Log sources › fs:fsusage
fs:fsusage
Inverted view: what can be detected if this is the log you have. macOS
30
channels
31
analytics
31
techniques
74
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
Detached process execution with no associated parent |
DC0021 OS API Execution | AN1224 | 1 |
Disk Activity Tracing |
DC0055 File Access | AN0618 | 1 |
File Access Monitor |
DC0055 File Access | AN0391 | 1 |
File IO |
DC0039 File Creation | AN0621 | 1 |
Filesystem Access Logging |
DC0061 File Modification | AN1322 | 1 |
Filesystem Call Monitoring |
DC0055 File Access | AN1042 | 1 |
access to BPF devices or interface IOCTLs |
DC0064 Command Execution | AN0877 | 1 |
binary execution of security_authtrampoline |
DC0032 Process Creation | AN0977 | 1 |
create: Attachment file creation in ~/Library/Mail directories |
DC0039 File Creation | AN1011 | 1 |
disk activity on /Library/LaunchAgents or LaunchDaemons |
DC0039 File Creation | AN0260 | 1 |
file |
DC0055 File Access | AN0313 | 1 |
file access to /usr/lib/cron/at and job execution path |
DC0061 File Modification | AN0945 | 1 |
file access to /usr/lib/cron/tabs/ and cron output files |
DC0061 File Modification | AN0806 | 1 |
file activity |
DC0039 File Creation | AN0659 | 1 |
file open for known browser cookie paths |
DC0055 File Access | AN1404 | 1 |
file open/write |
DC0039 File Creation | AN0784 AN0921 | 2 |
file reads/writes from /Volumes/ |
DC0055 File Access | AN1412 | 1 |
file system activity monitor |
DC0064 Command Execution | AN0344 | 1 |
file write |
DC0039 File Creation | AN1530 | 1 |
file write to launchd plist paths |
DC0061 File Modification | AN1577 | 1 |
filesystem activity |
DC0055 File Access | AN0813 | 1 |
filesystem monitoring of exec/open |
DC0059 File Metadata | AN0985 | 1 |
modification of existing LaunchAgents plist |
DC0061 File Modification | AN1208 | 1 |
open/read/mount operations |
DC0054 Drive Access | AN1147 | 1 |
open/write/exec calls |
DC0039 File Creation | AN0249 | 1 |
read/write |
DC0055 File Access | AN1072 | 1 |
truncate, unlink, write |
DC0061 File Modification | AN1439 | 1 |
unlink, fs_delete |
DC0040 File Deletion | AN0522 | 1 |
unlink, write |
DC0061 File Modification | AN0394 AN0468 | 2 |
write or chmod to ~/Library/LaunchAgents/*.plist |
DC0039 File Creation | AN1208 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2013-0629 | Adobe ColdFusion | T1005 | Mapped |
| CVE-2017-11292 | Adobe Flash Player | T1005 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1083 | Mapped |
| CVE-2017-5638 | Apache Struts | T1005 | Mapped |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | T1005 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1083 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1005 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1005 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1005 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1083 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1005 | Mapped |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1005 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1005 T1070.004 | Stale |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 | Mapped |
| CVE-2021-26085 | Atlassian Confluence Server | T1005 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1005 | Mapped |
| CVE-2021-27101 | Accellion FTA | T1005 | Mapped |
| CVE-2021-27102 | Accellion FTA | T1005 | Mapped |
| CVE-2021-27103 | Accellion FTA | T1005 | Mapped |
| CVE-2021-27104 | Accellion FTA | T1005 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1005 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1040 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1070.004 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1070.004 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1070 T1543 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1040 | Mapped |
| CVE-2022-1388 | F5 BIG-IP | T1548 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1548 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1070 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1037 | Mapped |
| CVE-2023-0386 | Linux Kernel | T1543 | Stale |
| CVE-2023-1389 | TP-Link Archer AX21 | T1070 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1070.004 T1083 | Stale |
| CVE-2023-26360 | Adobe ColdFusion | T1036.005 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1005 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1005 | Stale |
| CVE-2023-38831 | RARLAB WinRAR | T1005 T1053 | Mapped |
| CVE-2023-38950 | ZKTeco BioTime | T1005 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1543 T1548 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1005 | Mapped |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | T1005 | Mapped |
| CVE-2024-0769 | D-Link DIR-859 Router | T1005 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1005 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1005 | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | T1005 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1005 | Mapped |
| CVE-2024-41713 | Mitel MiCollab | T1005 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1053 T1543 | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | T1005 | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1005 | Mapped |
| CVE-2024-50302 | Linux Kernel | T1005 | Mapped |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 | Mapped |
| CVE-2024-53150 | Linux Kernel | T1005 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1083 | Mapped |
| CVE-2024-55550 | Mitel MiCollab | T1005 | Mapped |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | T1005 | Mapped |
| CVE-2025-21418 | Microsoft Windows | T1005 | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | T1005 | Mapped |
| CVE-2025-24991 | Microsoft Windows | T1005 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1548 | Mapped |
| CVE-2025-32701 | Microsoft Windows | T1543 | Mapped |
| CVE-2025-32706 | Microsoft Windows | T1543 | Mapped |
| CVE-2025-32709 | Microsoft Windows | T1543 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1070.004 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1543 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1005 | Mapped |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) | T1543 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1005 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1005 | Mapped |