kevmap

Log sources › macos:unifiedlog

macos:unifiedlog

Inverted view: what can be detected if this is the log you have. macOS

499
channels
350
analytics
348
techniques
419
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
*.opvault OR *.ldb OR *.kdbx DC0055 File Access AN1643 1
ARP table updates inconsistent with expected gateway or DHCP lease assignments DC0078 Network Traffic Flow AN1093 1
Abnormal memory operations (XOR/bitwise loops) during archive generation DC0020 Process Modification AN1215 1
Abnormal process access to Safari or Chrome cookie storage DC0055 File Access AN0486 1
Abnormal terminations of com.apple.security.* or 3rd-party security daemons DC0038 Application Log Content AN1635 1
Access decisions to kTCCServiceCamera for unexpected binaries DC0021 OS API Execution AN0570 1
Access to Keychain items or browser credential stores DC0067 Logon Session Creation AN0721 1
Access to ~/Library/*/Safari or Chrome directories by non-browser processes DC0055 File Access AN0039 1
Access to ~/Library/Safari/Bookmarks.plist or recent files DC0055 File Access AN1184 1
Anomalous dyld dynamic library loads or RWX memory mappings in browser process DC0020 Process Modification AN0500 1
Anomalous keychain access attempts targeting payment credentials DC0038 Application Log Content AN1363 1
Anomalous plist modifications or sensitive file overwrites by non-standard processes DC0061 File Modification AN0164 1
App/web server logs ingested via unified logging or filebeat (nginx/apache/node). DC0038 Application Log Content AN0221 1
AppleScript creating login item via 'System Events' dictionary DC0029 Script Execution AN0340 1
Application errors or resource contention from excessive frontend or script invocation DC0038 Application Log Content AN1167 1
Association and authentication events including failures and new SSIDs DC0082 Network Connection Creation AN1478 1
Attachment files written to ~/Downloads or temporary folders DC0039 File Creation AN0657 1
Authentication inconsistencies where commands are executed without corresponding login events DC0067 Logon Session Creation AN0218 1
Browser processes launching unexpected interpreters (osascript, bash) DC0032 Process Creation AN0300 1
Calls to AuthorizationExecuteWithPrivileges() observed via Apple System Logger or security_auditing tools DC0021 OS API Execution AN1111 1
Child processes of Safari, Chrome, or Firefox executing scripting interpreters DC0032 Process Creation AN0994 1
Code Execution & Entitlement Access DC0034 Process Metadata AN0650 1
Code signature validation fails or is absent post-binary modification DC0059 File Metadata AN0607 1
Code signing verification failures or bypassed trust decisions DC0059 File Metadata AN0644 1
Command line containing `trap` or `echo 'trap` written to login shell files DC0032 Process Creation AN1039 1
Command line contains smbutil view //, mount_smbfs // DC0064 Command Execution AN0515 1
Command line invocation of pip3, brew install, npm install from interactive Terminal DC0032 Process Creation AN0700 1
Configuration profile modified or new profile installed DC0038 Application Log Content AN0825 1
Connections to suspicious domains with mismatched certificate or unusual patterns DC0085 Network Traffic Content AN0300 1
Crash log entries for a process receiving malformed input or known exploit patterns DC0038 Application Log Content AN0852 1
Crash or abnormal termination of security agent or system extension host DC0034 Process Metadata AN2040 1
Creation of .plist under /Library/Managed Preferences/ DC0039 File Creation AN0252 1
Creation of .zip or .dmg files in user-accessible or temporary directories DC0039 File Creation AN1460 1
Creation of .zip, .dmg, .tar.gz files in /Users, /tmp, or application directories DC0039 File Creation AN0833 1
Creation of .zip, .gz, .dmg archives in /Users, /tmp, or application directories DC0039 File Creation AN0749 1
Creation of LaunchAgents/LaunchDaemons in hidden or non-standard directories DC0039 File Creation AN1386 1
Creation of files with anomalous headers and entropy values DC0039 File Creation AN1215 1
Creation of new LaunchAgent or LoginItem plist files in ~/Library/LaunchAgents/ DC0059 File Metadata AN0700 1
Creation of user account with UID <500 DC0013 User Account Metadata AN1003 1
Creation or modification of browser extension .plist files DC0039 File Creation AN0124 1
Creation or modification of postinstall scripts within .pkg or .mpkg contents DC0039 File Creation AN0938 1
DNS query with pseudo-random subdomain patterns DC0085 Network Traffic Content AN0111 1
DNS responses followed by connections to ports outside standard ranges DC0085 Network Traffic Content AN0730 1
DS daemon log entries DC0064 Command Execution AN0365 1
DYLD event subsystem DC0016 Module Load AN0391 1
Detection of altered _VBA_PROJECT or PerformanceCache streams DC0059 File Metadata AN0036 1
Device attached|enumerated VID/PID DC0038 Application Log Content AN0187 1
DirectoryService queries retrieving account information DC0013 User Account Metadata AN1614 1
Dylib loaded from abnormal location DC0016 Module Load AN0611 1
EFI firmware integrity check failed DC0018 Host Status AN1037 1
Electron app spawning unexpected child process DC0032 Process Creation AN0073 1
Encrypted connection with anomalous payload entropy DC0085 Network Traffic Content AN0402 1
Encrypted session initiation by unexpected binary DC0085 Network Traffic Content AN0761 1
Execution of 'profiles install -type=configuration' DC0064 Command Execution AN0252 1
Execution of /usr/bin/security add-trusted-cert or keychain modifications to System.keychain DC0064 Command Execution AN0155 1
Execution of /usr/libexec/security_authtrampoline or child processes originating from non-trusted binaries triggering credential prompts DC0032 Process Creation AN1111 1
Execution of /usr/sbin/installer spawning child process from within /private/tmp or package contents DC0032 Process Creation AN0938 1
Execution of Code.app, idea, JetBrainsToolbox, eclipse with install/extension flags DC0032 Process Creation AN1550 1
Execution of Java apps or other processes with hidden window attributes DC0032 Process Creation AN0362 1
Execution of Python, Swift, or other binaries invoking archiving libraries DC0032 Process Creation AN0749 1
Execution of Terminal, osascript, or other interpreters originating from Mail or Preview DC0032 Process Creation AN0657 1
Execution of binaries with TCC protected access under unexpected parent processes such as Finder.app, SystemUIServer, or nsurlsessiond DC0032 Process Creation AN1474 1
Execution of binaries with unsigned or anomalously signed certificates DC0032 Process Creation AN0644 1
Execution of binary listed in newly modified LaunchAgent plist DC0032 Process Creation AN0766 1
Execution of bless or nvram modifying boot parameters DC0032 Process Creation AN0776 1
Execution of chflags hidden or SetFile -a V DC0064 Command Execution AN0093 1
Execution of chflags hidden or setfile -a V DC0064 Command Execution AN1386 1
Execution of commands like `ls -l@`, `xattr -l`, or custom tools interacting with resource forks DC0064 Command Execution AN1609 1
Execution of diskutil or hdiutil attaching hidden partitions DC0032 Process Creation AN1273 1
Execution of dscl . create with IsHidden=1 DC0064 Command Execution AN1003 1
Execution of input detection APIs (e.g., CGEventSourceKeyState) DC0021 OS API Execution AN1184 1
Execution of launchctl unload, kill, or removal of security agent daemons DC0032 Process Creation AN1371 1
Execution of launchctl with setenv or bootout targeting TCC.db or AppleScript under Finder context DC0064 Command Execution AN1474 1
Execution of launchctl with suspicious arguments DC0032 Process Creation AN0026 1
Execution of log show, fs_usage, or cat targeting system.log DC0064 Command Execution AN0707 1
Execution of older or non-standard interpreters DC0032 Process Creation AN0997 1
Execution of osascript, bash, or Terminal initiated from Mail.app or Safari DC0032 Process Creation AN0322 1
Execution of osascript, sh, bash, zsh, installer, open DC0064 Command Execution AN2036 AN2065 2
Execution of ping, nping, or crafted network packets via bash or python to reflection services DC0032 Process Creation AN1142 1
Execution of process launched via loginwindow session restore DC0032 Process Creation AN0349 1
Execution of process with DYLD_INSERT_LIBRARIES set DC0032 Process Creation AN0611 1
Execution of processes linked to hijacked sessions (e.g., anomalous parent-child process lineage) DC0032 Process Creation AN0218 1
Execution of processes mimicking Apple Security & Privacy GUIs DC0032 Process Creation AN0870 1
Execution of scp, rsync, curl with remote destination DC0032 Process Creation AN0518 1
Execution of ssh or sftp without corresponding login event DC0032 Process Creation AN0711 1
Execution of system_profiler or osascript invoking enumeration DC0032 Process Creation AN1102 1
Execution of unexpected terminal or web scripts modifying /Library/WebServer/Documents DC0032 Process Creation AN0664 1
Execution of zip, ditto, hdiutil, or openssl by non-terminal parent processes DC0032 Process Creation AN1460 1
Execution of zip, ditto, hdiutil, or openssl by processes not normally associated with archiving DC0032 Process Creation AN0833 1
Extension disabled, unloaded, failed to start DC0074 Driver Metadata AN2040 1
File Events DC0039 File Creation AN0874 1
File created in ~/Library/LaunchAgents or executable directories DC0039 File Creation AN0518 1
File creation DC0039 File Creation AN0653 1
File creation of unsigned binaries/scripts in user cache or download directories DC0039 File Creation AN0994 1
File creation or modification with com.apple.ResourceFork extended attribute DC0059 File Metadata AN1609 1
File creation or overwrite in common web-hosting folders DC0061 File Modification AN0664 1
File metadata updated with UF_HIDDEN flag DC0059 File Metadata AN0093 1
File modification in /etc/paths.d or user shell rc files DC0061 File Modification AN0011 1
File write or append to .zshrc, .bash_profile, .zprofile, etc. DC0061 File Modification AN1039 1
Firewall rule enable/disable or listen socket changes DC0078 Network Traffic Flow AN1450 1
Firewall/PF anchor load or rule change events. DC0078 Network Traffic Flow AN0844 1
Firmware update events or kernel extension (kext) loads not signed by Apple DC0004 Firmware Modification AN0918 1
First outbound connection from the same PID/user shortly after an inbound trigger. DC0082 Network Connection Creation AN0464 1
Group membership change for admin or wheel DC0088 Logon Session Metadata AN1346 1
HTTP POST with encoded content in user-agent or cookie field DC0085 Network Traffic Content AN0304 1
HTTPS POST requests to pastebin.com or similar DC0078 Network Traffic Flow AN0789 1
HTTPS POST to known webhook URLs DC0078 Network Traffic Flow AN0438 1
Hardware enumeration events via IOKit or USBMuxd showing TinyPilot or unknown keyboard/mouse DC0042 Drive Creation AN0448 1
