kevmap

Log sources › auditd:FILE

auditd:FILE

Inverted view: what can be detected if this is the log you have. Linux

11
channels
11
analytics
11
techniques
3
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/home/*/.mozilla/firefox/*/logins.json OR /home/*/.config/google-chrome/*/Login Data DC0055 File Access AN0106 1
/proc/*/mem read attempt DC0055 File Access AN0157 1
Creation of hidden files (.*) in sensitive directories (/etc, /var, /usr/bin) DC0039 File Creation AN1385 1
File creation with name starting with '.' DC0039 File Creation AN0092 1
Modification of Display Manager configuration files (/etc/gdm3/*, /etc/lightdm/*) DC0061 File Modification AN1002 1
Modification or deletion of /etc/audit/audit.rules or /etc/audit/audit.conf DC0061 File Modification AN0171 1
create: Creation of .zip, .gz, .bz2 files in /tmp, /var/tmp, or /home directories DC0039 File Creation AN0748 1
create: Creation of archive files in /tmp, /var/tmp, or user home directories DC0039 File Creation AN0832 1
create: Creation of files ending in .tar, .gz, .bz2, .zip in /tmp or /var/tmp DC0039 File Creation AN1459 1
create: Creation of files with anomalous headers and entropy levels in /tmp or user directories DC0039 File Creation AN1214 1
create: New file created in system binaries or temp directories DC0039 File Creation AN0517 1

Techniques detectable from this source

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-40539Zoho ManageEngine T1560.001 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1560.001 Mapped
CVE-2024-4577PHP Group PHP T1570 Mapped