Log sources › linux:syslog
linux:syslog
Inverted view: what can be detected if this is the log you have. Linux, Network Devices
77
channels
81
analytics
80
techniques
138
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
/var/log/syslog |
DC0029 Script Execution | AN0174 AN0211 AN0735 | 3 |
Accepted publickey/password for * from * port * ssh2 |
DC0067 Logon Session Creation | AN1345 | 1 |
Application or browser logs (webview errors, plugin enumerations) indicating suspicious script evaluation or plugin loads |
DC0038 Application Log Content | AN0499 | 1 |
Authentication attempts into finance-related servers from unusual IPs or times |
DC0038 Application Log Content | AN1362 | 1 |
Block device write errors or unusual bootloader activity |
DC0046 Drive Modification | AN0429 | 1 |
CLI access to 'show running-config', 'show password', or 'cat config.txt' |
DC0064 Command Execution | AN1159 | 1 |
DNS response IPs followed by connections to non-standard calculated ports |
DC0085 Network Traffic Content | AN0729 | 1 |
Discrepancies in _VBA_PROJECT p-code vs source code extracted with oletools/pcodedmp |
DC0059 File Metadata | AN0035 | 1 |
Driver load events or firmware load failures for hardware devices |
DC0079 Driver Load | AN0917 | 1 |
Error/warning logs from services indicating load spike or worker exhaustion |
DC0038 Application Log Content | AN1166 | 1 |
Execution of modified binaries or abnormal library load sequences |
DC0021 OS API Execution | AN1098 | 1 |
Execution of non-standard script or binary by cron |
DC0001 Scheduled Job Creation | AN0025 | 1 |
Failed password for invalid user |
DC0002 User Account Authentication | AN1337 | 1 |
Inbound messages from webmail services containing attachments or URLs |
DC0038 Application Log Content | AN0321 | 1 |
Integrity mismatch warnings or malformed packets detected |
DC0085 Network Traffic Content | AN0703 | 1 |
Kernel or daemon warnings of downgraded TLS or cryptographic settings |
DC0034 Process Metadata | AN0996 | 1 |
Module registration or stacktrace logs indicating segmentation faults or unknown module errors |
DC0038 Application Log Content | AN1508 | 1 |
Multiple NXDOMAIN responses and high entropy domains |
DC0085 Network Traffic Content | AN1179 | 1 |
New HID device enumeration with type 'keyboard' followed by immediate input injection |
DC0042 Drive Creation | AN1568 | 1 |
New Wi-Fi connection established or repeated association failures |
DC0082 Network Connection Creation | AN1477 | 1 |
Non-standard processes negotiating SSL/TLS key exchanges |
DC0038 Application Log Content | AN1497 | 1 |
None |
DC0067 Logon Session Creation DC0082 Network Connection Creation DC0088 Logon Session Metadata |
AN0505 AN1532 AN1638 | 3 |
Out of memory killer invoked or kernel panic entries |
DC0018 Host Status | AN0585 | 1 |
Query to suspicious domain with high entropy or low reputation |
DC0085 Network Traffic Content | AN0110 | 1 |
Repetitive HTTP 408, 500, or 503 errors logged within short timeframe |
DC0038 Application Log Content | AN0490 | 1 |
SPF fail OR DKIM fail OR DMARC fail OR mismatched from_domain vs return_path_domain |
DC0038 Application Log Content | AN1203 | 1 |
SSH failed login |
DC0002 User Account Authentication | AN1263 | 1 |
Segfaults, kernel oops, or crashes in security software processes |
DC0038 Application Log Content | AN1634 | 1 |
Service restart with modified executable path |
DC0041 Service Metadata | AN0610 | 1 |
Service stop or disable messages for security tools not reflected in SIEM alerts |
DC0018 Host Status | AN0869 | 1 |
Sudo or root escalation followed by filesystem mount commands |
DC0064 Command Execution | AN1272 | 1 |
Suspicious script or command execution targeting browser folders |
DC0064 Command Execution | AN0038 | 1 |
System daemons initiating encrypted sessions with unexpected destinations |
DC0038 Application Log Content | AN0401 | 1 |
Unauthorized sudo or shell access, especially leading to file changes in /var/www or /srv/http |
DC0032 Process Creation | AN0663 | 1 |
Unexpected SQL or application log entries showing tampered or malformed data |
DC0085 Network Traffic Content | AN0163 | 1 |
Unexpected termination of daemons or critical services not aligned with admin change tickets |
DC0033 Process Termination | AN0046 | 1 |
Unusual kinit or klist activity |
DC0084 Active Directory Credential Request | AN1444 | 1 |
Unusual outbound transfers from CLI tools like base64, gzip, or netcat |
DC0064 Command Execution | AN0303 | 1 |
application or system execution logs |
DC0059 File Metadata | AN0812 | 1 |
auditd service stopped or disabled |
DC0041 Service Metadata | AN0171 | 1 |
auth.log / secure.log |
DC0067 Logon Session Creation | AN1081 | 1 |
auth.log or custom tool logs |
DC0055 File Access | AN0293 | 1 |
authentication and authorization events during environmental validation phase |
DC0002 User Account Authentication | AN1552 | 1 |
authentication success after file access |
DC0067 Logon Session Creation | AN0857 | 1 |
boot logs |
DC0029 Script Execution | AN0658 | 1 |
browser/office crash, segfault, abnormal termination |