Hidden volume attachment or modification events DC0061 File Modification AN1273 1
High entropy domain queries with multiple NXDOMAINs DC0078 Network Traffic Flow AN1180 1
IOKit disk write calls targeting raw devices DC0046 Drive Modification AN0386 1
IOKit raw disk write activity targeting physical devices DC0046 Drive Modification AN0884 1
IOKit raw disk write to EFI/boot partition sectors DC0046 Drive Modification AN0829 1
Inbound connections to VNC/SSH ports DC0082 Network Connection Creation AN1006 1
Inbound email activity with suspicious domains or mismatched sender information DC0038 Application Log Content AN0190 1
Inbound messages with attachments from suspicious domains DC0038 Application Log Content AN0657 1
Invocation of SMLoginItemSetEnabled by non-system or recently installed application DC0021 OS API Execution AN0340 1
Kerberos framework calls to API:{uuid} cache outside normal process lineage DC0055 File Access AN0070 1
Keychain or user login post-access DC0067 Logon Session Creation AN0858 1
Loading of libz.dylib, libarchive.dylib by non-standard applications DC0016 Module Load AN0749 1
Login Window and Authd errors DC0002 User Account Authentication AN1338 1
Login failure / authorization denied DC0002 User Account Authentication AN1264 1
Login success without MFA step DC0002 User Account Authentication AN0547 1
LoginWindow context with associated PID linked to reopened plist paths DC0088 Logon Session Metadata AN0349 1
Logs from unifiedlogging that show browser crashes, plugin enumerations, extension installs or errors around the same time as suspicious network fetches DC0038 Application Log Content AN0500 1
Mach-O binary modified or LC_LOAD_DYLIB segment inserted DC0061 File Modification AN0607 1
Mail or AppleScript subsystem DC0038 Application Log Content AN1311 1
Mail.app executing with parameters updating rules state DC0032 Process Creation AN0552 1
Mail.app or third-party clients sending messages with mismatched From headers DC0038 Application Log Content AN0794 1
Modification of /Library/Preferences/com.apple.loginwindow plist DC0061 File Modification AN1003 1
Modification of /Library/Security/SecurityAgentPlugins DC0061 File Modification AN0547 1
Modification of /System/Library/CoreServices/boot.efi DC0061 File Modification AN0776 1
Modification of LaunchAgents or LaunchDaemons plist files DC0061 File Modification AN0780 1
Modification of backgrounditems.btm or creation of LoginItems subdirectory in .app bundle DC0061 File Modification AN0340 1
Modification of plist with apple.awt.UIElement set to TRUE DC0061 File Modification AN0362 1
Modification of system configuration profiles affecting security tools DC0041 Service Metadata AN1371 1
Modification of ~/Library/LaunchAgents or /Library/LaunchDaemons plist DC0061 File Modification AN0026 1
Modification or replacement of /Library/Application Support/com.apple.TCC/TCC.db or ~/Library/Application Support/com.apple.TCC/TCC.db DC0061 File Modification AN1474 1
Modifications or writes to EFI system partition for downgraded bootloaders DC0034 Process Metadata AN0997 1
Modifications to Mail.app plist files controlling message rules DC0061 File Modification AN0552 1
Modified application plist or binary replacement in /Applications DC0061 File Modification AN0611 1
New IOUSB keyboard/HID device enumerated with suspicious attributes DC0042 Drive Creation AN1569 1
New certificate trust settings added by unexpected process DC0059 File Metadata AN1248 1
New files written to /var/folders, /tmp, ~/Library/Caches, or ~/Downloads by browser context or its children DC0039 File Creation AN0500 1
New session initiated using cookies without normal MFA or password validation DC0007 Web Credential Usage AN0486 1
New/modified launchd plist (persistence/scheduling) within TimeWindow after time query DC0005 Scheduled Job Metadata AN0432 1
Non-standard processes invoking financial applications or payment APIs DC0032 Process Creation AN1363 1
None DC0021 OS API Execution
DC0032 Process Creation
DC0064 Command Execution
DC0082 Network Connection Creation
DC0085 Network Traffic Content
AN0206 AN0214 AN0273 AN0848 AN1231 AN1327 AN1378 AN1533 8
Observed loading of new LaunchAgent or LaunchDaemon plist DC0041 Service Metadata AN0766 1
Outbound Traffic DC0082 Network Connection Creation AN1296 1
Outbound UDP spikes to external reflector IPs DC0078 Network Traffic Flow AN1142 1
Outbound connections from IDE processes to marketplace/tunnel domains DC0078 Network Traffic Flow AN1550 1
Outgoing or incoming calls with non-standard caller IDs or unusual metadata DC0038 Application Log Content AN0685 1
Persistent outbound connections with consistent periodicity DC0085 Network Traffic Content AN1491 1
Persistent outbound traffic to mining domains DC0085 Network Traffic Content AN0743 1
Plist modifications containing virtualization run configurations DC0061 File Modification AN0911 1
Post-login execution of unrecognized child process from launchd or loginwindow DC0032 Process Creation AN0340 1
Preview.app, Safari.app, or Mail.app spawning new processes outside normal patterns DC0032 Process Creation AN0190 1
Process Execution DC0032 Process Creation AN0365 1
Process creation events where command line = pmset with arguments affecting sleep, hibernatemode, displaysleep DC0032 Process Creation AN1176 1
Process creation involving binaries interacting with resource fork data DC0032 Process Creation AN1609 1
Process creation with parent PID of 1 (launchd) DC0032 Process Creation AN1224 1
Process exec of remote-control apps or binaries with headless/connect flags DC0032 Process Creation AN1368 1
Process execution for VBoxHeadless, prl_vm_app, vmware-vmx DC0032 Process Creation AN0911 1
Process execution logs showing discovery commands like mdfind, system_profiler, or launchctl list DC0032 Process Creation AN0242 1
Process execution of Microsoft Word, Excel, PowerPoint with macro execution attempts DC0032 Process Creation AN0036 1
Process execution or directory service changes DC0010 User Account Modification AN0867 1
Process execution path inconsistent with baseline PATH directories DC0032 Process Creation AN0011 1
Process invoking SSL routines from Security framework DC0032 Process Creation AN0761 1
Process invoking SecKeyCreateRandomKey or asymmetric crypto APIs DC0032 Process Creation AN1498 1
Process launch DC0032 Process Creation AN0784 1
Process memory maps new dylib (dylib_load event) DC0016 Module Load AN0607 1
Process opening SSH_AUTH_SOCK or /tmp/ssh-* socket not owned by same UID DC0034 Process Metadata AN0711 1
Process start of Java or native DB client tools DC0032 Process Creation AN0678 1
Process using AES/RC4 routines unexpectedly DC0032 Process Creation AN0402 1
Process wrote large .mov/.mp4 in user temp/hidden dirs DC0039 File Creation AN0570 1
Rapid domain-to-IP resolution changes for same domain DC0078 Network Traffic Flow AN1333 1
Rapid incoming TLS handshakes or HTTP requests in quick succession DC0085 Network Traffic Content AN0491 1
Read access to Time Machine plist files or CCC configurations in ~/Library/Preferences/ DC0055 File Access AN0242 1
Received messages containing embedded links or attachments from non-enterprise services DC0038 Application Log Content AN0322 1
Received messages with embedded or shortened URLs DC0038 Application Log Content AN0300 1
Recent download opened or executed DC0055 File Access AN2036 1
Remote login (ssh) or screen sharing authentication attempts DC0088 Logon Session Metadata AN1006 1
Repeated process crashes logged by CrashReporter or system instability logs in com.apple.console DC0038 Application Log Content AN0586 1
Repetitive inbound email delivery activity logged within a short time window DC0038 Application Log Content AN1011 1
SPF fail OR DKIM fail OR DMARC fail OR mismatched header vs envelope domains DC0038 Application Log Content AN1204 1
Script interpreter invoked by nginx/apache worker process DC0032 Process Creation AN1509 1
Security framework operations including keychain access, cryptographic operations, and certificate validation DC0064 Command Execution AN1307 1
SecurityAgentPlugins modification DC0061 File Modification AN0289 1
Session reuse without new auth event DC0067 Logon Session Creation AN0711 1
Set or unset HIST* variables in shell environment DC0064 Command Execution AN1556 1
Spike in CPU or memory use from non-user-initiated processes DC0018 Host Status AN0586 1
Suspicious Swift/Objective-C or scripting processes writing archive-like outputs DC0032 Process Creation AN1215 1
Suspicious anomalies in transmitted data integrity during application network operations DC0078 Network Traffic Flow AN0704 1
Suspicious outbound HTTPS requests to domains flagged as newly registered or untrusted after spearphishing message interaction DC0085 Network Traffic Content AN0322 1
Suspicious outbound traffic from browser binary to non-standard domains DC0078 Network Traffic Flow AN0252 1
System Integrity Protection (SIP) state reported as disabled DC0018 Host Status AN1474 1
System process modifications altering DNS/proxy settings DC0032 Process Creation AN1150 1
System shutdown or reboot requested DC0018 Host Status AN1540 1
TLS connections with abnormal handshake sequence or self-signed cert DC0085 Network Traffic Content AN1498 1
Terminal process killed (killall Terminal) immediately after sudoers modification DC0033 Process Termination AN0143 1
Terminal/Editor processes modifying web folder DC0061 File Modification AN1624 1
Termination of syspolicyd or XProtect processes DC0033 Process Termination AN0888 0
Termination or disabling of XProtect, Gatekeeper, or third-party AV daemons DC0018 Host Status AN0870 1
Trust validation failures or bypass attempts during notarization and code signing checks DC0032 Process Creation AN0800 1
Unexpected NSXPCConnection calls by non-Apple-signed or abnormal binaries DC0035 Process Access AN0948 1
Unexpected application binary modifications or altered signing status DC0059 File Metadata AN1099 1
Unexpected applications generating outbound DNS queries DC0032 Process Creation AN0111 1
Unexpected apps generating frequent DNS queries DC0032 Process Creation AN1333 1
Unexpected apps performing repeated DNS lookups DC0032 Process Creation AN1180 1
Unexpected child process of Safari or Chrome DC0032 Process Creation AN0124 1
Unexpected creation or modification of stored data files in protected directories DC0061 File Modification AN0557 1
Unexpected processes making network calls based on DNS-derived ports DC0032 Process Creation AN0730 1
Unexpected processes registered with launchd DC0032 Process Creation AN0780 1
Unsigned binary execution following SIP change DC0032 Process Creation AN1447 1
Unusual Kerberos TGS-REQ without TGT or anomalous ticket lifetime DC0088 Logon Session Metadata AN1445 1
Unusual Mach port registration or access attempts between unrelated processes DC0035 Process Access AN1359 1
Unusual child process tree indicating attempted recovery after crash DC0032 Process Creation AN0852 1
