kevmap

Log sources › AWS:CloudTrail

AWS:CloudTrail

Inverted view: what can be detected if this is the log you have. Containers, IaaS, Identity Provider, SaaS, Windows

106
channels
92
analytics
89
techniques
119
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
AWS ConsoleLogin, StartSession DC0067 Logon Session Creation AN0753 1
AWS IAM: ListUsers, ListRoles DC0002 User Account Authentication AN1088 1
AssumeRole DC0013 User Account Metadata AN0417 AN0958 AN0960 AN1328 3
AssumeRole or ConsoleLogin with repeated MFA failures followed by repeated MFA requests DC0002 User Account Authentication AN0450 1
AssumeRole, GetFederationToken API calls by unusual or new entities DC0006 Web Credential Creation AN0717 1
AssumeRole, GetFederationToken, GetSessionToken DC0007 Web Credential Usage AN0526 1
AssumeRole,AssumeRoleWithSAML,AssumeRoleWithWebIdentity DC0067 Logon Session Creation AN1348 1
AssumeRole: Discovery actions tied to assumed identities outside of normal context DC0013 User Account Metadata AN1127 1
AssumeRoleWithSAML DC0007 Web Credential Usage AN0419 1
AssumeRoleWithWebIdentity DC0002 User Account Authentication AN0530 1
AttachUserPolicy DC0010 User Account Modification AN0900 AN1608 2
AttachUserPolicy, CreatePolicyVersion, PutRolePolicy DC0010 User Account Modification AN0771 1
AuthorizeSecurityGroupIngress DC0051 Firewall Rule Modification AN0492 AN2041 2
ConsoleLogin DC0067 Logon Session Creation AN0201 AN0808 2
ConsoleLogin or AssumeRole DC0002 User Account Authentication AN1285 1
ConsoleLogin, AssumeRole, ListAccessKeys, CreateUser DC0002 User Account Authentication AN1504 1
ConsoleLogin, AssumeRole, ListResources DC0067 Logon Session Creation AN0017 1
ConsoleLogin: If IdP backed by cloud provider, Console login from new IP/agent after correlated endpoint compromise DC0067 Logon Session Creation AN0501 1
CopySnapshot DC0062 Snapshot Metadata AN1580 1
Create egress rule allowing UDP to port 53, 123, 11211 DC0051 Firewall Rule Modification AN1143 1
CreateAccessKey, ImportKeyPair, CreateLoginProfile, CreateKeyPair DC0087 Active Directory Object Creation AN1470 1
CreateBucket DC0024 Cloud Storage Creation AN0690 1
CreateFunction DC0069 Cloud Service Modification AN0027 1
CreateFunction / UpdateFunctionConfiguration: Function creation, role assignment, or configuration change events DC0069 Cloud Service Modification AN1053 1
CreatePod: Programmatic creation of new pod resources using container images not seen before in the environment DC0019 Pod Creation AN0233 1
CreateSnapshot DC0057 Snapshot Creation AN0861 AN1187 AN1580 3
CreateTrafficMirrorSession / ModifyTrafficMirrorTarget DC0069 Cloud Service Modification AN0878 1
CreateTrafficMirrorSession or ModifyTrafficMirrorTarget DC0078 Network Traffic Flow AN1131 1
CreateUser DC0014 User Account Creation AN0900 AN1608 2
CreateUser|AttachRolePolicy|CreateAccessKey|UpdateAssumeRolePolicy|CreateLoginProfile DC0038 Application Log Content AN1348 1
CreateVolume DC0097 Volume Creation AN0861 1
Decrypt DC0021 OS API Execution AN1201 1
Delete* / Stop*: DeleteAlarms, StopLogging, or DisableMonitoring API calls DC0069 Cloud Service Modification AN1372 1
DeleteBucket, DeleteDBCluster, DeleteSnapshot, TerminateInstances DC0022 Cloud Storage Deletion AN0414 AN0937 2
DeleteSnapshot DC0049 Snapshot Deletion AN0861 AN0937 2
DeleteVolume, ModifyVolume DC0098 Volume Deletion AN0861 1
Describe* or List* API calls DC0021 OS API Execution AN0908 1
DescribeDBInstances DC0075 Instance Enumeration AN0481 1
DescribeInstances DC0086 Instance Metadata AN0234 AN0481 AN1242 3
DescribeInstances, DescribeServices, ListFunctions: High frequency enumeration calls or unusual user agents performing discovery DC0083 Cloud Service Enumeration AN1127 1
DescribeInstances, GetConsoleOutput, DescribeImages DC0075 Instance Enumeration AN1456 1
DescribeSnapshots DC0062 Snapshot Metadata AN1187 1
