Log sources › auditd:SYSCALL
auditd:SYSCALL
Inverted view: what can be detected if this is the log you have. Containers, Linux, macOS
276
channels
344
analytics
331
techniques
418
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
ACCESS |
DC0035 Process Access | AN1420 | 1 |
AUDIT_SYSCALL (open, write, rename, unlink) |
DC0061 File Modification | AN0059 | 1 |
Access or modification to /lib/modules or creation of .ko files |
DC0039 File Creation | AN1243 | 1 |
Access to /var/lib/sss/secrets/secrets.ldb or .secrets.mkey |
DC0055 File Access | AN1444 | 1 |
Command line arguments including SPApplicationsDataType |
DC0064 Command Execution | AN1102 | 1 |
EXECVE |
DC0032 Process Creation | AN0312 | 1 |
Execution of binaries located in /etc/init.d/ or systemd service paths |
DC0032 Process Creation | AN0765 | 1 |
Execution of dpkg or rpm followed by fork/execve from within postinst, prerm, etc. |
DC0032 Process Creation | AN0939 | 1 |
Execution of dpkg, rpm, or other package manager with list flag |
DC0032 Process Creation | AN1101 | 1 |
Execution of insmod, modprobe, or rmmod commands by non-standard users or outside expected timeframes |
DC0064 Command Execution | AN1243 | 1 |
Execution of network stress tools or anomalies in socket/syscall behavior |
DC0032 Process Creation | AN1435 | 1 |
Execution of script interpreters by systemd timer (ExecStart) |
DC0064 Command Execution | AN0025 | 1 |
Execution of spoofing tools (e.g., hping3, nping, scapy) sending UDP packets to known amplifier ports |
DC0064 Command Execution | AN1141 | 1 |
Execution of xev, xdotool, or input activity emulators |
DC0064 Command Execution | AN1183 | 1 |
File creation events in /var/mail or /var/spool/mail exceeding baseline thresholds |
DC0039 File Creation | AN1009 | 1 |
File creations of *.qcow2, *.vdi, *.vmdk outside standard VM directories |
DC0039 File Creation | AN0910 | 1 |
High frequency of accept(), read(), or SSL_read() syscalls tied to nginx/apache processes |
DC0035 Process Access | AN0490 | 1 |
Inotify watch creation or auditctl changes on /etc/cron* or /lib/systemd/system/ |
DC0059 File Metadata | AN0025 | 1 |
Invocation of packet generation tools (e.g., hping3, nping) or fork bombs |
DC0032 Process Creation | AN1013 | 1 |
Kernel Device Events - USB Block Devices |
DC0042 Drive Creation | AN0617 | 1 |
LD_PRELOAD Logging |
DC0016 Module Load | AN0390 | 1 |
Modification of user shell profile or trap registration via echo/redirection (e.g., echo "trap 'malicious_cmd' INT" >> ~/.bashrc) |
DC0061 File Modification | AN1038 | 1 |
None |
DC0064 Command Execution | AN0213 AN1532 | 2 |
PATH |
DC0040 File Deletion DC0055 File Access DC0059 File Metadata DC0061 File Modification |
AN0134 AN0279 AN0393 AN0467 AN1217 AN1438 AN1613 | 7 |
PATH records referencing /dev/video* |
DC0055 File Access | AN0569 | 1 |
Process segfault or abnormal termination after invoking vulnerable syscall sequence |
DC0033 Process Termination | AN0851 | 1 |
Processes reading credential or token cache files |
DC0055 File Access | AN0720 | 1 |
Reads of ~/.bash_history, ~/.mozilla, or access to /dev/input |
DC0055 File Access | AN1183 | 1 |
Removable media mount notification |
DC0042 Drive Creation | AN0248 | 1 |
Rules capturing clock_gettime, time, gettimeofday syscalls when enabled |
DC0021 OS API Execution | AN0431 | 1 |
SYSCALL for usermod or /etc/group file modification |
DC0010 User Account Modification | AN0866 | 1 |
SYSCALL ptrace/mprotect |
DC0020 Process Modification | AN0914 | 1 |
SYSCALL record where exe contains passwd/userdel/chage and auid != root |
DC0032 Process Creation | AN0335 | 1 |
Unusual processes accessing or modifying cookie databases |
DC0055 File Access | AN0485 | 1 |
Use of fork/exec with DISPLAY unset or redirected |
DC0034 Process Metadata | AN0361 | 1 |
adduser |
DC0014 User Account Creation | AN1078 | 1 |
apache2 or nginx spawning sh, bash, or python interpreter |
DC0032 Process Creation | AN1109 | 1 |
bash/zsh of base64, tar, gzip, or openssl immediately after file write |
DC0064 Command Execution | AN0768 | 1 |
capset or setns |
DC0067 Logon Session Creation | AN1422 | 1 |
chattr, rm, shred, dd run on recovery directories or partitions |
DC0064 Command Execution | AN0934 | 1 |
chmod |
DC0061 File Modification | AN0783 AN0920 | 2 |
chmod, chown, setxattr, or file writes to /etc/ssl/* or /usr/local/share/ca-certificates/* |
DC0059 File Metadata | AN1247 | 1 |
chmod, execve |
DC0064 Command Execution | AN0307 | 1 |
chmod, write, create, open |
DC0061 File Modification | AN1056 | 1 |
chmod/chown to /etc/passwd or /etc/shadow |
DC0061 File Modification | AN1605 | 1 |
connect |
DC0082 Network Connection Creation | AN0145 AN0159 AN0227 AN0332 AN0368 AN0424 AN0729 AN0989 AN1390 AN1414 | 10 |
connect or sendto system call with burst pattern |
DC0078 Network Traffic Flow | AN0970 | 1 |
connect, execve, write |
DC0064 Command Execution | AN0166 | 1 |
connect/sendto |
DC0082 Network Connection Creation | AN0597 AN1190 | 2 |
creat |
DC0039 File Creation | AN0041 AN0765 AN0798 AN1096 AN1315 | 5 |
creat, open, write on /etc/systemd/system and /usr/lib/systemd/system |
DC0039 File Creation | AN0645 | 1 |
device event logs |
DC0042 Drive Creation | AN0343 | 1 |
dmesg |
DC0016 Module Load | AN1420 | 1 |
execution of known flash tools (e.g., flashrom, fwupd) |
DC0032 Process Creation | AN0475 | 1 |
execution of realmd, samba-tool, or ldapmodify with user-related arguments |
DC0064 Command Execution | AN0007 | 1 |
execution of ssh, scp, or sftp using previously unseen credentials or keys |
DC0002 User Account Authentication | AN0955 | 1 |
execution of systemctl or service with enable/start parameters |
DC0064 Command Execution | AN0701 | 1 |
execution of systemctl or service with enable/start/modify |
DC0064 Command Execution | AN1576 | 1 |
execution of tools like cat, grep, or awk on credential files |
DC0064 Command Execution | AN1154 | 1 |
execve |
DC0032 Process Creation | AN0003 AN0014 AN0022 AN0041 AN0049 AN0050 AN0067 AN0076 AN0096 AN0101 AN0114 AN0125 AN0134 AN0148 AN0174 AN0195 AN0205 AN0211 AN0220 AN0227 AN0230 AN0238 AN0253 AN0255 AN0259 AN0261 AN0279 AN0288 AN0293 AN0303 AN0307 AN0318 AN0332 AN0350 AN0356 AN0364 AN0368 AN0380 AN0390 AN0393 AN0412 AN0424 AN0456 AN0467 AN0508 AN0512 AN0532 AN0541 AN0565 AN0579 AN0585 AN0603 AN0624 AN0631 AN0649 AN0652 AN0658 AN0715 AN0725 AN0735 AN0738 AN0742 AN0779 AN0783 AN0798 AN0805 AN0812 AN0839 AN0863 AN0873 AN0904 AN0914 AN0920 AN0923 AN0944 AN0967 AN0970 AN0982 AN0984 AN0989 AN1026 AN1038 AN1041 AN1056 AN1058 AN1065 AN1071 AN1081 AN1114 AN1119 AN1122 AN1166 AN1170 AN1226 AN1230 AN1234 AN1250 AN1295 AN1304 AN1315 AN1354 AN1382 AN1390 AN1395 AN1408 AN1411 AN1414 AN1420 AN1429 AN1438 AN1441 AN1453 AN1463 AN1490 AN1492 AN1508 AN1529 AN1544 AN1549 AN1552 AN1600 AN1627 AN2031 | 120 |
execve call for modification of /etc/sudoers or writing to /var/db/sudo |
DC0061 File Modification | AN0142 | 1 |
execve call for sudo where euid != uid |
DC0034 Process Metadata | AN0142 | 1 |
execve call including 'nohup' or trailing '&' |
DC0064 Command Execution | AN0181 | 1 |
execve call with argv matching known disk enumeration commands (lsblk, parted, fdisk) |
