kevmap

Log sources › macos:osquery

macos:osquery

Inverted view: what can be detected if this is the log you have. macOS

59
channels
94
analytics
94
techniques
140
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
CALCULATE: Integrity validation of transmitted data via hash checks DC0021 OS API Execution AN0704 1
CALCULATE: Mismatch in file integrity of critical macOS applications DC0061 File Modification AN1099 1
CONNECT: Long-lived connections from remote-control parents to external IPs/domains DC0082 Network Connection Creation AN1368 1
CREATE, DELETE, WRITE: Stored data manipulation attempts by unauthorized processes DC0040 File Deletion AN0557 1
CREATE/MODIFY: Creation of LaunchAgents/Daemons plists in user/system locations DC0039 File Creation AN1368 1
CREATE/MODIFY: Modification of app.asar inside .app bundle DC0039 File Creation AN0073 1
Changes to LSFileQuarantineEnabled field in Info.plist DC0061 File Modification AN0800 1
Execution of flooding tools or compiled packet generators DC0032 Process Creation AN1014 1
Execution of non-standard binaries accessing Kerberos APIs DC0032 Process Creation AN0070 1
File modifications in ~/Library/Preferences/ DC0061 File Modification AN0522 1
Interpreter exec with suspicious arguments as above DC0064 Command Execution AN0964 1
Invocation of osascript or dylib injection DC0032 Process Creation AN0650 1
Memory Mappings DC0020 Process Modification AN0391 1
Modifications to /var/db/SystemPolicyConfiguration/KextPolicy or kext_policy table DC0061 File Modification AN1244 1
New kext entries not signed by Apple or outside standard identifier prefix DC0031 Kernel Module Load AN1244 1
None DC0055 File Access
DC0082 Network Connection Creation
AN1533 1
Process Context DC0034 Process Metadata AN0097 1
Process Events and Launch Daemons DC0060 Service Creation AN0206 1
Process Execution + Hash DC0034 Process Metadata AN1296 1
Processes executing kextload, spctl, or modifying kernel extension directories DC0032 Process Creation AN1244 1
Rapid spawning of resource-heavy applications (e.g., Preview, Safari, Office) DC0032 Process Creation AN1167 1
Unsigned or ad-hoc signed process executions in user contexts DC0032 Process Creation AN1248 1
code_signing, file_metadata DC0059 File Metadata AN0057 1
curl, python scripts, rsync with internal share URLs DC0032 Process Creation AN1163 1
detection of new launch agents with suspicious paths or unsigned binaries DC0060 Service Creation AN1208 1
exec DC0032 Process Creation AN0799 AN1316 2
exec: Unexpected execution of osascript or AppleScript targeting sensitive apps DC0029 Script Execution AN1359 1
execution of trusted tools interacting with external endpoints DC0082 Network Connection Creation AN0228 1
execve DC0032 Process Creation AN0121 AN1563 2
execve: Processes unexpectedly invoking Keychain or authentication APIs DC0032 Process Creation AN0495 1
execve: Unsigned or unnotarized processes launched with high privileges DC0032 Process Creation AN1635 1
file_events DC0039 File Creation
DC0040 File Deletion
DC0055 File Access
DC0059 File Metadata
DC0061 File Modification
AN0115 AN0135 AN0333 AN0344 AN0369 AN0542 AN0739 AN1066 AN1218 AN1383 AN1585 AN1628 12
interface_details DC0018 Host Status AN0214 1
launch_daemons DC0060 Service Creation AN1063 1
launchd DC0041 Service Metadata AN0313 1
launchd + process_events DC0064 Command Execution AN1082 1
launchd or network_events DC0082 Network Connection Creation AN0924 1
launchd or process_events DC0032 Process Creation AN0284 1
launchd, processes DC0032 Process Creation AN1482 1
launchd_jobs DC0001 Scheduled Job Creation AN0260 1
mach_o_info, file_metadata DC0059 File Metadata AN0601 1
open, execve: Unexpected processes accessing or modifying critical files DC0021 OS API Execution AN0164 1
parent_name in ('sshd','httpd','screensharingd') spawning shells or scripting runtimes. DC0032 Process Creation AN0330 1
process reading browser configuration paths DC0032 Process Creation AN0039 1
process_events DC0032 Process Creation AN0032 AN0173 AN0210 AN0214 AN0273 AN0333 AN0369 AN0425 AN0506 AN0566 AN0618 AN0653 AN0734 AN0752 AN0874 AN0905 AN0945 AN0990 AN1059 AN1327 AN1412 AN1415 AN1442 AN1639 24
process_events + launchd DC0082 Network Connection Creation AN1022 1