DescribeUsers / ListUsers / GetUser DC0083 Cloud Service Enumeration AN1615 1
GetAccountPasswordPolicy DC0013 User Account Metadata AN0458 1
GetCallerIdentity DC0007 Web Credential Usage AN0960 1
GetInstanceIdentityDocument DC0070 Cloud Service Metadata AN0001 1
GetInstanceIdentityDocument or IMDSv2 token requests DC0083 Cloud Service Enumeration AN1424 1
GetLogEvents: High frequency log exports from CloudWatch or equivalent services DC0064 Command Execution AN0708 1
GetMetadata, DescribeInstanceIdentity DC0021 OS API Execution AN0122 1
GetObject, CopyObject DC0025 Cloud Storage Access AN0043 AN0198 AN0370 AN0666 AN1328 AN1594 AN1625 7
GetSecretValue DC0070 Cloud Service Metadata
DC0083 Cloud Service Enumeration
AN0366 AN1157 AN1201 3
GetSessionToken, AssumeRoleWithWebIdentity DC0007 Web Credential Usage AN0483 1
Ingress rule creation or modification for security group DC0051 Firewall Rule Modification AN1188 1
InvokeFunction DC0064 Command Execution
DC0070 Cloud Service Metadata
AN0027 AN1168 2
InvokeFunction: Unexpected or repeated invocation of functions not tied to known workflows DC0038 Application Log Content AN1053 1
LeaveOrganization: API calls severing accounts from AWS Organizations DC0069 Cloud Service Modification AN0442 1
ListBuckets DC0017 Cloud Storage Enumeration AN0481 AN1625 2
ListGroups, ListAttachedRolePolicies DC0099 Group Enumeration AN0695 1
ListObjectsV2 DC0017 Cloud Storage Enumeration AN1594 1
ModifyImageAttribute DC0036 Image Modification AN0947 1
ModifyInstanceAttribute DC0073 Instance Modification AN2041 1
ModifySnapshotAttribute DC0058 Snapshot Modification AN0861 AN1580 2
ModifyVolume DC0092 Volume Modification AN0861 1
PassRole DC0013 User Account Metadata AN1105 1
Post-authentication metadata enumeration from GUI session DC0027 Cloud Storage Metadata AN0808 1
PutBucketLifecycle, PutLifecycleConfiguration, SetBucketLifecycle, storage.buckets.update DC0023 Cloud Storage Modification AN0117 1
PutBucketPolicy DC0023 Cloud Storage Modification AN1580 1
PutIdentityPolicy DC0069 Cloud Service Modification AN0417 1
PutObject DC0039 File Creation AN1625 1
PutObject (with SSE-C), UploadPart (SSE-C) DC0023 Cloud Storage Modification AN0606 1
PutObject: S3 writes with .sql/.csv extension by same identity or within 5 min of DB access DC0025 Cloud Storage Access AN0679 1
PutUserPolicy, PutGroupPolicy, PutRolePolicy, CreatePolicyVersion DC0069 Cloud Service Modification AN0087 1
RegisterImage DC0015 Image Creation AN0947 1
Removal of restrictive egress rules from a security group DC0043 Firewall Disable AN1188 1
RequestServiceQuotaIncrease DC0069 Cloud Service Modification AN1356 1
RevertSnapshot DC0073 Instance Modification AN0953 1
RunInstances DC0080 Instance Start AN0690 AN0692 AN0744 AN0861 AN0947 AN1242 AN1493 7
RunInstances,CreateImage DC0076 Instance Creation AN1318 1
SSM RunCommand DC0064 Command Execution AN0626 1
SendCommand, StartSession, ExecuteCommand: Unexpected AWS Systems Manager command execution targeting EC2 instances DC0064 Command Execution AN1502 1
SendEmail DC0038 Application Log Content AN0417 1
SendSSHPublicKey, StartSession (SSM), EC2InstanceConnect DC0067 Logon Session Creation AN0594 1
SessionToken used without preceding MFA or login event DC0007 Web Credential Usage AN0201 1
StartInstances DC0080 Instance Start AN0084 AN0587 AN0953 AN1318 4
Stop logging for an existing CloudTrail DC0090 Cloud Service Disable AN0801 1
StopInstances DC0089 Instance Stop AN0953 1
StopLogging, DeleteTrail, UpdateTrail: API calls that disable or modify logging services DC0038 Application Log Content AN1636 1
StopLogging, DeleteTrail, or DisableSecurityService DC0090 Cloud Service Disable AN0891 AN2041 1
Temporary security credentials used to authenticate into management console or APIs DC0067 Logon Session Creation AN0717 1