User credential prompt events without associated trusted installer package DC0002 User Account Authentication AN1111 1
UserLoggedIn DC0067 Logon Session Creation AN0008 1
Volume Mount + File Read DC0042 Drive Creation AN0344 1
Volume Mount + Process Trace + File Read DC0042 Drive Creation AN0618 1
Web server process initiating outbound TCP connections not tied to normal server traffic DC0085 Network Traffic Content AN1509 1
Web service process (e.g., httpd) entering crash loop or consuming excessive CPU DC0018 Host Status AN0491 1
Web sessions initiated with newly forged tokens DC0007 Web Credential Usage AN0721 1
Writes of .sql/.csv/.xlsx files to user documents/downloads DC0039 File Creation AN0678 1
Writes under ~/Library/Application Support/Code*/extensions or JetBrains plugins DC0039 File Creation AN1550 1
XPC messages requesting privileged actions from untrusted or unsigned clients DC0048 Named Pipe Metadata AN0948 1
access or unlock attempt to keychain database DC0021 OS API Execution AN1112 1
access to /Volumes/SharePoint or network mount DC0055 File Access AN1163 1
access to keychain database DC0055 File Access AN1200 1
application logs referencing NSTimer, sleep, or launchd delays DC0021 OS API Execution AN0398 1
audio APIs DC0021 OS API Execution AN0621 1
auth DC0002 User Account Authentication AN1278 1
authd DC0002 User Account Authentication AN1523 1
authd generating multiple MFA token requests DC0088 Logon Session Metadata AN0454 1
authentication DC0067 Logon Session Creation AN0506 1
authentication plugin load or modification events DC0067 Logon Session Creation AN1251 1
authorization execute privilege requests DC0021 OS API Execution AN0977 1
background process persists beyond user logout DC0032 Process Creation AN0183 1
base64 -d or osascript invoked on staged file DC0064 Command Execution AN0769 1
base64 or curl processes chained within short execution window DC0064 Command Execution AN0304 1
binary modified or replaced DC0061 File Modification AN0951 1
boot failure events or SMC validation errors DC0004 Firmware Modification AN0476 1
chmod command with arguments including '+s', 'u+s', or numeric values 4000–6777 DC0064 Command Execution AN0308 1
code signature/memory protection DC0034 Process Metadata AN0921 1
com.apple.accountsd, com.apple.opendirectoryd DC0010 User Account Modification AN0267 1
com.apple.diskarbitration DC0042 Drive Creation AN0249 1
com.apple.firmwareupdater activity or update-firmware binary invoked DC0032 Process Creation AN0476 1
com.apple.mail.* exec.* DC0032 Process Creation AN0149 1
com.apple.network DC0078 Network Traffic Flow AN0598 AN1256 2
com.apple.securityd, com.apple.tccd DC0021 OS API Execution AN0689 1
command execution triggered by emond (e.g., shell, curl, python) DC0064 Command Execution AN1534 1
command includes dscl . delete or sysadminctl --deleteUser DC0064 Command Execution AN0336 1
connection attempts DC0082 Network Connection Creation AN0032 1
connection open DC0082 Network Connection Creation AN0167 1
create/modify dylib files in monitored directories DC0039 File Creation AN0435 1
create/modify dylib in monitored directories DC0061 File Modification AN1210 1
create: New files in /tmp or ~/Library/Application Support/* with executable or script extensions DC0039 File Creation AN0964 1
creation of ~/.vscode-cli/code_tunnel.json DC0039 File Creation AN0377 1
creation or loading of new launchd services DC0060 Service Creation AN0736 1
csrutil disable DC0064 Command Execution AN1447 1
curl|osascript.*open location DC0085 Network Traffic Content AN0149 1
defaults read -g AppleLocale or systemsetup -gettimezone DC0064 Command Execution AN1563 1
defaults read -g AppleLocale, systemsetup -gettimezone DC0064 Command Execution AN0121 1
defaults write com.apple.system.logging or logd manipulation DC0064 Command Execution AN0669 0
delay/sleep library usage in user context DC0016 Module Load AN1050 1
diskutil eraseDisk / asr restore with destructive flags DC0064 Command Execution AN0386 1
diskutil eraseDisk/zeroDisk or asr restore with destructive flags DC0064 Command Execution AN0884 1
diskutil partitionDisk or eraseVolume with partition scheme modifications DC0064 Command Execution AN0829 1
dns-sd, mDNSResponder, socket activity DC0085 Network Traffic Content AN1059 1
dscl -create DC0064 Command Execution AN1237 1
dscl . -create DC0064 Command Execution AN1606 1
dsconfigad or dscl with create or append options for AD-bound users DC0064 Command Execution AN0008 1
dyld/unified log entries indicating image load from non-system paths DC0016 Module Load AN0054 1
dynamic loading of sleep-related functions or sandbox detection libraries DC0016 Module Load AN0129 1
encrypted outbound traffic carrying unexpected application data DC0085 Network Traffic Content AN1485 1
eventMessage = 'open', 'sendto', 'connect' DC0085 Network Traffic Content AN0990 1
eventMessage = 'promiscuous' DC0085 Network Traffic Content AN0877 1
eventMessage CONTAINS 'screensharingd' or 'AuthorizationRefCreate' DC0067 Logon Session Creation AN0752 1
exec /usr/bin/pwpolicy DC0032 Process Creation AN0457 1
exec events where web process starts a shell/tooling DC0032 Process Creation AN0221 1
exec logs DC0032 Process Creation AN0042 AN0196 AN0726 AN1545 AN2032 5
exec of binary with setuid/setgid and EUID != UID DC0034 Process Metadata AN0308 1
exec of osascript, bash, curl with suspicious parameters DC0032 Process Creation AN0228 1
exec or spawn calls to proxy tools or torrent clients DC0032 Process Creation AN0082 1
exec or spawn of 'system_profiler', 'ioreg', 'kextstat', 'sysctl', or calls to sysctl API DC0032 Process Creation AN0480 1
exec or sudo usage with NOPASSWD context or echo modifying sudoers DC0064 Command Execution AN0143 1
exec rm -rf|dd if=/dev|srm|file unlink DC0040 File Deletion AN0413 1
exec srm|exec openssl|exec gpg DC0032 Process Creation AN0604 1
exec: Execution of /sbin/pfctl, /usr/libexec/ApplicationFirewall/socketfilterfw, ifconfig, tcpdump, npcap/libpcap consumers DC0032 Process Creation AN1450 1
exec: Execution of defaults, plutil, or common editors (vim/nano) targeting plist files DC0032 Process Creation AN0306 1
exec: Execution of kextstat, kextfind, or ioreg targeting driver information DC0032 Process Creation AN1597 1
exec: Execution of pfctl, socketfilterfw, launchctl start ssh/telnet, libpcap consumers. DC0032 Process Creation AN0844 1
exec: Invocation of /usr/bin/defaults write or /usr/bin/plutil modifying plist keys DC0064 Command Execution AN0306 1
exec: ParentImage in (Terminal, iTerm2) AND Image in (/bin/zsh,/bin/bash,/usr/bin/python*) AND CommandLine matches '(curl|wget).*(\||\|\s*sh|bash)|base64 -D|python -c' DC0032 Process Creation AN0964 1
execution of 'security', 'cat', or 'grep' commands accessing credential storage DC0064 Command Execution AN1155 1
execution of /sbin/emond with child processes launched DC0032 Process Creation AN1534 1
execution of Office binaries with network activity DC0032 Process Creation AN1513 1
execution of curl, git, or Office processes with network connections DC0032 Process Creation AN0897 1
execution of curl, osascript, or unexpected Office processes DC0032 Process Creation AN0789 1
execution of curl, rclone, or Office apps invoking network sessions DC0032 Process Creation AN1573 1
execution of launchctl load/unload/start commands DC0064 Command Execution AN0736 1
execution of memory inspection tools (lldb, gdb, osqueryi) DC0032 Process Creation AN0156 1
execution of modified binary without valid signature DC0032 Process Creation AN0951 1
execution of osascript, curl, or unexpected automation DC0032 Process Creation AN0438 1
execution of process with DYLD_INSERT_LIBRARIES set DC0032 Process Creation AN1210 1
execution of security or osascript DC0032 Process Creation AN1112 AN1200 2
execution of security, sqlite3, or unauthorized binaries DC0032 Process Creation AN0107 1
execution of security-agent detection or enumeration commands DC0064 Command Execution AN0050 1
execution of system_profiler, ioreg, kextstat with argument patterns related to VM/sandbox checks DC0032 Process Creation AN0129 1
execve or dylib load from memory without backing file DC0032 Process Creation AN0840 1
execve: Helper tools invoked through XPC executing unexpected binaries DC0032 Process Creation AN0948 1
extended attribute write or modification DC0059 File Metadata AN1136 1
file create or modify in /etc/emond.d/rules or /private/var/db/emondClients DC0039 File Creation AN1534 1
file creation in AV exclusion directories DC0039 File Creation AN0141 1
file encrypted|new file with .encrypted extension|disk write burst DC0061 File Modification AN0604 1
file events DC0039 File Creation
DC0055 File Access
AN0042 AN0196 AN0726 3
file read of sensitive directories DC0055 File Access AN0438 AN0789 AN1573 3
file write DC0039 File Creation AN0057 1
file write/create DC0039 File Creation AN0167 1
file writes DC0061 File Modification AN1300 1
filesystem and process events DC0055 File Access AN1147 1
filesystem events DC0059 File Metadata AN0784 1
flock|NSDistributedLock|FileHandle.*lockForWriting DC0021 OS API Execution AN0374 1
forwarded encrypted traffic DC0078 Network Traffic Flow AN1022 1
g_CiOptions modification or SIP state change DC0063 Windows Registry Key Modification AN1447 1
grep/cat on files matching credential patterns DC0064 Command Execution AN0858 1
httpd spawning bash, zsh, python, or osascript DC0032 Process Creation AN1110 1
installer or system_installd 'PackageKit: install succeeded/failed' with non-notarized or unknown signer DC0059 File Metadata AN1482 1
kextload execution from Terminal or suspicious paths DC0064 Command Execution AN1244 1
launch and dylib load DC0016 Module Load AN1467 1
launch of Terminal.app or shell with non-standard environment setup DC0032 Process Creation AN0060 1
launch of bash/zsh/python/osascript targeting key file locations DC0032 Process Creation AN1518 1
launch of remote desktop app or helper binary DC0032 Process Creation AN0716 1
launchctl activity and process creation DC0032 Process Creation AN0743 1
launchctl disable or bootout calls DC0041 Service Metadata AN0063 1
launchctl load or boot-time plist registration DC0064 Command Execution AN1208 1
launchctl load/unload or plist file modification DC0064 Command Execution AN1577 1
launchctl spawning new processes DC0032 Process Creation AN0736 1
launchctl unload, kill, or pkill commands affecting daemons or background services DC0064 Command Execution AN0047 1
launchd loading new LaunchDaemon or changes to existing daemon configuration DC0060 Service Creation AN1126 1
launchd or cron spawning mining binaries DC0032 Process Creation AN1491 1
launchd or osascript spawns process with delay command DC0032 Process Creation AN1050 1
launchd services binding to non-standard ports DC0032 Process Creation AN0635 1
launchd spawning processes tied to new or modified LaunchDaemon .plist entries DC0032 Process Creation AN1126 1
launchservices events for misleading extensions DC0032 Process Creation AN0632 1
launchservices or loginwindow events DC0032 Process Creation AN1197 1
