kevmap

Log sources › NSM:Flow

NSM:Flow

Inverted view: what can be detected if this is the log you have. Containers, ESXi, Linux, Network Devices, Windows, macOS

229
channels
235
analytics
131
techniques
274
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Abnormal SMB authentication attempts correlated with poisoned LLMNR/NBT-NS sessions DC0078 Network Traffic Flow AN1274 1
Abnormal browser traffic volume or destination DC0078 Network Traffic Flow AN0253 1
Altered response metadata or blocked content based on user-agent or geolocation DC0106 Response Metadata AN1149 1
Base64 strings or gzip in URI, headers, or POST body DC0085 Network Traffic Content AN0303 1
Browser connections to known C2 or dynamic DNS domains DC0085 Network Traffic Content AN0125 1
C2 exfiltration DC0085 Network Traffic Content AN0653 1
Captured File Content DC0085 Network Traffic Content AN0652 1
Closed-port hits followed by success from same src_ip DC0082 Network Connection Creation AN1450 1
Connection Tracking DC0078 Network Traffic Flow AN1230 1
Connections from IDE hosts to marketplace/tunnel domains DC0078 Network Traffic Flow AN1549 1
Connections to *.devtunnels.ms or tunnels.api.visualstudio.com DC0082 Network Connection Creation AN0376 1
Connections to TCP 427 (SLP) or vCenter web services from untrusted sources DC0085 Network Traffic Content AN0224 1
Content injection observed in HTTPS responses with mismatched certificates or altered payloads DC0085 Network Traffic Content AN0994 1
DHCP OFFER or ACK with unauthorized DNS/gateway parameters DC0085 Network Traffic Content AN1290 1
Degraded encryption throughput or switch to weaker cipher suites compared to historical baselines DC0085 Network Traffic Content AN1360 1
Device-to-Device Deployment Flows DC0078 Network Traffic Flow AN0627 1
DrsAddEntry, DrsReplicaAdd, GetNCChanges calls between non-DC and DCs. DC0085 Network Traffic Content AN0770 1
Egress to non-approved networks from host after terminal exec DC0085 Network Traffic Content AN0964 1
Encrypted tunnels or proxy traffic to non-standard destinations DC0085 Network Traffic Content AN1151 1
Excessive gratuitous ARP replies on local subnet DC0085 Network Traffic Content AN1093 1
External access to container ports (2375, 6443) DC0082 Network Connection Creation AN1007 1
First-time egress from host after new install to unknown update endpoints DC0078 Network Traffic Flow AN1480 1
First-time egress to new registries/CDNs post-install/build DC0078 Network Traffic Flow AN0022 1
First-time egress to non-approved registries after dependency install DC0078 Network Traffic Flow AN0023 1
First-time egress to non-approved update hosts right after install/update DC0078 Network Traffic Flow AN0862 1
First-time egress to unknown registries/mirrors immediately after install DC0078 Network Traffic Flow AN1481 1
First-time outbound connections to package registries or unknown hosts immediately after restore/build DC0078 Network Traffic Flow AN0021 1
Flow Creation (NetFlow/sFlow) DC0078 Network Traffic Flow AN1233 1
Flow records with RSA key exchange on unexpected port DC0078 Network Traffic Flow AN1500 1
Flow records with entropy signatures resembling symmetric encryption DC0078 Network Traffic Flow AN0404 1
Flow/PCAP analysis for outbound payloads DC0085 Network Traffic Content AN0988 1
Gratuitous ARP replies with mismatched IP-MAC binding DC0078 Network Traffic Flow AN1092 1
Gratuitous or duplicate DHCP OFFER packets from non-legitimate servers DC0078 Network Traffic Flow AN1291 1
HTTP DC0085 Network Traffic Content AN0144 1
HTTP Request Logging DC0085 Network Traffic Content AN1320 1
HTTP payloads with SQLi/LFI/JNDI/deserialization indicators DC0085 Network Traffic Content AN0220 1
HTTP(S) requests with User-Agents typical of PowerShell or curl from desktop; or URIs matching paste-inspired payload hosts DC0085 Network Traffic Content AN0962 1
HTTP/HTTPS requests for script resources flagged by content inspection (excessive obfuscation, eval usage, unusual redirects) DC0085 Network Traffic Content AN0500 1
HTTP/TLS Logs DC0085 Network Traffic Content AN0159 1
HTTP/WebDAV requests that contain NTLMSSP or PROPFIND/MOVE/OPTIONS with Authorization: NTLM DC0085 Network Traffic Content AN0065 1
HTTPS API requests to Dropbox, iCloud, Google Drive, OneDrive shortly after DB tool usage DC0085 Network Traffic Content AN0678 1
HTTPs connection to tunnels.api.visualstudio.com DC0082 Network Connection Creation AN0377 1
High volume flows with incomplete TCP sessions or single-packet bursts DC0078 Network Traffic Flow AN1435 1
High volumes of SYN/ACK packets with unacknowledged TCP handshakes DC0078 Network Traffic Flow AN1013 1
High-volume or repeated SNMP GETBULK/GETNEXT queries from untrusted or external IPs DC0082 Network Connection Creation AN1249 1
ICMP/UDP monitoring (tcpdump, Wireshark, Zeek) DC0085 Network Traffic Content AN1256 1
ICMP/UDP traffic (Wireshark, Suricata, Zeek) DC0085 Network Traffic Content AN1254 1
Inbound HTTP POST with suspicious payload size or user-agent DC0085 Network Traffic Content AN1108 AN2029 AN2032 2
Inbound connections to 445, 3389, 5985-5986 with high error/connection-reset rate, followed by new outbound sessions from the same host to internal assets within short interval. DC0085 Network Traffic Content AN0327 1