TerminateInstances DC0089 Instance Stop AN0234 AN0853 AN0861 3
UpdateAccountPasswordPolicy DC0069 Cloud Service Modification AN0291 1
UpdateFederationSettings or RegisterHybridConnector DC0069 Cloud Service Modification AN0816 1
UpdateIdentityPolicy or DisableMFA DC0069 Cloud Service Modification AN0545 1
UpdateLoginProfile DC0010 User Account Modification AN0291 1
Use of temporary credentials issued from IMDS access DC0069 Cloud Service Modification AN1424 1
Web console logins using session cookies without corresponding MFA event DC0067 Logon Session Creation AN0483 1
command-line execution invoking credential enumeration DC0064 Command Execution AN0860 1
cross-account or unexpected assume role DC0034 Process Metadata AN0979 1
eventName: RunInstances, CreateUser, PutRolePolicy, InvokeCommand DC0064 Command Execution AN0215 1
eventName=ConsoleLogin | eventType=AwsConsoleSignIn DC0002 User Account Authentication AN1270 1
rds:ExecuteStatement: Large data access via RDS or Aurora with unknown session context DC0070 Cloud Service Metadata AN0679 1
role privilege expansion detected DC0010 User Account Modification AN0979 1
ssm:GetCommandInvocation DC0064 Command Execution AN1103 1
ssm:ListInventoryEntries DC0083 Cloud Service Enumeration AN1103 1
sts:GetFederationToken DC0002 User Account Authentication AN0526 1
sudden role assumption after credential file access DC0067 Logon Session Creation AN0860 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1020.001 Traffic Duplicationexfiltration00
T1021 Remote Serviceslateral movement114
T1021.007 Cloud Serviceslateral movement10
T1021.008 Direct Cloud VM Connectionslateral movement00
T1040 Network Sniffingcredential access, discovery92
T1048 Exfiltration Over Alternative Protocolexfiltration124
T1049 System Network Connections Discoverydiscovery91
T1059.009 Cloud APIexecution30
T1059.013 Container CLI/APIexecution00
T1069.003 Cloud Groupsdiscovery10
T1072 Software Deployment Toolsexecution, lateral movement40
T1074 Data Stagedcollection20
T1074.002 Remote Data Stagingcollection00
T1078.001 Default Accountsstealth, persistence, privilege escalation, initial access40
T1078.004 Cloud Accountsstealth, persistence, privilege escalation, initial access411
T1082 System Information Discoverydiscovery337
T1087 Account Discoverydiscovery166
T1087.004 Cloud Accountdiscovery30
T1098.001 Additional Cloud Credentialspersistence, privilege escalation30
T1098.003 Additional Cloud Rolespersistence, privilege escalation70
T1110.004 Credential Stuffingcredential access00
T1136 Create Accountpersistence310
T1136.003 Cloud Accountpersistence30
T1189 Drive-by Compromiseinitial access321
T1199 Trusted Relationshipinitial access21
T1201 Password Policy Discoverydiscovery60
T1204 User Executionexecution102
T1204.003 Malicious Imageexecution00
T1211 Exploitation for Stealthstealth41
T1213.006 Databasescollection00
T1485 Data Destructionimpact206
T1485.001 Lifecycle-Triggered Deletionimpact00
T1486 Data Encrypted for Impactimpact1615
T1490 Inhibit System Recoveryimpact272
T1491 Defacementimpact00
T1491.002 External Defacementimpact01
T1496 Resource Hijackingimpact1319
T1496.001 Compute Hijackingimpact00
T1496.002 Bandwidth Hijackingimpact00
T1496.004 Cloud Service Hijackingimpact00
T1498.002 Reflection Amplificationimpact00
T1499 Endpoint Denial of Serviceimpact37
T1499.002 Service Exhaustion Floodimpact02
T1499.003 Application Exhaustion Floodimpact00
T1499.004 Application or System Exploitationimpact32
T1518 Software Discoverydiscovery40
T1525 Implant Internal Imagepersistence10
T1526 Cloud Service Discoverydiscovery30
T1528 Steal Application Access Tokencredential access141
T1530 Data from Cloud Storagecollection02
T1535 Unused/Unsupported Cloud Regionsstealth00
T1537 Transfer Data to Cloud Accountexfiltration60
T1538 Cloud Service Dashboarddiscovery00
T1546 Event Triggered Executionprivilege escalation, persistence100
