Log sources › macos:unifiedlog
macos:unifiedlog
Inverted view: what can be detected if this is the log you have. macOS
499
channels
350
analytics
348
techniques
419
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
*.opvault OR *.ldb OR *.kdbx |
DC0055 File Access | AN1643 | 1 |
ARP table updates inconsistent with expected gateway or DHCP lease assignments |
DC0078 Network Traffic Flow | AN1093 | 1 |
Abnormal memory operations (XOR/bitwise loops) during archive generation |
DC0020 Process Modification | AN1215 | 1 |
Abnormal process access to Safari or Chrome cookie storage |
DC0055 File Access | AN0486 | 1 |
Abnormal terminations of com.apple.security.* or 3rd-party security daemons |
DC0038 Application Log Content | AN1635 | 1 |
Access decisions to kTCCServiceCamera for unexpected binaries |
DC0021 OS API Execution | AN0570 | 1 |
Access to Keychain items or browser credential stores |
DC0067 Logon Session Creation | AN0721 | 1 |
Access to ~/Library/*/Safari or Chrome directories by non-browser processes |
DC0055 File Access | AN0039 | 1 |
Access to ~/Library/Safari/Bookmarks.plist or recent files |
DC0055 File Access | AN1184 | 1 |
Anomalous dyld dynamic library loads or RWX memory mappings in browser process |
DC0020 Process Modification | AN0500 | 1 |
Anomalous keychain access attempts targeting payment credentials |
DC0038 Application Log Content | AN1363 | 1 |
Anomalous plist modifications or sensitive file overwrites by non-standard processes |
DC0061 File Modification | AN0164 | 1 |
App/web server logs ingested via unified logging or filebeat (nginx/apache/node). |
DC0038 Application Log Content | AN0221 | 1 |
AppleScript creating login item via 'System Events' dictionary |
DC0029 Script Execution | AN0340 | 1 |
Application errors or resource contention from excessive frontend or script invocation |
DC0038 Application Log Content | AN1167 | 1 |
Association and authentication events including failures and new SSIDs |
DC0082 Network Connection Creation | AN1478 | 1 |
Attachment files written to ~/Downloads or temporary folders |
DC0039 File Creation | AN0657 | 1 |
Authentication inconsistencies where commands are executed without corresponding login events |
DC0067 Logon Session Creation | AN0218 | 1 |
Browser processes launching unexpected interpreters (osascript, bash) |
DC0032 Process Creation | AN0300 | 1 |
Calls to AuthorizationExecuteWithPrivileges() observed via Apple System Logger or security_auditing tools |
DC0021 OS API Execution | AN1111 | 1 |
Child processes of Safari, Chrome, or Firefox executing scripting interpreters |
DC0032 Process Creation | AN0994 | 1 |
Code Execution & Entitlement Access |
DC0034 Process Metadata | AN0650 | 1 |
Code signature validation fails or is absent post-binary modification |
DC0059 File Metadata | AN0607 | 1 |
Code signing verification failures or bypassed trust decisions |
DC0059 File Metadata | AN0644 | 1 |
Command line containing `trap` or `echo 'trap` written to login shell files |
DC0032 Process Creation | AN1039 | 1 |
Command line contains smbutil view //, mount_smbfs // |
DC0064 Command Execution | AN0515 | 1 |
Command line invocation of pip3, brew install, npm install from interactive Terminal |
DC0032 Process Creation | AN0700 | 1 |
Configuration profile modified or new profile installed |
DC0038 Application Log Content | AN0825 | 1 |
Connections to suspicious domains with mismatched certificate or unusual patterns |
DC0085 Network Traffic Content | AN0300 | 1 |
Crash log entries for a process receiving malformed input or known exploit patterns |
DC0038 Application Log Content | AN0852 | 1 |
Crash or abnormal termination of security agent or system extension host |
DC0034 Process Metadata | AN2040 | 1 |
Creation of .plist under /Library/Managed Preferences/ |
DC0039 File Creation | AN0252 | 1 |
Creation of .zip or .dmg files in user-accessible or temporary directories |
DC0039 File Creation | AN1460 | 1 |
Creation of .zip, .dmg, .tar.gz files in /Users, /tmp, or application directories |
DC0039 File Creation | AN0833 | 1 |
Creation of .zip, .gz, .dmg archives in /Users, /tmp, or application directories |
DC0039 File Creation | AN0749 | 1 |
Creation of LaunchAgents/LaunchDaemons in hidden or non-standard directories |
DC0039 File Creation | AN1386 | 1 |
Creation of files with anomalous headers and entropy values |
DC0039 File Creation | AN1215 | 1 |