DC0032 Process Creation | AN0537 | 1 |
execve calls for qemu-system*, kvm, or VBoxHeadless |
DC0032 Process Creation | AN0910 | 1 |
execve calls modifying HISTFILE or HISTCONTROL via unset/export |
DC0064 Command Execution | AN1555 | 1 |
execve calls modifying local mail filter configuration files |
DC0064 Command Execution | AN0553 | 1 |
execve calls to /usr/bin/locale or shell execution of $LANG |
DC0064 Command Execution | AN1562 | 1 |
execve calls to locale, timedatectl, or cat /etc/timezone |
DC0064 Command Execution | AN0120 | 1 |
execve calls to soffice.bin with suspicious macro execution flags |
DC0032 Process Creation | AN0035 | 1 |
execve calls with high-frequency or known bandwidth-intensive tools |
DC0032 Process Creation | AN0081 | 1 |
execve for proxy tools |
DC0032 Process Creation | AN1021 | 1 |
execve logging for /usr/bin/systemctl and systemd-run |
DC0032 Process Creation | AN0645 | 1 |
execve network tools |
DC0032 Process Creation | AN0031 | 1 |
execve of /bin/sh,/bin/bash,/usr/bin/curl,/usr/bin/python by service accounts (e.g., apache, mysql, nobody) immediately after inbound network activity. |
DC0032 Process Creation | AN0328 | 1 |
execve of base64|openssl|xxd|python|perl with arguments matching Base64 flags |
DC0032 Process Creation | AN0346 | 1 |
execve of curl, rsync, wget with internal knowledge base or IPs |
DC0064 Command Execution | AN1161 | 1 |
execve of dd or sed targeting /proc/*/mem |
DC0021 OS API Execution | AN1494 | 1 |
execve of interpreters (python, perl), custom binaries, or shell utilities with long arguments containing non-standard tokens |
DC0032 Process Creation | AN0928 | 1 |
execve of launchctl or pkill |
DC0032 Process Creation | AN0063 | 1 |
execve of re-parented process |
DC0032 Process Creation | AN1223 | 1 |
execve of sleep or ping command within script interpreted by bash/python |
DC0032 Process Creation | AN0397 | 1 |
execve of smbclient, smbmap, rpcclient, nmblookup, crackmapexec smb |
DC0032 Process Creation | AN0514 | 1 |
execve of system tools like dmidecode, lspci, lscpu, dmesg, systemd-detect-virt |
DC0032 Process Creation | AN0479 | 1 |
execve of systemctl or service stop |
DC0032 Process Creation | AN0062 | 1 |
execve on code or jetbrains-gateway with remote flags |
DC0032 Process Creation | AN0376 | 1 |
execve or nanosleep with no stdout/stderr I/O |
DC0032 Process Creation | AN1049 | 1 |
execve or socket/connect system calls for processes using RSA handshake |
DC0032 Process Creation | AN1497 | 1 |
execve or socket/connect system calls from processes using crypto libraries |
DC0032 Process Creation | AN0401 | 1 |
execve or syscall invoking vm artifact check commands (e.g., dmidecode, lspci, dmesg) |
DC0032 Process Creation | AN0128 | 1 |
execve syscalls for discovery commands (uname, hostname, id, whoami, ps, netstat, mount) with command-line parameter analysis |
DC0064 Command Execution | AN1306 | 1 |
execve with LD_PRELOAD or linker-related environment variables set |
DC0032 Process Creation | AN1209 | 1 |
execve with UID ≠ EUID |
DC0034 Process Metadata | AN0976 | 1 |
execve with escalated privileges |
DC0034 Process Metadata | AN0977 | 1 |
execve, USER_CMD |
DC0064 Command Execution | AN0751 | 1 |
execve, connect |
DC0032 Process Creation | AN0638 | 1 |
execve, fork, mmap, ptrace |
DC0035 Process Access | AN1466 | 1 |
execve, prctl, or ptrace activity affecting process memory or command-line arguments |
DC0034 Process Metadata | AN0466 | 1 |
execve, setifflags |
DC0032 Process Creation | AN0876 | 1 |
execve, unlink |
DC0032 Process Creation | AN1481 | 1 |
execve,socket,connect,openat |
DC0088 Logon Session Metadata | AN1345 | 1 |
execve: Agent/headless flags (listen/connect/reverse/tunnel) or remote-control binaries spawning shells |
DC0032 Process Creation | AN1367 | 1 |
execve: Commands altering firewall or enabling listeners (iptables, nft, ufw, firewall-cmd, systemctl start *ssh*/*telnet*, ip route add, tcpdump, tshark) |
DC0032 Process Creation | AN1449 | 1 |
execve: Commands executed within an SSH session where no matching logon/authentication event exists |
DC0064 Command Execution | AN0217 | 1 |
execve: Commands like systemctl stop <service>, service <service> stop, or kill -9 <pid> |
DC0064 Command Execution | AN0046 | 1 |
execve: Commands that alter firewall or start listeners: iptables|nft|ufw|firewall-cmd|pfctl|systemctl start sshd/telnet/dropbear; raw-socket/libpcap tools (tcpdump, tshark, nmap --raw). |
DC0032 Process Creation | AN0843 | 1 |
execve: Electron-based binary spawning shell or script interpreter |
DC0032 Process Creation | AN0072 | 1 |
execve: Execs of chromium, google-chrome, firefox, libreoffice with http(s) in cmdline |
DC0082 Network Connection Creation | AN0179 | 1 |
execve: Execution of CLI tools like psql, mysql, mongo, sqlite3 |
DC0032 Process Creation | AN0676 | 1 |
execve: Execution of bash, python, or perl processes spawned by browser/email client |
DC0032 Process Creation | AN0321 | 1 |
execve: Execution of binaries/scripts presenting false health messages for security daemons |
DC0032 Process Creation | AN0869 | 1 |
execve: Execution of cat, less, grep, journalctl targeting log directories (/var/log/) |
DC0064 Command Execution | AN0706 | 1 |
execve: Execution of commands modifying iptables/nftables to block selective IPs |
DC0032 Process Creation | AN1149 | 1 |
execve: Execution of container management CLIs (docker, crictl, kubectl) or interpreted shells (sh, bash, python) within container context |
DC0032 Process Creation | AN0233 | 1 |
execve: Execution of curl or wget writing files to /tmp/* followed by chmod or execution |
DC0064 Command Execution | AN0993 | 1 |
execve: Execution of curl, wget, or custom scripts accessing financial endpoints |
DC0064 Command Execution | AN1362 | 1 |
execve: Execution of discovery commands targeting backup binaries, processes, or config paths |
DC0032 Process Creation | AN0241 | 1 |
execve: Execution of downgraded interpreters such as python2 or forced fallback commands |
DC0064 Command Execution | AN0996 | 1 |
execve: Execution of files saved in mail or download directories |
DC0032 Process Creation | AN0656 | 1 |
execve: Execution of interpreters creating archive-like outputs without calling tar/gzip |
DC0064 Command Execution | AN1214 | 1 |
execve: Execution of klist, kinit, or tools interacting with ccache outside normal user context |
DC0032 Process Creation | AN0069 | 1 |
execve: Execution of lsmod, modinfo, or cat /proc/modules |
DC0064 Command Execution | AN1596 | 1 |
execve: Execution of pip, npm, gem, or similar package managers |
DC0032 Process Creation | AN0698 | 1 |
execve: Execution of python, perl, or custom binaries invoking compression libraries |
DC0064 Command Execution | AN0748 | 1 |
execve: Execution of scripts or binaries sourced from mail directories (/var/mail, ~/Maildir) |
DC0032 Process Creation | AN0189 | 1 |
execve: Execution of scripts or binaries spawned from browser processes |
DC0032 Process Creation | AN0299 | 1 |
execve: Execution of suspicious exploit binaries targeting security daemons |
DC0032 Process Creation | AN1634 | 1 |