loading of unexpected dylibs compared to historical baselines DC0016 Module Load AN1210 1
log DC0029 Script Execution AN0313 1
log collect --predicate DC0032 Process Creation AN1042 1
log collect from launchd and process start DC0034 Process Metadata AN0985 1
log messages related to disk enumeration context or Terminal session DC0064 Command Execution AN0538 1
log show --predicate 'eventMessage contains "Authentication"' DC0002 User Account Authentication AN0592 1
log show --predicate 'process == <utility>' DC0064 Command Execution AN1454 1
log stream DC0064 Command Execution AN0115 AN0239 AN0280 AN0739 AN1218 AN1227 6
log stream 'eventMessage contains "dns_request"' DC0078 Network Traffic Flow AN1123 1
log stream 'eventMessage contains pubsub or broker' DC0032 Process Creation AN0004 1
log stream (subsystem: com.apple.system.networking) DC0085 Network Traffic Content AN0369 1
log stream - file provider subsystem DC0055 File Access AN1415 1
log stream - file subsystem DC0055 File Access AN0425 1
log stream --info --predicate 'eventMessage CONTAINS "exec"' DC0032 Process Creation AN1430 1
log stream --info --predicate 'subsystem == "com.apple.cfprefsd"' DC0032 Process Creation AN0102 1
log stream --predicate DC0064 Command Execution AN0077 AN1171 AN1590 AN1628 4
log stream --predicate 'eventMessage contains "USBMSC"' DC0042 Drive Creation AN1412 1
log stream --predicate 'eventMessage contains "exec"' DC0032 Process Creation AN1082 1
log stream --predicate 'eventMessage contains "loginwindow" or "pfctl"' DC0064 Command Execution AN0135 1
log stream --predicate 'eventMessage contains "python"' DC0029 Script Execution AN0173 1
log stream --predicate 'eventMessage contains "wscript" OR "vbs"' DC0029 Script Execution AN0210 1
log stream --predicate 'processImagePath CONTAINS "curl" OR "osascript"' DC0032 Process Creation AN0381 1
log stream --predicate 'processImagePath contains "zip" OR "base64"' DC0064 Command Execution AN1066 1
log stream cleared or truncated DC0038 Application Log Content AN0522 1
log stream network activity DC0082 Network Connection Creation AN1391 1
log stream process subsystem DC0032 Process Creation AN1391 1
log stream with predicate 'eventMessage CONTAINS "osascript"' DC0029 Script Execution AN0734 1
logMessage contains pbpaste or osascript DC0032 Process Creation AN0533 1
logd:file write DC0039 File Creation AN0601 1
loginwindow or desktopservices modified settings or files DC0061 File Modification AN0231 1
loginwindow or sshd DC0088 Logon Session Metadata AN1139 1
loginwindow or sshd events with external IP DC0088 Logon Session Metadata AN1624 1
loginwindow or sshd successful login events DC0067 Logon Session Creation AN1346 1
loginwindow or tccd-related entries DC0032 Process Creation AN0682 1
loginwindow, sshd DC0088 Logon Session Metadata AN1545 1
looking for file access to scripts with abnormal encoding patterns DC0055 File Access AN2065 1
memory mapping DC0020 Process Modification AN0239 1
modification to /var/db/dslocal/nodes/Default/users/ DC0061 File Modification AN1237 AN1606 2
mounted|appeared|DA: disk* attached DC0042 Drive Creation AN0187 1
network DC0082 Network Connection Creation AN1115 1
network connection events DC0082 Network Connection Creation AN0333 AN2032 2
network flow DC0085 Network Traffic Content AN0146 1
network sessions initiated by remote desktop apps DC0082 Network Connection Creation AN0716 1
network stack resource exhaustion, tcp_accept queue overflow, repeated resets DC0018 Host Status AN1014 1
network, socket, and http logs DC0085 Network Traffic Content AN0566 1
networkd or com.apple.network DC0078 Network Traffic Flow AN1120 1
networkd or socket DC0082 Network Connection Creation AN1383 1
new DHCP configuration with anomalous DNS or router values DC0038 Application Log Content AN1292 1
nohup, disown, or osascript execution patterns DC0064 Command Execution AN0183 1
non-shell process tree accessing bash history DC0034 Process Metadata AN1086 1
open URL|clicked link|LSQuarantineAttach DC0085 Network Traffic Content AN0180 1
open/read access to private key files (id_rsa, *.pem, *.p12) DC0055 File Access AN1518 1
open/read of *.plist or .env files DC0055 File Access AN0858 1
open: Access to /var/log/system.log or related security event logs DC0055 File Access AN0707 1
opendirectoryd crashes or abnormal authentication errors DC0038 Application Log Content AN0495 1
opened document|clicked link|EXC_BAD_ACCESS|abort|LSQuarantine DC0038 Application Log Content AN1316 1
osascript or AppleScript invocation modifying UI DC0029 Script Execution AN0231 1
osascript, AppleScript, or Python execution triggered immediately after HID connection DC0029 Script Execution AN1569 1
outbound HTTPS connections to cloud storage APIs DC0085 Network Traffic Content AN1573 1
outbound HTTPS connections to code repository APIs DC0085 Network Traffic Content AN0897 1
outbound TCP/UDP traffic over unexpected port DC0078 Network Traffic Flow AN0635 1
outbound TLS connections to cloud storage providers DC0085 Network Traffic Content AN1513 1
pfctl -d, socketfilterfw --setglobalstate off, or modifications to com.apple.alf DC0064 Command Execution AN0408 1
pkginstalld/softwareupdated/Homebrew install transactions DC0059 File Metadata AN0864 1
process DC0032 Process Creation
DC0034 Process Metadata
AN0146 AN0357 AN0394 AN0468 AN0561 AN0966 AN1017 AN1282 AN1439 AN1585 10
process 'crashed'|'EXC_BAD_ACCESS' for sshd, screensharingd, httpd; launchd restarts of these daemons. DC0038 Application Log Content AN0330 1
process + network activity DC0085 Network Traffic Content AN1191 1
process + network metrics correlation for bandwidth saturation DC0085 Network Traffic Content AN0082 1
process = 'ssh' OR eventMessage CONTAINS 'ssh' DC0085 Network Traffic Content AN1639 1
process = 'sshd' DC0088 Logon Session Metadata AN1639 1
process activity, exec events DC0032 Process Creation AN1383 1
process and file events via log stream DC0032 Process Creation AN0294 1
process and signing chain events DC0032 Process Creation AN0625 1
process calling security find-certificate, export, or import DC0064 Command Execution AN0673 1
process command line contains base64, -enc, openssl enc -base64 DC0032 Process Creation AN0347 1
process crash, abort, code signing violations DC0038 Application Log Content AN0799 1
process created with repeated ICMP or UDP flood behavior DC0032 Process Creation AN0971 1
process event DC0032 Process Creation AN1614 1
process events DC0032 Process Creation AN0659 AN0813 AN1027 3
process exec DC0032 Process Creation AN1355 1
process exec events of systemsetup, date, ioreg with command_line parameters indicating time discovery DC0032 Process Creation AN0432 1
process execution events for chmod, chown, chflags with parameter analysis and target path examination DC0032 Process Creation AN0999 1
process execution events for chmod, chown, chflags with unusual parameters or targets DC0032 Process Creation AN0836 1
process execution events for discovery utilities (system_profiler, sw_vers, dscl, networksetup) with command-line parameter analysis DC0032 Process Creation AN1307 1
process execution events for system discovery utilities (system_profiler, sysctl, networksetup, ioreg) with parameter analysis DC0032 Process Creation AN1553 1
process execution events with dylib load activity DC0016 Module Load AN0435 1
process execution of ssh with -L/-R forwarding flags DC0032 Process Creation AN1485 1
process launch DC0032 Process Creation AN0097 AN0260 2
process launch of diskutil or system_profiler with SPStorageDataType DC0032 Process Creation AN0538 1
process logs DC0032 Process Creation AN0924 1
process writes or modifies files in excluded paths DC0032 Process Creation AN0141 1
process, network DC0085 Network Traffic Content AN1601 1
process, socket, and DNS logs DC0032 Process Creation AN1022 1
process.*exit.*code DC0033 Process Termination AN0374 AN0413 2
process: at, job runner DC0064 Command Execution AN0945 1
process: code or jetbrains-gateway launching with --tunnel or --remote DC0032 Process Creation AN0377 1
process: crontab edits, launch of cron job DC0001 Scheduled Job Creation AN0806 1
process: exec DC0032 Process Creation AN0981 AN1115 2
process: exec + filewrite: ~/.ssh/authorized_keys DC0032 Process Creation AN0351 1
process: spawn, exec DC0032 Process Creation AN1164 1
process::exec DC0032 Process Creation AN0068 1
process:exec DC0032 Process Creation AN0319 1
process:exec and kext load events DC0032 Process Creation AN1421 1
process:launch DC0032 Process Creation AN0509 1
process:spawn DC0032 Process Creation AN1072 AN1530 2
process:spawn, process:exec DC0064 Command Execution AN1396 1
process_create: Process creation where parent is Safari/Google Chrome and child is script interpreter or signed-but-unusual helper binary DC0032 Process Creation AN0500 1
process_exec: image in {/bin/bash,/bin/zsh,/usr/bin/osascript,/usr/bin/python*,/usr/bin/curl,/usr/bin/ssh,/usr/bin/open} AND parent in {Preview, TextEdit, Microsoft Word, Microsoft Excel, AdobeReader, Archive Utility, Finder} DC0032 Process Creation AN0820 1
process_name IN ("VBoxManage", "prlctl") AND command CONTAINS ("list", "show") DC0032 Process Creation AN0575 1
profiles install -type=configuration DC0064 Command Execution AN0124 1
ptrace or task_for_pid DC0035 Process Access AN0156 1
ptrace: Processes invoking ptrace with PTRACE_TRACEME flag DC0021 OS API Execution AN1047 1
pwpolicy|PasswordPolicy DC0064 Command Execution AN0457 1
quarantine or AV-related subsystem DC0038 Application Log Content AN0542 1
read access to ~/Library/Keychains or history files by terminal processes DC0055 File Access AN1155 1
read access to ~/Library/Keychains/login.keychain-db DC0055 File Access AN1112 1
read of user document directories DC0055 File Access AN0897 1
read/write of user documents prior to upload DC0055 File Access AN1513 1
read: File access to /System/Library/Extensions/ or related kernel extension paths DC0055 File Access AN1597 1
replace existing dylibs DC0061 File Modification AN0435 1
rule definitions written to emond rule plists DC0061 File Modification AN1534 1
security OR injection attempts into 1Password OR LastPass DC0032 Process Creation AN1643 1
shutdown -h now or reboot DC0032 Process Creation AN1540 1
softwareupdated/homebrew/install logs, pkginstalld events DC0059 File Metadata AN0023 1
spctl --master-disable, csrutil disable, or defaults write to disable Gatekeeper DC0064 Command Execution AN0888 0
subsystem: com.apple.WebKit or com.apple.WebKit.Networking DC0085 Network Traffic Content AN1409 1
subsystem: com.apple.network DC0085 Network Traffic Content AN0160 1
subsystem:com.apple.Terminal DC0064 Command Execution AN0256 1
subsystem:syspolicyd DC0059 File Metadata AN0090 1
subsystem=com.apple.Security or com.apple.applescript DC0029 Script Execution AN1442 1
subsystem=com.apple.TCC DC0034 Process Metadata AN0245 AN0284 2
subsystem=com.apple.WebKit DC0085 Network Traffic Content AN1322 1