Creation of new LaunchAgent or LoginItem plist files in ~/Library/LaunchAgents/ |
DC0059 File Metadata | AN0700 | 1 |
Creation of user account with UID <500 |
DC0013 User Account Metadata | AN1003 | 1 |
Creation or modification of browser extension .plist files |
DC0039 File Creation | AN0124 | 1 |
Creation or modification of postinstall scripts within .pkg or .mpkg contents |
DC0039 File Creation | AN0938 | 1 |
DNS query with pseudo-random subdomain patterns |
DC0085 Network Traffic Content | AN0111 | 1 |
DNS responses followed by connections to ports outside standard ranges |
DC0085 Network Traffic Content | AN0730 | 1 |
DS daemon log entries |
DC0064 Command Execution | AN0365 | 1 |
DYLD event subsystem |
DC0016 Module Load | AN0391 | 1 |
Detection of altered _VBA_PROJECT or PerformanceCache streams |
DC0059 File Metadata | AN0036 | 1 |
Device attached|enumerated VID/PID |
DC0038 Application Log Content | AN0187 | 1 |
DirectoryService queries retrieving account information |
DC0013 User Account Metadata | AN1614 | 1 |
Dylib loaded from abnormal location |
DC0016 Module Load | AN0611 | 1 |
EFI firmware integrity check failed |
DC0018 Host Status | AN1037 | 1 |
Electron app spawning unexpected child process |
DC0032 Process Creation | AN0073 | 1 |
Encrypted connection with anomalous payload entropy |
DC0085 Network Traffic Content | AN0402 | 1 |
Encrypted session initiation by unexpected binary |
DC0085 Network Traffic Content | AN0761 | 1 |
Execution of 'profiles install -type=configuration' |
DC0064 Command Execution | AN0252 | 1 |
Execution of /usr/bin/security add-trusted-cert or keychain modifications to System.keychain |
DC0064 Command Execution | AN0155 | 1 |
Execution of /usr/libexec/security_authtrampoline or child processes originating from non-trusted binaries triggering credential prompts |
DC0032 Process Creation | AN1111 | 1 |
Execution of /usr/sbin/installer spawning child process from within /private/tmp or package contents |
DC0032 Process Creation | AN0938 | 1 |
Execution of Code.app, idea, JetBrainsToolbox, eclipse with install/extension flags |
DC0032 Process Creation | AN1550 | 1 |
Execution of Java apps or other processes with hidden window attributes |
DC0032 Process Creation | AN0362 | 1 |
Execution of Python, Swift, or other binaries invoking archiving libraries |
DC0032 Process Creation | AN0749 | 1 |
Execution of Terminal, osascript, or other interpreters originating from Mail or Preview |
DC0032 Process Creation | AN0657 | 1 |
Execution of binaries with TCC protected access under unexpected parent processes such as Finder.app, SystemUIServer, or nsurlsessiond |
DC0032 Process Creation | AN1474 | 1 |
Execution of binaries with unsigned or anomalously signed certificates |
DC0032 Process Creation | AN0644 | 1 |
Execution of binary listed in newly modified LaunchAgent plist |
DC0032 Process Creation | AN0766 | 1 |
Execution of bless or nvram modifying boot parameters |
DC0032 Process Creation | AN0776 | 1 |
Execution of chflags hidden or SetFile -a V |
DC0064 Command Execution | AN0093 | 1 |
Execution of chflags hidden or setfile -a V |
DC0064 Command Execution | AN1386 | 1 |
Execution of commands like `ls -l@`, `xattr -l`, or custom tools interacting with resource forks |
DC0064 Command Execution | AN1609 | 1 |
Execution of diskutil or hdiutil attaching hidden partitions |
DC0032 Process Creation | AN1273 | 1 |
Execution of dscl . create with IsHidden=1 |
DC0064 Command Execution | AN1003 | 1 |
Execution of input detection APIs (e.g., CGEventSourceKeyState) |
DC0021 OS API Execution | AN1184 | 1 |
Execution of launchctl unload, kill, or removal of security agent daemons |
DC0032 Process Creation | AN1371 | 1 |
Execution of launchctl with setenv or bootout targeting TCC.db or AppleScript under Finder context |
DC0064 Command Execution | AN1474 | 1 |
Execution of launchctl with suspicious arguments |
DC0032 Process Creation | AN0026 | 1 |
Execution of log show, fs_usage, or cat targeting system.log |
DC0064 Command Execution | AN0707 | 1 |
Execution of older or non-standard interpreters |
DC0032 Process Creation | AN0997 | 1 |
Execution of osascript, bash, or Terminal initiated from Mail.app or Safari |
DC0032 Process Creation | AN0322 | 1 |
Execution of osascript, sh, bash, zsh, installer, open |
DC0064 Command Execution | AN2036 AN2065 | 2 |
Execution of ping, nping, or crafted network packets via bash or python to reflection services |