process_events OR launchd DC0032 Process Creation AN0245 1
process_events where path like '%tcpdump%' DC0032 Process Creation AN0877 1
process_events, socket_events DC0082 Network Connection Creation AN1191 1
process_events/socket_events DC0082 Network Connection Creation AN0160 1
process_open DC0035 Process Access AN0289 1
process_termination: Unexpected termination of processes tied to vulnerable or high-value services DC0033 Process Termination AN0047 1
query: Enumeration of root certificates showing unexpected additions DC0061 File Modification AN0155 1
query: Historical list of associated SSIDs compared against baseline DC0078 Network Traffic Flow AN1478 1
query: process_events, launchd, and tcc.db access DC0032 Process Creation AN0689 1
socket_events DC0078 Network Traffic Flow AN0004 AN0077 AN0381 AN0425 AN0990 AN1171 AN1227 AN1391 AN1415 9
unexpected memory inspection DC0035 Process Access AN1643 1
usb_devices DC0054 Drive Access AN1355 1
write DC0061 File Modification AN1251 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1001.001 Junk Datacommand and control00
T1001.002 Steganographycommand and control00
T1001.003 Protocol or Service Impersonationcommand and control20
T1003 OS Credential Dumpingcredential access3718
T1007 System Service Discoverydiscovery111
T1010 Application Window Discoverydiscovery10
T1011 Exfiltration Over Other Network Mediumexfiltration04
T1011.001 Exfiltration Over Bluetoothexfiltration00
T1014 Rootkitstealth10
T1018 Remote System Discoverydiscovery172
T1021 Remote Serviceslateral movement114
T1021.004 SSHlateral movement52
T1021.005 VNClateral movement10
T1025 Data from Removable Mediacollection00
T1027 Obfuscated Files or Informationstealth945
T1027.003 Steganographystealth50
T1027.004 Compile After Deliverystealth60
T1027.005 Indicator Removal from Toolsstealth40
T1027.006 HTML Smugglingstealth00
T1027.008 Stripped Payloadsstealth00
T1027.009 Embedded Payloadsstealth20
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation03
T1040 Network Sniffingcredential access, discovery92
T1041 Exfiltration Over C2 Channelexfiltration512
T1046 Network Service Discoverydiscovery207
T1048 Exfiltration Over Alternative Protocolexfiltration124
T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocolexfiltration10
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocolexfiltration00
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocolexfiltration91
T1049 System Network Connections Discoverydiscovery91
T1052 Exfiltration Over Physical Mediumexfiltration00
T1052.001 Exfiltration over USBexfiltration00
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1053.002 Atexecution, persistence, privilege escalation80
T1056 Input Capturecollection, credential access23
T1056.001 Keyloggingcollection, credential access31
T1056.002 GUI Input Capturecollection, credential access30
T1056.004 Credential API Hookingcollection, credential access00
T1057 Process Discoverydiscovery80
T1059.004 Unix Shellexecution1814
T1059.005 Visual Basicexecution290
T1059.006 Pythonexecution130
T1059.007 JavaScriptexecution2914
T1070 Indicator Removalstealth203
T1070.006 Timestompstealth60
T1070.007 Clear Network Connection History and Configurationsstealth00
T1070.008 Clear Mailbox Datastealth20
T1070.009 Clear Persistencestealth00
T1070.010 Relocate Malwarestealth00
T1071 Application Layer Protocolcommand and control71
T1071.001 Web Protocolscommand and control4210
T1071.002 File Transfer Protocolscommand and control01
T1071.003 Mail Protocolscommand and control00
T1071.005 Publish/Subscribe Protocolscommand and control00
T1090.001 Internal Proxycommand and control61
T1090.002 External Proxycommand and control20
T1090.003 Multi-hop Proxycommand and control30
T1090.004 Domain Frontingcommand and control10
T1102 Web Servicecommand and control130
T1102.001 Dead Drop Resolvercommand and control40
T1111 Multi-Factor Authentication Interceptioncredential access00
T1120 Peripheral Device Discoverydiscovery20
T1195 Supply Chain Compromiseinitial access11
T1203 Exploitation for Client Executionexecution3543
T1204 User Executionexecution102
T1204.004 Malicious Copy and Pasteexecution60
T1210 Exploitation of Remote Serviceslateral movement154
