Log sources › esxi:hostd
esxi:hostd
Inverted view: what can be detected if this is the log you have. ESXi, IaaS
51
channels
54
analytics
53
techniques
221
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/var/log/hostd.log |
DC0064 Command Execution DC0088 Logon Session Metadata |
AN0175 AN0593 | 2 |
/var/log/hostd.log API calls reading/altering time/ntp settings |
DC0034 Process Metadata | AN0433 | 1 |
/var/log/hostd.log anomalies (faults, crashes, restarts) around inbound connections |
DC0038 Application Log Content | AN0224 | 1 |
CLI network calls |
DC0078 Network Traffic Flow | AN0640 AN1602 | 2 |
Command Execution |
DC0064 Command Execution | AN1074 | 1 |
Execution of '/bin/vmx' or modifications to '/etc/rc.local.d/local.sh' |
DC0064 Command Execution | AN0912 | 1 |
Guest Operations API invocation: StartProgramInGuest, ListProcessesInGuest, ListFileInGuest, InitiateFileTransferFromGuest |
DC0038 Application Log Content | AN0646 | 1 |
Host daemon command log entries related to vib enumeration |
DC0038 Application Log Content | AN1104 | 1 |
Keywords: 'Backtrace','Signal 11','PANIC','hostd restarted','assert' or 'Service terminated unexpectedly' in /var/log/hostd.log, /var/log/vmkernel.log, /var/log/syslog.log. |
DC0038 Application Log Content | AN0329 | 1 |
Log entries indicating VM powered off or forcibly terminated |
DC0033 Process Termination | AN0064 | 1 |
New extension/module install with unknown vendor ID |
DC0038 Application Log Content | AN1510 | 1 |
None |
DC0064 Command Execution | AN0562 AN1586 | 2 |
Powering off or restarting host |
DC0018 Host Status | AN1541 | 1 |
Remote access API calls and file uploads |
DC0021 OS API Execution | AN1068 | 1 |
Service events |
DC0041 Service Metadata | AN0987 | 1 |
Service initiated connections |
DC0082 Network Connection Creation | AN0654 | 1 |
Service-Based Network Connection |
DC0082 Network Connection Creation | AN1297 | 1 |
Stop VM or disable service events via vim-cmd |
DC0041 Service Metadata | AN0064 | 1 |
System service interactions |
DC0082 Network Connection Creation | AN0033 | 1 |
binary or module replacement event |
DC0061 File Modification | AN0952 | 1 |
boot |
DC0061 File Modification | AN0314 | 1 |
command execution |
DC0064 Command Execution | AN0168 | 1 |
command log |
DC0064 Command Execution | AN0906 | 1 |
datastore file access |
DC0055 File Access | AN0439 AN0898 AN1574 | 3 |
datastore/log file access |
DC0055 File Access | AN0790 | 1 |
esxcli network firewall set commands |
DC0064 Command Execution | AN0409 | 1 |
esxcli system syslog config set or reload |
DC0064 Command Execution | AN0670 | 0 |
event stream |
DC0064 Command Execution | AN0426 AN1416 | 2 |
execution + payload hints |
DC0064 Command Execution | AN1392 | 1 |
execution of esxcli with args matching 'storage', 'filesystem', 'core device list' |
DC0032 Process Creation | AN0539 | 1 |
file copy or datastore upload via HTTPS |
DC0055 File Access | AN1515 | 1 |
host daemon events related to VM operations and configuration queries during reconnaissance |
DC0032 Process Creation | AN1554 | 1 |
host daemon events related to file or VM permission changes |
DC0059 File Metadata | AN0837 | 1 |
logline inspection |
DC0064 Command Execution | AN0371 | 1 |
method=RemoveUser or esxcli system account remove invocation |
DC0009 User Account Deletion | AN0337 | 1 |
modification of config files or shell command execution |
DC0064 Command Execution | AN0232 | 1 |
modification of crontab or local.sh entries |
DC0061 File Modification | AN0807 | 1 |
process |
DC0032 Process Creation | AN1018 | 1 |
process execution across cloud VM |
DC0032 Process Creation | AN0198 | 1 |
read: Access to sensitive log files by non-admin users |
DC0055 File Access | AN0709 | 1 |
registers services with legitimate-sounding names |
DC0041 Service Metadata | AN0359 | 1 |
rm, clearlogs, logrotate |
DC0040 File Deletion | AN0524 | 1 |
scp/ssh used to move file across hosts |
DC0064 Command Execution | AN0519 | 1 |
service state change |
DC0065 Service Modification | AN2044 | 1 |
shell access or job registration |
DC0064 Command Execution | AN0262 | 1 |
snapshot.removeall or snapshot file deletion |
DC0049 Snapshot Deletion | AN0935 | 1 |
task creation events |
DC0001 Scheduled Job Creation | AN0987 | 1 |
unexpected script invocations producing long encoded strings |
DC0038 Application Log Content | AN0930 | 1 |
unexpected script/command invocations via hostd |
DC0038 Application Log Content | AN0348 | 1 |
vSphere API calls modifying firewall settings |
DC0051 Firewall Rule Modification | AN0409 | 1 |
vSphere File API Access |
DC0055 File Access | AN1043 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2009-3960 | Adobe BlazeDS | T1190 | Mapped |
| CVE-2010-0188 | Adobe Reader and Acrobat | T1105 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1105 | Mapped |
| CVE-2010-2861 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2010-2883 | Adobe Acrobat and Reader | T1027 | Mapped |
| CVE-2011-0611 | Adobe Flash Player | T1105 | Mapped |
| CVE-2012-0754 | Adobe Flash Player | T1105 | Mapped |
| CVE-2012-1535 | Adobe Flash Player | T1105 | Mapped |
| CVE-2013-0625 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0629 | Adobe ColdFusion | T1005 T1190 | Mapped |
| CVE-2013-0631 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0632 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0641 | Adobe Reader | T1048 T1105 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1190 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1190 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1105 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1105 | Mapped |
| CVE-2016-0984 | Adobe Flash Player and AIR | T1105 | Mapped |
| CVE-2016-10033 | PHP PHPMailer | T1190 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1105 | Mapped |
| CVE-2016-4117 | Adobe Flash Player | T1105 | Mapped |
| CVE-2016-4437 | Apache Shiro | T1190 | Mapped |