DC0032 Process Creation | AN1142 | 1 |
Execution of process launched via loginwindow session restore |
DC0032 Process Creation | AN0349 | 1 |
Execution of process with DYLD_INSERT_LIBRARIES set |
DC0032 Process Creation | AN0611 | 1 |
Execution of processes linked to hijacked sessions (e.g., anomalous parent-child process lineage) |
DC0032 Process Creation | AN0218 | 1 |
Execution of processes mimicking Apple Security & Privacy GUIs |
DC0032 Process Creation | AN0870 | 1 |
Execution of scp, rsync, curl with remote destination |
DC0032 Process Creation | AN0518 | 1 |
Execution of ssh or sftp without corresponding login event |
DC0032 Process Creation | AN0711 | 1 |
Execution of system_profiler or osascript invoking enumeration |
DC0032 Process Creation | AN1102 | 1 |
Execution of unexpected terminal or web scripts modifying /Library/WebServer/Documents |
DC0032 Process Creation | AN0664 | 1 |
Execution of zip, ditto, hdiutil, or openssl by non-terminal parent processes |
DC0032 Process Creation | AN1460 | 1 |
Execution of zip, ditto, hdiutil, or openssl by processes not normally associated with archiving |
DC0032 Process Creation | AN0833 | 1 |
Extension disabled, unloaded, failed to start |
DC0074 Driver Metadata | AN2040 | 1 |
File Events |
DC0039 File Creation | AN0874 | 1 |
File created in ~/Library/LaunchAgents or executable directories |
DC0039 File Creation | AN0518 | 1 |
File creation |
DC0039 File Creation | AN0653 | 1 |
File creation of unsigned binaries/scripts in user cache or download directories |
DC0039 File Creation | AN0994 | 1 |
File creation or modification with com.apple.ResourceFork extended attribute |
DC0059 File Metadata | AN1609 | 1 |
File creation or overwrite in common web-hosting folders |
DC0061 File Modification | AN0664 | 1 |
File metadata updated with UF_HIDDEN flag |
DC0059 File Metadata | AN0093 | 1 |
File modification in /etc/paths.d or user shell rc files |
DC0061 File Modification | AN0011 | 1 |
File write or append to .zshrc, .bash_profile, .zprofile, etc. |
DC0061 File Modification | AN1039 | 1 |
Firewall rule enable/disable or listen socket changes |
DC0078 Network Traffic Flow | AN1450 | 1 |
Firewall/PF anchor load or rule change events. |
DC0078 Network Traffic Flow | AN0844 | 1 |
Firmware update events or kernel extension (kext) loads not signed by Apple |
DC0004 Firmware Modification | AN0918 | 1 |
First outbound connection from the same PID/user shortly after an inbound trigger. |
DC0082 Network Connection Creation | AN0464 | 1 |
Group membership change for admin or wheel |
DC0088 Logon Session Metadata | AN1346 | 1 |
HTTP POST with encoded content in user-agent or cookie field |
DC0085 Network Traffic Content | AN0304 | 1 |
HTTPS POST requests to pastebin.com or similar |
DC0078 Network Traffic Flow | AN0789 | 1 |
HTTPS POST to known webhook URLs |
DC0078 Network Traffic Flow | AN0438 | 1 |
Hardware enumeration events via IOKit or USBMuxd showing TinyPilot or unknown keyboard/mouse |
DC0042 Drive Creation | AN0448 | 1 |
Hidden volume attachment or modification events |
DC0061 File Modification | AN1273 | 1 |
High entropy domain queries with multiple NXDOMAINs |
DC0078 Network Traffic Flow | AN1180 | 1 |
IOKit disk write calls targeting raw devices |
DC0046 Drive Modification | AN0386 | 1 |
IOKit raw disk write activity targeting physical devices |
DC0046 Drive Modification | AN0884 | 1 |
IOKit raw disk write to EFI/boot partition sectors |
DC0046 Drive Modification | AN0829 | 1 |
Inbound connections to VNC/SSH ports |
DC0082 Network Connection Creation | AN1006 | 1 |
Inbound email activity with suspicious domains or mismatched sender information |
DC0038 Application Log Content | AN0190 | 1 |
Inbound messages with attachments from suspicious domains |
DC0038 Application Log Content | AN0657 | 1 |
Invocation of SMLoginItemSetEnabled by non-system or recently installed application |
DC0021 OS API Execution | AN0340 | 1 |
Kerberos framework calls to API:{uuid} cache outside normal process lineage |
DC0055 File Access | AN0070 | 1 |
Keychain or user login post-access |
DC0067 Logon Session Creation | AN0858 | 1 |
Loading of libz.dylib, libarchive.dylib by non-standard applications |
DC0016 Module Load | AN0749 | 1 |
Login Window and Authd errors |
DC0002 User Account Authentication | AN1338 | 1 |
Login failure / authorization denied |