T1211 Exploitation for Stealthstealth41
T1212 Exploitation for Credential Accesscredential access54
T1213 Data from Information Repositoriescollection72
T1217 Browser Information Discoverydiscovery41
T1218 System Binary Proxy Executionstealth1532
T1218.015 Electron Applicationsstealth00
T1219 Remote Access Toolscommand and control61
T1499.001 OS Exhaustion Floodimpact10
T1499.003 Application Exhaustion Floodimpact00
T1543.001 Launch Agentpersistence, privilege escalation20
T1547.006 Kernel Modules and Extensionspersistence, privilege escalation20
T1553 Subvert Trust Controlsdefense impairment40
T1553.001 Gatekeeper Bypassdefense impairment10
T1553.004 Install Root Certificatedefense impairment100
T1555.005 Password Managerscredential access10
T1556 Modify Authentication Processdefense impairment, persistence, credential access122
T1556.003 Pluggable Authentication Modulesdefense impairment, persistence, credential access00
T1558.005 Ccache Filescredential access00
T1559 Inter-Process Communicationexecution10
T1565 Data Manipulationimpact32
T1565.001 Stored Data Manipulationimpact62
T1565.002 Transmitted Data Manipulationimpact20
T1565.003 Runtime Data Manipulationimpact00
T1614 System Location Discoverydiscovery00
T1614.001 System Language Discoverydiscovery20
T1668 Exclusive Controlpersistence00
T1669 Wi-Fi Networksinitial access00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2009-4324Adobe Acrobat and Reader T1071.001 Mapped
CVE-2010-2883Adobe Acrobat and Reader T1027 Mapped
CVE-2013-0641Adobe Reader T1048 Mapped
CVE-2013-3346Adobe Reader and Acrobat T1059.007 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1059.004 Mapped
CVE-2015-3113Adobe Flash Player T1071.001 Mapped
CVE-2015-5119Adobe Flash Player T1059.007 T1071.001 T1203 Mapped
CVE-2016-10033PHP PHPMailer T1059.004 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1048 Mapped
CVE-2018-4878Adobe Flash Player T1041 T1219 Mapped
CVE-2018-4939Adobe ColdFusion T1203 Mapped
CVE-2018-4990Adobe Acrobat and Reader T1059.007 Mapped
CVE-2019-0604Microsoft SharePoint T1003 T1041 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1059.004 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1003 T1046 Mapped
CVE-2019-13608Citrix StoreFront Server T1003 T1046 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1007 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1041 Mapped
CVE-2020-12812Fortinet FortiOS T1556 Mapped
CVE-2020-1472Microsoft Netlogon T1021 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1217 Mapped
CVE-2020-5902F5 BIG-IP T1003 Stale
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1556 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1056 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1056 Mapped
CVE-2021-21148Google Chromium V8 T1059.007 T1203 Mapped
CVE-2021-21166Google Chromium T1059.007 T1203 Mapped
CVE-2021-21206Google Chromium Blink T1059.007 T1203 Mapped
CVE-2021-21973VMware vCenter Server and Cloud Foundation T1046 Mapped
CVE-2021-22017VMware vCenter Server T1090.001 Mapped
CVE-2021-22893Ivanti Pulse Connect Secure T1003 Mapped
CVE-2021-27059Microsoft Office T1203 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1203 Mapped
CVE-2021-30554Google Chromium WebGL T1059.007 T1203 Mapped
CVE-2021-31207Microsoft Exchange Server T1565 Mapped
CVE-2021-32030ASUS Routers T1040 Mapped
CVE-2021-34473Microsoft Exchange Server T1048.003 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1071.001 Mapped
CVE-2021-36380Sunhillo SureLine T1059.004 Mapped
CVE-2021-37975Google Chromium V8 T1059.007 T1203 Mapped
CVE-2021-39144XStream XStream T1203 Mapped
CVE-2021-40449Microsoft Windows T1027 T1071.001 Mapped
CVE-2021-40539Zoho ManageEngine T1003 T1027 T1218 Mapped
CVE-2021-41773Apache HTTP Server T1210 Mapped
CVE-2021-42013Apache HTTP Server T1210 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1003 T1027 T1218 Mapped
CVE-2021-44515Zoho Desktop Central T1003 Mapped
CVE-2021-45382D-Link Multiple Routers T1070 T1071 Mapped
CVE-2022-1040Sophos Firewall T1040 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-21999Microsoft Windows T1211 Mapped
CVE-2022-22948VMware vCenter Server T1212 Mapped
CVE-2022-22963VMware Tanzu Spring Cloud T1059.007 Mapped