Inbound connections to monitored service ports from external or unusual internal sources; rapid follow-on lateral connections from the same host. DC0085 Network Traffic Content AN0328 1
Inbound one-off packet to uncommon port → outbound SF to same src_ip within TimeWindow. DC0085 Network Traffic Content AN0464 1
Inbound to 22/5900/8080 and follow-on internal connections. DC0085 Network Traffic Content AN0330 1
Inbound to tcp/427 (OpenSLP), tcp/443 (vSphere APIs), tcp/902, tcp/5989 followed by new unexpected outbound sessions from the ESXi/vCenter host. DC0085 Network Traffic Content AN0329 1
Injected content responses with unexpected script/malware signatures DC0085 Network Traffic Content AN0993 1
Inter-segment traffic DC0078 Network Traffic Flow AN0208 1
Knock pattern: multiple REJ/S0 to distinct closed ports then successful connection to service_port DC0078 Network Traffic Flow AN1449 1
Knock pattern: repeated REJ/S0 across ≥MinSequenceLen ports from same src_ip then SF success. DC0078 Network Traffic Flow AN0843 1
LDAP Bind/Search DC0085 Network Traffic Content AN0363 1
LDAP Query DC0085 Network Traffic Content AN0364 1
LEASE_GRANTED DC0078 Network Traffic Flow AN0186 1
Long-lived or hijacked SSH sessions maintained with no active user activity DC0078 Network Traffic Flow AN0217 1
MAC not in allow-list acquiring IP (DHCP) DC0078 Network Traffic Flow AN0187 1
Multiple DHCP OFFER responses for a single DISCOVER DC0085 Network Traffic Content AN1292 1
NetFlow/Zeek conn.log DC0078 Network Traffic Flow AN0368 1
NetFlow/sFlow for odd egress to Internet from mgmt plane DC0085 Network Traffic Content AN0225 1
NetFlow/sFlow/PCAP DC0078 Network Traffic Flow AN0596 1
Network Capture TLS/HTTP DC0085 Network Traffic Content AN1295 1
New VM egress to crypto-mining pools or non-approved Internet ranges within minutes of boot DC0085 Network Traffic Content AN0692 1
New egress from app just installed to unknown update endpoints DC0078 Network Traffic Flow AN1482 1
New egress from container IP/namespace to Internet or non-approved CIDRs/ASNs DC0085 Network Traffic Content AN0691 1
New egress to Internet by the same UID/host shortly after terminal exec DC0082 Network Connection Creation AN0963 1
New outbound flows to non-approved vendor hosts post install DC0078 Network Traffic Flow AN0863 1
New/rare egress to non-approved update hosts after install DC0078 Network Traffic Flow AN0864 1
None DC0078 Network Traffic Flow AN0213 AN1378 2
Observed File Transfers DC0059 File Metadata AN0652 1
Observed downgrade in negotiated cipher suites or TLS/SSH versions across sessions DC0085 Network Traffic Content AN0681 1
Outbound Connections DC0082 Network Connection Creation AN1114 AN1119 2
Outbound HTTP/S DC0085 Network Traffic Content AN1408 1
Outbound HTTP/S initiated by newly installed interpreter process DC0082 Network Connection Creation AN0700 1
Outbound Network Flow DC0078 Network Traffic Flow AN0597 1
Outbound SCP, TFTP, or FTP sessions carrying configuration file content DC0085 Network Traffic Content AN0647 1
Outbound TCP SYN or UDP to multiple ports/hosts DC0078 Network Traffic Flow AN1058 1
Outbound UDP floods targeting common reflection services with spoofed IP headers DC0078 Network Traffic Flow AN1141 1
Outbound connection to *.tunnels.api.visualstudio.com or *.devtunnels.ms DC0082 Network Connection Creation AN0375 1
Outbound connection to mining pool port (3333, 4444, 5555) DC0078 Network Traffic Flow AN1490 1
Outbound connections from web server binaries (apache2, nginx, php-fpm) to unknown external IPs DC0078 Network Traffic Flow AN1508 1
Outbound connections to TCP 139,445 and HTTP/HTTPS to WebDAV endpoints from workstation subnets DC0078 Network Traffic Flow AN0065 1
Outbound flow records DC0078 Network Traffic Flow AN0926 1
Outbound or inbound TFTP file transfers of ROMMON or firmware binaries DC0082 Network Connection Creation AN0497 1
Outbound requests to domains not previously resolved or associated with phishing campaigns DC0078 Network Traffic Flow AN0299 1
Outbound traffic from suspicious new processes post-attachment execution DC0078 Network Traffic Flow AN0656 1
Outbound traffic spike through formerly blocked ports/subnets following config change DC0082 Network Connection Creation AN0855 1
Outbound traffic to domains/IPs not previously resolved, occurring shortly after attachment download or link click DC0078 Network Traffic Flow AN0321 1
Outbound traffic to mining pool upon container launch DC0078 Network Traffic Flow AN1492 1
Outbound traffic to mining pools or proxies DC0078 Network Traffic Flow AN0742 1
PCAP inspection DC0085 Network Traffic Content AN0427 1
POST requests to .php, .jsp, .aspx files with high entropy body DC0085 Network Traffic Content AN1109 1
Packets with unusual flags or payloads outside established flows (e.g., WoL magic FF×6 + 16×MAC) DC0085 Network Traffic Content AN1449 1
Port-knock pattern from one src to device unicast,broadcast,network addresses on same port within TimeWindowKnock DC0082 Network Connection Creation AN1451 1
Probe responses from unauthorized APs responding to client probe requests DC0085 Network Traffic Content AN1069 1
Rare inbound packet characteristics (ICMP/UDP/TCP to uncommon port) from src_ip followed ≤TimeWindow by outbound SF from same host to src_ip. DC0085 Network Traffic Content AN0463 1
Relay patterns across IP hops DC0085 Network Traffic Content AN1023 1
Relayed session pathing (multi-hop) DC0078 Network Traffic Flow AN1024 1