subsystem=com.apple.kextd DC0016 Module Load AN1063 1
subsystem=com.apple.launchservices DC0041 Service Metadata AN0326 1
subsystem=com.apple.lsd DC0059 File Metadata AN1462 1
subsystem=com.apple.process DC0034 Process Metadata AN0013 1
subsystem=com.apple.security, library=libsystem_kernel.dylib DC0035 Process Access AN1401 1
subsystem=launchservices DC0029 Script Execution AN0533 1
successful sudo or authentication for account not normally associated with admin actions DC0002 User Account Authentication AN0336 1
sudden burst in outgoing packets from same PID DC0078 Network Traffic Flow AN0971 1
suspicious dlopen/dlsym usage in non-development processes DC0016 Module Load AN0840 1
tcp/udp DC0078 Network Traffic Flow AN0639 1
vm_read, task_for_pid, or file open to cookie databases DC0035 Process Access AN1404 1
write DC0061 File Modification AN0766 1
write of plist files in /Library/LaunchAgents or /Library/LaunchDaemons DC0061 File Modification AN0736 1
write: File modification to com.apple.PowerManagement.plist or related system preference files DC0061 File Modification AN1176 1
write: File modifications to *.plist within LaunchAgents, LaunchDaemons, Application Support, or Preferences directories DC0061 File Modification AN0306 1
xattr -d com.apple.quarantine or similar attribute removal commands DC0059 File Metadata AN0800 1
xattr -d com.apple.quarantine or similar removal commands DC0064 Command Execution AN1248 1
xattr utility execution with -w or -p flags DC0064 Command Execution AN1136 1
~/Library/Application Support/Google/Chrome/*/Login Data OR ~/Library/Application Support/Firefox/*/logins.json DC0055 File Access AN0107 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1001 Data Obfuscationcommand and control02
T1001.001 Junk Datacommand and control00
T1001.002 Steganographycommand and control00
T1001.003 Protocol or Service Impersonationcommand and control20
T1003 OS Credential Dumpingcredential access3718
T1005 Data from Local Systemcollection1446
T1007 System Service Discoverydiscovery111
T1008 Fallback Channelscommand and control40
T1010 Application Window Discoverydiscovery10
T1011 Exfiltration Over Other Network Mediumexfiltration04
T1011.001 Exfiltration Over Bluetoothexfiltration00
T1014 Rootkitstealth10
T1016 System Network Configuration Discoverydiscovery121
T1016.001 Internet Connection Discoverydiscovery00
T1016.002 Wi-Fi Discoverydiscovery00
T1018 Remote System Discoverydiscovery172
T1020 Automated Exfiltrationexfiltration100
T1021 Remote Serviceslateral movement114
T1021.004 SSHlateral movement52
T1021.005 VNClateral movement10
T1025 Data from Removable Mediacollection00
T1027 Obfuscated Files or Informationstealth945
T1027.001 Binary Paddingstealth30
T1027.002 Software Packingstealth10
T1027.003 Steganographystealth50
T1027.004 Compile After Deliverystealth60
T1027.005 Indicator Removal from Toolsstealth40
T1027.006 HTML Smugglingstealth00
T1027.008 Stripped Payloadsstealth00
T1027.009 Embedded Payloadsstealth20
T1027.010 Command Obfuscationstealth100
T1027.013 Encrypted/Encoded Filestealth00
T1027.014 Polymorphic Codestealth00
T1027.015 Compressionstealth00
T1027.017 SVG Smugglingstealth00
T1027.018 Invisible Unicodestealth00
T1029 Scheduled Transferexfiltration00
T1030 Data Transfer Size Limitsexfiltration20
T1033 System Owner/User Discoverydiscovery302
T1036 Masqueradingstealth402
T1036.001 Invalid Code Signaturestealth00
T1036.002 Right-to-Left Overridestealth30
T1036.003 Rename Legitimate Utilitiesstealth270
T1036.004 Masquerade Task or Servicestealth30
T1036.005 Match Legitimate Resource Name or Locationstealth211
T1036.006 Space after Filenamestealth10
T1036.008 Masquerade File Typestealth10
T1036.009 Break Process Treesstealth00
T1036.012 Browser Fingerprintstealth00
T1037 Boot or Logon Initialization Scriptspersistence, privilege escalation03
T1037.002 Login Hookpersistence, privilege escalation00
T1037.004 RC Scriptspersistence, privilege escalation00
T1037.005 Startup Itemspersistence, privilege escalation10
T1039 Data from Network Shared Drivecollection20
T1040 Network Sniffingcredential access, discovery92
T1041 Exfiltration Over C2 Channelexfiltration512
T1046 Network Service Discoverydiscovery207
T1048 Exfiltration Over Alternative Protocolexfiltration124
T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocolexfiltration10
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocolexfiltration00
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocolexfiltration91
T1052 Exfiltration Over Physical Mediumexfiltration00
T1052.001 Exfiltration over USBexfiltration00
T1053 Scheduled Task/Jobexecution, persistence, privilege escalation122
T1053.002 Atexecution, persistence, privilege escalation80
T1053.003 Cronexecution, persistence, privilege escalation60
T1055 Process Injectionstealth, privilege escalation3719
T1056 Input Capturecollection, credential access23
T1056.001 Keyloggingcollection, credential access31
T1056.002 GUI Input Capturecollection, credential access30
T1056.003 Web Portal Capturecollection, credential access00
T1056.004 Credential API Hookingcollection, credential access00
T1057 Process Discoverydiscovery80
T1059 Command and Scripting Interpreterexecution95170
T1059.002 AppleScriptexecution90
T1059.004 Unix Shellexecution1814
T1059.005 Visual Basicexecution290
T1059.006 Pythonexecution130
T1059.007 JavaScriptexecution2914
T1059.011 Luaexecution00
T1068 Exploitation for Privilege Escalationprivilege escalation3169
T1069 Permission Groups Discoverydiscovery31
T1069.001 Local Groupsdiscovery160
T1069.002 Domain Groupsdiscovery150
T1070 Indicator Removalstealth203
T1070.003 Clear Command Historystealth90
T1070.004 File Deletionstealth155
T1070.006 Timestompstealth60
T1070.007 Clear Network Connection History and Configurationsstealth00
T1070.008 Clear Mailbox Datastealth20
T1070.009 Clear Persistencestealth00
T1070.010 Relocate Malwarestealth00
T1071 Application Layer Protocolcommand and control71
T1071.001 Web Protocolscommand and control4210
T1071.002 File Transfer Protocolscommand and control01
T1071.003 Mail Protocolscommand and control00
T1071.004 DNScommand and control170
T1071.005 Publish/Subscribe Protocolscommand and control00
T1072 Software Deployment Toolsexecution, lateral movement40
T1074 Data Stagedcollection20
T1074.001 Local Data Stagingcollection40
T1074.002 Remote Data Stagingcollection00
T1078 Valid Accountsstealth, persistence, privilege escalation, initial access5646
T1078.002 Domain Accountsstealth, persistence, privilege escalation, initial access70
T1078.003 Local Accountsstealth, persistence, privilege escalation, initial access51
T1080 Taint Shared Contentlateral movement00
T1082 System Information Discoverydiscovery337
T1083 File and Directory Discoverydiscovery245
T1087 Account Discoverydiscovery166
T1087.001 Local Accountdiscovery131
T1087.002 Domain Accountdiscovery215
T1090 Proxycommand and control223
T1090.001 Internal Proxycommand and control61
T1090.002 External Proxycommand and control20
T1090.003 Multi-hop Proxycommand and control30
T1090.004 Domain Frontingcommand and control10
T1092 Communication Through Removable Mediacommand and control00
T1095 Non-Application Layer Protocolcommand and control30
T1098 Account Manipulationpersistence, privilege escalation342
T1098.004 SSH Authorized Keyspersistence, privilege escalation01
T1098.007 Additional Local or Domain Groupspersistence, privilege escalation00
T1102 Web Servicecommand and control130
T1102.001 Dead Drop Resolvercommand and control40
T1102.002 Bidirectional Communicationcommand and control40
T1102.003 One-Way Communicationcommand and control20
T1104 Multi-Stage Channelscommand and control00
T1105 Ingress Tool Transfercommand and control8735
T1106 Native APIexecution147
T1110 Brute Forcecredential access252
T1110.001 Password Guessingcredential access30
T1110.002 Password Crackingcredential access10
T1110.003 Password Sprayingcredential access00
T1110.004 Credential Stuffingcredential access00
T1111 Multi-Factor Authentication Interceptioncredential access00
T1113 Screen Capturecollection100
T1114 Email Collectioncollection43
T1114.003 Email Forwarding Rulecollection60
T1115 Clipboard Datacollection80
T1119 Automated Collectioncollection51
T1120 Peripheral Device Discoverydiscovery20
T1123 Audio Capturecollection60
T1124 System Time Discoverydiscovery30
T1125 Video Capturecollection10
T1129 Shared Modulesexecution20
T1132 Data Encodingcommand and control00
T1132.001 Standard Encodingcommand and control40
T1133 External Remote Servicespersistence, initial access2025
T1135 Network Share Discoverydiscovery70
T1136 Create Accountpersistence310
T1136.001 Local Accountpersistence182
T1136.002 Domain Accountpersistence60
T1140 Deobfuscate/Decode Files or Informationstealth182
T1176 Software Extensionspersistence10
T1176.001 Browser Extensionspersistence20
T1176.002 IDE Extensionspersistence00
T1189 Drive-by Compromiseinitial access321
T1190 Exploit Public-Facing Applicationinitial access149157
T1195 Supply Chain Compromiseinitial access11
T1195.001 Compromise Software Dependencies and Development Toolsinitial access20
T1195.002 Compromise Software Supply Chaininitial access172
T1195.003 Compromise Hardware Supply Chaininitial access00
T1199 Trusted Relationshipinitial access21
T1200 Hardware Additionsinitial access30
T1201 Password Policy Discoverydiscovery60
T1203 Exploitation for Client Executionexecution3543
T1204 User Executionexecution102
T1204.001 Malicious Linkexecution411
T1204.002 Malicious Fileexecution3933
T1204.004 Malicious Copy and Pasteexecution60
T1204.005 Malicious Libraryexecution00
T1205 Traffic Signalingstealth, persistence, command and control00
T1205.001 Port Knockingstealth, persistence, command and control00
T1205.002 Socket Filtersstealth, persistence, command and control00
T1210 Exploitation of Remote Serviceslateral movement154
T1211 Exploitation for Stealthstealth41
T1212 Exploitation for Credential Accesscredential access54
T1213 Data from Information Repositoriescollection72
T1213.006 Databasescollection00
T1217 Browser Information Discoverydiscovery41
T1218 System Binary Proxy Executionstealth1532
T1218.015 Electron Applicationsstealth00
T1219 Remote Access Toolscommand and control61
T1219.001 IDE Tunnelingcommand and control00
T1219.002 Remote Desktop Softwarecommand and control460
T1219.003 Remote Access Hardwarecommand and control00
T1222 File and Directory Permissions Modificationdefense impairment21
T1222.002 Linux and Mac Permissionsdefense impairment40
T1480 Execution Guardrailsstealth00
T1480.001 Environmental Keyingstealth00
T1480.002 Mutual Exclusionstealth00
T1485 Data Destructionimpact206
T1486 Data Encrypted for Impactimpact1615
T1489 Service Stopimpact201
T1491 Defacementimpact00
T1491.001 Internal Defacementimpact40
T1491.002 External Defacementimpact01
T1495 Firmware Corruptionimpact12
T1496 Resource Hijackingimpact1319
T1496.001 Compute Hijackingimpact00
T1496.002 Bandwidth Hijackingimpact00
T1497 Virtualization/Sandbox Evasionstealth, discovery04
T1497.001 System Checksstealth, discovery30
