kevmap

Log sources › auditd:PROCTITLE

auditd:PROCTITLE

Inverted view: what can be detected if this is the log you have. Linux

4
channels
4
analytics
4
techniques
1
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
command-line execution patterns for system discovery utilities (uname, hostname, ifconfig, netstat, lsof, ps, mount) DC0064 Command Execution AN1552 1
proctitle contains chmod, chown, chgrp, setfacl, or attr with suspicious parameters (777, 755, +x, -R) DC0064 Command Execution AN0998 1
proctitle contains chmod, chown, setfacl, or attr commands with suspicious parameters DC0064 Command Execution AN0835 1
scripting loop invoking sleep/ping DC0029 Script Execution AN1049 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1222 File and Directory Permissions Modificationdefense impairment21
T1222.002 Linux and Mac Permissionsdefense impairment40
T1480 Execution Guardrailsstealth00
T1678 Delay Executionstealth00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2022-22960VMware Multiple Products T1222 Mapped