Requests towards cloud metadata or command & control from pod IPs DC0085 Network Traffic Content AN0222 1
SMB2_LOGOFF/SMB_TREE_DISCONNECT DC0085 Network Traffic Content AN0286 1
SPAN or port-mirrored HTTP/S DC0085 Network Traffic Content AN0078 1
SSH logins or scp activity DC0085 Network Traffic Content AN0195 1
SSL/TLS Handshake Analysis DC0085 Network Traffic Content AN1294 1
SSL/TLS Inspection or PCAP DC0085 Network Traffic Content AN1189 1
Sequence of REJ/S0 then SF success from same src_ip within TimeWindow. DC0082 Network Connection Creation AN0844 1
Series of denied/closed flows to distinct ports then success to mgmt port from same src_ip within TimeWindow. DC0082 Network Connection Creation AN0845 1
Session History Reset DC0085 Network Traffic Content AN0136 1
Session Transfer Content DC0085 Network Traffic Content AN0651 1
Session records with TLS-like byte patterns DC0078 Network Traffic Flow AN0763 1
Single, low-volume inbound packet (REJ/S0/OTH or uncommon dport/protocol) from src_ip followed by outbound SF connection to src_ip. DC0085 Network Traffic Content AN0462 1
Source/destination IP translation inconsistent with intended policy DC0078 Network Traffic Flow AN0465 1
Sudden spike in incoming flows to web service ports from single/multiple IPs DC0078 Network Traffic Flow AN0490 1
Suspicious POSTs to upload endpoints DC0085 Network Traffic Content AN1623 1
Suspicious URL patterns, uncommon TLDs, URL shorteners DC0085 Network Traffic Content AN0179 1
Suspicious URL patterns, uncommon TLDs, short-lived domains, URL shorteners; HTTP method GET/POST DC0085 Network Traffic Content AN0178 1
Suspicious changes in TLS certificate responses or redirected domains DC0104 Response Content AN1150 1
Suspicious long-lived or reattached remote desktop sessions from unexpected IPs DC0085 Network Traffic Content AN0218 1
Sustained abnormal inbound request rate targeting application ports (e.g., 80/443/25) DC0085 Network Traffic Content AN1166 1
TCP port 22 traffic DC0078 Network Traffic Flow AN1638 1
TCP port 5900 open DC0078 Network Traffic Flow AN0505 1
TCP session tracking DC0085 Network Traffic Content AN0031 1
TCP/UDP DC0085 Network Traffic Content AN0030 1
TCP: possible SYN flood or backlog limit exceeded DC0018 Host Status AN1013 1
TGS-REQ and AS-REQ seen for new user shortly after domain-modifying process DC0002 User Account Authentication AN0007 1
TLS downgrade or inconsistent DNS answers DC0085 Network Traffic Content AN0825 1
Traffic patterns showing downgrade from strong encryption (AES-256) to weaker or plaintext protocols DC0085 Network Traffic Content AN0961 1
Traffic spike preceding control crash DC0085 Network Traffic Content AN2040 1
Transferred file observations DC0085 Network Traffic Content AN0654 1
Unexpected ARP replies or DNS responses inconsistent with authoritative servers DC0085 Network Traffic Content AN0824 1
Unexpected flows between segmented networks or prohibited ports DC0078 Network Traffic Flow AN0015 1
Unexpected inbound/outbound TFTP traffic for device image files DC0082 Network Connection Creation AN1603 1
Unexpected or unauthorized inbound connections to SNMP, NETCONF, or RESTCONF services DC0082 Network Connection Creation AN1630 1
Unexpected route changes or duplicate gateway advertisements DC0078 Network Traffic Flow AN0826 1
Unexpected script or binary content returned in HTTP response body DC0085 Network Traffic Content AN0992 1
Unusual Base64-encoded content in URI, headers, or POST body DC0085 Network Traffic Content AN0302 1
Unusual request pattern leading up to service crash (e.g., malformed or oversized payload) DC0085 Network Traffic Content AN0851 1
Unusual responses to LLMNR (UDP 5355) or NBT-NS (UDP 137) queries from unauthorized hosts DC0085 Network Traffic Content AN1274 1
alert log DC0078 Network Traffic Flow AN0923 1
alternate ports DC0078 Network Traffic Flow AN1377 1
conn.log DC0078 Network Traffic Flow
DC0082 Network Connection Creation
DC0085 Network Traffic Content
AN0101 AN0205 AN0207 AN0925 AN1232 AN1382 5
conn.log + files.log + ssl.log DC0085 Network Traffic Content AN0989 1
conn.log + ssl.log with Tor fingerprinting DC0078 Network Traffic Flow AN1021 1
conn.log or flow data DC0078 Network Traffic Flow AN1390 1
conn.log or http.log DC0085 Network Traffic Content AN0923 1
conn.log, http.log, dns.log, ssl.log DC0085 Network Traffic Content AN1228 1
conn.log, icmp.log DC0078 Network Traffic Flow AN1258 1
conn.log, ssl.log DC0085 Network Traffic Content AN1190 1
connection attempts DC0082 Network Connection Creation AN1231 1
connection metadata DC0078 Network Traffic Flow AN0169 1
connection: Inbound connections to SSH or VPN ports DC0082 Network Connection Creation AN1005 1
connection: SMB connections to multiple internal hosts DC0082 Network Connection Creation AN0515 1
connection: TCP connections to ports 139/445 to multiple hosts DC0082 Network Connection Creation AN0514 1
container egress to unknown IPs/domains DC0085 Network Traffic Content AN1317 1
dns, ssl, conn DC0085 Network Traffic Content AN1226 1
dns.log DC0085 Network Traffic Content AN1121 AN1122 AN1124 AN1125 1
flow records DC0078 Network Traffic Flow AN0424 AN0426 1
ftp.log, conn.log DC0085 Network Traffic Content AN1170 1
ftp.log, conn.log, smb_files.log DC0085 Network Traffic Content AN1173 1
ftp.log, smb_files.log DC0085 Network Traffic Content AN1169 1