DC0002 User Account Authentication | AN1264 | 1 |
Login success without MFA step |
DC0002 User Account Authentication | AN0547 | 1 |
LoginWindow context with associated PID linked to reopened plist paths |
DC0088 Logon Session Metadata | AN0349 | 1 |
Logs from unifiedlogging that show browser crashes, plugin enumerations, extension installs or errors around the same time as suspicious network fetches |
DC0038 Application Log Content | AN0500 | 1 |
Mach-O binary modified or LC_LOAD_DYLIB segment inserted |
DC0061 File Modification | AN0607 | 1 |
Mail or AppleScript subsystem |
DC0038 Application Log Content | AN1311 | 1 |
Mail.app executing with parameters updating rules state |
DC0032 Process Creation | AN0552 | 1 |
Mail.app or third-party clients sending messages with mismatched From headers |
DC0038 Application Log Content | AN0794 | 1 |
Modification of /Library/Preferences/com.apple.loginwindow plist |
DC0061 File Modification | AN1003 | 1 |
Modification of /Library/Security/SecurityAgentPlugins |
DC0061 File Modification | AN0547 | 1 |
Modification of /System/Library/CoreServices/boot.efi |
DC0061 File Modification | AN0776 | 1 |
Modification of LaunchAgents or LaunchDaemons plist files |
DC0061 File Modification | AN0780 | 1 |
Modification of backgrounditems.btm or creation of LoginItems subdirectory in .app bundle |
DC0061 File Modification | AN0340 | 1 |
Modification of plist with apple.awt.UIElement set to TRUE |
DC0061 File Modification | AN0362 | 1 |
Modification of system configuration profiles affecting security tools |
DC0041 Service Metadata | AN1371 | 1 |
Modification of ~/Library/LaunchAgents or /Library/LaunchDaemons plist |
DC0061 File Modification | AN0026 | 1 |
Modification or replacement of /Library/Application Support/com.apple.TCC/TCC.db or ~/Library/Application Support/com.apple.TCC/TCC.db |
DC0061 File Modification | AN1474 | 1 |
Modifications or writes to EFI system partition for downgraded bootloaders |
DC0034 Process Metadata | AN0997 | 1 |
Modifications to Mail.app plist files controlling message rules |
DC0061 File Modification | AN0552 | 1 |
Modified application plist or binary replacement in /Applications |
DC0061 File Modification | AN0611 | 1 |
New IOUSB keyboard/HID device enumerated with suspicious attributes |
DC0042 Drive Creation | AN1569 | 1 |
New certificate trust settings added by unexpected process |
DC0059 File Metadata | AN1248 | 1 |
New files written to /var/folders, /tmp, ~/Library/Caches, or ~/Downloads by browser context or its children |
DC0039 File Creation | AN0500 | 1 |
New session initiated using cookies without normal MFA or password validation |
DC0007 Web Credential Usage | AN0486 | 1 |
New/modified launchd plist (persistence/scheduling) within TimeWindow after time query |
DC0005 Scheduled Job Metadata | AN0432 | 1 |
Non-standard processes invoking financial applications or payment APIs |
DC0032 Process Creation | AN1363 | 1 |
None |
DC0021 OS API Execution DC0032 Process Creation DC0064 Command Execution DC0082 Network Connection Creation DC0085 Network Traffic Content |
AN0206 AN0214 AN0273 AN0848 AN1231 AN1327 AN1378 AN1533 | 8 |
Observed loading of new LaunchAgent or LaunchDaemon plist |
DC0041 Service Metadata | AN0766 | 1 |
Outbound Traffic |
DC0082 Network Connection Creation | AN1296 | 1 |
Outbound UDP spikes to external reflector IPs |
DC0078 Network Traffic Flow | AN1142 | 1 |
Outbound connections from IDE processes to marketplace/tunnel domains |
DC0078 Network Traffic Flow | AN1550 | 1 |
Outgoing or incoming calls with non-standard caller IDs or unusual metadata |
DC0038 Application Log Content | AN0685 | 1 |
Persistent outbound connections with consistent periodicity |
DC0085 Network Traffic Content | AN1491 | 1 |
Persistent outbound traffic to mining domains |
DC0085 Network Traffic Content | AN0743 | 1 |
Plist modifications containing virtualization run configurations |
DC0061 File Modification | AN0911 | 1 |
Post-login execution of unrecognized child process from launchd or loginwindow |
DC0032 Process Creation | AN0340 | 1 |
Preview.app, Safari.app, or Mail.app spawning new processes outside normal patterns |
DC0032 Process Creation | AN0190 | 1 |
Process Execution |
DC0032 Process Creation | AN0365 | 1 |
Process creation events where command line = pmset with arguments affecting sleep, hibernatemode, displaysleep |
DC0032 Process Creation | AN1176 | 1 |