execve: Execution of systemctl, loginctl, or systemd-inhibit commands related to sleep/hibernate |
DC0064 Command Execution | AN1175 | 1 |
execve: Execution of tar, gzip, bzip2, or openssl with output redirection |
DC0064 Command Execution | AN1459 | 1 |
execve: Execution of tar, gzip, bzip2, xz, zip, or openssl with compression/encryption arguments |
DC0064 Command Execution | AN0832 | 1 |
execve: Invocation of scp, rsync, curl, or sftp |
DC0064 Command Execution | AN0517 | 1 |
execve: Process in container namespace executes curl|wget|bash|sh|python|nc with outbound args |
DC0064 Command Execution | AN0691 | 1 |
execve: Processes executing sendmail/postfix with forged headers |
DC0064 Command Execution | AN0793 | 1 |
execve: Suspicious binaries or scripts interacting with authentication binaries (sshd, gdm, login) |
DC0032 Process Creation | AN0494 | 1 |
execve: exe in (/usr/bin/bash,/usr/bin/sh,/usr/bin/zsh,/usr/bin/python*) AND cmdline matches '(curl|wget).*(\||\|\s*sh|bash)|base64\s*-d|python\s*-c' |
DC0032 Process Creation | AN0963 | 1 |
execve: exe in {/bin/bash,/bin/sh,/usr/bin/python*,/usr/bin/perl,/usr/bin/php,/usr/bin/node,/usr/bin/curl,/usr/bin/wget,/usr/bin/xdg-open,/usr/bin/ssh,/usr/bin/rundll32 (wine)} AND ppid process is a document viewer/browser |
DC0032 Process Creation | AN0821 | 1 |
execve: execve calls where a browser/webview process is parent and child is interpreter (python, sh, ruby) or downloader (curl, wget) |
DC0032 Process Creation | AN0499 | 1 |
execve: execve where exe=/usr/bin/python3 or similar interpreter |
DC0032 Process Creation | AN0713 | 1 |
execve: iptables, nft, firewall-cmd modifications |
DC0064 Command Execution | AN0407 | 1 |
execve: openssl pkcs12, certutil, keytool |
DC0064 Command Execution | AN0672 | 1 |
execve: parent process is usb/hid device handler, child process bash/python invoked |
DC0032 Process Creation | AN1568 | 1 |
execve: process_name IN ("virsh", "VBoxManage", "qemu-img") AND command IN ("list", "info") |
DC0064 Command Execution | AN0573 | 1 |
execve: service stop syslog, systemctl stop rsyslog, kill -9 syslog |
DC0064 Command Execution | AN0668 | 0 |
execve: systemctl stop, service stop, or kill -9 on security daemons (e.g., falcon-sensor, auditd) |
DC0032 Process Creation | AN1370 | 1 |
execve=/sbin/shutdown or /sbin/reboot |
DC0064 Command Execution | AN1539 | 1 |
exit_group |
DC0033 Process Termination | AN0373 | 1 |
file |
DC0055 File Access | AN1418 | 1 |
file creation/modification |
DC0039 File Creation | AN0166 | 1 |
file deletion |
DC0040 File Deletion | AN0114 | 1 |
file write after sleep delay |
DC0059 File Metadata | AN0397 | 1 |
file write operations in /Library/WebServer/Documents |
DC0061 File Modification | AN1110 | 1 |
firmware_update, kexec_load |
DC0018 Host Status | AN1036 | 1 |
fork/clone/daemon syscall tracing |
DC0021 OS API Execution | AN1223 | 1 |
fork/exec of service via PID 1 (systemd) |
DC0032 Process Creation | AN0701 | 1 |
ioctl/write: Direct firmware update or device memory manipulation syscalls |
DC0004 Firmware Modification | AN0917 | 1 |
ioctl: Changes to wireless network interfaces (up, down, reassociate) |
DC0078 Network Traffic Flow | AN1477 | 1 |
kill syscalls targeting auditd process |
DC0020 Process Modification | AN0171 | 1 |
kill syscalls targeting logging/security processes |
DC0033 Process Termination | AN0887 | 0 |
mknod,open,openat |
DC0042 Drive Creation | AN0186 | 1 |
mmap |
DC0016 Module Load | AN0920 | 1 |
mmap, ptrace, process_vm_writev or direct memory ops |
DC0021 OS API Execution | AN0579 | 1 |
modification of entrypoint scripts or init containers |
DC0061 File Modification | AN1578 | 1 |
modification of existing .service file |
DC0061 File Modification | AN0701 | 1 |
module load or memory map path |
DC0016 Module Load | AN1466 | 1 |
mount or losetup commands creating hidden or encrypted FS |
DC0061 File Modification | AN1272 | 1 |
mount system call with bind or remap flags |
DC0021 OS API Execution | AN1196 | 1 |
mprotect |
DC0020 Process Modification | AN0067 | 1 |
new file created in /var/www/html, /srv/http, or similar web root |
DC0039 File Creation | AN1109 | 1 |
open |
DC0055 File Access | AN0125 AN0195 AN0332 AN0343 AN0368 AN0532 AN0620 AN0649 AN0725 AN0798 AN0984 AN1038 AN1071 AN1096 AN1310 AN1315 AN1400 AN1529 AN1552 | 19 |
open or connect syscalls on /tmp/ssh-* or $SSH_AUTH_SOCK |
DC0082 Network Connection Creation | AN0710 | 1 |
open or creat syscalls targeting excluded paths |
DC0039 File Creation | AN0140 | 1 |
open or read to browser cookie storage |
DC0055 File Access | AN1403 | 1 |
open, flock, fcntl, unlink |
DC0055 File Access | AN0373 | 1 |
open, read |
DC0055 File Access | AN0244 AN0283 AN0617 AN1234 AN1414 AN1631 | 6 |
open, read, mount |
DC0055 File Access | AN1411 | 1 |
open, read, or stat of browser config files |
DC0055 File Access | AN0038 | 1 |
open, read: /etc/ssl/, /etc/pki/, ~/.pki/nssdb/ |
DC0055 File Access | AN0672 | 1 |
open, rename |
DC0020 Process Modification | AN0541 AN1481 | 2 |
open, unlink, rename: File creation or deletion involving critical stored data |
DC0039 File Creation | AN0556 | 1 |
open, unlink, rename: Suspicious file access, deletion, or modification of sensitive paths |
DC0061 File Modification | AN0163 | 1 |
open, write |
DC0061 File Modification | AN0056 AN0288 AN0600 AN0824 AN0950 AN1065 AN1250 AN1408 | 8 |
open, write, unlink |
DC0039 File Creation | AN0974 | 1 |
open, write: File modifications under /etc/ssl/certs, /usr/local/share/ca-certificates, or /etc/pki/ca-trust/source/anchors |
DC0061 File Modification | AN0154 | 1 |
open, write: File writes to application binaries or libraries at runtime |
DC0061 File Modification | AN1098 | 1 |
open, write: Modification of /boot/grub/* or /boot/efi/* |
DC0061 File Modification | AN0775 | 1 |
open, write: Write operations targeting /dev/sda, /dev/nvme0n1, or EFI partition mounts |
DC0061 File Modification | AN0429 | 1 |
open,creat,rename,write |
DC0039 File Creation | AN1549 | 1 |
open,creat,rename: Writes in $HOME/Downloads, /tmp, ~/.cache with exe/script/archive/office extensions |
DC0039 File Creation | AN0179 | 1 |
open,create |
DC0039 File Creation | AN1382 | 1 |
open,openat,read |
DC0013 User Account Metadata | AN0456 | 1 |
open,read |
DC0055 File Access | AN1146 | 1 |
open/create/rename: name in (/home/*/Downloads/*|/tmp/*|/run/user/*|/media/*) AND ext in SuspiciousExtensions |
DC0039 File Creation | AN0821 | 1 |
open/read |
DC0055 File Access | AN1199 AN1354 | 2 |
open/read access to ~/.bash_history |
DC0055 File Access | AN1085 | 1 |
open/read of sensitive config or secret files |
DC0055 File Access | AN0857 | 1 |
open/read of sensitive directories |
DC0055 File Access | AN0896 | 1 |
open/read of sensitive directories (/etc, /home/*) |
DC0055 File Access | AN1512 | 1 |
open/read on ~/.local/share/keepassxc/* OR ~/.password-store/* |
DC0055 File Access | AN1642 | 1 |
open/read system calls to ~/.bash_history or /etc/shadow |
DC0055 File Access | AN1154 | 1 |
open/read: Access to /proc/self/status with focus on TracerPID field |
DC0055 File Access | AN1046 | 1 |
open/write calls modifying ~/.bashrc, ~/.profile, or /etc/paths.d |