host switch egress data DC0085 Network Traffic Content AN1392 1
http, dns, smb, ssl logs DC0085 Network Traffic Content AN1225 1
http.log DC0085 Network Traffic Content AN0285 AN0426 2
http.log, conn.log DC0085 Network Traffic Content AN0076 AN2031 2
http.log, files.log DC0085 Network Traffic Content AN0058 1
http.log, ftp.log DC0085 Network Traffic Content AN0423 AN0424 AN0425 1
http.log, ssl.log DC0085 Network Traffic Content AN0075 1
http.log, ssl.log, websocket.log DC0085 Network Traffic Content AN0079 1
http.request: HTTP requests and responses for specific script resources, unexpected content-types (application/octet-stream for script URLs), suspicious referrers, or obfuscated javascript resources DC0085 Network Traffic Content AN0498 1
http/file-xfer: Inbound/outbound transfer of ELF shared objects DC0085 Network Traffic Content AN0053 1
http/file-xfer: Outbound transfer of large video-like MIME types soon after capture DC0085 Network Traffic Content AN0569 1
http: Base64/MIME looking payloads from ESXi host IP DC0085 Network Traffic Content AN0348 1
http: HTTP bodies from ESXi host IPs containing long, non-standard tokens DC0085 Network Traffic Content AN0930 1
http: HTTP bodies/headers contain long tokens with non-standard alphabets or constant-size periodic POSTs DC0085 Network Traffic Content AN0928 1
http: HTTP body contains long Base64 sections DC0085 Network Traffic Content AN0347 1
http: HTTP body or headers contain long Base64 sections; gzip/deflate + Base64 DC0085 Network Traffic Content AN0346 1
http: suspicious long tokens with custom alphabets in body/headers DC0085 Network Traffic Content AN0929 1
http::post: Outbound HTTP POST from host shortly after DB export activity DC0085 Network Traffic Content AN0676 1
http::request: Network connection to package registry or C2 from interpreter shortly after install DC0085 Network Traffic Content AN0698 1
http::request: Outbound HTTP initiated by Python interpreter DC0085 Network Traffic Content AN0713 1
http::response: HTTP responses with suspicious content-type for scripts, long obfuscated javascript bodies, or redirects to exploit kit domains DC0085 Network Traffic Content AN0499 1
icmp.log, weird.log DC0085 Network Traffic Content AN1255 1
large HTTPS POST requests to text storage domains DC0085 Network Traffic Content AN0788 1
large HTTPS POST requests to webhook endpoints DC0085 Network Traffic Content AN0437 1
large HTTPS outbound uploads DC0078 Network Traffic Flow AN1572 1
large outbound HTTPS uploads to repo domains DC0078 Network Traffic Flow AN0896 1
large outbound data flows or long-duration connections DC0078 Network Traffic Flow AN0081 1
large transfer from management IPs to unauthorized host DC0085 Network Traffic Content AN1159 1
large upload to firmware interface port or path DC0085 Network Traffic Content AN0477 1
ldap.log DC0085 Network Traffic Content AN1026 1
log entries indicating network connection initiation on macOS DC0082 Network Connection Creation AN2065 1
mirror/SPAN port DC0085 Network Traffic Content AN1172 1
mqtt.log / xmpp.log (custom log feeds) DC0085 Network Traffic Content AN0002 1
mqtt.log or AMQP custom log DC0085 Network Traffic Content AN0003 1
mqtt.log, xmpp.log, amqp.log DC0085 Network Traffic Content AN0005 1
network_flow: bytes_out >> bytes_in, fixed packet sizes/intervals to non-approved CIDRs DC0078 Network Traffic Flow AN0930 1
new outbound connection from browser/office lineage DC0082 Network Connection Creation AN1315 1
new outbound connection from exploited lineage DC0082 Network Connection Creation AN1316 1
outbound connections from host during or immediately after image build DC0082 Network Connection Creation AN1261 1
outbound connections to RMM services or to unusual destination ports DC0082 Network Connection Creation AN0715 1
outbound egress from web host after suspicious request DC0085 Network Traffic Content AN0221 1
packet capture or DPI logs DC0085 Network Traffic Content AN0246 1
pf firewall logs DC0078 Network Traffic Flow AN0206 AN0924 2
port 5900 inbound DC0078 Network Traffic Flow AN0504 1
query: High-volume LDAP traffic with filters targeting groupPolicyContainer attributes DC0085 Network Traffic Content AN0152 1
remote CLI session detection DC0085 Network Traffic Content AN0399 1
remote access DC0082 Network Connection Creation AN1084 1
remote login and transfer DC0085 Network Traffic Content AN0196 1
session behavior DC0085 Network Traffic Content AN0032 1
session stats with bytes_out > bytes_in DC0078 Network Traffic Flow AN0989 1
smb_command: TreeConnectAndX to \\*\IPC$ / srvsvc or Trans2/NT_CREATE for listing shares DC0021 OS API Execution AN0514 1
smb_files.log DC0102 Network Share Access AN1299 1
smtp.log DC0085 Network Traffic Content AN0379 1
smtp.log, conn.log DC0085 Network Traffic Content AN0380 AN0382 1
ssh connections originating from third-party CIDRs DC0085 Network Traffic Content AN1345 1
ssh/smb connections to internal resources from third-party devices DC0085 Network Traffic Content AN1346 1
ssl.log DC0085 Network Traffic Content AN0101 1
ssl.log (for TLS handshake analysis), dns.log (tunneling indicators) DC0085 Network Traffic Content AN1390 1
ssl.log + http.log DC0085 Network Traffic Content AN0565 1
ssl.log - Certificate Analysis DC0085 Network Traffic Content AN1413 1
ssl.log, conn.log DC0085 Network Traffic Content AN1414 1
