE-2024-45195Apache OFBiz T1059 Mapped
CVE-2024-4577PHP Group PHP T1033 T1059 Mapped
CVE-2024-4671Google Chromium T1059 Mapped
CVE-2024-4761Google Chromium V8 T1059 Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform T1059 Mapped
CVE-2024-4885Progress WhatsUp Gold T1059 Mapped
CVE-2024-4947Google Chromium V8 T1059 Mapped
CVE-2024-50603Aviatrix Controllers T1059 Mapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now Platform T1059 Mapped
CVE-2024-53104Linux Kernel T1059 Mapped
CVE-2024-53197Linux Kernel T1059 Mapped
CVE-2024-53704SonicWall SonicOS T1083 Mapped
CVE-2024-56145Craft CMS Craft CMS T1059 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1059 T1552.004 Mapped
CVE-2024-57968Advantive VeraCore T1059 Mapped
CVE-2024-58136Yiiframework Yii T1059 Mapped
CVE-2024-6047GeoVision Multiple Devices T1059 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1018 Mapped
CVE-2025-0994Trimble Cityworks T1059 Mapped
CVE-2025-1976Broadcom Brocade Fabric OS T1059 Mapped
CVE-2025-20281Cisco Identity Services Engine T1059 Mapped
CVE-2025-20337Cisco Identity Services Engine T1059 Mapped
CVE-2025-21391Microsoft Windows T1490 Mapped
CVE-2025-21590Juniper Junos OS T1059 Mapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1059 Mapped
CVE-2025-23006SonicWall SMA1000 Appliances T1059 Mapped
CVE-2025-24016Wazuh Wazuh Server T1059 Mapped
CVE-2025-24085Apple Multiple Products T1059 Mapped
CVE-2025-24201Apple Multiple Products T1059 Mapped
CVE-2025-24985Microsoft Windows T1059 Mapped
CVE-2025-25257Fortinet FortiWeb T1059.004 Mapped
CVE-2025-27038Qualcomm Multiple Chipsets T1059 Mapped
CVE-2025-30397Microsoft Windows T1059 Mapped
CVE-2025-30406Gladinet CentreStack T1059 Mapped
CVE-2025-31161CrushFTP CrushFTP T1059 Mapped
CVE-2025-31200Apple Multiple Products T1059 Stale
CVE-2025-31201Apple Multiple Products T1059 Stale
CVE-2025-31324SAP NetWeaver T1059 T1602 Mapped
CVE-2025-32433Erlang Erlang/OTP T1059 Mapped
CVE-2025-3248Langflow Langflow T1059 Mapped
CVE-2025-32701Microsoft Windows T1059 Mapped
CVE-2025-32706Microsoft Windows T1059 Mapped
CVE-2025-32709Microsoft Windows T1059 Mapped
CVE-2025-32756Fortinet Multiple Products T1059 Mapped
CVE-2025-33053Microsoft Windows T1056.001 T1059 Mapped
CVE-2025-35939Craft CMS Craft CMS T1059 Mapped
CVE-2025-3928Commvault Web Server T1059 Mapped
CVE-2025-3935ConnectWise ScreenConnect T1059 Mapped
CVE-2025-42599Qualitia Active! Mail T1059 Mapped
CVE-2025-42999SAP NetWeaver T1059 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1059 Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) T1059 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1059 Mapped
CVE-2025-47812Wing FTP Server Wing FTP Server T1059 Mapped
CVE-2025-53770Microsoft SharePoint T1059 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1059 Mapped
CVE-2025-6554Google Chromium V8 T1059 Mapped