T1497.002 User Activity Based Checksstealth, discovery00
T1497.003 Time Based Checksstealth, discovery00
T1498.001 Direct Network Floodimpact01
T1498.002 Reflection Amplificationimpact00
T1499 Endpoint Denial of Serviceimpact37
T1499.001 OS Exhaustion Floodimpact10
T1499.002 Service Exhaustion Floodimpact02
T1499.003 Application Exhaustion Floodimpact00
T1499.004 Application or System Exploitationimpact32
T1505 Server Software Componentpersistence12
T1505.003 Web Shellpersistence3526
T1518 Software Discoverydiscovery40
T1518.001 Security Software Discoverydiscovery90
T1518.002 Backup Software Discoverydiscovery00
T1529 System Shutdown/Rebootimpact80
T1531 Account Access Removalimpact91
T1534 Internal Spearphishinglateral movement00
T1539 Steal Web Session Cookiecredential access20
T1542 Pre-OS Bootstealth, persistence00
T1542.002 Component Firmwarestealth, persistence00
T1543 Create or Modify System Processpersistence, privilege escalation99
T1543.001 Launch Agentpersistence, privilege escalation20
T1543.004 Launch Daemonpersistence, privilege escalation30
T1546 Event Triggered Executionprivilege escalation, persistence100
T1546.004 Unix Shell Configuration Modificationprivilege escalation, persistence10
T1546.005 Trapprivilege escalation, persistence00
T1546.006 LC_LOAD_DYLIB Additionprivilege escalation, persistence00
T1546.014 Emondprivilege escalation, persistence10
T1546.016 Installer Packagesprivilege escalation, persistence00
T1547 Boot or Logon Autostart Executionpersistence, privilege escalation71
T1547.006 Kernel Modules and Extensionspersistence, privilege escalation20
T1547.007 Re-opened Applicationspersistence, privilege escalation00
T1547.015 Login Itemspersistence, privilege escalation10
T1548 Abuse Elevation Control Mechanismprivilege escalation244
T1548.001 Setuid and Setgidprivilege escalation21
T1548.003 Sudo and Sudo Cachingprivilege escalation30
T1548.004 Elevated Execution with Promptprivilege escalation00
T1548.006 TCC Manipulationprivilege escalation00
T1552 Unsecured Credentialscredential access134
T1552.001 Credentials In Filescredential access243
T1552.003 Shell Historycredential access30
T1552.004 Private Keyscredential access71
T1553 Subvert Trust Controlsdefense impairment40
T1553.001 Gatekeeper Bypassdefense impairment10
T1553.002 Code Signingdefense impairment10
T1553.004 Install Root Certificatedefense impairment100
T1553.006 Code Signing Policy Modificationdefense impairment00
T1554 Compromise Host Software Binarypersistence60
T1555 Credentials from Password Storescredential access89
T1555.001 Keychaincredential access10
T1555.002 Securityd Memorycredential access00
T1555.003 Credentials from Web Browserscredential access80
T1555.005 Password Managerscredential access10
T1556 Modify Authentication Processdefense impairment, persistence, credential access122
T1556.003 Pluggable Authentication Modulesdefense impairment, persistence, credential access00
T1556.006 Multi-Factor Authenticationdefense impairment, persistence, credential access30
T1557 Adversary-in-the-Middlecredential access, collection104
T1557.002 ARP Cache Poisoningcredential access, collection00
T1557.003 DHCP Spoofingcredential access, collection10
T1558 Steal or Forge Kerberos Ticketscredential access63
T1558.005 Ccache Filescredential access00
T1559 Inter-Process Communicationexecution10
T1559.003 XPC Servicesexecution00
T1560 Archive Collected Datacollection40
T1560.001 Archive via Utilitycollection172
T1560.002 Archive via Librarycollection00
T1560.003 Archive via Custom Methodcollection00
T1561 Disk Wipeimpact00
T1561.001 Disk Content Wipeimpact10
T1561.002 Disk Structure Wipeimpact10
T1563 Remote Service Session Hijackinglateral movement00
T1563.001 SSH Hijackinglateral movement00
T1564 Hide Artifactsstealth100
T1564.001 Hidden Files and Directoriesstealth90
T1564.002 Hidden Usersstealth40
T1564.003 Hidden Windowstealth80
T1564.005 Hidden File Systemstealth00
T1564.006 Run Virtual Instancestealth20
T1564.007 VBA Stompingstealth00
T1564.008 Email Hiding Rulesstealth40
T1564.009 Resource Forkingstealth00
T1564.011 Ignore Process Interruptsstealth00
T1564.012 File/Path Exclusionsstealth00
T1564.014 Extended Attributesstealth00
T1565 Data Manipulationimpact32
T1565.001 Stored Data Manipulationimpact62
T1565.002 Transmitted Data Manipulationimpact20
T1565.003 Runtime Data Manipulationimpact00
T1566 Phishinginitial access146
T1566.001 Spearphishing Attachmentinitial access247
T1566.002 Spearphishing Linkinitial access45
T1566.003 Spearphishing via Serviceinitial access00
T1566.004 Spearphishing Voiceinitial access00
T1567 Exfiltration Over Web Serviceexfiltration123
T1567.001 Exfiltration to Code Repositoryexfiltration20
T1567.002 Exfiltration to Cloud Storageexfiltration140
T1567.003 Exfiltration to Text Storage Sitesexfiltration00
T1567.004 Exfiltration Over Webhookexfiltration00
T1568 Dynamic Resolutioncommand and control20
T1568.001 Fast Flux DNScommand and control00
T1568.002 Domain Generation Algorithmscommand and control20
T1568.003 DNS Calculationcommand and control00
T1569 System Servicesexecution40
T1569.001 Launchctlexecution10
T1570 Lateral Tool Transferlateral movement61
T1571 Non-Standard Portcommand and control51
T1572 Protocol Tunnelingcommand and control240
T1573 Encrypted Channelcommand and control60
T1573.001 Symmetric Cryptographycommand and control03
T1573.002 Asymmetric Cryptographycommand and control00
T1574 Hijack Execution Flowstealth, execution816
T1574.004 Dylib Hijackingstealth, execution00
T1574.006 Dynamic Linker Hijackingstealth, execution20
T1574.007 Path Interception by PATH Environment Variablestealth, execution20
T1606 Forge Web Credentialscredential access10
T1606.001 Web Cookiescredential access00
T1614 System Location Discoverydiscovery00
T1614.001 System Language Discoverydiscovery20
T1620 Reflective Code Loadingstealth30
T1621 Multi-Factor Authentication Request Generationcredential access20
T1622 Debugger Evasionstealth, discovery12
T1647 Plist File Modificationdefense impairment00
T1649 Steal or Forge Authentication Certificatescredential access110
T1652 Device Driver Discoverydiscovery00
T1653 Power Settingspersistence11
T1654 Log Enumerationdiscovery00
T1657 Financial Theftimpact00
T1659 Content Injectioninitial access, command and control00
T1665 Hide Infrastructurecommand and control00
T1667 Email Bombingimpact00
T1668 Exclusive Controlpersistence00
T1669 Wi-Fi Networksinitial access00
T1673 Virtual Machine Discoverydiscovery00
T1674 Input Injectionexecution00
T1678 Delay Executionstealth00
T1680 Local Storage Discoverydiscovery00
T1684 Social Engineeringstealth00
T1684.001 Impersonationstealth00
T1684.002 Email Spoofingstealth00
T1685 Disable or Modify Toolsdefense impairment1640
T1685.003 Modify or Spoof Tool UIdefense impairment00
T1685.006 Clear Linux or Mac System Logsdefense impairment40
T1686 Disable or Modify System Firewalldefense impairment70
T1687 Exploitation for Defense Impairmentdefense impairment00
T1689 Downgrade Attackdefense impairment10
T1690 Prevent Command History Loggingdefense impairment10

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2007-5659Adobe Acrobat and Reader T1204.002 Mapped
CVE-2008-0655Adobe Acrobat and Reader T1204.002 Mapped
CVE-2008-2992Adobe Acrobat and Reader T1204.002 Mapped
CVE-2009-1862Adobe Acrobat and Reader, Flash Player T1204.002 Mapped
CVE-2009-3953Adobe Acrobat and Reader T1204.002 Mapped
CVE-2009-3960Adobe BlazeDS T1190 T1486 Mapped
CVE-2009-4324Adobe Acrobat and Reader T1071.001 T1204.002 Mapped
CVE-2010-0188Adobe Reader and Acrobat T1105 T1189 Mapped
CVE-2010-1297Adobe Flash Player T1105 T1189 T1204.002 Mapped
CVE-2010-2861Adobe ColdFusion T1105 T1119 T1190 Mapped
CVE-2010-2883Adobe Acrobat and Reader T1027 T1059 T1204.002 Mapped
CVE-2011-0611Adobe Flash Player T1105 T1204.002 Mapped
CVE-2011-2462Adobe Reader and Acrobat T1204.002 Mapped
CVE-2012-0754Adobe Flash Player T1105 T1204.002 Mapped
CVE-2012-0767Adobe Flash Player T1098 T1204.001 Mapped
CVE-2012-1535Adobe Flash Player T1105 T1204.002 Mapped
CVE-2012-2034Adobe Flash Player T1189 Mapped
CVE-2012-5054Adobe Flash Player T1189 Mapped
CVE-2013-0625Adobe ColdFusion T1190 Mapped
CVE-2013-0629Adobe ColdFusion T1005 T1190 Mapped
CVE-2013-0631Adobe ColdFusion T1190 Mapped
CVE-2013-0632Adobe ColdFusion T1190 Mapped
CVE-2013-0640Adobe Reader and Acrobat T1566.001 Mapped
CVE-2013-0641Adobe Reader T1048 T1105 T1204.002 Mapped
CVE-2013-3346Adobe Reader and Acrobat T1059.007 Mapped
CVE-2014-0496Adobe Reader and Acrobat T1204.002 Mapped
CVE-2014-0546Adobe Reader and Acrobat T1068 T1497 Mapped
CVE-2014-6271GNU Bourne-Again Shell (Bash) T1059.004 T1133 T1190 Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash) T1059.004 T1133 T1190 Mapped
CVE-2014-8439Adobe Flash Player T1189 Mapped
CVE-2015-0310Adobe Flash Player T1189 Mapped
CVE-2015-0313Adobe Flash Player T1189 Mapped
CVE-2015-3043Adobe Flash Player T1189 T1204.002 T1499.004 Mapped
CVE-2015-3113Adobe Flash Player T1071.001 T1204.002 T1497 T1622 Mapped
CVE-2015-5119Adobe Flash Player T1059.007 T1071.001 T1105 T1203 T1204.001 T1566.002 Mapped
CVE-2015-7645Adobe Flash Player T1204.002 Mapped
CVE-2015-8651Adobe Flash Player T1105 T1189 T1486 Mapped
CVE-2016-0984Adobe Flash Player and AIR T1105 T1204.002 Mapped
CVE-2016-10033PHP PHPMailer T1059.004 T1190 Mapped
CVE-2016-1010Adobe Flash Player and AIR T1574 Mapped
CVE-2016-1019Adobe Flash Player T1105 T1189 T1486 Mapped
CVE-2016-4117Adobe Flash Player T1105 T1204.002 Mapped
CVE-2016-4437Apache Shiro T1059 T1190 Mapped
CVE-2016-7855Adobe Flash Player T1189 Mapped
CVE-2017-11292Adobe Flash Player T1005 T1105 T1204.002 T1566.001 Mapped
CVE-2017-11882Microsoft Office T1059 T1566.001 Mapped
CVE-2017-12637SAP NetWeaver T1083 T1190 T1555 Mapped
CVE-2017-5638Apache Struts T1005 T1059 T1190 Mapped
CVE-2017-6742Cisco IOS and IOS XE Software T1048 T1059 T1574 Mapped
CVE-2017-9805Apache Struts T1059 T1190 Mapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) T1059 T1190 T1496 Mapped
CVE-2018-0296Cisco Adaptive Security Appliance (ASA) T1005 Mapped
CVE-2018-11776Apache Struts T1059 T1190 T1496 Mapped
CVE-2018-13379Fortinet FortiOS T1190 Mapped
CVE-2018-15961Adobe ColdFusion T1190 T1491.002 Mapped
CVE-2018-15982Adobe Flash Player T1105 T1204.002 Mapped
CVE-2018-4878Adobe Flash Player T1041 T1204.002 T1219 Mapped
CVE-2018-4939Adobe ColdFusion T1133 T1190 T1203 Mapped
CVE-2018-4990Adobe Acrobat and Reader T1059.007 T1204.002 Mapped
CVE-2018-6789Exim Exim T1059 T1190 Mapped
CVE-2018-7600Drupal Drupal Core T1059 T1190 T1485 T1496 Mapped
CVE-2019-0211Apache HTTP Server T1068 Mapped
CVE-2019-0604Microsoft SharePoint T1003 T1041 T1190 T1505.003 Mapped
CVE-2019-0708Microsoft Remote Desktop Services T1059.004 T1133 Mapped
CVE-2019-11510Ivanti Pulse Connect Secure T1059 T1083 T1133 T1552.001 Mapped
CVE-2019-11580Atlassian Crowd and Crowd Data Center T1059 Mapped
CVE-2019-11634Citrix Workspace Application and Receiver for Windows T1003 T1005 T1046 T1059 T1078 T1190 T1486 Mapped