ssl.log, x509.log DC0085 Network Traffic Content AN1415 1
sustained outbound HTTPS sessions with high data volume DC0078 Network Traffic Flow AN1512 1
uncommon ports DC0078 Network Traffic Flow AN1376 1
unexpected network activity initiated shortly after shell session starts DC0085 Network Traffic Content AN0059 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1001 Data Obfuscationcommand and control02
T1001.001 Junk Datacommand and control00
T1001.002 Steganographycommand and control00
T1001.003 Protocol or Service Impersonationcommand and control20
T1008 Fallback Channelscommand and control40
T1011 Exfiltration Over Other Network Mediumexfiltration04
T1020 Automated Exfiltrationexfiltration100
T1021.004 SSHlateral movement52
T1021.005 VNClateral movement10
T1027.004 Compile After Deliverystealth60
T1027.008 Stripped Payloadsstealth00
T1027.017 SVG Smugglingstealth00
T1027.018 Invisible Unicodestealth00
T1029 Scheduled Transferexfiltration00
T1030 Data Transfer Size Limitsexfiltration20
T1036.012 Browser Fingerprintstealth00
T1041 Exfiltration Over C2 Channelexfiltration512
T1046 Network Service Discoverydiscovery207
T1048 Exfiltration Over Alternative Protocolexfiltration124
T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocolexfiltration10
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocolexfiltration00
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocolexfiltration91
T1056 Input Capturecollection, credential access23
T1056.001 Keyloggingcollection, credential access31
T1056.003 Web Portal Capturecollection, credential access00
T1059.004 Unix Shellexecution1814
T1059.008 Network Device CLIexecution00
T1069.002 Domain Groupsdiscovery150
T1070.005 Network Share Connection Removalstealth40
T1070.007 Clear Network Connection History and Configurationsstealth00
T1071 Application Layer Protocolcommand and control71
T1071.001 Web Protocolscommand and control4210
T1071.002 File Transfer Protocolscommand and control01
T1071.003 Mail Protocolscommand and control00
T1071.004 DNScommand and control170
T1071.005 Publish/Subscribe Protocolscommand and control00
T1072 Software Deployment Toolsexecution, lateral movement40
T1074.002 Remote Data Stagingcollection00
T1080 Taint Shared Contentlateral movement00
T1087.002 Domain Accountdiscovery215
T1090 Proxycommand and control223
T1090.001 Internal Proxycommand and control61
T1090.002 External Proxycommand and control20
T1090.003 Multi-hop Proxycommand and control30
T1090.004 Domain Frontingcommand and control10
T1095 Non-Application Layer Protocolcommand and control30
T1102 Web Servicecommand and control130
T1102.001 Dead Drop Resolvercommand and control40
T1102.002 Bidirectional Communicationcommand and control40
T1105 Ingress Tool Transfercommand and control8735
T1125 Video Capturecollection10
T1129 Shared Modulesexecution20
T1132 Data Encodingcommand and control00
T1132.001 Standard Encodingcommand and control40
T1132.002 Non-Standard Encodingcommand and control00
T1133 External Remote Servicespersistence, initial access2025
T1135 Network Share Discoverydiscovery70
T1136.002 Domain Accountpersistence60
T1176 Software Extensionspersistence10
T1176.001 Browser Extensionspersistence20
T1176.002 IDE Extensionspersistence00
T1187 Forced Authenticationcredential access90
T1189 Drive-by Compromiseinitial access321
T1190 Exploit Public-Facing Applicationinitial access149157
T1195 Supply Chain Compromiseinitial access11
T1195.001 Compromise Software Dependencies and Development Toolsinitial access20
T1195.002 Compromise Software Supply Chaininitial access172
T1199 Trusted Relationshipinitial access21
T1200 Hardware Additionsinitial access30
T1204 User Executionexecution102
T1204.001 Malicious Linkexecution411
T1204.003 Malicious Imageexecution00
T1204.004 Malicious Copy and Pasteexecution60
T1204.005 Malicious Libraryexecution00
T1205 Traffic Signalingstealth, persistence, command and control00
T1205.001 Port Knockingstealth, persistence, command and control00
T1205.002 Socket Filtersstealth, persistence, command and control00
T1207 Rogue Domain Controllerdefense impairment20
T1210 Exploitation of Remote Serviceslateral movement154
T1213.006 Databasescollection00
T1219.001 IDE Tunnelingcommand and control00
T1219.002 Remote Desktop Softwarecommand and control460
T1491.002 External Defacementimpact01
T1495 Firmware Corruptionimpact12
T1496 Resource Hijackingimpact1319
T1496.001 Compute Hijackingimpact00
T1496.002 Bandwidth Hijackingimpact00
T1498 Network Denial of Serviceimpact38
T1498.002 Reflection Amplificationimpact00
T1499.001 OS Exhaustion Floodimpact10
T1499.002 Service Exhaustion Floodimpact02
T1499.003 Application Exhaustion Floodimpact00
T1499.004 Application or System Exploitationimpact32
T1505 Server Software Componentpersistence12
T1505.003 Web Shellpersistence3526
T1542.004 ROMMONkitstealth, persistence00
T1542.005 TFTP Bootstealth, persistence01
T1546.004 Unix Shell Configuration Modificationprivilege escalation, persistence10
T1546.018 Python Startup Hookspersistence, privilege escalation00
T1552 Unsecured Credentialscredential access134
T1557 Adversary-in-the-Middlecredential access, collection104
T1557.001 Name Resolution Poisoning and SMB Relaycredential access, collection101
T1557.002 ARP Cache Poisoningcredential access, collection00
T1557.003 DHCP Spoofingcredential access, collection10
T1557.004 Evil Twincredential access, collection00
