kevmap

Log sources › linux:osquery

linux:osquery

Inverted view: what can be detected if this is the log you have. Linux

38
channels
48
analytics
47
techniques
42
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
/proc/*/maps access DC0055 File Access AN1494 1
Detection of bitwise operations or custom encryption functions in memory traces DC0020 Process Modification AN1214 1
Execution of binary resolved from $PATH not located in /usr/bin or /bin DC0032 Process Creation AN0010 1
Filesystem modifications to trusted paths DC0059 File Metadata AN0984 1
Listing of /etc/passwd and /etc/shadow metadata DC0013 User Account Metadata AN1078 1
New or modified kernel object files (.ko) within /lib/modules directory DC0061 File Modification AN1243 1
None DC0055 File Access AN1532 1
Process State DC0035 Process Access AN0096 1
Process execution with LD_PRELOAD or modified library path DC0032 Process Creation AN0610 1
Process linked with libcrypto.so making external connections DC0016 Module Load AN0401 1
Processes linked with libssl or crypto libraries making outbound connections DC0032 Process Creation AN0760 1
Processes linked with libssl/libcrypto performing network activity DC0016 Module Load AN1497 1
Read headers and detect MIME type mismatch DC0059 File Metadata AN0631 1
Write or modify .desktop file in XDG autostart path DC0059 File Metadata AN1096 1
child process invoking dynamic linker post-ptrace DC0032 Process Creation AN1241 1
crontab, systemd_timers DC0001 Scheduled Job Creation AN0259 1
elf_info, hash, yara_matches DC0059 File Metadata AN0600 1
event-based DC0059 File Metadata AN0014 AN1463 2
execution of known firewall binaries DC0032 Process Creation AN0407 1
family=AF_PACKET or protocol raw; process name not in allowlist. DC0082 Network Connection Creation AN0463 1
file_events DC0001 Scheduled Job Creation
DC0039 File Creation
DC0059 File Metadata
DC0061 File Modification
AN0312 AN0356 AN0541 AN0645 AN0873 AN1062 AN1529 AN1627 8
file_events.path DC0059 File Metadata AN0974 1
hardware_events DC0054 Drive Access AN1354 1
hash, elf_info, file_metadata DC0059 File Metadata AN0056 1
newly registered unit file with ExecStart pointing to unknown binary DC0060 Service Creation AN0701 1
process environment variables containing LD_PRELOAD DC0034 Process Metadata AN1209 1
process execution events for permission modification utilities with command-line analysis DC0032 Process Creation AN0998 1
process listening or connecting on non-standard ports DC0032 Process Creation AN0634 1
process metadata mismatch between /proc and runtime attributes DC0034 Process Metadata AN1196 1
process_events DC0032 Process Creation
DC0035 Process Access
AN1306 AN1310 AN1418 3
process_events.command_line DC0064 Command Execution AN1395 1
processes modifying environment variables related to history logging DC0032 Process Creation AN1555 1
scheduled/real-time DC0041 Service Metadata AN0325 1
select: path LIKE '/dev/video%' DC0034 Process Metadata AN0569 1
socat, ssh, or nc processes opening unexpected ports DC0032 Process Creation AN1484 1
socket_events DC0078 Network Traffic Flow AN1081 1
state=attached/debugged DC0034 Process Metadata AN0579 1
unexpected termination of syslog or rsyslog processes DC0033 Process Termination AN0668 0

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1003.005 Cached Domain Credentialscredential access80
T1011.001 Exfiltration Over Bluetoothexfiltration00
T1014 Rootkitstealth10
T1027.001 Binary Paddingstealth30
T1027.005 Indicator Removal from Toolsstealth40
T1027.006 HTML Smugglingstealth00
T1027.008 Stripped Payloadsstealth00
T1027.009 Embedded Payloadsstealth20
T1027.010 Command Obfuscationstealth100
T1027.011 Fileless Storagestealth10
T1036 Masqueradingstealth402
T1036.002 Right-to-Left Overridestealth30
T1036.003 Rename Legitimate Utilitiesstealth270
T1036.004 Masquerade Task or Servicestealth30
T1036.005 Match Legitimate Resource Name or Locationstealth211
T1036.008 Masquerade File Typestealth10
T1036.010 Masquerade Account Namestealth00
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation03
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1053.006 Systemd Timersexecution, persistence, privilege escalation00
T1055.008 Ptrace System Callsstealth, privilege escalation00
T1055.009 Proc Memorystealth, privilege escalation20
T1055.014 VDSO Hijackingstealth, privilege escalation00
T1057 Process Discoverydiscovery80
T1059.004 Unix Shellexecution1814
T1070.006 Timestompstealth60
T1114 Email Collectioncollection43
T1120 Peripheral Device Discoverydiscovery20
T1125 Video Capturecollection10
T1205.002 Socket Filtersstealth, persistence, command and control00
T1222.002 Linux and Mac Permissionsdefense impairment40
T1480.001 Environmental Keyingstealth00
T1543.002 Systemd Servicepersistence, privilege escalation40
T1547.006 Kernel Modules and Extensionspersistence, privilege escalation20
T1547.013 XDG Autostart Entriespersistence, privilege escalation00
T1560.003 Archive via Custom Methodcollection00
T1564.013 Bind Mountsstealth00
T1571 Non-Standard Portcommand and control51
T1572 Protocol Tunnelingcommand and control240
T1573 Encrypted Channelcommand and control60
T1573.001 Symmetric Cryptographycommand and control03
T1573.002 Asymmetric Cryptographycommand and control00
T1574 Hijack Execution Flowstealth, execution816
T1574.006 Dynamic Linker Hijackingstealth, execution20
T1574.007 Path Interception by PATH Environment Variablestealth, execution20
T1686 Disable or Modify System Firewalldefense impairment70
T1690 Prevent Command History Loggingdefense impairment10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2016-10033PHP PHPMailer T1059.004 Mapped
CVE-2016-1010Adobe Flash Player and AIR T1574 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1574 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1059.004 Mapped
CVE-2020-0688Microsoft Exchange Server T1114 Mapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1574 Mapped
CVE-2021-36380Sunhillo SureLine T1059.004 Mapped
CVE-2021-40449Microsoft Windows T1573.001 Mapped
CVE-2021-40539Zoho ManageEngine T1573.001 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1573.001 Mapped
CVE-2022-1040Sophos Firewall T1574 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 Mapped
CVE-2022-3038Google Chromium Network Service T1574 Mapped
CVE-2022-41073Microsoft Windows T1574 Mapped
CVE-2022-41328Fortinet FortiOS T1037 T1574 Mapped
CVE-2022-42475Fortinet FortiOS T1574 Mapped
CVE-2023-26360Adobe ColdFusion T1036.005 Mapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN T1574 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1574 Mapped
CVE-2023-38035Ivanti Sentry T1571 Mapped
CVE-2023-38831RARLAB WinRAR T1053 T1059.004 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1059.004 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1059.004 Mapped
CVE-2023-46604Apache ActiveMQ T1059.004 Mapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway T1574 Mapped
CVE-2023-5217Google Chromium libvpx T1574 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1574 Mapped
CVE-2023-7024Google Chromium WebRTC T1574 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-21762Fortinet FortiOS T1574 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1059.004 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1059.004 T1114 Mapped
CVE-2024-42009Roundcube Webmail T1114 Mapped
CVE-2024-4577PHP Group PHP T1053 Mapped
CVE-2025-25257Fortinet FortiWeb T1059.004 Mapped
CVE-2025-27363FreeType FreeType T1574 Mapped