kevmap

TechniquesT1068 › AN1419

AN1419 Analytic 1419

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects exploitation attempts targeting vulnerable kernel drivers or OS components, often followed by unusual process or token behavior.</p>
Detects
T1068 Exploitation for Privilege Escalation
Part of
DET0514 Detection Strategy for Exploitation for Privilege Escalation

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=6DC0079 Driver Load
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SecurityEventCode=4672DC0088 Logon Session Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
DriverNamePatternTargeted BYOVD drivers may vary based on campaign and tooling.
TimeWindowControls temporal linking of driver load → process spawn → privilege use.
ParentProcessPathParent-child relationships vary by exploitation vector (e.g., LOLBin vs. dropper).

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2014-0546Adobe Reader and AcrobatMapped
CVE-2019-0211Apache HTTP ServerMapped
CVE-2020-0069MediaTek Multiple ChipsetsMapped
CVE-2020-0787Microsoft WindowsMapped
CVE-2020-1472Microsoft NetlogonMapped
CVE-2021-22900Ivanti Pulse Connect SecureMapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU)Mapped
CVE-2021-32030ASUS RoutersMapped
CVE-2021-33739Microsoft WindowsMapped
CVE-2021-36934Microsoft WindowsMapped
CVE-2021-4034Red Hat PolkitMapped
CVE-2021-40449Microsoft WindowsMapped
CVE-2021-41379Microsoft WindowsMapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-21919Microsoft WindowsMapped
CVE-2022-21999Microsoft WindowsMapped
CVE-2022-22047Microsoft WindowsMapped
CVE-2022-22718Microsoft WindowsMapped
CVE-2022-22948VMware vCenter ServerMapped
CVE-2022-24521Microsoft WindowsMapped
CVE-2022-26904Microsoft WindowsMapped
CVE-2022-37969Microsoft WindowsMapped
CVE-2022-41033Microsoft Windows COM+ Event System ServiceMapped
CVE-2022-41073Microsoft WindowsMapped
CVE-2022-41125Microsoft WindowsMapped
CVE-2022-47966Zoho ManageEngineMapped
CVE-2023-20118Cisco Small Business RV Series RoutersMapped
CVE-2023-20273Cisco Cisco IOS XE Web UIMapped
CVE-2023-21674Microsoft WindowsMapped
CVE-2023-28229Microsoft Windows CNG Key Isolation ServiceMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2023-33538TP-Link Multiple RoutersMapped
CVE-2023-44221SonicWall SMA100 AppliancesMapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS)Mapped
CVE-2024-12987DrayTek Vigor RoutersMapped
CVE-2024-29059Microsoft .NET FrameworkMapped
CVE-2024-30051Microsoft DWM Core LibraryMapped
CVE-2024-37085VMware ESXiMapped
CVE-2024-38080Microsoft Windows Mapped
CVE-2024-41710Mitel SIP PhonesMapped
CVE-2024-41713Mitel MiCollabMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-4885Progress WhatsUp GoldMapped
CVE-2024-49035Microsoft Partner CenterMapped
CVE-2024-53104Linux KernelMapped
CVE-2024-53197Linux KernelMapped
CVE-2024-54085AMI MegaRAC SPxMapped
CVE-2024-55591Fortinet FortiOS and FortiProxyMapped
CVE-2025-0111Palo Alto Networks PAN-OSMapped
CVE-2025-0994Trimble CityworksMapped
CVE-2025-1976Broadcom Brocade Fabric OSMapped
CVE-2025-21333Microsoft WindowsMapped
CVE-2025-21334Microsoft WindowsMapped
CVE-2025-21335Microsoft WindowsMapped
CVE-2025-21391Microsoft WindowsMapped
CVE-2025-21418Microsoft WindowsMapped
CVE-2025-21590Juniper Junos OSMapped
CVE-2025-22225VMware ESXiMapped
CVE-2025-24085Apple Multiple ProductsMapped
CVE-2025-24993Microsoft WindowsMapped
CVE-2025-25181Advantive VeraCoreMapped
CVE-2025-25257Fortinet FortiWebMapped
CVE-2025-30400Microsoft WindowsMapped
CVE-2025-32701Microsoft WindowsMapped
CVE-2025-32706Microsoft WindowsMapped
CVE-2025-32709Microsoft WindowsMapped
CVE-2025-4632Samsung MagicINFO 9 ServerMapped
CVE-2025-47812Wing FTP Server Wing FTP ServerMapped
CVE-2025-54309CrushFTP CrushFTPMapped