CVE-2022-23748Audinate Dante Discovery T1203 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1027 T1213 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1059.007 Mapped
CVE-2022-26500Veeam Backup & Replication T1048 Mapped
CVE-2022-26501Veeam Backup & Replication T1048 Mapped
CVE-2022-41128Microsoft Windows T1070 T1203 Mapped
CVE-2022-41328Fortinet FortiOS T1037 T1049 T1565.001 Mapped
CVE-2022-42475Fortinet FortiOS T1071.001 Mapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server T1203 Mapped
CVE-2023-0669Fortra GoAnywhere MFT T1210 Mapped
CVE-2023-1389TP-Link Archer AX21 T1041 T1070 Mapped
CVE-2023-21608Adobe Acrobat and Reader T1203 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1059.007 Mapped
CVE-2023-23397Microsoft Office T1203 Mapped
CVE-2023-26360Adobe ColdFusion T1046 T1059.007 T1071.001 Mapped
CVE-2023-26369Adobe Acrobat and Reader T1203 Mapped
CVE-2023-28252Microsoft Windows T1003 T1021 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1041 Mapped
CVE-2023-34048VMware vCenter Server T1203 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1213 Mapped
CVE-2023-36844Juniper Junos OS T1203 Mapped
CVE-2023-38035Ivanti Sentry T1018 T1046 T1071.001 Mapped
CVE-2023-38831RARLAB WinRAR T1041 T1053 T1059.004 T1204 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1021.004 T1059.004 Mapped
CVE-2023-40044Progress WS_FTP Server T1071.002 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1059.004 Mapped
CVE-2023-46604Apache ActiveMQ T1059.004 Mapped
CVE-2023-47565QNAP VioStor NVR T1203 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1203 Mapped
CVE-2023-5631Roundcube Webmail T1041 T1059.007 Mapped
CVE-2024-11120GeoVision Multiple Devices T1203 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1059.004 Mapped
CVE-2024-26169Microsoft Windows T1203 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1041 T1059.004 Mapped
CVE-2024-40890Zyxel DSL CPE Devices T1011 Mapped
CVE-2024-40891Zyxel DSL CPE Devices T1011 Mapped
CVE-2024-42009Roundcube Webmail T1056 Mapped
CVE-2024-45195Apache OFBiz T1203 Mapped
CVE-2024-4577PHP Group PHP T1003 T1041 T1053 T1071.001 Mapped
CVE-2024-48248NAKIVO Backup and Replication T1003 Mapped
CVE-2024-49035Microsoft Partner Center T1195 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1071.001 Mapped
CVE-2024-50302Linux Kernel T1011 Mapped
CVE-2024-5274Google Chromium V8 T1203 Mapped
CVE-2024-53150Linux Kernel T1011 Mapped
CVE-2024-53704SonicWall SonicOS T1212 Mapped
CVE-2024-54085AMI MegaRAC SPx T1210 Mapped
CVE-2024-55550Mitel MiCollab T1041 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1021 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1003 Mapped
CVE-2025-0108Palo Alto Networks PAN-OS T1565.001 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1003 T1018 T1046 Mapped
CVE-2025-21333Microsoft Windows T1003 Mapped
CVE-2025-21334Microsoft Windows T1003 Mapped
CVE-2025-21335Microsoft Windows T1003 Mapped
CVE-2025-24016Wazuh Wazuh Server T1203 Mapped
CVE-2025-24993Microsoft Windows T1203 T1204 T1565 Mapped
CVE-2025-25257Fortinet FortiWeb T1059.004 Mapped
CVE-2025-27038Qualcomm Multiple Chipsets T1203 Mapped
CVE-2025-2783Google Chromium Mojo T1203 Mapped
CVE-2025-30397Microsoft Windows T1203 Mapped
CVE-2025-30406Gladinet CentreStack T1203 Mapped
CVE-2025-31200Apple Multiple Products T1203 Stale
CVE-2025-31201Apple Multiple Products T1203 Stale
CVE-2025-32433Erlang Erlang/OTP T1021.004 Mapped
CVE-2025-3248Langflow Langflow T1203 Mapped
CVE-2025-32709Microsoft Windows T1003 Mapped
CVE-2025-32756Fortinet Multiple Products T1003 T1041 T1046 Mapped
CVE-2025-33053Microsoft Windows T1041 T1056.001 Mapped
CVE-2025-34028Commvault Command Center T1059.007 Mapped
CVE-2025-3935ConnectWise ScreenConnect T1203 Mapped
CVE-2025-42999SAP NetWeaver T1203 Mapped
CVE-2025-43200Apple Multiple Products T1203 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1203 Mapped
CVE-2025-48927TeleMessage TM SGNL T1212 Mapped
CVE-2025-48928TeleMessage TM SGNL T1212 Mapped
CVE-2025-5419Google Chromium V8 T1203 Mapped
CVE-2025-54309CrushFTP CrushFTP T1021 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1203 Mapped
CVE-2025-6554Google Chromium V8 T1203 Mapped
CVE-2025-6558Google Chromium T1203 Mapped