kevmap

For a vulnerability being exploited right now, what do we actually know about detecting it?

kevmap joins CISA's Known Exploited Vulnerabilities catalogue to ATT&CK techniques, MITRE's detection strategies and log sources, and SigmaHQ rules — and shows, without guessing, where that chain breaks.

1687
CVEs in KEV (2026.08.31)
25.1%
424 have a public ATT&CK mapping
74.9%
1263 have none — from any public source
6
mapped under ATT&CK 16.1 to a technique since revoked or deprecated
20
of 152 mapped techniques have no Sigma rule
Mapped 418 Stale 6 Unmapped 1263

Mapped = 424 of 1687 (25.1%), from CTID Mappings Explorer pinned to KEV 2025-07-28 and ATT&CK 16.1, counting any mapping type. Counting only exploitation_technique: 410 (24.3%). Definitions.

296 CVEs have been added to KEV since the mapping snapshot of 2025-07-28. 0 of them have a mapping. The authoritative CVE → ATT&CK source is not keeping pace with the catalogue it describes. kevmap shows those entries as unmapped rather than filling the gap with inference — the obvious way to fill it produces noise.

What works: technique → detection

ATT&CK v19.2 publishes a detection strategy for 697 of 697 live techniques, through 1758 analytics naming 4182 concrete log source / channel pairs across 261 log sources. SigmaHQ adds 3312 rules tagged to 400 techniques. That half of the chain is dense, current and machine-checkable; the site traverses it exactly.

Browse by log source → · Browse techniques →

What is missing: CVE → technique

One public source maps KEV CVEs to ATT&CK: CTID's Mappings Explorer, 424 CVEs, last updated for KEV 2025-07-28 against ATT&CK 16.1. CISA's catalogue carries no technique field. CVE records carry CWE (1512 of 1687 KEV entries do) but CWE does not say how a thing is exploited, and the CAPEC bridge people use to pretend otherwise has not been updated since 2023-01-24.

The gap, by vendor, product and year →

Mapped but uncovered

Techniques that at least one KEV CVE maps to, for which MITRE publishes a detection strategy, and for which SigmaHQ has no rule. If you write detections, start here.

TechniqueTacticsKEV CVEsMITRE analytics
T1608.001 Upload Malwareresource development111
T1011 Exfiltration Over Other Network Mediumexfiltration43
T1497 Virtualization/Sandbox Evasionstealth, discovery43
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation35
T1573.001 Symmetric Cryptographycommand and control35
T1001 Data Obfuscationcommand and control23
T1499.002 Service Exhaustion Floodimpact24
T1530 Data from Cloud Storagecollection23
T1584.005 Botnetresource development21
T1592 Gather Victim Host Informationreconnaissance21
T1003.008 /etc/passwd and /etc/shadowcredential access11
T1071.002 File Transfer Protocolscommand and control15

All 20 →

Recently added to KEV

AddedCVEVendor / productStateSigma
2026-08-31CVE-2026-82078PaperCut NG/MFUnmapped
2026-08-31CVE-2026-81578PaperCut NG/MFUnmapped
2026-08-27CVE-2026-66384JFrog ArtifactoryUnmapped
2026-08-27CVE-2026-53362Linux KernelUnmapped
2026-08-27CVE-2023-49105ownCloud ownCloudUnmapped
2026-08-26CVE-2026-8452Citrix NetScaler ADC and NetScaler GatewayUnmapped
2026-08-26CVE-2022-0995Linux KernelUnmapped
2026-08-26CVE-2021-23758Ajax.NET Professional Ajax.NET ProfessionalUnmapped
2026-08-26CVE-2019-1068Microsoft SQL ServerUnmapped
2026-08-26CVE-2015-5287Red Hat Automatic Bug Reporting ToolUnmapped
2026-08-26CVE-2015-3246Red Hat LibuserUnmapped
2026-08-25CVE-2026-60004Gitea GiteaUnmapped
2026-08-24CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-inUnmapped
2026-08-21CVE-2026-73570Synacor Zimbra Collaboration Suite (ZCS)Unmapped
2026-08-20CVE-2026-72530TrueConf ServerUnmapped
2026-08-20CVE-2026-72529TrueConf ServerUnmapped
2026-08-19CVE-2026-64849MLflow MLflowUnmapped
2026-08-18CVE-2026-65400Apple macOSUnmapped
2026-08-18CVE-2026-59310Broadcom VMware vCenterUnmapped
2026-08-18CVE-2026-55040Microsoft SharePointUnmapped

Last 7 days (2026-08-26 → 2026-09-01): 11 added to KEV, 0 with an ATT&CK mapping, 0 with Sigma coverage via a mapped technique. Changes over time →