Process creation involving binaries interacting with resource fork data |
DC0032 Process Creation | AN1609 | 1 |
Process creation with parent PID of 1 (launchd) |
DC0032 Process Creation | AN1224 | 1 |
Process exec of remote-control apps or binaries with headless/connect flags |
DC0032 Process Creation | AN1368 | 1 |
Process execution for VBoxHeadless, prl_vm_app, vmware-vmx |
DC0032 Process Creation | AN0911 | 1 |
Process execution logs showing discovery commands like mdfind, system_profiler, or launchctl list |
DC0032 Process Creation | AN0242 | 1 |
Process execution of Microsoft Word, Excel, PowerPoint with macro execution attempts |
DC0032 Process Creation | AN0036 | 1 |
Process execution or directory service changes |
DC0010 User Account Modification | AN0867 | 1 |
Process execution path inconsistent with baseline PATH directories |
DC0032 Process Creation | AN0011 | 1 |
Process invoking SSL routines from Security framework |
DC0032 Process Creation | AN0761 | 1 |
Process invoking SecKeyCreateRandomKey or asymmetric crypto APIs |
DC0032 Process Creation | AN1498 | 1 |
Process launch |
DC0032 Process Creation | AN0784 | 1 |
Process memory maps new dylib (dylib_load event) |
DC0016 Module Load | AN0607 | 1 |
Process opening SSH_AUTH_SOCK or /tmp/ssh-* socket not owned by same UID |
DC0034 Process Metadata | AN0711 | 1 |
Process start of Java or native DB client tools |
DC0032 Process Creation | AN0678 | 1 |
Process using AES/RC4 routines unexpectedly |
DC0032 Process Creation | AN0402 | 1 |
Process wrote large .mov/.mp4 in user temp/hidden dirs |
DC0039 File Creation | AN0570 | 1 |
Rapid domain-to-IP resolution changes for same domain |
DC0078 Network Traffic Flow | AN1333 | 1 |
Rapid incoming TLS handshakes or HTTP requests in quick succession |
DC0085 Network Traffic Content | AN0491 | 1 |
Read access to Time Machine plist files or CCC configurations in ~/Library/Preferences/ |
DC0055 File Access | AN0242 | 1 |
Received messages containing embedded links or attachments from non-enterprise services |
DC0038 Application Log Content | AN0322 | 1 |
Received messages with embedded or shortened URLs |
DC0038 Application Log Content | AN0300 | 1 |
Recent download opened or executed |
DC0055 File Access | AN2036 | 1 |
Remote login (ssh) or screen sharing authentication attempts |
DC0088 Logon Session Metadata | AN1006 | 1 |
Repeated process crashes logged by CrashReporter or system instability logs in com.apple.console |
DC0038 Application Log Content | AN0586 | 1 |
Repetitive inbound email delivery activity logged within a short time window |
DC0038 Application Log Content | AN1011 | 1 |
SPF fail OR DKIM fail OR DMARC fail OR mismatched header vs envelope domains |
DC0038 Application Log Content | AN1204 | 1 |
Script interpreter invoked by nginx/apache worker process |
DC0032 Process Creation | AN1509 | 1 |
Security framework operations including keychain access, cryptographic operations, and certificate validation |
DC0064 Command Execution | AN1307 | 1 |
SecurityAgentPlugins modification |
DC0061 File Modification | AN0289 | 1 |
Session reuse without new auth event |
DC0067 Logon Session Creation | AN0711 | 1 |
Set or unset HIST* variables in shell environment |
DC0064 Command Execution | AN1556 | 1 |
Spike in CPU or memory use from non-user-initiated processes |
DC0018 Host Status | AN0586 | 1 |
Suspicious Swift/Objective-C or scripting processes writing archive-like outputs |
DC0032 Process Creation | AN1215 | 1 |
Suspicious anomalies in transmitted data integrity during application network operations |
DC0078 Network Traffic Flow | AN0704 | 1 |
Suspicious outbound HTTPS requests to domains flagged as newly registered or untrusted after spearphishing message interaction |
DC0085 Network Traffic Content | AN0322 | 1 |
Suspicious outbound traffic from browser binary to non-standard domains |
DC0078 Network Traffic Flow | AN0252 | 1 |
System Integrity Protection (SIP) state reported as disabled |
DC0018 Host Status | AN1474 | 1 |
System process modifications altering DNS/proxy settings |
DC0032 Process Creation | AN1150 | 1 |
System shutdown or reboot requested |
DC0018 Host Status | AN1540 | 1 |
TLS connections with abnormal handshake sequence or self-signed cert |
DC0085 Network Traffic Content | AN1498 | 1 |
Terminal process killed (killall Terminal) immediately after sudoers modification |
