kevmap

TechniquesT1133 › AN1006

AN1006 Analytic 1006

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Unexpected inbound or outbound VNC/SSH/Screen Sharing connections from external sources → repeated failed logins followed by success → remote interactive sessions or abnormal file transfers.</p>
Detects
T1133 External Remote Services
Part of
DET0354 Behavior-chain detection for T1133 External Remote Services across Windows, Linux, macOS, Containers

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogRemote login (ssh) or screen sharing authentication attemptsDC0088 Logon Session Metadata
macos:unifiedlogInbound connections to VNC/SSH portsDC0082 Network Connection Creation
PF:LogsExternal traffic to remote access servicesDC0078 Network Traffic Flow

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
KnownVNCServersList of approved VNC/SSH sources.
TimeWindowTime correlation between failed attempts and success.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2014-6271GNU Bourne-Again Shell (Bash)Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash)Mapped
CVE-2018-4939Adobe ColdFusionMapped
CVE-2019-0708Microsoft Remote Desktop ServicesMapped
CVE-2019-11510Ivanti Pulse Connect SecureMapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP ApplianceMapped
CVE-2019-3396Atlassian Confluence Server and Data ServerMapped
CVE-2019-5591Fortinet FortiOSMapped
CVE-2020-1472Microsoft NetlogonMapped
CVE-2020-25506D-Link DNS-320 DeviceMapped
CVE-2020-5902F5 BIG-IPStale
CVE-2020-8515DrayTek Multiple Vigor RoutersMapped
CVE-2021-1497Cisco HyperFlex HXMapped
CVE-2021-1498Cisco HyperFlex HXMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26855Microsoft Exchange ServerMapped
CVE-2021-26857Microsoft Exchange ServerMapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat DefenseMapped
CVE-2023-27532Veeam Backup & ReplicationMapped
CVE-2023-39780ASUS RT-AX55 RoutersMapped
CVE-2023-48365Qlik SenseMapped
CVE-2024-11120GeoVision Multiple DevicesMapped
CVE-2024-45195Apache OFBizMapped
CVE-2025-32756Fortinet Multiple ProductsMapped