kevmap

Log sources › containerd:Events

containerd:Events

Inverted view: what can be detected if this is the log you have. Containers, Linux

5
channels
5
analytics
5
techniques
24
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Docker or containerd image pulls and process executions DC0034 Process Metadata AN0986 1
Image pull from untrusted registry (name NOT IN allowlist) or new digest never seen before DC0015 Image Creation AN0691 1
New container with suspicious image name or high resource usage DC0032 Process Creation AN0745 1
create DC0072 Container Creation AN1492 1
unusual process spawned from container image context DC0032 Process Creation AN1158 1

Techniques detectable from this source

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1496 Mapped
CVE-2018-11776Apache Struts T1496 Mapped
CVE-2018-7600Drupal Drupal Core T1496 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1496 Mapped
CVE-2020-5902F5 BIG-IP T1552 Stale
CVE-2020-8515DrayTek Multiple Vigor Routers T1496 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1496 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1496 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1496 Mapped
CVE-2021-44228Apache Log4j2 T1496 Mapped
CVE-2022-29303SolarView Compact T1496 Mapped
CVE-2022-29464WSO2 Multiple Products T1496 Mapped
CVE-2023-1389TP-Link Archer AX21 T1496 Mapped
CVE-2023-22527Atlassian Confluence Data Center and Server T1496 Mapped
CVE-2023-26360Adobe ColdFusion T1036.005 Mapped
CVE-2023-32315Ignite Realtime Openfire T1496 Mapped
CVE-2023-38035Ivanti Sentry T1496 Mapped
CVE-2023-47565QNAP VioStor NVR T1496 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1552 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1496 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1552 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1552 Mapped
CVE-2024-23692Rejetto HTTP File Server T1496 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1496 Mapped