T1548 Abuse Elevation Control Mechanismprivilege escalation244
T1548.005 Temporary Elevated Cloud Accessprivilege escalation00
T1550 Use Alternate Authentication Materiallateral movement50
T1550.001 Application Access Tokenlateral movement40
T1550.004 Web Session Cookielateral movement00
T1552 Unsecured Credentialscredential access134
T1552.001 Credentials In Filescredential access243
T1552.005 Cloud Instance Metadata APIcredential access00
T1555 Credentials from Password Storescredential access89
T1555.006 Cloud Secrets Management Storescredential access00
T1556 Modify Authentication Processdefense impairment, persistence, credential access122
T1556.006 Multi-Factor Authenticationdefense impairment, persistence, credential access30
T1556.007 Hybrid Identitydefense impairment, persistence, credential access00
T1556.009 Conditional Access Policiesdefense impairment, persistence, credential access00
T1578 Modify Cloud Compute Infrastructuredefense impairment10
T1578.001 Create Snapshotdefense impairment00
T1578.002 Create Cloud Instancedefense impairment00
T1578.003 Delete Cloud Instancedefense impairment10
T1578.004 Revert Cloud Instancedefense impairment00
T1578.005 Modify Cloud Compute Configurationsdefense impairment00
T1580 Cloud Infrastructure Discoverydiscovery10
T1606 Forge Web Credentialscredential access10
T1606.001 Web Cookiescredential access00
T1606.002 SAML Tokenscredential access00
T1614 System Location Discoverydiscovery00
T1619 Cloud Storage Object Discoverydiscovery10
T1621 Multi-Factor Authentication Request Generationcredential access20
T1648 Serverless Executionexecution00
T1651 Cloud Administration Commandexecution00
T1654 Log Enumerationdiscovery00
T1666 Modify Cloud Resource Hierarchydefense impairment00
T1685 Disable or Modify Toolsdefense impairment1640
T1685.002 Disable or Modify Cloud Logdefense impairment30
T1686.001 Cloud Firewalldefense impairment50
T1687 Exploitation for Defense Impairmentdefense impairment00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2009-3960Adobe BlazeDS T1486 Mapped
CVE-2010-0188Adobe Reader and Acrobat T1189 Mapped
CVE-2010-1297Adobe Flash Player T1189 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2013-0641Adobe Reader T1048 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 T1499.004 Mapped
CVE-2015-8651Adobe Flash Player T1189 T1486 Mapped
CVE-2016-1019Adobe Flash Player T1189 T1486 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2017-12637SAP NetWeaver T1555 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1048 Mapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1496 Mapped
CVE-2018-11776Apache Struts T1496 Mapped
CVE-2018-15961Adobe ColdFusion T1491.002 Mapped
CVE-2018-7600Drupal Drupal Core T1485 T1496 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1552.001 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1486 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1082 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1496 Mapped
CVE-2020-12812Fortinet FortiOS T1556 Mapped
CVE-2020-1472Microsoft Netlogon T1021 T1486 Mapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1499 Mapped
CVE-2020-5902F5 BIG-IP T1552 Stale
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1556 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1082 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1082 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1496 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1496 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1485 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1496 Mapped
CVE-2021-32030ASUS Routers T1040 Mapped
CVE-2021-34473Microsoft Exchange Server T1136 T1486 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1496 T1499 Mapped
CVE-2021-39226Grafana Labs Grafana T1485 Mapped
CVE-2021-40449Microsoft Windows T1082 Mapped