CVE-2019-13608Citrix StoreFront Server T1003 T1005 T1046 T1059 T1078 Mapped
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers T1005 T1007 T1082 T1190 Mapped
CVE-2019-17558Apache Solr T1059 T1190 Mapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX T1041 T1190 T1496 T1505.003 Mapped
CVE-2019-19781Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1059 T1083 T1133 Mapped
CVE-2019-3396Atlassian Confluence Server and Data Server T1090 T1133 Mapped
CVE-2019-3398Atlassian Confluence Server and Data Center T1059 Mapped
CVE-2019-5591Fortinet FortiOS T1005 T1133 T1557 Mapped
CVE-2020-0069MediaTek Multiple Chipsets T1068 Mapped
CVE-2020-0688Microsoft Exchange Server T1110 T1114 T1190 T1505.003 Mapped
CVE-2020-0787Microsoft Windows T1059 T1068 Mapped
CVE-2020-12812Fortinet FortiOS T1556 Mapped
CVE-2020-1472Microsoft Netlogon T1021 T1068 T1087.002 T1110 T1133 T1486 Mapped
CVE-2020-15505Ivanti MobileIron Multiple Products T1059 T1190 Mapped
CVE-2020-17530Apache Struts T1059 T1190 Mapped
CVE-2020-25506D-Link DNS-320 Device T1059 T1133 Mapped
CVE-2020-29557D-Link DIR-825 R1 Devices T1059 T1190 Mapped
CVE-2020-29574Sophos CyberoamOS T1055 T1059 Mapped
CVE-2020-3452Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1005 Mapped
CVE-2020-3580Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1059 T1204.001 T1217 Mapped
CVE-2020-5735Amcrest Cameras and Network Video Recorder (NVR) T1499 T1574 Mapped
CVE-2020-5902F5 BIG-IP T1003 T1005 T1059 T1070.004 T1133 T1190 T1552 Stale
CVE-2020-8193Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 T1556 Mapped
CVE-2020-8195Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 T1056 T1082 Mapped
CVE-2020-8196Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance T1005 T1056 T1082 Mapped
CVE-2020-8515DrayTek Multiple Vigor Routers T1059 T1133 T1496 Mapped
CVE-2020-8657EyesOfNetwork EyesOfNetwork T1106 Mapped
CVE-2021-1497Cisco HyperFlex HX T1059 T1133 Mapped
CVE-2021-1498Cisco HyperFlex HX T1059 T1133 Mapped
CVE-2021-20035SonicWall SMA100 Appliances T1059 T1078 Mapped
CVE-2021-21017Adobe Acrobat and Reader T1204.002 Mapped
CVE-2021-21148Google Chromium V8 T1059.007 T1203 Mapped
CVE-2021-21166Google Chromium T1059.007 T1203 Mapped
CVE-2021-21206Google Chromium Blink T1059.007 T1203 Mapped
CVE-2021-21972VMware vCenter Server T1059 T1190 Mapped
CVE-2021-21973VMware vCenter Server and Cloud Foundation T1046 T1190 Mapped
CVE-2021-21975VMware vRealize Operations Manager API T1190 Mapped
CVE-2021-22005VMware vCenter Server T1059 T1190 Mapped
CVE-2021-22017VMware vCenter Server T1090.001 T1190 Mapped
CVE-2021-22204Perl Exiftool T1059 T1190 Mapped
CVE-2021-22205GitLab Community and Enterprise Editions T1059 T1190 T1496 Mapped
CVE-2021-22893Ivanti Pulse Connect Secure T1003 T1059 T1190 Mapped
CVE-2021-22894Ivanti Pulse Connect Secure T1059 T1078 Mapped
CVE-2021-22899Ivanti Pulse Connect Secure T1078 Mapped
CVE-2021-22900Ivanti Pulse Connect Secure T1059 T1068 Mapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management T1059 T1090 T1133 T1190 T1485 Mapped
CVE-2021-26084Atlassian Confluence Server and Data Center T1059 T1496 Mapped
CVE-2021-26085Atlassian Confluence Server T1005 T1190 Mapped
CVE-2021-26855Microsoft Exchange Server T1005 T1090 T1133 T1505.003 Mapped
CVE-2021-26857Microsoft Exchange Server T1133 T1505.003 Mapped
CVE-2021-26858Microsoft Exchange Server T1190 T1505.003 Mapped
CVE-2021-27059Microsoft Office T1203 Mapped
CVE-2021-27065Microsoft Exchange Server T1190 T1505.003 Mapped
CVE-2021-27101Accellion FTA T1005 T1059 Mapped
CVE-2021-27102Accellion FTA T1005 T1059 T1190 Mapped
CVE-2021-27103Accellion FTA T1005 T1190 Mapped
CVE-2021-27104Accellion FTA T1005 T1059 T1190 Mapped
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPN software T1190 T1505.003 Mapped
CVE-2021-28550Adobe Acrobat and Reader T1204.002 Mapped
CVE-2021-29256Arm Mali Graphics Processing Unit (GPU) T1005 T1068 T1203 Mapped
CVE-2021-30554Google Chromium WebGL T1059.007 T1203 Mapped
CVE-2021-31166Microsoft HTTP Protocol Stack T1059 T1190 Mapped
CVE-2021-31207Microsoft Exchange Server T1565 Mapped
CVE-2021-3129Laravel Ignition T1059 T1190 Mapped
CVE-2021-32030ASUS Routers T1040 T1068 T1098 Mapped
CVE-2021-33739Microsoft Windows T1068 Mapped
CVE-2021-34473Microsoft Exchange Server T1048.003 T1136 T1190 T1486 Mapped
CVE-2021-34523Microsoft Exchange Server T1190 Mapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) T1059 T1071.001 T1105 T1190 T1496 T1499 Mapped
CVE-2021-35464ForgeRock Access Management (AM) T1059 T1190 Mapped
CVE-2021-36380Sunhillo SureLine T1059.004 T1190 Mapped
CVE-2021-36934Microsoft Windows T1068 T1078 Mapped
CVE-2021-37415Zoho ManageEngine ServiceDesk Plus (SDP) T1190 Mapped
CVE-2021-37975Google Chromium V8 T1059.007 T1203 Mapped
CVE-2021-39144XStream XStream T1190 T1203 Mapped
CVE-2021-39226Grafana Labs Grafana T1190 T1485 Mapped
CVE-2021-4034Red Hat Polkit T1068 Mapped
CVE-2021-40449Microsoft Windows T1016 T1027 T1068 T1071.001 T1082 T1566 T1573.001 Mapped
CVE-2021-40539Zoho ManageEngine T1003 T1027 T1070.004 T1087.002 T1136 T1140 T1190 T1218 T1505.003 T1560.001 T1573.001 Mapped
CVE-2021-40655D-Link DIR-605 Router T1190 Mapped
CVE-2021-41379Microsoft Windows T1068 T1078 Mapped
CVE-2021-41773Apache HTTP Server T1059 T1210 Mapped
CVE-2021-42013Apache HTTP Server T1059 T1210 Mapped
CVE-2021-42237Sitecore XP T1059 Mapped
CVE-2021-42258BQE BillQuick Web Suite T1059 T1486 Mapped
CVE-2021-42321Microsoft Exchange T1059 T1078 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1003 T1027 T1070.004 T1087.002 T1136 T1140 T1190 T1218 T1505.003 T1560.001 T1573.001 Mapped
CVE-2021-44168Fortinet FortiOS T1078.003 Mapped
CVE-2021-44228Apache Log4j2 T1190 T1486 T1496 T1505.003 Mapped
CVE-2021-44515Zoho Desktop Central T1003 T1069 T1087 T1105 T1190 Mapped
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) T1190 T1195.002 Mapped
CVE-2021-45046Apache Log4j2 T1059 T1486 Mapped
CVE-2021-45382D-Link Multiple Routers T1059 T1070 T1071 T1190 T1499.002 T1543 Mapped
CVE-2022-0028Palo Alto Networks PAN-OS T1190 Mapped
CVE-2022-1040Sophos Firewall T1040 T1059 T1078 T1190 T1557 T1574 Mapped
CVE-2022-1388F5 BIG-IP T1548 Mapped
CVE-2022-20699Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 T1133 Mapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1059.004 T1190 Mapped
CVE-2022-20701Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1078 T1203 Mapped
CVE-2022-20703Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1203 Mapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers T1068 T1190 Mapped
CVE-2022-20821Cisco IOS XR T1190 Mapped
CVE-2022-21919Microsoft Windows T1068 T1078 Mapped
CVE-2022-21971Microsoft Windows T1059 T1204.001 Mapped
CVE-2022-21999Microsoft Windows T1059 T1068 T1078 T1136.001 T1211 Mapped
CVE-2022-22047Microsoft Windows T1059 T1068 T1078 Mapped
CVE-2022-22718Microsoft Windows T1068 T1078 Mapped
CVE-2022-22947VMware Spring Cloud Gateway T1059 T1190 T1486 Mapped
CVE-2022-22948VMware vCenter Server T1068 T1078 T1212 Mapped
CVE-2022-22954VMware Workspace ONE Access and Identity Manager T1505.003 Mapped
CVE-2022-22960VMware Multiple Products T1222 Mapped
CVE-2022-22963VMware Tanzu Spring Cloud T1059.007 T1190 T1505.003 Mapped
CVE-2022-22965VMware Spring Framework T1059 T1190 Mapped
CVE-2022-23131Zabbix Frontend T1059 T1078 T1190 T1548 Mapped
CVE-2022-23748Audinate Dante Discovery T1059 T1203 Mapped
CVE-2022-24086Adobe Commerce and Magento Open Source T1027 T1190 T1213 Mapped
CVE-2022-24521Microsoft Windows T1059 T1068 T1078 Mapped
CVE-2022-24682Synacor Zimbra Collaborate Suite (ZCS) T1059.007 T1204.001 Mapped
CVE-2022-26134Atlassian Confluence Server/Data Center T1190 Mapped
CVE-2022-26138Atlassian Confluence T1552.001 Mapped
CVE-2022-26258D-Link DIR-820L T1059 T1190 T1499.002 Mapped
CVE-2022-26500Veeam Backup & Replication T1036 T1048 T1059 T1078 T1190 Mapped
CVE-2022-26501Veeam Backup & Replication T1036 T1048 T1059 T1190 Mapped
CVE-2022-26904Microsoft Windows T1068 T1078 Mapped
CVE-2022-28810Zoho ManageEngine T1190 Mapped
CVE-2022-29303SolarView Compact T1059 T1496 T1505 Mapped
CVE-2022-29464WSO2 Multiple Products T1190 T1496 Mapped
CVE-2022-30190Microsoft Windows T1105 T1204.002 Mapped
CVE-2022-3038Google Chromium Network Service T1204.001 T1574 Mapped
CVE-2022-3075Google Chromium Mojo T1204.001 Mapped
CVE-2022-34713Microsoft Windows T1059 T1204.002 T1566 Mapped
CVE-2022-35405Zoho ManageEngine T1059 Mapped
CVE-2022-35914Teclib GLPI T1059 T1190 Mapped
CVE-2022-36804Atlassian Bitbucket Server and Data Center T1059 T1190 Mapped
CVE-2022-37969Microsoft Windows T1059 T1068 T1078 Mapped
CVE-2022-39197Fortra Cobalt Strike T1059 T1190 Mapped
CVE-2022-40684Fortinet Multiple Products T1098.004 T1190 Mapped
CVE-2022-41033Microsoft Windows COM+ Event System Service T1068 T1566.001 Mapped
CVE-2022-41073Microsoft Windows T1068 T1078 T1574 Mapped
CVE-2022-41082Microsoft Exchange Server T1078 T1087 T1505.003 T1567 Mapped
CVE-2022-41125Microsoft Windows T1059 T1068 T1078 Mapped
CVE-2022-41128Microsoft Windows T1070 T1203 T1566 Mapped
CVE-2022-41328Fortinet FortiOS T1037 T1565.001 T1574 Mapped
CVE-2022-42475Fortinet FortiOS T1071.001 T1190 T1574 T1622 Mapped
CVE-2022-42948Fortra Cobalt Strike T1059 T1190 Mapped
CVE-2022-43769Hitachi Vantara Pentaho Business Analytics (BA) Server T1059 T1203 Mapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) Server T1059 T1190 Mapped
CVE-2022-47966Zoho ManageEngine T1068 T1136.001 T1190 Mapped
CVE-2023-0386Linux Kernel T1543 T1548.001 Stale
CVE-2023-0669Fortra GoAnywhere MFT T1190 T1210 T1486 Mapped
CVE-2023-1389TP-Link Archer AX21 T1041 T1070 T1106 T1496 Mapped
CVE-2023-20109Cisco IOS and IOS XE T1059 T1078 T1499 Mapped
CVE-2023-20118Cisco Small Business RV Series Routers T1059 T1068 T1078 T1505.003 Mapped
CVE-2023-20198Cisco IOS XE Web UI T1136 T1190 Mapped
CVE-2023-20269Cisco Adaptive Security Appliance and Firepower Threat Defense T1078 T1133 Mapped
CVE-2023-20273Cisco Cisco IOS XE Web UI T1059 T1068 T1078 Mapped
CVE-2023-20867VMware Tools T1059 T1078 T1105 Mapped
CVE-2023-20887VMware Aria Operations for Networks T1059 T1190 Mapped
CVE-2023-2136Google Chromium Skia T1204.001 Mapped
CVE-2023-21608Adobe Acrobat and Reader T1203 T1204.002 Mapped
CVE-2023-21674Microsoft Windows T1068 T1078 Mapped
CVE-2023-21715Microsoft Office T1204.002 Mapped
CVE-2023-22515Atlassian Confluence Data Center and Server T1059 T1059.007 T1078 T1136 T1190 Mapped
CVE-2023-22518Atlassian Confluence Data Center and Server T1033 T1105 T1190 Mapped
CVE-2023-22527Atlassian Confluence Data Center and Server T1496 Mapped
CVE-2023-22952SugarCRM Multiple Products T1059 T1070.004 T1078 T1083 T1190 T1505.003 Stale
CVE-2023-23397Microsoft Office T1078 T1203 Mapped
CVE-2023-2533PaperCut NG/MF T1059 T1547 T1566.002 Mapped
CVE-2023-26359Adobe ColdFusion T1059 T1190 Mapped
CVE-2023-26360Adobe ColdFusion T1036.005 T1046 T1059.007 T1071.001 T1105 T1190 T1505.003 Mapped
CVE-2023-26369Adobe Acrobat and Reader T1203 T1204.002 Mapped
CVE-2023-27350PaperCut MF/NG T1059 T1105 T1190 Mapped
CVE-2023-27524Apache Superset T1078 T1190 Mapped