T1563 Remote Service Session Hijackinglateral movement00
T1566.001 Spearphishing Attachmentinitial access247
T1566.002 Spearphishing Linkinitial access45
T1566.003 Spearphishing via Serviceinitial access00
T1567 Exfiltration Over Web Serviceexfiltration123
T1567.001 Exfiltration to Code Repositoryexfiltration20
T1567.002 Exfiltration to Cloud Storageexfiltration140
T1567.003 Exfiltration to Text Storage Sitesexfiltration00
T1567.004 Exfiltration Over Webhookexfiltration00
T1573 Encrypted Channelcommand and control60
T1573.001 Symmetric Cryptographycommand and control03
T1573.002 Asymmetric Cryptographycommand and control00
T1599 Network Boundary Bridgingdefense impairment00
T1599.001 Network Address Translation Traversaldefense impairment10
T1600 Weaken Encryptiondefense impairment00
T1600.001 Reduce Key Spacedefense impairment00
T1600.002 Disable Crypto Hardwaredefense impairment00
T1602 Data from Configuration Repositorycollection01
T1602.001 SNMP (MIB Dump)collection00
T1602.002 Network Device Configuration Dumpcollection00
T1612 Build Image on Hoststealth00
T1615 Group Policy Discoverydiscovery50
T1659 Content Injectioninitial access, command and control00
T1665 Hide Infrastructurecommand and control00
T1686.002 Network Device Firewalldefense impairment20
T1687 Exploitation for Defense Impairmentdefense impairment00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2009-3960Adobe BlazeDS T1190 Mapped
CVE-2009-4324Adobe Acrobat and Reader T1071.001 Mapped
CVE-2010-0188Adobe Reader and Acrobat T1105 T1189 Mapped
CVE-2010-1297Adobe Flash Player T1105 T1189 Mapped
CVE-2010-2861Adobe ColdFusion T1105 T1190 Mapped
CVE-2011-0611Adobe Flash Player T1105 Mapped
CVE-2012-0754Adobe Flash Player T1105 Mapped
CVE-2012-0767Adobe Flash Player T1204.001 Mapped
CVE-2012-1535Adobe Flash Player T1105 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2013-0625Adobe ColdFusion T1190 Mapped
CVE-2013-0629Adobe ColdFusion T1190 Mapped
CVE-2013-0631Adobe ColdFusion T1190 Mapped
CVE-2013-0632Adobe ColdFusion T1190 Mapped
CVE-2013-0640Adobe Reader and Acrobat T1566.001 Mapped
CVE-2013-0641Adobe Reader T1048 T1105 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1059.004 T1133 T1190 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1059.004 T1133 T1190 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 T1499.004 Mapped
CVE-2015-3113Adobe Flash Player T1071.001 Mapped
CVE-2015-5119Adobe Flash Player T1071.001 T1105 T1204.001 T1566.002 Mapped
CVE-2015-8651Adobe Flash Player T1105 T1189 Mapped
CVE-2016-0984Adobe Flash Player and AIR T1105 Mapped
CVE-2016-10033PHP PHPMailer T1059.004 T1190 Mapped
CVE-2016-1019Adobe Flash Player T1105 T1189 Mapped
CVE-2016-4117Adobe Flash Player T1105 Mapped
CVE-2016-4437Apache Shiro T1190 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2017-11292Adobe Flash Player T1105 T1566.001 Mapped
CVE-2017-11882Microsoft Office T1566.001 Mapped
CVE-2017-12637SAP NetWeaver T1190 Mapped
CVE-2017-5638Apache Struts T1190 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1048 T1542.005 Mapped
CVE-2017-9805Apache Struts T1190 Mapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1190 T1496 Mapped
CVE-2018-11776Apache Struts T1190 T1496 Mapped
CVE-2018-13379Fortinet FortiOS T1190 Mapped
CVE-2018-15961Adobe ColdFusion T1190 T1491.002 Mapped
CVE-2018-15982Adobe Flash Player T1105 Mapped
CVE-2018-4878Adobe Flash Player T1041 Mapped
CVE-2018-4939Adobe ColdFusion T1133 T1190 Mapped
CVE-2018-6789Exim Exim T1190 Mapped
CVE-2018-7600Drupal Drupal Core T1190 T1496 Mapped
CVE-2019-0604Microsoft SharePoint T1041 T1190 T1505.003 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1059.004 T1133 T1498 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1133 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1046 T1190 Mapped
CVE-2019-13608Citrix StoreFront Server T1046 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1190 Mapped
CVE-2019-17558Apache Solr T1190 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1041 T1190 T1496 T1505.003 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1133 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1090 T1133 Mapped
CVE-2019-5591Fortinet FortiOS T1133 T1557 Mapped
CVE-2020-0688Microsoft Exchange Server T1190 T1505.003 Mapped
CVE-2020-1472Microsoft Netlogon T1087.002 T1133 Mapped
CVE-2020-15505Ivanti MobileIron Multiple Products T1190 Mapped
CVE-2020-17530Apache Struts T1190 Mapped
CVE-2020-25506D-Link DNS-320 Device T1133 Mapped
CVE-2020-29557D-Link DIR-825 R1 Devices T1190 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1204.001 Mapped
CVE-2020-5902F5 BIG-IP T1133 T1190 T1552 Stale
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1056 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1056 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1133 T1496 Mapped
CVE-2021-1497Cisco HyperFlex HX T1133 Mapped
CVE-2021-1498Cisco HyperFlex HX T1133 Mapped
CVE-2021-21972VMware vCenter Server T1190 Mapped
CVE-2021-21973VMware vCenter Server and Cloud Foundation T1046 T1190 Mapped
CVE-2021-21975VMware vRealize Operations Manager API T1190 Mapped
CVE-2021-22005VMware vCenter Server T1190 Mapped
CVE-2021-22017VMware vCenter Server T1090.001 T1190 Mapped
CVE-2021-22204Perl Exiftool T1190 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1190 T1496 T1498 Mapped