DC0038 Application Log Content | AN0798 | 1 |
cron activity |
DC0064 Command Execution | AN0014 | 1 |
curl|wget|python .*http |
DC0085 Network Traffic Content | AN0148 | 1 |
dmesg or syslog for module loads |
DC0079 Driver Load | AN0688 | 1 |
iptables or nftables rule changes |
DC0051 Firewall Rule Modification | AN0887 | 0 |
kernel messages related to cryptographic operations, module loading, and filesystem access patterns |
DC0055 File Access | AN1306 | 1 |
kernel|systemd messages indicating 'segmentation fault'|'core dumped'|'service terminated unexpectedly' for sshd, smbd, vsftpd, mysqld, httpd, etc. |
DC0038 Application Log Content | AN0328 | 1 |
kmod |
DC0016 Module Load | AN1062 | 1 |
milter configuration updated, transport rule initialized, unexpected script execution |
DC0038 Application Log Content | AN0473 | 1 |
mount/umount or file copy logs |
DC0054 Drive Access | AN1146 | 1 |
network |
DC0082 Network Connection Creation | AN1016 AN1584 | 2 |
opened document|clicked link|segfault|abnormal termination|sandbox |
DC0038 Application Log Content | AN1315 | 1 |
postfix/smtpd |
DC0082 Network Connection Creation | AN1310 | 1 |
processes binding to non-standard ports or sshd configured on unexpected port |
DC0038 Application Log Content | AN0634 | 1 |
rename |
DC0061 File Modification | AN0356 | 1 |
service stopped messages |
DC0041 Service Metadata | AN0062 | 1 |
sshd logs |
DC0064 Command Execution | AN1026 | 1 |
sshd sessions with unusual port forwarding parameters |
DC0038 Application Log Content | AN1484 | 1 |
sshd: Accepted password/publickey |
DC0067 Logon Session Creation | AN0751 | 1 |
sshd[pid]: Failed password |
DC0002 User Account Authentication | AN1522 | 1 |
sssd / sudo logs |
DC0088 Logon Session Metadata | AN0591 | 1 |
sudo chage|grep pam_pwquality|cat /etc/login.defs |
DC0064 Command Execution | AN0456 | 1 |
sudo execution of ffmpeg/gst-launch/v4l2-ctl by non-standard user |
DC0064 Command Execution | AN0569 | 1 |
sudo or service accounts invoking loaders with suspicious env vars |
DC0034 Process Metadata | AN0053 | 1 |
sudo or su access prior to content change |
DC0010 User Account Modification | AN0230 | 1 |
sudo/date/timedatectl execution by non-standard users |
DC0002 User Account Authentication | AN0431 | 1 |
suspicious DHCP lease assignment with unexpected DNS or gateway |
DC0038 Application Log Content | AN1291 | 1 |
syscalls (open, read, ioctl) on /dev/input or /proc/*/fd/* |
DC0035 Process Access | AN0688 | 1 |
system daemons initiating TLS sessions outside expected services |
DC0038 Application Log Content | AN0760 | 1 |
system is powering down |
DC0018 Host Status | AN1539 | 1 |
systemctl start/enable with uncommon binary paths |
DC0060 Service Creation | AN0779 | 1 |
usb * new|thunderbolt|pci .* added|block.*: new .* device |
DC0038 Application Log Content | AN0186 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2010-0188 | Adobe Reader and Acrobat | T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2013-3346 | Adobe Reader and Acrobat | T1059.007 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1059.004 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1059.007 T1203 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-10033 | PHP PHPMailer | T1059.004 | Mapped |
| CVE-2016-1010 | Adobe Flash Player and AIR | T1574 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1189 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1574 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1203 | Mapped |
| CVE-2018-4990 | Adobe Acrobat and Reader | T1059.007 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1059.004 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1552.001 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1114 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1021 | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1217 | Mapped |
| CVE-2020-5735 | Amcrest Cameras and Network Video Recorder (NVR) | T1499 T1574 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1552 | Stale |
| CVE-2021-21148 | Google Chromium V8 | T1059.007 T1203 | Mapped |
| CVE-2021-21166 | Google Chromium | T1059.007 T1203 | Mapped |
| CVE-2021-21206 | Google Chromium Blink | T1059.007 T1203 | Mapped |
| CVE-2021-27059 | Microsoft Office | T1203 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1203 | Mapped |
| CVE-2021-30554 | Google Chromium WebGL | T1059.007 T1203 | Mapped |
| CVE-2021-31207 | Microsoft Exchange Server | T1565 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1499 | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | T1059.004 | Mapped |
| CVE-2021-37975 | Google Chromium V8 | T1059.007 T1203 | Mapped |
| CVE-2021-39144 | XStream XStream | T1203 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1573.001 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1573.001 | Mapped |
| CVE-2021-41773 | Apache HTTP Server | T1210 | Mapped |
| CVE-2021-42013 | Apache HTTP Server | T1210 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1573.001 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1499.002 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1574 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-20703 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1211 | Mapped |