DC0033 Process Termination | AN0143 | 1 |
Terminal/Editor processes modifying web folder |
DC0061 File Modification | AN1624 | 1 |
Termination of syspolicyd or XProtect processes |
DC0033 Process Termination | AN0888 | 0 |
Termination or disabling of XProtect, Gatekeeper, or third-party AV daemons |
DC0018 Host Status | AN0870 | 1 |
Trust validation failures or bypass attempts during notarization and code signing checks |
DC0032 Process Creation | AN0800 | 1 |
Unexpected NSXPCConnection calls by non-Apple-signed or abnormal binaries |
DC0035 Process Access | AN0948 | 1 |
Unexpected application binary modifications or altered signing status |
DC0059 File Metadata | AN1099 | 1 |
Unexpected applications generating outbound DNS queries |
DC0032 Process Creation | AN0111 | 1 |
Unexpected apps generating frequent DNS queries |
DC0032 Process Creation | AN1333 | 1 |
Unexpected apps performing repeated DNS lookups |
DC0032 Process Creation | AN1180 | 1 |
Unexpected child process of Safari or Chrome |
DC0032 Process Creation | AN0124 | 1 |
Unexpected creation or modification of stored data files in protected directories |
DC0061 File Modification | AN0557 | 1 |
Unexpected processes making network calls based on DNS-derived ports |
DC0032 Process Creation | AN0730 | 1 |
Unexpected processes registered with launchd |
DC0032 Process Creation | AN0780 | 1 |
Unsigned binary execution following SIP change |
DC0032 Process Creation | AN1447 | 1 |
Unusual Kerberos TGS-REQ without TGT or anomalous ticket lifetime |
DC0088 Logon Session Metadata | AN1445 | 1 |
Unusual Mach port registration or access attempts between unrelated processes |
DC0035 Process Access | AN1359 | 1 |
Unusual child process tree indicating attempted recovery after crash |
DC0032 Process Creation | AN0852 | 1 |
User credential prompt events without associated trusted installer package |
DC0002 User Account Authentication | AN1111 | 1 |
UserLoggedIn |
DC0067 Logon Session Creation | AN0008 | 1 |
Volume Mount + File Read |
DC0042 Drive Creation | AN0344 | 1 |
Volume Mount + Process Trace + File Read |
DC0042 Drive Creation | AN0618 | 1 |
Web server process initiating outbound TCP connections not tied to normal server traffic |
DC0085 Network Traffic Content | AN1509 | 1 |
Web service process (e.g., httpd) entering crash loop or consuming excessive CPU |
DC0018 Host Status | AN0491 | 1 |
Web sessions initiated with newly forged tokens |
DC0007 Web Credential Usage | AN0721 | 1 |
Writes of .sql/.csv/.xlsx files to user documents/downloads |
DC0039 File Creation | AN0678 | 1 |
Writes under ~/Library/Application Support/Code*/extensions or JetBrains plugins |
DC0039 File Creation | AN1550 | 1 |
XPC messages requesting privileged actions from untrusted or unsigned clients |
DC0048 Named Pipe Metadata | AN0948 | 1 |
access or unlock attempt to keychain database |
DC0021 OS API Execution | AN1112 | 1 |
access to /Volumes/SharePoint or network mount |
DC0055 File Access | AN1163 | 1 |
access to keychain database |
DC0055 File Access | AN1200 | 1 |
application logs referencing NSTimer, sleep, or launchd delays |
DC0021 OS API Execution | AN0398 | 1 |
audio APIs |
DC0021 OS API Execution | AN0621 | 1 |
auth |
DC0002 User Account Authentication | AN1278 | 1 |
authd |
DC0002 User Account Authentication | AN1523 | 1 |
authd generating multiple MFA token requests |
DC0088 Logon Session Metadata | AN0454 | 1 |
authentication |
DC0067 Logon Session Creation | AN0506 | 1 |
authentication plugin load or modification events |
DC0067 Logon Session Creation | AN1251 | 1 |
authorization execute privilege requests |
DC0021 OS API Execution | AN0977 | 1 |
background process persists beyond user logout |
DC0032 Process Creation | AN0183 | 1 |
base64 -d or osascript invoked on staged file |
DC0064 Command Execution | AN0769 | 1 |
base64 or curl processes chained within short execution window |
DC0064 Command Execution | AN0304 | 1 |
binary modified or replaced |
DC0061 File Modification | AN0951 | 1 |
boot failure events or SMC validation errors |
DC0004 Firmware Modification | AN0476 | 1 |
chmod command with arguments including '+s', 'u+s', or numeric values 4000–6777 |
DC0064 Command Execution | AN0308 | 1 |
code signature/memory protection |
DC0034 Process Metadata | AN0921 | 1 |
com.apple.accountsd, com.apple.opendirectoryd |
DC0010 User Account Modification | AN0267 | 1 |
com.apple.diskarbitration |
