kevmap

Log sources › WinEventLog:System

WinEventLog:System

Inverted view: what can be detected if this is the log you have. Windows

20
channels
39
analytics
38
techniques
28
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Changes to applicationhost.config or DLLs loaded by w3wp.exe DC0038 Application Log Content AN0184 1
EventCode=1000 DC0038 Application Log Content AN0327 1
EventCode=1006 DC0042 Drive Creation AN0247 AN0841 2
EventCode=1006, 10001 DC0042 Drive Creation AN0342 1
EventCode=106, 200 DC0005 Scheduled Job Metadata AN1118 1
EventCode=1341, 1342, 1020, 1063 DC0038 Application Log Content AN1290 1
EventCode=1502, 1503 DC0029 Script Execution AN0199 1
EventCode=2003 DC0042 Drive Creation AN0446 AN0616 AN1410 AN1567 4
EventCode=4016, 5312 DC0029 Script Execution AN1034 1
EventCode=5005 (WLAN), EventCode=302 (Bluetooth) DC0085 Network Traffic Content AN0212 1
EventCode=7031, 7034 DC0060 Service Creation AN0850 1
EventCode=7035 DC0041 Service Metadata AN0535 AN2038 2
EventCode=7036 DC0060 Service Creation AN0061 AN0274 AN0868 AN2043 4
EventCode=7040 DC0065 Service Modification AN1195 1
EventCode=7045 DC0060 Service Creation AN0243 AN0324 AN0355 AN0462 AN0875 AN0886 AN0909 AN1061 AN1211 AN1366 AN1369 AN1620 11
EventCode=8001 DC0082 Network Connection Creation AN1531 1
Kernel-PnP 410/400 device install, disk added DC0042 Drive Creation AN0185 1
Service stopped or RecoveryDisabled set via REAgentC DC0041 Service Metadata AN0933 1
System shutdowns due to bugcheck (Event ID 1001) or watchdog timer expirations DC0018 Host Status AN0584 1
Unexpected modification to lsass.exe or cryptdll.dll DC0061 File Modification AN0757 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1011 Exfiltration Over Other Network Mediumexfiltration04
T1011.001 Exfiltration Over Bluetoothexfiltration00
T1014 Rootkitstealth10
T1025 Data from Removable Mediacollection00
T1029 Scheduled Transferexfiltration00
T1036 Masqueradingstealth402
T1036.004 Masquerade Task or Servicestealth30
T1037.001 Logon Script (Windows)persistence, privilege escalation30
T1037.003 Network Logon Scriptpersistence, privilege escalation00
T1040 Network Sniffingcredential access, discovery92
T1052 Exfiltration Over Physical Mediumexfiltration00
T1052.001 Exfiltration over USBexfiltration00
T1056.001 Keyloggingcollection, credential access31
T1091 Replication Through Removable Medialateral movement, initial access16
T1092 Communication Through Removable Mediacommand and control00
T1197 BITS Jobsstealth, persistence, execution160
T1200 Hardware Additionsinitial access30
T1205.002 Socket Filtersstealth, persistence, command and control00
T1210 Exploitation of Remote Serviceslateral movement154
T1219 Remote Access Toolscommand and control61
T1219.003 Remote Access Hardwarecommand and control00
T1489 Service Stopimpact201
T1490 Inhibit System Recoveryimpact272
T1499 Endpoint Denial of Serviceimpact37
T1499.004 Application or System Exploitationimpact32
T1505.004 IIS Componentspersistence50
T1556.001 Domain Controller Authenticationdefense impairment, persistence, credential access00
T1557.003 DHCP Spoofingcredential access, collection10
T1563.002 RDP Hijackinglateral movement20
T1564.006 Run Virtual Instancestealth20
T1574.010 Services File Permissions Weaknessstealth, execution00
T1574.011 Services Registry Permissions Weaknessstealth, execution110
T1674 Input Injectionexecution00
T1685 Disable or Modify Toolsdefense impairment1640
T1685.001 Disable or Modify Windows Event Logdefense impairment280
T1685.003 Modify or Spoof Tool UIdefense impairment00
T1686.003 Windows Host Firewalldefense impairment200
T1687 Exploitation for Defense Impairmentdefense impairment00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2015-3043Adobe Flash Player T1499.004 Mapped
CVE-2018-4878Adobe Flash Player T1219 Mapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1499 Mapped
CVE-2021-32030ASUS Routers T1040 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1499 Mapped
CVE-2021-41773Apache HTTP Server T1210 Mapped
CVE-2021-42013Apache HTTP Server T1210 Mapped
CVE-2022-1040Sophos Firewall T1040 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 Mapped
CVE-2023-0669Fortra GoAnywhere MFT T1210 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1499 Mapped
CVE-2023-36884Microsoft Windows T1489 T1490 Stale
CVE-2023-44487IETF HTTP/2 T1499 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1499 Mapped
CVE-2024-40890Zyxel DSL CPE Devices T1011 Mapped
CVE-2024-40891Zyxel DSL CPE Devices T1011 Mapped
CVE-2024-50302Linux Kernel T1011 T1091 Mapped
CVE-2024-53104Linux Kernel T1091 Mapped
CVE-2024-53150Linux Kernel T1011 T1091 Mapped
CVE-2024-53197Linux Kernel T1091 Mapped
CVE-2024-54085AMI MegaRAC SPx T1210 T1499 Mapped
CVE-2025-21391Microsoft Windows T1490 Mapped
CVE-2025-24985Microsoft Windows T1091 Mapped
CVE-2025-24991Microsoft Windows T1091 Mapped
CVE-2025-27363FreeType FreeType T1499.004 Mapped
CVE-2025-33053Microsoft Windows T1056.001 Mapped
CVE-2025-42599Qualitia Active! Mail T1499 Mapped