DC0061 File Modification | AN0010 | 1 |
open/write of .service unit files |
DC0061 File Modification | AN0200 | 1 |
open/write syscalls on /dev/sd* or /dev/nvme* |
DC0054 Drive Access | AN0385 | 1 |
open/write syscalls targeting /etc/ld.so.preload or binaries in /usr/bin |
DC0061 File Modification | AN0610 | 1 |
open/write syscalls targeting web directory files |
DC0061 File Modification | AN1623 | 1 |
open/write syscalls to block devices (/dev/sd*, /dev/nvme*) |
DC0054 Drive Access | AN0883 | 1 |
open/write to /etc/pam.d/* |
DC0061 File Modification | AN0546 | 1 |
open/write to /proc/*/mem or /proc/*/maps |
DC0061 File Modification | AN1494 | 1 |
open/write/unlink |
DC0061 File Modification | AN0230 | 1 |
open: Access to named pipes or FIFO in /tmp or /dev/shm by unexpected processes |
DC0055 File Access | AN1358 | 1 |
open: File access attempt on /tmp/krb5cc_* or /tmp/krb5.ccache |
DC0055 File Access | AN0069 | 1 |
open: File creation under /tmp, /var/tmp, ~/.cache with executable bit or shell shebang |
DC0039 File Creation | AN0963 | 1 |
open: Write to ~/.vscode-cli/code_tunnel.json |
DC0039 File Creation | AN0376 | 1 |
openat |
DC0055 File Access | AN0096 AN0783 AN1517 | 3 |
openat, write, rename, unlink |
DC0061 File Modification | AN0603 | 1 |
openat,connect -k discovery |
DC0082 Network Connection Creation | AN1552 | 1 |
openat/read/ioctl: openat/read/ioctl on /dev/video* by uncommon user/process |
DC0021 OS API Execution | AN0569 | 1 |
openat/read/mmap: Open/mmap .so files from non-standard paths |
DC0016 Module Load | AN0053 | 1 |
outbound connections |
DC0082 Network Connection Creation | AN1377 AN2031 | 2 |
pam_authenticate, sshd |
DC0002 User Account Authentication | AN0591 | 1 |
process persists beyond parent shell termination |
DC0032 Process Creation | AN0181 | 1 |
promiscuous mode transitions (ioctl or ifconfig) |
DC0064 Command Execution | AN0876 | 1 |
ptrace |
DC0035 Process Access | AN0649 AN1642 | 2 |
ptrace attach |
DC0035 Process Access | AN0106 AN0157 | 2 |
ptrace or process_vm_readv |
DC0035 Process Access | AN1631 | 1 |
ptrace syscall or access to /proc/*/mem |
DC0035 Process Access | AN1403 | 1 |
ptrace, ioctl |
DC0021 OS API Execution | AN0244 AN0283 | 2 |
ptrace, mmap, mprotect, open, dlopen |
DC0021 OS API Execution | AN1241 | 1 |
ptrace, mmap, process_vm_writev |
DC0021 OS API Execution | AN1400 | 1 |
read of /run/secrets or docker volumes by non-entrypoint process |
DC0055 File Access | AN1158 | 1 |
read/open of sensitive file directories |
DC0055 File Access | AN0788 AN1572 | 2 |
read/open of sensitive files |
DC0055 File Access | AN0437 | 1 |
rename |
DC0020 Process Modification | AN0984 | 1 |
rename, chmod |
DC0020 Process Modification | AN0022 | 1 |
rename,chmod |
DC0061 File Modification | AN0798 AN1315 | 2 |
send, recv, write: Abnormal interception or alteration of transmitted data |
DC0021 OS API Execution | AN0703 | 1 |
sendto/connect |
DC0082 Network Connection Creation | AN1255 | 1 |
setsockopt, ioctl modifying ARP entries |
DC0085 Network Traffic Content | AN1092 | 1 |
setuid or setgid bit changes |
DC0059 File Metadata | AN0976 | 1 |
setxattr or getxattr system call |
DC0059 File Metadata | AN1135 | 1 |
sleep function usage or loops (nanosleep, usleep) in scripts |
DC0064 Command Execution | AN0128 | 1 |
socket(AF_PACKET|AF_INET, SOCK_RAW, *), setsockopt(… SO_ATTACH_FILTER|SO_ATTACH_BPF …), bpf(cmd=BPF_PROG_LOAD), open/openat path="/dev/bpf*" (BSD/macOS-like) or setcap cap_net_raw. |
DC0032 Process Creation | AN0463 | 1 |
socket/bind: New bind() to a previously closed port shortly after the sequence. |
DC0082 Network Connection Creation | AN0843 | 1 |
socket/bind: Process binds to a new local port shortly after knock |
DC0082 Network Connection Creation | AN1449 | 1 |
socket/connect |
DC0078 Network Traffic Flow | AN0110 AN1179 AN1332 | 3 |
socket/connect calls showing SSH processes forwarding arbitrary ports |
DC0082 Network Connection Creation | AN1484 | 1 |
socket/connect syscalls |
DC0078 Network Traffic Flow | AN0634 | 1 |
socket/connect with TLS context by unexpected process |
DC0082 Network Connection Creation | AN0760 | 1 |
socket: Suspicious creation of AF_UNIX sockets outside expected daemons |
DC0032 Process Creation | AN1358 | 1 |
ssh logins or execve of remote commands |
DC0088 Logon Session Metadata | AN1005 | 1 |
stat and lstat syscall results on files, including inode and permission info |
DC0059 File Metadata | AN2064 | 1 |
sudo or pkexec invocation |
DC0021 OS API Execution | AN0976 | 1 |
syscall in (chmod, fchmod, fchmodat, chown, fchown, fchownat, lchown, setxattr, lsetxattr, fsetxattr, removexattr, lremovexattr, fremovexattr) |
DC0059 File Metadata | AN0998 | 1 |
syscall in (chmod, fchmod, fchmodat, chown, fchown, fchownat, setxattr, lsetxattr, fsetxattr) |
DC0059 File Metadata | AN0835 | 1 |
type=EXECVE or SYSCALL for /bin/date, /usr/bin/timedatectl, /sbin/hwclock, /bin/cat /etc/timezone, /bin/cat /proc/uptime |
DC0032 Process Creation | AN0431 | 1 |
udev events or drive enumeration involving TinyPilot paths or device classes |
DC0042 Drive Creation | AN0447 | 1 |
unlink, rename, open |
DC0040 File Deletion | AN0521 | 1 |
unlink, unlinkat, openat, write |
DC0040 File Deletion | AN0412 | 1 |
unlink, unlinkat, rmdir |
DC0040 File Deletion | AN0416 | 1 |
unlink/unlinkat |
DC0040 File Deletion | AN0738 | 1 |
unlink/unlinkat on service binaries or data targets |
DC0040 File Deletion | AN0062 | 1 |
unshare, mount, keyctl, setns syscalls executed by containerized processes |
DC0021 OS API Execution | AN0613 | 1 |
useradd or adduser executed |
DC0014 User Account Creation | AN1236 AN1605 | 2 |
usermod, groupmod, passwd |
DC0010 User Account Modification | AN0266 | 1 |
usermod, or account rename system calls |
DC0010 User Account Modification | AN1078 | 1 |
write |
DC0039 File Creation DC0061 File Modification |
AN0283 AN0368 AN0473 AN0620 AN0663 AN0765 AN0779 AN0783 AN0805 AN0914 AN0939 AN0944 AN1299 AN1320 AN1592 AN1631 | 16 |
write access to /dev/mem or /sys/firmware/efi/efivars |
DC0004 Firmware Modification | AN0475 | 1 |
write operation on /etc/passwd or /etc/shadow |
DC0061 File Modification | AN1236 | 1 |
write or create file after .bash_history access |
DC0039 File Creation | AN1085 | 1 |
write or rename to /etc/systemd/system or /etc/init.d |
DC0061 File Modification | AN1576 | 1 |
write syscalls to /dev/sd* targeting offset 0 |
DC0054 Drive Access | AN0828 | 1 |
write | PATH=/home/*/.ssh/authorized_keys |
DC0061 File Modification | AN0350 | 1 |
write, open, or rename to /etc/systemd/system/*.service |
DC0039 File Creation | AN0701 | 1 |
write, rename |
DC0061 File Modification | AN0259 | 1 |
write/open, FIM audit |
DC0039 File Creation | AN0248 | 1 |
write: Modification of structured stored data by suspicious processes |
DC0061 File Modification | AN0556 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2007-5659 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2008-0655 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2008-2992 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2009-1862 | Adobe Acrobat and Reader, Flash Player | T1204.002 | Mapped |