DC0042 Drive Creation | AN0249 | 1 |
com.apple.firmwareupdater activity or update-firmware binary invoked |
DC0032 Process Creation | AN0476 | 1 |
com.apple.mail.* exec.* |
DC0032 Process Creation | AN0149 | 1 |
com.apple.network |
DC0078 Network Traffic Flow | AN0598 AN1256 | 2 |
com.apple.securityd, com.apple.tccd |
DC0021 OS API Execution | AN0689 | 1 |
command execution triggered by emond (e.g., shell, curl, python) |
DC0064 Command Execution | AN1534 | 1 |
command includes dscl . delete or sysadminctl --deleteUser |
DC0064 Command Execution | AN0336 | 1 |
connection attempts |
DC0082 Network Connection Creation | AN0032 | 1 |
connection open |
DC0082 Network Connection Creation | AN0167 | 1 |
create/modify dylib files in monitored directories |
DC0039 File Creation | AN0435 | 1 |
create/modify dylib in monitored directories |
DC0061 File Modification | AN1210 | 1 |
create: New files in /tmp or ~/Library/Application Support/* with executable or script extensions |
DC0039 File Creation | AN0964 | 1 |
creation of ~/.vscode-cli/code_tunnel.json |
DC0039 File Creation | AN0377 | 1 |
creation or loading of new launchd services |
DC0060 Service Creation | AN0736 | 1 |
csrutil disable |
DC0064 Command Execution | AN1447 | 1 |
curl|osascript.*open location |
DC0085 Network Traffic Content | AN0149 | 1 |
defaults read -g AppleLocale or systemsetup -gettimezone |
DC0064 Command Execution | AN1563 | 1 |
defaults read -g AppleLocale, systemsetup -gettimezone |
DC0064 Command Execution | AN0121 | 1 |
defaults write com.apple.system.logging or logd manipulation |
DC0064 Command Execution | AN0669 | 0 |
delay/sleep library usage in user context |
DC0016 Module Load | AN1050 | 1 |
diskutil eraseDisk / asr restore with destructive flags |
DC0064 Command Execution | AN0386 | 1 |
diskutil eraseDisk/zeroDisk or asr restore with destructive flags |
DC0064 Command Execution | AN0884 | 1 |
diskutil partitionDisk or eraseVolume with partition scheme modifications |
DC0064 Command Execution | AN0829 | 1 |
dns-sd, mDNSResponder, socket activity |
DC0085 Network Traffic Content | AN1059 | 1 |
dscl -create |
DC0064 Command Execution | AN1237 | 1 |
dscl . -create |
DC0064 Command Execution | AN1606 | 1 |
dsconfigad or dscl with create or append options for AD-bound users |
DC0064 Command Execution | AN0008 | 1 |
dyld/unified log entries indicating image load from non-system paths |
DC0016 Module Load | AN0054 | 1 |
dynamic loading of sleep-related functions or sandbox detection libraries |
DC0016 Module Load | AN0129 | 1 |
encrypted outbound traffic carrying unexpected application data |
DC0085 Network Traffic Content | AN1485 | 1 |
eventMessage = 'open', 'sendto', 'connect' |
DC0085 Network Traffic Content | AN0990 | 1 |
eventMessage = 'promiscuous' |
DC0085 Network Traffic Content | AN0877 | 1 |
eventMessage CONTAINS 'screensharingd' or 'AuthorizationRefCreate' |
DC0067 Logon Session Creation | AN0752 | 1 |
exec /usr/bin/pwpolicy |
DC0032 Process Creation | AN0457 | 1 |
exec events where web process starts a shell/tooling |
DC0032 Process Creation | AN0221 | 1 |
exec logs |
DC0032 Process Creation | AN0042 AN0196 AN0726 AN1545 AN2032 | 5 |
exec of binary with setuid/setgid and EUID != UID |
DC0034 Process Metadata | AN0308 | 1 |
exec of osascript, bash, curl with suspicious parameters |
DC0032 Process Creation | AN0228 | 1 |
exec or spawn calls to proxy tools or torrent clients |
DC0032 Process Creation | AN0082 | 1 |
exec or spawn of 'system_profiler', 'ioreg', 'kextstat', 'sysctl', or calls to sysctl API |
DC0032 Process Creation | AN0480 | 1 |
exec or sudo usage with NOPASSWD context or echo modifying sudoers |
DC0064 Command Execution | AN0143 | 1 |
exec rm -rf|dd if=/dev|srm|file unlink |
DC0040 File Deletion | AN0413 | 1 |
exec srm|exec openssl|exec gpg |
DC0032 Process Creation | AN0604 | 1 |
exec: Execution of /sbin/pfctl, /usr/libexec/ApplicationFirewall/socketfilterfw, ifconfig, tcpdump, npcap/libpcap consumers |
DC0032 Process Creation | AN1450 | 1 |
exec: Execution of defaults, plutil, or common editors (vim/nano) targeting plist files |
DC0032 Process Creation | AN0306 | 1 |
exec: Execution of kextstat, kextfind, or ioreg targeting driver information |
DC0032 Process Creation | AN1597 | 1 |
exec: Execution of pfctl, socketfilterfw, launchctl start ssh/telnet, libpcap consumers. |
DC0032 Process Creation | AN0844 | 1 |
