kevmap

Log sources › saas:application

saas:application

Inverted view: what can be detected if this is the log you have. SaaS

2
channels
2
analytics
2
techniques
19
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
High-frequency invocation of SMS-related API endpoints from publicly accessible OTP or verification forms (e.g., Twilio: SendMessage, Cognito: AdminCreateUser) with irregular destination patterns. DC0038 Application Log Content AN0443 1
High-volume API calls or traffic via messaging or webhook service DC0038 Application Log Content AN0746 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1496 Resource Hijackingimpact1319
T1496.003 SMS Pumpingimpact00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1496 Mapped
CVE-2018-11776Apache Struts T1496 Mapped
CVE-2018-7600Drupal Drupal Core T1496 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1496 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1496 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1496 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1496 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1496 Mapped
CVE-2021-44228Apache Log4j2 T1496 Mapped
CVE-2022-29303SolarView Compact T1496 Mapped
CVE-2022-29464WSO2 Multiple Products T1496 Mapped
CVE-2023-1389TP-Link Archer AX21 T1496 Mapped
CVE-2023-22527Atlassian Confluence Data Center and Server T1496 Mapped
CVE-2023-32315Ignite Realtime Openfire T1496 Mapped
CVE-2023-38035Ivanti Sentry T1496 Mapped
CVE-2023-47565QNAP VioStor NVR T1496 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1496 Mapped
CVE-2024-23692Rejetto HTTP File Server T1496 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1496 Mapped