| CVE-2009-3953 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2009-3960 | Adobe BlazeDS | T1190 T1486 | Mapped |
| CVE-2009-4324 | Adobe Acrobat and Reader | T1071.001 T1204.002 | Mapped |
| CVE-2010-0188 | Adobe Reader and Acrobat | T1105 T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1105 T1189 T1204.002 | Mapped |
| CVE-2010-2861 | Adobe ColdFusion | T1105 T1119 T1190 | Mapped |
| CVE-2010-2883 | Adobe Acrobat and Reader | T1027 T1059 T1204.002 | Mapped |
| CVE-2011-0611 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2011-2462 | Adobe Reader and Acrobat | T1204.002 | Mapped |
| CVE-2012-0754 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2012-0767 | Adobe Flash Player | T1098 T1204.001 | Mapped |
| CVE-2012-1535 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2013-0625 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0629 | Adobe ColdFusion | T1005 T1190 | Mapped |
| CVE-2013-0631 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0632 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0640 | Adobe Reader and Acrobat | T1566.001 | Mapped |
| CVE-2013-0641 | Adobe Reader | T1048 T1105 T1204.002 | Mapped |
| CVE-2013-3346 | Adobe Reader and Acrobat | T1059.007 | Mapped |
| CVE-2014-0496 | Adobe Reader and Acrobat | T1204.002 | Mapped |
| CVE-2014-0546 | Adobe Reader and Acrobat | T1068 T1497 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1059.004 T1133 T1190 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1059.004 T1133 T1190 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 T1204.002 T1499.004 | Mapped |
| CVE-2015-3113 | Adobe Flash Player | T1071.001 T1204.002 T1497 T1622 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1059.007 T1071.001 T1105 T1203 T1204.001 T1566.002 | Mapped |
| CVE-2015-7645 | Adobe Flash Player | T1204.002 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1105 T1189 T1486 | Mapped |
| CVE-2016-0984 | Adobe Flash Player and AIR | T1105 T1204.002 | Mapped |
| CVE-2016-10033 | PHP PHPMailer | T1059.004 T1190 | Mapped |
| CVE-2016-1010 | Adobe Flash Player and AIR | T1574 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1105 T1189 T1486 | Mapped |
| CVE-2016-4117 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2016-4437 | Apache Shiro | T1059 T1190 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2017-11292 | Adobe Flash Player | T1005 T1105 T1204.002 T1566.001 | Mapped |
| CVE-2017-11882 | Microsoft Office | T1059 T1566.001 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1083 T1190 T1555 | Mapped |
| CVE-2017-5638 | Apache Struts | T1005 T1059 T1190 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1048 T1059 T1574 | Mapped |
| CVE-2017-9805 | Apache Struts | T1059 T1190 | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1059 T1190 T1496 | Mapped |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | T1005 | Mapped |
| CVE-2018-11776 | Apache Struts | T1059 T1190 T1496 | Mapped |
| CVE-2018-13379 | Fortinet FortiOS | T1190 | Mapped |
| CVE-2018-15961 | Adobe ColdFusion | T1190 T1491.002 | Mapped |
| CVE-2018-15982 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2018-4878 | Adobe Flash Player | T1041 T1204.002 T1219 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1133 T1190 T1203 | Mapped |
| CVE-2018-4990 | Adobe Acrobat and Reader | T1059.007 T1204.002 | Mapped |
| CVE-2018-6789 | Exim Exim | T1059 T1190 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1059 T1190 T1485 T1496 | Mapped |
| CVE-2019-0211 | Apache HTTP Server | T1068 | Mapped |
| CVE-2019-0604 | Microsoft SharePoint | T1003 T1041 T1190 T1505.003 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1059.004 T1133 T1498 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1059 T1083 T1133 T1552.001 | Mapped |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center | T1059 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1003 T1005 T1046 T1059 T1078 T1190 T1486 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1003 T1005 T1046 T1059 T1078 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1005 T1082 T1190 | Mapped |
| CVE-2019-17558 | Apache Solr | T1059 T1190 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1041 T1190 T1496 T1505.003 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1059 T1083 T1133 | Mapped |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1090 T1133 | Mapped |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center | T1059 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1005 T1133 T1557 | Mapped |
| CVE-2020-0069 | MediaTek Multiple Chipsets | T1068 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1114 T1190 T1505.003 | Mapped |
| CVE-2020-0787 | Microsoft Windows | T1059 T1068 | Mapped |
| CVE-2020-12812 | Fortinet FortiOS | T1556 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1021 T1068 T1087.002 T1133 T1486 | Mapped |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products | T1059 T1190 | Mapped |
| CVE-2020-17530 | Apache Struts | T1059 T1190 | Mapped |
| CVE-2020-25506 | D-Link DNS-320 Device | T1059 T1133 | Mapped |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices | T1059 T1190 | Mapped |
| CVE-2020-29574 | Sophos CyberoamOS | T1055 T1059 | Mapped |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1005 | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1059 T1204.001 T1217 | Mapped |
| CVE-2020-5735 | Amcrest Cameras and Network Video Recorder (NVR) | T1499 T1574 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1003 T1005 T1059 T1070.004 T1133 T1190 T1552 | Stale |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 T1556 | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 T1056 T1082 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 T1056 T1082 | Mapped |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1059 T1133 T1496 | Mapped |
| CVE-2020-8657 | EyesOfNetwork EyesOfNetwork | T1106 | Mapped |
| CVE-2021-1497 | Cisco HyperFlex HX | T1059 T1133 | Mapped |
| CVE-2021-1498 | Cisco HyperFlex HX | T1059 T1133 | Mapped |
| CVE-2021-20035 | SonicWall SMA100 Appliances | T1059 T1078 | Mapped |
| CVE-2021-21017 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2021-21148 | Google Chromium V8 | T1059.007 T1203 | Mapped |
| CVE-2021-21166 | Google Chromium | T1059.007 T1203 | Mapped |
| CVE-2021-21206 | Google Chromium Blink | T1059.007 T1203 | Mapped |
| CVE-2021-21972 | VMware vCenter Server | T1059 T1190 | Mapped |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | T1046 T1190 | Mapped |
| CVE-2021-21975 | VMware vRealize Operations Manager API | T1190 | Mapped |
| CVE-2021-22005 | VMware vCenter Server | T1059 T1190 | Mapped |
| CVE-2021-22017 | VMware vCenter Server | T1090.001 T1190 | Mapped |
| CVE-2021-22204 | Perl Exiftool | T1059 T1190 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1059 T1190 T1496 T1498 | Mapped |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | T1003 T1059 T1190 | Mapped |
| CVE-2021-22894 | Ivanti Pulse Connect Secure | T1059 T1078 | Mapped |
| CVE-2021-22899 | Ivanti Pulse Connect Secure | T1078 | Mapped |
| CVE-2021-22900 | Ivanti Pulse Connect Secure | T1059 T1068 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1059 T1090 T1133 T1190 T1485 | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | T1059 T1496 | Mapped |