| CVE-2017-11292 | Adobe Flash Player | T1005 T1105 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1083 T1190 | Mapped |
| CVE-2017-5638 | Apache Struts | T1005 T1190 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1048 | Mapped |
| CVE-2017-9805 | Apache Struts | T1190 | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1190 | Mapped |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | T1005 | Mapped |
| CVE-2018-11776 | Apache Struts | T1190 | Mapped |
| CVE-2018-13379 | Fortinet FortiOS | T1190 | Mapped |
| CVE-2018-15961 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2018-15982 | Adobe Flash Player | T1105 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2018-6789 | Exim Exim | T1190 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1190 | Mapped |
| CVE-2019-0604 | Microsoft SharePoint | T1190 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1083 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1005 T1190 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1005 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1005 T1190 | Mapped |
| CVE-2019-17558 | Apache Solr | T1190 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1190 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1083 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1005 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1190 | Mapped |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products | T1190 | Mapped |
| CVE-2020-17530 | Apache Struts | T1190 | Mapped |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices | T1190 | Mapped |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1005 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1005 T1190 | Stale |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 | Mapped |
| CVE-2021-21972 | VMware vCenter Server | T1190 | Mapped |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | T1190 | Mapped |
| CVE-2021-21975 | VMware vRealize Operations Manager API | T1190 | Mapped |
| CVE-2021-22005 | VMware vCenter Server | T1190 | Mapped |
| CVE-2021-22017 | VMware vCenter Server | T1190 | Mapped |
| CVE-2021-22204 | Perl Exiftool | T1190 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1190 | Mapped |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | T1190 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1190 | Mapped |
| CVE-2021-26085 | Atlassian Confluence Server | T1005 T1190 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1005 | Mapped |
| CVE-2021-26858 | Microsoft Exchange Server | T1190 | Mapped |
| CVE-2021-27065 | Microsoft Exchange Server | T1190 | Mapped |
| CVE-2021-27101 | Accellion FTA | T1005 | Mapped |
| CVE-2021-27102 | Accellion FTA | T1005 T1190 | Mapped |
| CVE-2021-27103 | Accellion FTA | T1005 T1190 | Mapped |
| CVE-2021-27104 | Accellion FTA | T1005 T1190 | Mapped |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN software | T1190 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1005 | Mapped |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack | T1190 | Mapped |
| CVE-2021-3129 | Laravel Ignition | T1190 | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | T1048.003 T1190 | Mapped |
| CVE-2021-34523 | Microsoft Exchange Server | T1190 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1105 T1190 | Mapped |
| CVE-2021-35464 | ForgeRock Access Management (AM) | T1190 | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | T1190 | Mapped |
| CVE-2021-37415 | Zoho ManageEngine ServiceDesk Plus (SDP) | T1190 | Mapped |
| CVE-2021-39144 | XStream XStream | T1190 | Mapped |
| CVE-2021-39226 | Grafana Labs Grafana | T1190 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1016 T1027 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1027 T1190 | Mapped |
| CVE-2021-40655 | D-Link DIR-605 Router | T1190 | Mapped |
| CVE-2021-41773 | Apache HTTP Server | T1210 | Mapped |
| CVE-2021-42013 | Apache HTTP Server | T1210 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1027 T1190 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1190 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1105 T1190 | Mapped |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | T1190 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1070 T1190 | Mapped |
| CVE-2022-0028 | Palo Alto Networks PAN-OS | T1190 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1190 | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1190 | Mapped |
| CVE-2022-20708 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1190 | Mapped |
| CVE-2022-20821 | Cisco IOS XR | T1190 | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | T1190 | Mapped |
| CVE-2022-22960 | VMware Multiple Products | T1222 | Mapped |
| CVE-2022-22963 | VMware Tanzu Spring Cloud | T1190 | Mapped |
| CVE-2022-22965 | VMware Spring Framework | T1190 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1190 | Mapped |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | T1027 T1190 | Mapped |
| CVE-2022-26134 | Atlassian Confluence Server/Data Center | T1190 | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | T1190 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1036 T1048 T1190 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1036 T1048 T1190 | Mapped |
| CVE-2022-28810 | Zoho ManageEngine | T1190 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1505 | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | T1190 | Mapped |
| CVE-2022-30190 | Microsoft Windows | T1105 | Mapped |
| CVE-2022-35914 | Teclib GLPI | T1190 | Mapped |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center | T1190 | Mapped |
| CVE-2022-39197 | Fortra Cobalt Strike | T1190 | Mapped |
| CVE-2022-40684 | Fortinet Multiple Products | T1190 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1567 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1070 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1037 T1049 | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | T1190 | Mapped |
| CVE-2022-42948 | Fortra Cobalt Strike | T1190 | Mapped |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1190 | Mapped |