CVE-2021-22893Ivanti Pulse Connect Secure T1190 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1090 T1133 T1190 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1496 Mapped
CVE-2021-26085Atlassian Confluence Server T1190 Mapped
CVE-2021-26855Microsoft Exchange Server T1090 T1133 T1505.003 Mapped
CVE-2021-26857Microsoft Exchange Server T1133 T1505.003 Mapped
CVE-2021-26858Microsoft Exchange Server T1190 T1505.003 Mapped
CVE-2021-27065Microsoft Exchange Server T1190 T1505.003 Mapped
CVE-2021-27102Accellion FTA T1190 Mapped
CVE-2021-27103Accellion FTA T1190 Mapped
CVE-2021-27104Accellion FTA T1190 Mapped
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPN software T1190 T1505.003 Mapped
CVE-2021-31166Microsoft HTTP Protocol Stack T1190 Mapped
CVE-2021-3129Laravel Ignition T1190 Mapped
CVE-2021-34473Microsoft Exchange Server T1048.003 T1190 Mapped
CVE-2021-34523Microsoft Exchange Server T1190 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1071.001 T1105 T1190 T1496 Mapped
CVE-2021-35464ForgeRock Access Management (AM) T1190 Mapped
CVE-2021-36380Sunhillo SureLine T1059.004 T1190 Mapped
CVE-2021-37415Zoho ManageEngine ServiceDesk Plus (SDP) T1190 Mapped
CVE-2021-39144XStream XStream T1190 Mapped
CVE-2021-39226Grafana Labs Grafana T1190 Mapped
CVE-2021-40449Microsoft Windows T1071.001 T1573.001 Mapped
CVE-2021-40539Zoho ManageEngine T1087.002 T1190 T1505.003 T1573.001 Mapped
CVE-2021-40655D-Link DIR-605 Router T1190 Mapped
CVE-2021-41773Apache HTTP Server T1210 Mapped
CVE-2021-42013Apache HTTP Server T1210 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1087.002 T1190 T1505.003 T1573.001 Mapped
CVE-2021-44228Apache Log4j2 T1190 T1496 T1505.003 Mapped
CVE-2021-44515Zoho Desktop Central T1105 T1190 Mapped
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) T1190 T1195.002 Mapped
CVE-2021-45382D-Link Multiple Routers T1071 T1190 T1499.002 Mapped
CVE-2022-0028Palo Alto Networks PAN-OS T1190 T1498 Mapped
CVE-2022-1040Sophos Firewall T1190 T1557 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 T1133 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 T1190 Mapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1190 Mapped
CVE-2022-20821Cisco IOS XR T1190 Mapped
CVE-2022-21971Microsoft Windows T1204.001 Mapped
CVE-2022-22947VMware Spring Cloud Gateway T1190 Mapped
CVE-2022-22954VMware Workspace ONE Access and Identity Manager T1505.003 Mapped
CVE-2022-22963VMware Tanzu Spring Cloud T1190 T1505.003 Mapped
CVE-2022-22965VMware Spring Framework T1190 Mapped
CVE-2022-23131Zabbix Frontend T1190 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1190 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1204.001 Mapped
CVE-2022-26134Atlassian Confluence Server/Data Center T1190 Mapped
CVE-2022-26258D-Link DIR-820L T1190 T1499.002 Mapped
CVE-2022-26500Veeam Backup & Replication T1048 T1190 Mapped
CVE-2022-26501Veeam Backup & Replication T1048 T1190 Mapped
CVE-2022-28810Zoho ManageEngine T1190 Mapped
CVE-2022-29303SolarView Compact T1496 T1505 Mapped
CVE-2022-29464WSO2 Multiple Products T1190 T1496 Mapped
CVE-2022-30190Microsoft Windows T1105 Mapped
CVE-2022-3038Google Chromium Network Service T1204.001 Mapped
CVE-2022-3075Google Chromium Mojo T1204.001 Mapped
CVE-2022-35914Teclib GLPI T1190 Mapped
CVE-2022-36804Atlassian Bitbucket Server and Data Center T1190 Mapped
CVE-2022-39197Fortra Cobalt Strike T1190 Mapped
CVE-2022-40684Fortinet Multiple Products T1190 Mapped
CVE-2022-41033Microsoft Windows COM+ Event System Service T1566.001 Mapped
CVE-2022-41082Microsoft Exchange Server T1505.003 T1567 Mapped
CVE-2022-42475Fortinet FortiOS T1071.001 T1190 Mapped
CVE-2022-42948Fortra Cobalt Strike T1190 Mapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) Server T1190 Mapped
CVE-2022-47966Zoho ManageEngine T1190 Mapped
CVE-2023-0669Fortra GoAnywhere MFT T1190 T1210 Mapped
CVE-2023-1389TP-Link Archer AX21 T1041 T1496 T1498 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1505.003 Mapped
CVE-2023-20198Cisco IOS XE Web UI T1190 Mapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense T1133 Mapped
CVE-2023-20867VMware Tools T1105 Mapped
CVE-2023-20887VMware Aria Operations for Networks T1190 Mapped
CVE-2023-2136Google Chromium Skia T1204.001 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1190 Mapped
CVE-2023-22518Atlassian Confluence Data Center and Server T1105 T1190 Mapped
CVE-2023-22527Atlassian Confluence Data Center and Server T1496 Mapped
CVE-2023-22952SugarCRM Multiple Products T1190 T1505.003 Stale
CVE-2023-2533PaperCut NG/MF T1566.002 Mapped
CVE-2023-26359Adobe ColdFusion T1190 Mapped
CVE-2023-26360Adobe ColdFusion T1046 T1071.001 T1105 T1190 T1505.003 Mapped
CVE-2023-27350PaperCut MF/NG T1105 T1190 Mapped
CVE-2023-27524Apache Superset T1190 Mapped
CVE-2023-27532Veeam Backup & Replication T1133 Mapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN T1190 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1041 T1105 T1566.001 Mapped
CVE-2023-29298Adobe ColdFusion T1190 Mapped
CVE-2023-29300Adobe ColdFusion T1105 T1190 Mapped
CVE-2023-29492Novi Survey Novi Survey T1190 Mapped
CVE-2023-32315Ignite Realtime Openfire T1087.002 T1496 T1505.003 Mapped
CVE-2023-33246Apache RocketMQ T1190 Mapped
CVE-2023-34362Progress MOVEit Transfer T1105 T1190 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1190 Mapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) T1190 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1087.002 T1105 T1190 Mapped