| CVE-2021-26085 | Atlassian Confluence Server | T1005 T1190 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1005 T1090 T1133 T1505.003 | Mapped |
| CVE-2021-26857 | Microsoft Exchange Server | T1133 T1505.003 | Mapped |
| CVE-2021-26858 | Microsoft Exchange Server | T1190 T1505.003 | Mapped |
| CVE-2021-27059 | Microsoft Office | T1203 | Mapped |
| CVE-2021-27065 | Microsoft Exchange Server | T1190 T1505.003 | Mapped |
| CVE-2021-27101 | Accellion FTA | T1005 T1059 | Mapped |
| CVE-2021-27102 | Accellion FTA | T1005 T1059 T1190 | Mapped |
| CVE-2021-27103 | Accellion FTA | T1005 T1190 | Mapped |
| CVE-2021-27104 | Accellion FTA | T1005 T1059 T1190 | Mapped |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN software | T1190 T1505.003 | Mapped |
| CVE-2021-28550 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1005 T1068 T1203 | Mapped |
| CVE-2021-30554 | Google Chromium WebGL | T1059.007 T1203 | Mapped |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack | T1059 T1190 | Mapped |
| CVE-2021-31207 | Microsoft Exchange Server | T1565 | Mapped |
| CVE-2021-3129 | Laravel Ignition | T1059 T1190 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1040 T1068 T1098 | Mapped |
| CVE-2021-33739 | Microsoft Windows | T1068 | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | T1048.003 T1136 T1190 T1486 | Mapped |
| CVE-2021-34523 | Microsoft Exchange Server | T1190 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1059 T1071.001 T1105 T1190 T1496 T1499 | Mapped |
| CVE-2021-35464 | ForgeRock Access Management (AM) | T1059 T1190 | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | T1059.004 T1190 | Mapped |
| CVE-2021-36934 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2021-37415 | Zoho ManageEngine ServiceDesk Plus (SDP) | T1190 | Mapped |
| CVE-2021-37975 | Google Chromium V8 | T1059.007 T1203 | Mapped |
| CVE-2021-39144 | XStream XStream | T1190 T1203 | Mapped |
| CVE-2021-39226 | Grafana Labs Grafana | T1190 T1485 | Mapped |
| CVE-2021-4034 | Red Hat Polkit | T1068 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1027 T1068 T1071.001 T1082 T1566 T1573.001 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1003 T1027 T1070.004 T1087.002 T1136 T1140 T1190 T1218 T1505.003 T1560.001 T1573.001 | Mapped |
| CVE-2021-40655 | D-Link DIR-605 Router | T1190 | Mapped |
| CVE-2021-41379 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2021-41773 | Apache HTTP Server | T1059 T1210 | Mapped |
| CVE-2021-42013 | Apache HTTP Server | T1059 T1210 | Mapped |
| CVE-2021-42237 | Sitecore XP | T1059 | Mapped |
| CVE-2021-42258 | BQE BillQuick Web Suite | T1059 T1486 | Mapped |
| CVE-2021-42321 | Microsoft Exchange | T1059 T1078 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1003 T1027 T1070.004 T1087.002 T1136 T1140 T1190 T1218 T1505.003 T1560.001 T1573.001 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1190 T1486 T1496 T1505.003 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1003 T1069 T1087 T1105 T1190 | Mapped |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | T1190 T1195.002 | Mapped |
| CVE-2021-45046 | Apache Log4j2 | T1059 T1486 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1059 T1070 T1071 T1190 T1499.002 T1543 | Mapped |
| CVE-2022-0028 | Palo Alto Networks PAN-OS | T1190 T1498 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1040 T1059 T1078 T1190 T1557 T1574 | Mapped |
| CVE-2022-1388 | F5 BIG-IP | T1548 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 T1133 | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 T1190 | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1078 T1203 | Mapped |
| CVE-2022-20703 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-20708 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1068 T1190 | Mapped |
| CVE-2022-20821 | Cisco IOS XR | T1190 | Mapped |
| CVE-2022-21919 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2022-21971 | Microsoft Windows | T1059 T1204.001 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1059 T1068 T1078 T1136.001 T1211 | Mapped |
| CVE-2022-22047 | Microsoft Windows | T1059 T1068 T1078 | Mapped |
| CVE-2022-22718 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | T1059 T1190 T1486 | Mapped |
| CVE-2022-22948 | VMware vCenter Server | T1068 T1078 T1212 | Mapped |
| CVE-2022-22954 | VMware Workspace ONE Access and Identity Manager | T1505.003 | Mapped |
| CVE-2022-22960 | VMware Multiple Products | T1222 | Mapped |
| CVE-2022-22963 | VMware Tanzu Spring Cloud | T1059.007 T1190 T1505.003 | Mapped |
| CVE-2022-22965 | VMware Spring Framework | T1059 T1190 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1059 T1078 T1190 T1548 | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | T1059 T1203 | Mapped |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | T1027 T1190 T1213 | Mapped |
| CVE-2022-24521 | Microsoft Windows | T1059 T1068 T1078 | Mapped |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) | T1059.007 T1204.001 | Mapped |
| CVE-2022-26134 | Atlassian Confluence Server/Data Center | T1190 | Mapped |
| CVE-2022-26138 | Atlassian Confluence | T1552.001 | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | T1059 T1190 T1499.002 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1036 T1048 T1059 T1078 T1190 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1036 T1048 T1059 T1190 | Mapped |
| CVE-2022-26904 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2022-28810 | Zoho ManageEngine | T1190 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1059 T1496 T1505 | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | T1190 T1496 | Mapped |
| CVE-2022-30190 | Microsoft Windows | T1105 T1204.002 | Mapped |
| CVE-2022-3038 | Google Chromium Network Service | T1204.001 T1574 | Mapped |
| CVE-2022-3075 | Google Chromium Mojo | T1204.001 | Mapped |
| CVE-2022-34713 | Microsoft Windows | T1059 T1204.002 T1566 | Mapped |
| CVE-2022-35405 | Zoho ManageEngine | T1059 | Mapped |
| CVE-2022-35914 | Teclib GLPI | T1059 T1190 | Mapped |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center | T1059 T1190 | Mapped |
| CVE-2022-37969 | Microsoft Windows | T1059 T1068 T1078 | Mapped |
| CVE-2022-39197 | Fortra Cobalt Strike | T1059 T1190 | Mapped |
| CVE-2022-40684 | Fortinet Multiple Products | T1098.004 T1190 | Mapped |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service | T1068 T1566.001 | Mapped |
| CVE-2022-41073 | Microsoft Windows | T1068 T1078 T1574 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1078 T1087 T1505.003 T1567 | Mapped |
| CVE-2022-41125 | Microsoft Windows | T1059 T1068 T1078 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1070 T1203 T1566 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1037 T1049 T1565.001 T1574 | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | T1071.001 T1190 T1574 T1622 | Mapped |
| CVE-2022-42948 | Fortra Cobalt Strike | T1059 T1190 | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1059 T1203 | Mapped |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1059 T1190 | Mapped |
| CVE-2022-47966 | Zoho ManageEngine | T1068 T1136.001 T1190 | Mapped |
