kevmap

Log sources › saas:zoom

saas:zoom

Inverted view: what can be detected if this is the log you have. SaaS

5
channels
5
analytics
5
techniques
4
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
DisableMFA or RegisterNewFactor DC0010 User Account Modification AN0548 1
New user created DC0014 User Account Creation AN0901 1
Unexpected contact interaction preceding follow-on admin requests DC0038 Application Log Content AN2034 1
Zoom Admin Dashboard accessed from unfamiliar IP/device DC0067 Logon Session Creation AN0811 1
unusual web session tokens and automation patterns during login DC0038 Application Log Content AN1156 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1136.003 Cloud Accountpersistence30
T1538 Cloud Service Dashboarddiscovery00
T1552 Unsecured Credentialscredential access134
T1556.006 Multi-Factor Authenticationdefense impairment, persistence, credential access30
T1684 Social Engineeringstealth00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2020-5902F5 BIG-IP T1552 Stale
CVE-2023-49103ownCloud ownCloud graphapi T1552 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1552 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1552 Mapped