Log sources › WinEventLog:System
WinEventLog:System
Inverted view: what can be detected if this is the log you have. Windows
20
channels
39
analytics
38
techniques
28
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Changes to applicationhost.config or DLLs loaded by w3wp.exe |
DC0038 Application Log Content | AN0184 | 1 |
EventCode=1000 |
DC0038 Application Log Content | AN0327 | 1 |
EventCode=1006 |
DC0042 Drive Creation | AN0247 AN0841 | 2 |
EventCode=1006, 10001 |
DC0042 Drive Creation | AN0342 | 1 |
EventCode=106, 200 |
DC0005 Scheduled Job Metadata | AN1118 | 1 |
EventCode=1341, 1342, 1020, 1063 |
DC0038 Application Log Content | AN1290 | 1 |
EventCode=1502, 1503 |
DC0029 Script Execution | AN0199 | 1 |
EventCode=2003 |
DC0042 Drive Creation | AN0446 AN0616 AN1410 AN1567 | 4 |
EventCode=4016, 5312 |
DC0029 Script Execution | AN1034 | 1 |
EventCode=5005 (WLAN), EventCode=302 (Bluetooth) |
DC0085 Network Traffic Content | AN0212 | 1 |
EventCode=7031, 7034 |
DC0060 Service Creation | AN0850 | 1 |
EventCode=7035 |
DC0041 Service Metadata | AN0535 AN2038 | 2 |
EventCode=7036 |
DC0060 Service Creation | AN0061 AN0274 AN0868 AN2043 | 4 |
EventCode=7040 |
DC0065 Service Modification | AN1195 | 1 |
EventCode=7045 |
DC0060 Service Creation | AN0243 AN0324 AN0355 AN0462 AN0875 AN0886 AN0909 AN1061 AN1211 AN1366 AN1369 AN1620 | 11 |
EventCode=8001 |
DC0082 Network Connection Creation | AN1531 | 1 |
Kernel-PnP 410/400 device install, disk added |
DC0042 Drive Creation | AN0185 | 1 |
Service stopped or RecoveryDisabled set via REAgentC |
DC0041 Service Metadata | AN0933 | 1 |
System shutdowns due to bugcheck (Event ID 1001) or watchdog timer expirations |
DC0018 Host Status | AN0584 | 1 |
Unexpected modification to lsass.exe or cryptdll.dll |
DC0061 File Modification | AN0757 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2015-3043 | Adobe Flash Player | T1499.004 | Mapped |
| CVE-2018-4878 | Adobe Flash Player | T1219 | Mapped |
| CVE-2020-5735 | Amcrest Cameras and Network Video Recorder (NVR) | T1499 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1040 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1499 | Mapped |
| CVE-2021-41773 | Apache HTTP Server | T1210 | Mapped |
| CVE-2021-42013 | Apache HTTP Server | T1210 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1040 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1210 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1499 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1489 T1490 | Stale |
| CVE-2023-44487 | IETF HTTP/2 | T1499 | Mapped |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway | T1499 | Mapped |
| CVE-2024-40890 | Zyxel DSL CPE Devices | T1011 | Mapped |
| CVE-2024-40891 | Zyxel DSL CPE Devices | T1011 | Mapped |
| CVE-2024-50302 | Linux Kernel | T1011 T1091 | Mapped |
| CVE-2024-53104 | Linux Kernel | T1091 | Mapped |
| CVE-2024-53150 | Linux Kernel | T1011 T1091 | Mapped |
| CVE-2024-53197 | Linux Kernel | T1091 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1210 T1499 | Mapped |
| CVE-2025-21391 | Microsoft Windows | T1490 | Mapped |
| CVE-2025-24985 | Microsoft Windows | T1091 | Mapped |
| CVE-2025-24991 | Microsoft Windows | T1091 | Mapped |
| CVE-2025-27363 | FreeType FreeType | T1499.004 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1056.001 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1499 | Mapped |