| CVE-2023-0386 | Linux Kernel | T1543 T1548.001 | Stale |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1190 T1210 T1486 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1041 T1070 T1106 T1496 T1498 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1059 T1078 T1499 | Mapped |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | T1059 T1068 T1078 T1505.003 | Mapped |
| CVE-2023-20198 | Cisco IOS XE Web UI | T1136 T1190 | Mapped |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense | T1078 T1133 | Mapped |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | T1059 T1068 T1078 | Mapped |
| CVE-2023-20867 | VMware Tools | T1059 T1078 T1105 | Mapped |
| CVE-2023-20887 | VMware Aria Operations for Networks | T1059 T1190 | Mapped |
| CVE-2023-2136 | Google Chromium Skia | T1204.001 | Mapped |
| CVE-2023-21608 | Adobe Acrobat and Reader | T1203 T1204.002 | Mapped |
| CVE-2023-21674 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2023-21715 | Microsoft Office | T1204.002 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1059 T1059.007 T1078 T1136 T1190 | Mapped |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | T1033 T1105 T1190 | Mapped |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | T1496 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1059 T1070.004 T1078 T1083 T1190 T1505.003 | Stale |
| CVE-2023-23397 | Microsoft Office | T1078 T1203 | Mapped |
| CVE-2023-2533 | PaperCut NG/MF | T1059 T1547 T1566.002 | Mapped |
| CVE-2023-26359 | Adobe ColdFusion | T1059 T1190 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1036.005 T1046 T1059.007 T1071.001 T1105 T1190 T1505.003 | Mapped |
| CVE-2023-26369 | Adobe Acrobat and Reader | T1203 T1204.002 | Mapped |
| CVE-2023-27350 | PaperCut MF/NG | T1059 T1105 T1190 | Mapped |
| CVE-2023-27524 | Apache Superset | T1078 T1190 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1087 T1133 T1486 T1555 | Mapped |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | T1136 T1190 T1574 | Mapped |
| CVE-2023-28229 | Microsoft Windows CNG Key Isolation Service | T1068 T1078 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1003 T1021 T1059 T1068 T1078 T1136 T1486 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1041 T1059 T1105 T1566.001 | Mapped |
| CVE-2023-29298 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-29300 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2023-29492 | Novi Survey Novi Survey | T1190 | Mapped |
| CVE-2023-32315 | Ignite Realtime Openfire | T1087.002 T1496 T1505.003 | Mapped |
| CVE-2023-33246 | Apache RocketMQ | T1059 T1190 | Mapped |
| CVE-2023-33538 | TP-Link Multiple Routers | T1059 T1068 | Mapped |
| CVE-2023-34048 | VMware vCenter Server | T1203 | Mapped |
| CVE-2023-34192 | Synacor Zimbra Collaboration Suite (ZCS) | T1055 T1059 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1005 T1059 T1082 T1105 T1136 T1190 T1531 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1136 T1190 T1213 | Mapped |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) | T1059 T1190 | Mapped |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | T1087.002 T1105 T1190 T1574 | Mapped |
| CVE-2023-36844 | Juniper Junos OS | T1190 T1203 | Mapped |
| CVE-2023-36845 | Juniper Junos OS | T1059 T1190 | Mapped |
| CVE-2023-36846 | Juniper Junos OS | T1059 T1190 | Mapped |
| CVE-2023-36847 | Juniper Junos OS | T1059 T1190 | Mapped |
| CVE-2023-36851 | Juniper Junos OS | T1059 T1190 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1005 T1204.002 T1486 T1489 T1490 T1566 | Stale |
| CVE-2023-38035 | Ivanti Sentry | T1046 T1059 T1071.001 T1105 T1190 T1496 T1571 | Mapped |
| CVE-2023-38203 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2023-38205 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1005 T1041 T1053 T1059.004 T1105 T1204 T1486 | Mapped |
| CVE-2023-38950 | ZKTeco BioTime | T1005 T1190 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1059.004 T1078 T1133 | Mapped |
| CVE-2023-40044 | Progress WS_FTP Server | T1059 T1071.002 | Mapped |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security | T1059 T1078 | Mapped |
| CVE-2023-42793 | JetBrains TeamCity | T1190 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1059 T1082 T1189 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1059.004 T1068 T1543 T1548 | Mapped |
| CVE-2023-44487 | IETF HTTP/2 | T1190 T1499 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | T1059.004 T1190 | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | T1078 T1190 T1505.003 T1555 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1203 T1496 T1498 | Mapped |
| CVE-2023-48365 | Qlik Sense | T1059 T1133 T1190 | Mapped |
| CVE-2023-48788 | Fortinet FortiClient EMS | T1059 T1105 T1190 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1005 T1190 T1552 | Mapped |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | T1005 T1574 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1203 T1496 T1498 | Mapped |
| CVE-2023-5217 | Google Chromium libvpx | T1204.001 T1574 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1041 T1059.007 T1204.001 | Mapped |
| CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway | T1055 | Mapped |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway | T1499 T1574 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 T1574 | Mapped |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | T1059 T1105 T1190 | Mapped |
| CVE-2024-0769 | D-Link DIR-859 Router | T1005 T1190 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1133 T1203 T1498 | Mapped |
| CVE-2024-11182 | MDaemon Email Server | T1059 T1566 T1567 | Mapped |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | T1059 T1068 | Mapped |
| CVE-2024-12987 | DrayTek Vigor Routers | T1059 T1068 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1087 T1190 T1558 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1087 T1190 T1558 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1087 T1190 T1558 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 T1190 T1653 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 T1059 T1078 | Mapped |
| CVE-2024-20399 | Cisco NX-OS | T1059 T1078 | Mapped |
| CVE-2024-20439 | Cisco Smart Licensing Utility | T1106 T1552 | Mapped |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) | T1059 T1190 | Mapped |
| CVE-2024-21413 | Microsoft Office Outlook | T1059 T1566.002 | Mapped |
| CVE-2024-21762 | Fortinet FortiOS | T1190 T1574 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1059 T1190 T1505.003 T1552 | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | T1078 T1190 T1505.003 T1555 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1005 T1082 T1105 T1496 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1003.008 T1005 T1059.004 | Mapped |
| CVE-2024-26169 | Microsoft Windows | T1059 T1203 | Mapped |
| CVE-2024-27198 | JetBrains TeamCity | T1059 T1190 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1041 T1059.004 T1114 T1566.002 | Mapped |
| CVE-2024-29059 | Microsoft .NET Framework | T1059 T1068 | Mapped |
| CVE-2024-30051 | Microsoft DWM Core Library | T1068 | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | T1005 T1059 T1190 | Mapped |