| CVE-2022-22963 | VMware Tanzu Spring Cloud | T1059.007 | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | T1203 | Mapped |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) | T1059.007 | Mapped |
| CVE-2022-26138 | Atlassian Confluence | T1552.001 | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | T1499.002 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1036 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1505 | Mapped |
| CVE-2022-3038 | Google Chromium Network Service | T1574 | Mapped |
| CVE-2022-41073 | Microsoft Windows | T1574 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1203 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1574 | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | T1574 | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1203 | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1210 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1499 | Mapped |
| CVE-2023-21608 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1059.007 | Mapped |
| CVE-2023-23397 | Microsoft Office | T1203 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1059.007 | Mapped |
| CVE-2023-26369 | Adobe Acrobat and Reader | T1203 | Mapped |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | T1574 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1021 | Mapped |
| CVE-2023-34048 | VMware vCenter Server | T1203 | Mapped |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | T1574 | Mapped |
| CVE-2023-36844 | Juniper Junos OS | T1203 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1489 | Stale |
| CVE-2023-38035 | Ivanti Sentry | T1018 T1571 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1059.004 T1204 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1021.004 T1059.004 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1189 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1059.004 | Mapped |
| CVE-2023-44487 | IETF HTTP/2 | T1499 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | T1059.004 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1203 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1552 | Mapped |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | T1574 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1203 | Mapped |
| CVE-2023-5217 | Google Chromium libvpx | T1574 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1059.007 | Mapped |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway | T1499 T1574 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 T1574 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1203 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1558 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1558 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1558 | Mapped |
| CVE-2024-20439 | Cisco Smart Licensing Utility | T1552 | Mapped |
| CVE-2024-21762 | Fortinet FortiOS | T1574 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1552 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1059.004 | Mapped |
| CVE-2024-26169 | Microsoft Windows | T1203 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1059.004 T1114 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1114 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1203 | Mapped |
| CVE-2024-4671 | Google Chromium | T1189 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1189 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1199 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1210 T1499 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1021 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1552.001 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1018 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1203 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1189 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1203 T1204 T1565 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1059.004 | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | T1203 | Mapped |
| CVE-2025-27363 | FreeType FreeType | T1574 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1203 | Mapped |
| CVE-2025-30397 | Microsoft Windows | T1203 | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | T1203 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1203 | Stale |
| CVE-2025-32433 | Erlang Erlang/OTP | T1021.004 | Mapped |
| CVE-2025-3248 | Langflow Langflow | T1203 | Mapped |
| CVE-2025-34028 | Commvault Command Center | T1059.007 | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | T1203 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1499 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1203 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1203 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1203 | Mapped |
| CVE-2025-49706 | Microsoft SharePoint | T1505 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1021 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | T1203 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 T1203 | Mapped |