| CVE-2022-47966 | Zoho ManageEngine | T1190 | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1190 T1210 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1070 | Mapped |
| CVE-2023-20198 | Cisco IOS XE Web UI | T1190 | Mapped |
| CVE-2023-20867 | VMware Tools | T1105 | Mapped |
| CVE-2023-20887 | VMware Aria Operations for Networks | T1190 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1190 | Mapped |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | T1105 T1190 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1083 T1190 | Stale |
| CVE-2023-26359 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1036.005 T1105 T1190 | Mapped |
| CVE-2023-27350 | PaperCut MF/NG | T1105 T1190 | Mapped |
| CVE-2023-27524 | Apache Superset | T1190 | Mapped |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | T1190 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1105 | Mapped |
| CVE-2023-29298 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-29300 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2023-29492 | Novi Survey Novi Survey | T1190 | Mapped |
| CVE-2023-33246 | Apache RocketMQ | T1190 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1005 T1105 T1190 T1531 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1190 | Mapped |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) | T1190 | Mapped |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | T1105 T1190 | Mapped |
| CVE-2023-36844 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-36845 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-36846 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-36847 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-36851 | Juniper Junos OS | T1190 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1005 T1489 T1490 | Stale |
| CVE-2023-38035 | Ivanti Sentry | T1018 T1105 T1190 | Mapped |
| CVE-2023-38203 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2023-38205 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1005 T1053 T1105 | Mapped |
| CVE-2023-38950 | ZKTeco BioTime | T1005 T1190 | Mapped |
| CVE-2023-42793 | JetBrains TeamCity | T1190 | Mapped |
| CVE-2023-44487 | IETF HTTP/2 | T1190 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | T1190 | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | T1190 | Mapped |
| CVE-2023-48365 | Qlik Sense | T1190 | Mapped |
| CVE-2023-48788 | Fortinet FortiClient EMS | T1105 T1190 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1005 T1190 | Mapped |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | T1005 | Mapped |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | T1105 T1190 | Mapped |
| CVE-2024-0769 | D-Link DIR-859 Router | T1005 T1190 | Mapped |
| CVE-2024-11182 | MDaemon Email Server | T1567 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1190 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1190 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1190 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 T1190 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) | T1190 | Mapped |
| CVE-2024-21762 | Fortinet FortiOS | T1190 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1190 | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | T1190 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1005 T1105 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1005 | Mapped |
| CVE-2024-27198 | JetBrains TeamCity | T1190 | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | T1005 T1190 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1005 T1190 | Mapped |
| CVE-2024-41713 | Mitel MiCollab | T1005 | Mapped |
| CVE-2024-4358 | Progress Telerik Report Server | T1190 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1053 T1190 T1570 | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | T1005 T1190 | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 T1190 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1005 T1105 | Mapped |
| CVE-2024-50302 | Linux Kernel | T1005 | Mapped |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 | Mapped |
| CVE-2024-53150 | Linux Kernel | T1005 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1083 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1210 | Mapped |
| CVE-2024-55550 | Mitel MiCollab | T1005 T1190 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1190 | Mapped |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | T1190 | Mapped |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | T1005 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1018 T1190 | Mapped |
| CVE-2025-1316 | Edimax IC-7100 IP Camera | T1190 | Mapped |
| CVE-2025-21391 | Microsoft Windows | T1490 | Mapped |
| CVE-2025-21418 | Microsoft Windows | T1005 | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | T1005 | Mapped |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1190 | Mapped |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | T1190 | Mapped |
| CVE-2025-24991 | Microsoft Windows | T1005 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1190 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1105 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1105 | Stale |
| CVE-2025-34028 | Commvault Command Center | T1190 | Mapped |
| CVE-2025-35939 | Craft CMS Craft CMS | T1190 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1190 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1190 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1005 T1105 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1190 | Mapped |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) | T1190 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1005 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1005 | Mapped |
| CVE-2025-49704 | Microsoft SharePoint | T1190 | Mapped |
| CVE-2025-49706 | Microsoft SharePoint | T1190 T1505 | Mapped |
| CVE-2025-53770 | Microsoft SharePoint | T1190 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1567 | Mapped |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | T1190 | Mapped |