| CVE-2024-37085 | VMware ESXi | T1068 T1078 | Mapped |
| CVE-2024-38080 | Microsoft Windows | T1068 T1204.002 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 T1204.001 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1005 T1059 T1190 | Mapped |
| CVE-2024-40890 | Zyxel DSL CPE Devices | T1011 T1055 | Mapped |
| CVE-2024-40891 | Zyxel DSL CPE Devices | T1011 T1055 | Mapped |
| CVE-2024-41710 | Mitel SIP Phones | T1059 T1068 | Mapped |
| CVE-2024-41713 | Mitel MiCollab | T1005 T1068 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1056 T1114 T1566.002 | Mapped |
| CVE-2024-4358 | Progress Telerik Report Server | T1190 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1059 T1133 T1203 T1498.001 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1003 T1033 T1041 T1053 T1059 T1068 T1071.001 T1190 T1543 T1570 | Mapped |
| CVE-2024-4671 | Google Chromium | T1059 T1189 | Mapped |
| CVE-2024-4761 | Google Chromium V8 | T1059 | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | T1003 T1005 T1190 | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 T1059 T1190 | Mapped |
| CVE-2024-4885 | Progress WhatsUp Gold | T1059 T1068 | Mapped |
| CVE-2024-49035 | Microsoft Partner Center | T1068 T1195 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1059 T1189 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1005 T1071.001 T1105 T1195.002 | Mapped |
| CVE-2024-50302 | Linux Kernel | T1005 T1011 | Mapped |
| CVE-2024-50603 | Aviatrix Controllers | T1055 T1059 | Mapped |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 T1059 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2024-53104 | Linux Kernel | T1059 T1068 | Mapped |
| CVE-2024-53150 | Linux Kernel | T1005 T1011 | Mapped |
| CVE-2024-53197 | Linux Kernel | T1059 T1068 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1083 T1199 T1212 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1068 T1210 T1495 T1499 | Mapped |
| CVE-2024-55550 | Mitel MiCollab | T1005 T1041 T1190 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1021 T1068 T1078 T1555 | Mapped |
| CVE-2024-56145 | Craft CMS Craft CMS | T1055 T1059 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1003 T1059 T1190 T1552.001 T1552.004 | Mapped |
| CVE-2024-57968 | Advantive VeraCore | T1059 T1078 | Mapped |
| CVE-2024-58136 | Yiiframework Yii | T1055 T1059 | Mapped |
| CVE-2024-6047 | GeoVision Multiple Devices | T1055 T1059 | Mapped |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | T1055 T1190 T1565.001 | Mapped |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | T1005 T1068 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1003 T1046 T1055 T1190 | Mapped |
| CVE-2025-0411 | 7-Zip 7-Zip | T1566.001 | Mapped |
| CVE-2025-0994 | Trimble Cityworks | T1059 T1068 | Mapped |
| CVE-2025-1316 | Edimax IC-7100 IP Camera | T1055 T1190 | Mapped |
| CVE-2025-1976 | Broadcom Brocade Fabric OS | T1059 T1068 | Mapped |
| CVE-2025-20281 | Cisco Identity Services Engine | T1059 T1106 | Mapped |
| CVE-2025-20337 | Cisco Identity Services Engine | T1059 T1106 | Mapped |
| CVE-2025-21333 | Microsoft Windows | T1003 T1068 | Mapped |
| CVE-2025-21334 | Microsoft Windows | T1003 T1068 | Mapped |
| CVE-2025-21335 | Microsoft Windows | T1003 T1068 | Mapped |
| CVE-2025-21391 | Microsoft Windows | T1068 T1485 T1490 | Mapped |
| CVE-2025-21418 | Microsoft Windows | T1005 T1055 T1068 | Mapped |
| CVE-2025-21480 | Qualcomm Multiple Chipsets | T1055 T1495 | Mapped |
| CVE-2025-21590 | Juniper Junos OS | T1059 T1068 | Mapped |
| CVE-2025-22224 | VMware ESXi and Workstation | T1055 T1611 | Mapped |
| CVE-2025-22225 | VMware ESXi | T1068 T1611 | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | T1005 T1611 | Mapped |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1059 T1190 | Mapped |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | T1059 T1190 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1059 T1078 T1203 | Mapped |
| CVE-2025-24054 | Microsoft Windows | T1555 T1566 | Mapped |
| CVE-2025-24085 | Apple Multiple Products | T1059 T1068 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1059 T1189 | Mapped |
| CVE-2025-24985 | Microsoft Windows | T1059 | Mapped |
| CVE-2025-24991 | Microsoft Windows | T1005 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1055 T1068 T1203 T1204 T1565 | Mapped |
| CVE-2025-25181 | Advantive VeraCore | T1055 T1068 T1485 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1055 T1059.004 T1068 T1190 T1485 | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | T1059 T1203 | Mapped |
| CVE-2025-27363 | FreeType FreeType | T1204.002 T1499.004 T1574 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1203 T1497 T1548 | Mapped |
| CVE-2025-30397 | Microsoft Windows | T1059 T1203 | Mapped |
| CVE-2025-30400 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | T1059 T1203 | Mapped |
| CVE-2025-31161 | CrushFTP CrushFTP | T1059 T1078 T1136 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1001 T1059 T1105 T1106 T1203 T1557 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1001 T1059 T1105 T1106 T1203 T1557 | Stale |
| CVE-2025-31324 | SAP NetWeaver | T1055 T1059 T1505.003 | Mapped |
| CVE-2025-32433 | Erlang Erlang/OTP | T1059 | Mapped |
| CVE-2025-3248 | Langflow Langflow | T1059 T1203 | Mapped |
| CVE-2025-32701 | Microsoft Windows | T1059 T1068 T1543 | Mapped |
| CVE-2025-32706 | Microsoft Windows | T1059 T1068 T1543 | Mapped |
| CVE-2025-32709 | Microsoft Windows | T1003 T1059 T1068 T1543 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1003 T1041 T1046 T1059 T1070.004 T1133 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1041 T1056.001 T1059 T1543 T1566.001 | Mapped |
| CVE-2025-34028 | Commvault Command Center | T1059.007 T1190 | Mapped |
| CVE-2025-35939 | Craft CMS Craft CMS | T1059 T1190 T1505.003 | Mapped |
| CVE-2025-3928 | Commvault Web Server | T1059 T1505.003 | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | T1059 T1203 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1059 T1190 T1499 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1059 T1190 T1203 T1505.003 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1005 T1105 T1203 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1059 T1190 T1203 T1505.003 | Mapped |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) | T1059 T1190 T1543 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1059 T1068 T1496 | Mapped |
| CVE-2025-47812 | Wing FTP Server Wing FTP Server | T1059 T1068 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1005 T1212 T1555 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1005 T1212 T1555 | Mapped |
| CVE-2025-49704 | Microsoft SharePoint | T1190 | Mapped |
| CVE-2025-49706 | Microsoft SharePoint | T1190 T1505 | Mapped |
| CVE-2025-53770 | Microsoft SharePoint | T1059 T1190 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1021 T1068 T1567 | Mapped |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | T1190 T1555 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | T1059 T1203 T1498 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1059 T1189 T1203 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 T1203 T1497 | Mapped |