CVE-2023-27532Veeam Backup & Replication T1087 T1087.001 T1133 T1486 T1555 Mapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN T1136 T1190 T1574 Mapped
CVE-2023-28229Microsoft Windows CNG Key Isolation Service T1068 T1078 Mapped
CVE-2023-28252Microsoft Windows T1003 T1021 T1059 T1068 T1078 T1136 T1486 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1041 T1059 T1105 T1566.001 Mapped
CVE-2023-29298Adobe ColdFusion T1190 Mapped
CVE-2023-29300Adobe ColdFusion T1105 T1190 Mapped
CVE-2023-29492Novi Survey Novi Survey T1190 Mapped
CVE-2023-32315Ignite Realtime Openfire T1087.002 T1496 T1505.003 Mapped
CVE-2023-33246Apache RocketMQ T1059 T1190 Mapped
CVE-2023-33538TP-Link Multiple Routers T1059 T1068 Mapped
CVE-2023-34048VMware vCenter Server T1203 Mapped
CVE-2023-34192Synacor Zimbra Collaboration Suite (ZCS) T1055 T1059 Mapped
CVE-2023-34362Progress MOVEit Transfer T1005 T1059 T1082 T1105 T1136 T1190 T1531 Mapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) T1136 T1190 T1213 Mapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) T1059 T1190 Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway T1087.002 T1105 T1190 T1574 Mapped
CVE-2023-36844Juniper Junos OS T1190 T1203 Mapped
CVE-2023-36845Juniper Junos OS T1059 T1190 Mapped
CVE-2023-36846Juniper Junos OS T1059 T1190 Mapped
CVE-2023-36847Juniper Junos OS T1059 T1190 Mapped
CVE-2023-36851Juniper Junos OS T1059 T1190 Mapped
CVE-2023-36884Microsoft Windows T1005 T1204.002 T1486 T1489 T1566 Stale
CVE-2023-38035Ivanti Sentry T1018 T1046 T1059 T1071.001 T1105 T1190 T1496 T1571 Mapped
CVE-2023-38203Adobe ColdFusion T1105 T1190 Mapped
CVE-2023-38205Adobe ColdFusion T1190 Mapped
CVE-2023-38831RARLAB WinRAR T1005 T1041 T1053 T1059.004 T1105 T1204 T1486 Mapped
CVE-2023-38950ZKTeco BioTime T1005 T1190 Mapped
CVE-2023-39780ASUS RT-AX55 Routers T1021.004 T1059.004 T1078 T1133 Mapped
CVE-2023-40044Progress WS_FTP Server T1059 T1071.002 Mapped
CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security T1059 T1078 Mapped
CVE-2023-42793JetBrains TeamCity T1190 Mapped
CVE-2023-43770Roundcube Webmail T1059 T1082 T1189 Mapped
CVE-2023-44221SonicWall SMA100 Appliances T1059.004 T1068 T1543 T1548 Mapped
CVE-2023-44487IETF HTTP/2 T1190 T1499 Mapped
CVE-2023-46604Apache ActiveMQ T1059.004 T1190 Mapped
CVE-2023-46805Ivanti Connect Secure and Policy Secure T1078 T1190 T1505.003 T1555 Mapped
CVE-2023-47565QNAP VioStor NVR T1203 T1496 Mapped
CVE-2023-48365Qlik Sense T1059 T1133 T1190 Mapped
CVE-2023-48788Fortinet FortiClient EMS T1059 T1105 T1190 Mapped
CVE-2023-49103ownCloud ownCloud graphapi T1005 T1190 T1552 Mapped
CVE-2023-4966Citrix NetScaler ADC and NetScaler Gateway T1005 T1574 Mapped
CVE-2023-49897FXC AE1021, AE1021PE T1203 T1496 Mapped
CVE-2023-5217Google Chromium libvpx T1204.001 T1574 Mapped
CVE-2023-5631Roundcube Webmail T1041 T1059.007 T1204.001 Mapped
CVE-2023-6548Citrix NetScaler ADC and NetScaler Gateway T1055 Mapped
CVE-2023-6549Citrix NetScaler ADC and NetScaler Gateway T1499 T1574 Mapped
CVE-2023-7024Google Chromium WebRTC T1189 T1574 Mapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcel T1059 T1105 T1190 Mapped
CVE-2024-0769D-Link DIR-859 Router T1005 T1190 Mapped
CVE-2024-11120GeoVision Multiple Devices T1133 T1203 Mapped
CVE-2024-11182MDaemon Email Server T1059 T1566 T1567 Mapped
CVE-2024-12686BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) T1059 T1068 Mapped
CVE-2024-12987DrayTek Vigor Routers T1059 T1068 Mapped
CVE-2024-13159Ivanti Endpoint Manager (EPM) T1087 T1190 T1558 Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM) T1087 T1190 T1558 Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM) T1087 T1190 T1558 Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 T1190 T1653 Mapped
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) T1037 T1059 T1078 Mapped
CVE-2024-20399Cisco NX-OS T1059 T1078 Mapped
CVE-2024-20439Cisco Smart Licensing Utility T1106 T1552 Mapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) T1059 T1190 Mapped
CVE-2024-21413Microsoft Office Outlook T1059 T1566.002 Mapped
CVE-2024-21762Fortinet FortiOS T1190 T1574 Mapped
CVE-2024-21887Ivanti Connect Secure and Policy Secure T1059 T1190 T1505.003 T1552 Mapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons T1078 T1190 T1505.003 T1555 Mapped
CVE-2024-23692Rejetto HTTP File Server T1005 T1082 T1105 T1496 Mapped
CVE-2024-24919Check Point Quantum Security Gateways T1005 T1059.004 Mapped
CVE-2024-26169Microsoft Windows T1059 T1203 Mapped
CVE-2024-27198JetBrains TeamCity T1059 T1190 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1041 T1059.004 T1114 T1566.002 Mapped
CVE-2024-29059Microsoft .NET Framework T1059 T1068 Mapped
CVE-2024-30051Microsoft DWM Core Library T1068 Mapped
CVE-2024-34102Adobe Commerce and Magento Open Source T1005 T1059 T1190 Mapped
CVE-2024-37085VMware ESXi T1068 T1078 Mapped
CVE-2024-38080Microsoft Windows T1068 T1204.002 Mapped
CVE-2024-38112Microsoft Windows T1189 T1204.001 Mapped
CVE-2024-38475Apache HTTP Server T1005 T1059 T1190 Mapped
CVE-2024-40890Zyxel DSL CPE Devices T1011 T1055 Mapped
CVE-2024-40891Zyxel DSL CPE Devices T1011 T1055 Mapped
CVE-2024-41710Mitel SIP Phones T1059 T1068 Mapped
CVE-2024-41713Mitel MiCollab T1005 T1068 Mapped
CVE-2024-42009Roundcube Webmail T1056 T1114 T1566.002 Mapped
CVE-2024-4358Progress Telerik Report Server T1190 Mapped
CVE-2024-45195Apache OFBiz T1059 T1133 T1203 T1498.001 Mapped
CVE-2024-4577PHP Group PHP T1003 T1033 T1041 T1053 T1059 T1068 T1071.001 T1190 T1543 T1570 Mapped
CVE-2024-4671Google Chromium T1059 T1189 Mapped
CVE-2024-4761Google Chromium V8 T1059 Mapped
CVE-2024-48248NAKIVO Backup and Replication T1003 T1005 T1190 Mapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 T1059 T1190 Mapped
CVE-2024-4885Progress WhatsUp Gold T1059 T1068 Mapped
CVE-2024-49035Microsoft Partner Center T1068 T1195 Mapped
CVE-2024-4947Google Chromium V8 T1059 T1189 Mapped
CVE-2024-4978Justice AV Solutions Viewer T1005 T1071.001 T1105 T1195.002 Mapped
CVE-2024-50302Linux Kernel T1005 T1011 Mapped
CVE-2024-50603Aviatrix Controllers T1055 T1059 Mapped
CVE-2024-5217ServiceNow Utah, Vancouver, and Washington DC Now Platform T1005 T1059 Mapped
CVE-2024-5274Google Chromium V8 T1189 T1203 Mapped
CVE-2024-53104Linux Kernel T1059 T1068 Mapped
CVE-2024-53150Linux Kernel T1005 T1011 Mapped
CVE-2024-53197Linux Kernel T1059 T1068 Mapped
CVE-2024-53704SonicWall SonicOS T1083 T1199 T1212 Mapped
CVE-2024-54085AMI MegaRAC SPx T1068 T1210 T1495 T1499 Mapped
CVE-2024-55550Mitel MiCollab T1005 T1041 T1190 Mapped
CVE-2024-55591Fortinet FortiOS and FortiProxy T1021 T1068 T1078 T1555 Mapped
CVE-2024-56145Craft CMS Craft CMS T1055 T1059 Mapped
CVE-2024-57727SimpleHelp SimpleHelp T1003 T1059 T1190 T1552.001 T1552.004 Mapped
CVE-2024-57968Advantive VeraCore T1059 T1078 Mapped
CVE-2024-58136Yiiframework Yii T1055 T1059 Mapped
CVE-2024-6047GeoVision Multiple Devices T1055 T1059 Mapped
CVE-2025-0108Palo Alto Networks PAN-OS T1055 T1190 T1565.001 Mapped
CVE-2025-0111Palo Alto Networks PAN-OS T1005 T1068 Mapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1003 T1018 T1046 T1055 T1190 Mapped
CVE-2025-04117-Zip 7-Zip T1566.001 Mapped
CVE-2025-0994Trimble Cityworks T1059 T1068 Mapped
CVE-2025-1316Edimax IC-7100 IP Camera T1055 T1190 Mapped
CVE-2025-1976Broadcom Brocade Fabric OS T1059 T1068 Mapped
CVE-2025-20281Cisco Identity Services Engine T1059 T1106 Mapped
CVE-2025-20337Cisco Identity Services Engine T1059 T1106 Mapped
CVE-2025-21333Microsoft Windows T1003 T1068 Mapped
CVE-2025-21334Microsoft Windows T1003 T1068 Mapped
CVE-2025-21335Microsoft Windows T1003 T1068 Mapped
CVE-2025-21391Microsoft Windows T1068 T1485 Mapped
CVE-2025-21418Microsoft Windows T1005 T1055 T1068 Mapped
CVE-2025-21480Qualcomm Multiple Chipsets T1055 T1495 Mapped
CVE-2025-21590Juniper Junos OS T1059 T1068 Mapped
CVE-2025-22224VMware ESXi and Workstation T1055 Mapped
CVE-2025-22225VMware ESXi T1068 Mapped
CVE-2025-22226VMware ESXi, Workstation, and Fusion T1005 Mapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA Gateways T1059 T1190 Mapped
CVE-2025-23006SonicWall SMA1000 Appliances T1059 T1190 Mapped
CVE-2025-24016Wazuh Wazuh Server T1059 T1078 T1203 Mapped
CVE-2025-24054Microsoft Windows T1555 T1566 Mapped
CVE-2025-24085Apple Multiple Products T1059 T1068 Mapped
CVE-2025-24201Apple Multiple Products T1059 T1189 Mapped
CVE-2025-24985Microsoft Windows T1059 Mapped
CVE-2025-24991Microsoft Windows T1005 Mapped
CVE-2025-24993Microsoft Windows T1055 T1068 T1203 T1204 T1565 Mapped
CVE-2025-25181Advantive VeraCore T1055 T1068 T1485 Mapped
CVE-2025-25257Fortinet FortiWeb T1055 T1059.004 T1068 T1190 T1485 Mapped
CVE-2025-27038Qualcomm Multiple Chipsets T1059 T1203 Mapped
CVE-2025-27363FreeType FreeType T1204.002 T1499.004 T1574 Mapped
CVE-2025-2783Google Chromium Mojo T1203 T1497 T1548 Mapped
CVE-2025-30397Microsoft Windows T1059 T1203 Mapped
CVE-2025-30400Microsoft Windows T1068 Mapped
CVE-2025-30406Gladinet CentreStack T1059 T1203 Mapped
CVE-2025-31161CrushFTP CrushFTP T1059 T1078 T1136 Mapped
CVE-2025-31200Apple Multiple Products T1001 T1059 T1105 T1106 T1203 T1557 Stale
CVE-2025-31201Apple Multiple Products T1001 T1059 T1105 T1106 T1203 T1557 Stale
CVE-2025-31324SAP NetWeaver T1055 T1059 T1505.003 Mapped
CVE-2025-32433Erlang Erlang/OTP T1021.004 T1059 Mapped
CVE-2025-3248Langflow Langflow T1059 T1203 Mapped
CVE-2025-32701Microsoft Windows T1059 T1068 T1543 Mapped
CVE-2025-32706Microsoft Windows T1059 T1068 T1543 Mapped
CVE-2025-32709Microsoft Windows T1003 T1059 T1068 T1543 Mapped
CVE-2025-32756Fortinet Multiple Products T1003 T1041 T1046 T1059 T1070.004 T1133 Mapped
CVE-2025-33053Microsoft Windows T1041 T1056.001 T1059 T1543 T1566.001 Mapped
CVE-2025-34028Commvault Command Center T1059.007 T1190 Mapped
CVE-2025-35939Craft CMS Craft CMS T1059 T1190 T1505.003 Mapped
CVE-2025-3928Commvault Web Server T1059 T1505.003 Mapped
CVE-2025-3935ConnectWise ScreenConnect T1059 T1203 Mapped
CVE-2025-42599Qualitia Active! Mail T1059 T1190 T1499 Mapped
CVE-2025-42999SAP NetWeaver T1059 T1190 T1203 T1505.003 Mapped
CVE-2025-43200Apple Multiple Products T1005 T1105 T1203 Mapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) T1059 T1190 T1203 T1505.003 Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) T1059 T1190 T1543 Mapped
CVE-2025-4632Samsung MagicINFO 9 Server T1059 T1068 T1496 Mapped
CVE-2025-47812Wing FTP Server Wing FTP Server T1059 T1068 Mapped
CVE-2025-48927TeleMessage TM SGNL T1005 T1212 T1555 Mapped
CVE-2025-48928TeleMessage TM SGNL T1005 T1212 T1555 Mapped
CVE-2025-49704Microsoft SharePoint T1190 Mapped
CVE-2025-49706Microsoft SharePoint T1190 T1505 Mapped
CVE-2025-53770Microsoft SharePoint T1059 T1190 Mapped
CVE-2025-5419Google Chromium V8 T1189 T1203 Mapped
CVE-2025-54309CrushFTP CrushFTP T1021 T1068 T1567 Mapped
CVE-2025-5777Citrix NetScaler ADC and Gateway T1190 T1555 Mapped
CVE-2025-6543Citrix NetScaler ADC and Gateway T1059 T1203 Mapped
CVE-2025-6554Google Chromium V8 T1059 T1189 T1203 Mapped
CVE-2025-6558Google Chromium T1189 T1203 T1497 Mapped