CVE-2021-40539Zoho ManageEngine T1136 Mapped
CVE-2021-42258BQE BillQuick Web Suite T1486 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1136 Mapped
CVE-2021-44228Apache Log4j2 T1486 T1496 Mapped
CVE-2021-44515Zoho Desktop Central T1087 Mapped
CVE-2021-45046Apache Log4j2 T1486 Mapped
CVE-2021-45382D-Link Multiple Routers T1499.002 Mapped
CVE-2022-1040Sophos Firewall T1040 Mapped
CVE-2022-1388F5 BIG-IP T1548 Mapped
CVE-2022-21999Microsoft Windows T1211 Mapped
CVE-2022-22947VMware Spring Cloud Gateway T1486 Mapped
CVE-2022-23131Zabbix Frontend T1548 Mapped
CVE-2022-26138Atlassian Confluence T1552.001 Mapped
CVE-2022-26258D-Link DIR-820L T1499.002 Mapped
CVE-2022-26500Veeam Backup & Replication T1048 Mapped
CVE-2022-26501Veeam Backup & Replication T1048 Mapped
CVE-2022-29303SolarView Compact T1496 Mapped
CVE-2022-29464WSO2 Multiple Products T1496 Mapped
CVE-2022-41082Microsoft Exchange Server T1087 Mapped
CVE-2022-41328Fortinet FortiOS T1049 Mapped
CVE-2023-0669Fortra GoAnywhere MFT T1486 Mapped
CVE-2023-1389TP-Link Archer AX21 T1496 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1499 Mapped
CVE-2023-20198Cisco IOS XE Web UI T1136 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1136 Mapped
CVE-2023-22527Atlassian Confluence Data Center and Server T1496 Mapped
CVE-2023-22952SugarCRM Multiple Products T1530 Stale
CVE-2023-27532Veeam Backup & Replication T1087 T1486 T1555 Mapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN T1136 Mapped
CVE-2023-28252Microsoft Windows T1021 T1136 T1486 Mapped
CVE-2023-32315Ignite Realtime Openfire T1496 Mapped
CVE-2023-34362Progress MOVEit Transfer T1082 T1136 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1136 Mapped
CVE-2023-36884Microsoft Windows T1486 T1490 Stale
CVE-2023-38035Ivanti Sentry T1496 Mapped
CVE-2023-38831RARLAB WinRAR T1204 T1486 Mapped
CVE-2023-43770Roundcube Webmail T1082 T1189 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1548 Mapped
CVE-2023-44487IETF HTTP/2 T1499 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1555 Mapped
CVE-2023-47565QNAP VioStor NVR T1496 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1552 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1496 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1499 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1552 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1552 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1555 Mapped
CVE-2024-23692Rejetto HTTP File Server T1082 T1496 Mapped
CVE-2024-38112Microsoft Windows T1189 Mapped
CVE-2024-38475Apache HTTP Server T1528 Mapped
CVE-2024-4671Google Chromium T1189 Mapped
CVE-2024-49035Microsoft Partner Center T1530 Mapped
CVE-2024-4947Google Chromium V8 T1189 Mapped
CVE-2024-5274Google Chromium V8 T1189 Mapped
CVE-2024-53704SonicWall SonicOS T1078.004 T1199 Mapped
CVE-2024-54085AMI MegaRAC SPx T1499 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1021 T1555 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1552.001 Mapped
CVE-2025-21391Microsoft Windows T1485 T1490 Mapped
CVE-2025-24054Microsoft Windows T1555 Mapped
CVE-2025-24201Apple Multiple Products T1189 Mapped
CVE-2025-24993Microsoft Windows T1204 Mapped
CVE-2025-25181Advantive VeraCore T1485 Mapped
CVE-2025-25257Fortinet FortiWeb T1485 Mapped
CVE-2025-27363FreeType FreeType T1499.004 Mapped
CVE-2025-2783Google Chromium Mojo T1548 Mapped
CVE-2025-31161CrushFTP CrushFTP T1136 Mapped
CVE-2025-42599Qualitia Active! Mail T1499 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1496 Mapped
CVE-2025-48927TeleMessage TM SGNL T1555 Mapped
CVE-2025-48928TeleMessage TM SGNL T1555 Mapped
CVE-2025-5419Google Chromium V8 T1189 Mapped
CVE-2025-54309CrushFTP CrushFTP T1021 Mapped
CVE-2025-5777Citrix NetScaler ADC and Gateway T1555 Mapped
CVE-2025-6554Google Chromium V8 T1189 Mapped
CVE-2025-6558Google Chromium T1189 Mapped