For a vulnerability being exploited right now, what do we actually know about detecting it?
kevmap joins CISA's Known Exploited Vulnerabilities catalogue to ATT&CK techniques, MITRE's detection strategies and log sources, and SigmaHQ rules — and shows, without guessing, where that chain breaks.
Mapped = 424 of 1674 (25.3%), from CTID Mappings Explorer pinned to KEV 2025-07-28 and ATT&CK 16.1, counting any mapping type. Counting only exploitation_technique: 410 (24.5%). Definitions.
283 CVEs have been added to KEV since the mapping snapshot of 2025-07-28. 0 of them have a mapping. The authoritative CVE → ATT&CK source is not keeping pace with the catalogue it describes. kevmap shows those entries as unmapped rather than filling the gap with inference — the obvious way to fill it produces noise.
What works: technique → detection
ATT&CK v19.2 publishes a detection strategy for 697 of 697 live techniques, through 1758 analytics naming 4182 concrete log source / channel pairs across 261 log sources. SigmaHQ adds 3312 rules tagged to 400 techniques. That half of the chain is dense, current and machine-checkable; the site traverses it exactly.
What is missing: CVE → technique
One public source maps KEV CVEs to ATT&CK: CTID's Mappings Explorer, 424 CVEs, last updated for KEV 2025-07-28 against ATT&CK 16.1. CISA's catalogue carries no technique field. CVE records carry CWE (1503 of 1674 KEV entries do) but CWE does not say how a thing is exploited, and the CAPEC bridge people use to pretend otherwise has not been updated since 2023-01-24.
Mapped but uncovered
Techniques that at least one KEV CVE maps to, for which MITRE publishes a detection strategy, and for which SigmaHQ has no rule. If you write detections, start here.
| Technique | Tactics | KEV CVEs | MITRE analytics |
|---|---|---|---|
| T1608.001 Upload Malware | resource development | 11 | 1 |
| T1011 Exfiltration Over Other Network Medium | exfiltration | 4 | 3 |
| T1497 Virtualization/Sandbox Evasion | stealth, discovery | 4 | 3 |
| T1037 Boot or Logon Initialization Scripts | persistence, privilege escalation | 3 | 5 |
| T1573.001 Symmetric Cryptography | command and control | 3 | 5 |
| T1001 Data Obfuscation | command and control | 2 | 3 |
| T1499.002 Service Exhaustion Flood | impact | 2 | 4 |
| T1530 Data from Cloud Storage | collection | 2 | 3 |
| T1584.005 Botnet | resource development | 2 | 1 |
| T1592 Gather Victim Host Information | reconnaissance | 2 | 1 |
| T1003.008 /etc/passwd and /etc/shadow | credential access | 1 | 1 |
| T1071.002 File Transfer Protocols | command and control | 1 | 5 |
Recently added to KEV
| Added | CVE | Vendor / product | State | Sigma |
|---|---|---|---|---|
| 2026-08-21 | CVE-2026-73570 | Synacor Zimbra Collaboration Suite (ZCS) | Unmapped | |
| 2026-08-20 | CVE-2026-72530 | TrueConf Server | Unmapped | |
| 2026-08-20 | CVE-2026-72529 | TrueConf Server | Unmapped | |
| 2026-08-19 | CVE-2026-64849 | MLflow MLflow | Unmapped | |
| 2026-08-18 | CVE-2026-65400 | Apple macOS | Unmapped | |
| 2026-08-18 | CVE-2026-59310 | Broadcom VMware vCenter | Unmapped | |
| 2026-08-18 | CVE-2026-55040 | Microsoft SharePoint | Unmapped | |
| 2026-08-18 | CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | Unmapped | |
| 2026-08-17 | CVE-2025-62593 | Ray-Project Ray | Unmapped | |
| 2026-08-11 | CVE-2026-72898 | Metabase Metabase | Unmapped | |
| 2026-08-11 | CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Unmapped | |
| 2026-08-11 | CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Unmapped | |
| 2026-08-07 | CVE-2026-8037 | Progress LoadMaster | Unmapped | |
| 2026-08-05 | CVE-2026-63077 | JetBrains TeamCity | Unmapped | |
| 2026-08-04 | CVE-2026-9198 | IBM Langflow | Unmapped | |
| 2026-08-04 | CVE-2026-34486 | Apache Tomcat | Unmapped | |
| 2026-08-04 | CVE-2026-18556 | N-able N-central | Unmapped | |
| 2026-08-03 | CVE-2026-18577 | N-able N-central | Unmapped | |
| 2026-07-29 | CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | Unmapped | |
| 2026-07-27 | CVE-2026-16812 | Arista VeloCloud Orchestrator | Unmapped |
Last 7 days (2026-08-17 → 2026-08-23): 9 added to KEV, 0 with an ATT&CK mapping, 0 with Sigma coverage via a mapped technique. Changes over time →