CVE-2023-36844Juniper Junos OS T1190 Mapped
CVE-2023-36845Juniper Junos OS T1190 Mapped
CVE-2023-36846Juniper Junos OS T1190 Mapped
CVE-2023-36847Juniper Junos OS T1190 Mapped
CVE-2023-36851Juniper Junos OS T1190 Mapped
CVE-2023-38035Ivanti Sentry T1046 T1071.001 T1105 T1190 T1496 T1557.001 Mapped
CVE-2023-38203Adobe ColdFusion T1105 T1190 Mapped
CVE-2023-38205Adobe ColdFusion T1190 Mapped
CVE-2023-38831RARLAB WinRAR T1041 T1059.004 T1105 T1204 Mapped
CVE-2023-38950ZKTeco BioTime T1190 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1021.004 T1059.004 T1133 Mapped
CVE-2023-40044Progress WS_FTP Server T1071.002 Mapped
CVE-2023-42793JetBrains TeamCity T1190 Mapped
CVE-2023-43770Roundcube Webmail T1189 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1059.004 Mapped
CVE-2023-44487IETF HTTP/2 T1190 Mapped
CVE-2023-46604Apache ActiveMQ T1059.004 T1190 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1190 T1505.003 Mapped
CVE-2023-47565QNAP VioStor NVR T1496 T1498 Mapped
CVE-2023-48365Qlik Sense T1133 T1190 Mapped
CVE-2023-48788Fortinet FortiClient EMS T1105 T1190 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1190 T1552 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1496 T1498 Mapped
CVE-2023-5217Google Chromium libvpx T1204.001 Mapped
CVE-2023-5631Roundcube Webmail T1041 T1204.001 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 Mapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcel T1105 T1190 Mapped
CVE-2024-0769D-Link DIR-859 Router T1190 Mapped
CVE-2024-11120GeoVision Multiple Devices T1133 T1498 Mapped
CVE-2024-11182MDaemon Email Server T1567 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1190 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1190 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1190 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1190 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1552 Mapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) T1190 Mapped
CVE-2024-21413Microsoft Office Outlook T1566.002 Mapped
CVE-2024-21762Fortinet FortiOS T1190 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1190 T1505.003 T1552 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1190 T1505.003 Mapped
CVE-2024-23692Rejetto HTTP File Server T1105 T1496 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1059.004 Mapped
CVE-2024-27198JetBrains TeamCity T1190 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1041 T1059.004 T1566.002 Mapped
CVE-2024-34102Adobe Commerce and Magento Open Source T1190 Mapped
CVE-2024-38112Microsoft Windows T1189 T1204.001 Mapped
CVE-2024-38475Apache HTTP Server T1190 Mapped
CVE-2024-40890Zyxel DSL CPE Devices T1011 Mapped
CVE-2024-40891Zyxel DSL CPE Devices T1011 Mapped
CVE-2024-42009Roundcube Webmail T1056 T1566.002 Mapped
CVE-2024-4358Progress Telerik Report Server T1190 Mapped
CVE-2024-45195Apache OFBiz T1133 Mapped
CVE-2024-4577PHP Group PHP T1041 T1071.001 T1190 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-48248NAKIVO Backup and Replication T1190 Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform T1190 Mapped
CVE-2024-49035Microsoft Partner Center T1195 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1071.001 T1105 T1195.002 Mapped
CVE-2024-50302Linux Kernel T1011 Mapped
CVE-2024-5274Google Chromium V8 T1189 Mapped
CVE-2024-53150Linux Kernel T1011 Mapped
CVE-2024-53704SonicWall SonicOS T1199 Mapped
CVE-2024-54085AMI MegaRAC SPx T1210 T1495 Mapped
CVE-2024-55550Mitel MiCollab T1041 T1190 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1190 Mapped
CVE-2025-0108Palo Alto Networks PAN-OS T1190 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1046 T1190 Mapped
CVE-2025-04117-Zip 7-Zip T1566.001 Mapped
CVE-2025-1316Edimax IC-7100 IP Camera T1190 Mapped
CVE-2025-21480Qualcomm Multiple Chipsets T1495 Mapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1190 Mapped
CVE-2025-23006SonicWall SMA1000 Appliances T1190 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-24993Microsoft Windows T1204 Mapped
CVE-2025-25257Fortinet FortiWeb T1059.004 T1190 Mapped
CVE-2025-27363FreeType FreeType T1499.004 Mapped
CVE-2025-31200Apple Multiple Products T1001 T1105 T1557 Stale
CVE-2025-31201Apple Multiple Products T1001 T1105 T1557 Stale
CVE-2025-31324SAP NetWeaver T1505.003 T1602 Mapped
CVE-2025-32433Erlang Erlang/OTP T1021.004 Mapped
CVE-2025-32756Fortinet Multiple Products T1041 T1046 T1133 Mapped
CVE-2025-33053Microsoft Windows T1041 T1056.001 T1566.001 Mapped
CVE-2025-34028Commvault Command Center T1190 Mapped
CVE-2025-35939Craft CMS Craft CMS T1190 T1505.003 Mapped
CVE-2025-3928Commvault Web Server T1505.003 Mapped
CVE-2025-42599Qualitia Active! Mail T1190 Mapped
CVE-2025-42999SAP NetWeaver T1190 T1505.003 Mapped
CVE-2025-43200Apple Multiple Products T1105 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1190 T1505.003 Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) T1190 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1496 Mapped
CVE-2025-49704Microsoft SharePoint T1190 Mapped
CVE-2025-49706Microsoft SharePoint T1190 T1505 Mapped
CVE-2025-53770Microsoft SharePoint T1190 Mapped
CVE-2025-5419Google Chromium V8 T1189 Mapped
CVE-2025-54309CrushFTP CrushFTP T1567 Mapped
CVE-2025-5777Citrix NetScaler ADC and Gateway T1190 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1498 Mapped
CVE-2025-6554Google Chromium V8 T1189 Mapped
CVE-2025-6558Google Chromium T1189 Mapped