exec: Invocation of /usr/bin/defaults write or /usr/bin/plutil modifying plist keys |
DC0064 Command Execution | AN0306 | 1 |
exec: ParentImage in (Terminal, iTerm2) AND Image in (/bin/zsh,/bin/bash,/usr/bin/python*) AND CommandLine matches '(curl|wget).*(\||\|\s*sh|bash)|base64 -D|python -c' |
DC0032 Process Creation | AN0964 | 1 |
execution of 'security', 'cat', or 'grep' commands accessing credential storage |
DC0064 Command Execution | AN1155 | 1 |
execution of /sbin/emond with child processes launched |
DC0032 Process Creation | AN1534 | 1 |
execution of Office binaries with network activity |
DC0032 Process Creation | AN1513 | 1 |
execution of curl, git, or Office processes with network connections |
DC0032 Process Creation | AN0897 | 1 |
execution of curl, osascript, or unexpected Office processes |
DC0032 Process Creation | AN0789 | 1 |
execution of curl, rclone, or Office apps invoking network sessions |
DC0032 Process Creation | AN1573 | 1 |
execution of launchctl load/unload/start commands |
DC0064 Command Execution | AN0736 | 1 |
execution of memory inspection tools (lldb, gdb, osqueryi) |
DC0032 Process Creation | AN0156 | 1 |
execution of modified binary without valid signature |
DC0032 Process Creation | AN0951 | 1 |
execution of osascript, curl, or unexpected automation |
DC0032 Process Creation | AN0438 | 1 |
execution of process with DYLD_INSERT_LIBRARIES set |
DC0032 Process Creation | AN1210 | 1 |
execution of security or osascript |
DC0032 Process Creation | AN1112 AN1200 | 2 |
execution of security, sqlite3, or unauthorized binaries |
DC0032 Process Creation | AN0107 | 1 |
execution of security-agent detection or enumeration commands |
DC0064 Command Execution | AN0050 | 1 |
execution of system_profiler, ioreg, kextstat with argument patterns related to VM/sandbox checks |
DC0032 Process Creation | AN0129 | 1 |
execve or dylib load from memory without backing file |
DC0032 Process Creation | AN0840 | 1 |
execve: Helper tools invoked through XPC executing unexpected binaries |
DC0032 Process Creation | AN0948 | 1 |
extended attribute write or modification |
DC0059 File Metadata | AN1136 | 1 |
file create or modify in /etc/emond.d/rules or /private/var/db/emondClients |
DC0039 File Creation | AN1534 | 1 |
file creation in AV exclusion directories |
DC0039 File Creation | AN0141 | 1 |
file encrypted|new file with .encrypted extension|disk write burst |
DC0061 File Modification | AN0604 | 1 |
file events |
DC0039 File Creation DC0055 File Access |
AN0042 AN0196 AN0726 | 3 |
file read of sensitive directories |
DC0055 File Access | AN0438 AN0789 AN1573 | 3 |
file write |
DC0039 File Creation | AN0057 | 1 |
file write/create |
DC0039 File Creation | AN0167 | 1 |
file writes |
DC0061 File Modification | AN1300 | 1 |
filesystem and process events |
DC0055 File Access | AN1147 | 1 |
filesystem events |
DC0059 File Metadata | AN0784 | 1 |
flock|NSDistributedLock|FileHandle.*lockForWriting |
DC0021 OS API Execution | AN0374 | 1 |
forwarded encrypted traffic |
DC0078 Network Traffic Flow | AN1022 | 1 |
g_CiOptions modification or SIP state change |
DC0063 Windows Registry Key Modification | AN1447 | 1 |
grep/cat on files matching credential patterns |
DC0064 Command Execution | AN0858 | 1 |
httpd spawning bash, zsh, python, or osascript |
DC0032 Process Creation | AN1110 | 1 |
installer or system_installd 'PackageKit: install succeeded/failed' with non-notarized or unknown signer |
DC0059 File Metadata | AN1482 | 1 |
kextload execution from Terminal or suspicious paths |
DC0064 Command Execution | AN1244 | 1 |
launch and dylib load |
DC0016 Module Load | AN1467 | 1 |
launch of Terminal.app or shell with non-standard environment setup |
DC0032 Process Creation | AN0060 | 1 |
launch of bash/zsh/python/osascript targeting key file locations |
DC0032 Process Creation | AN1518 | 1 |
launch of remote desktop app or helper binary |
DC0032 Process Creation | AN0716 | 1 |
launchctl activity and process creation |
DC0032 Process Creation | AN0743 | 1 |
launchctl disable or bootout calls |
DC0041 Service Metadata | AN0063 | 1 |
launchctl load or boot-time plist registration |
DC0064 Command Execution | AN1208 | 1 |
launchctl load/unload or plist file modification |
DC0064 Command Execution | AN1577 | 1 |
launchctl spawning new processes |
DC0032 Process Creation | AN0736 | 1 |
launchctl unload, kill, or pkill commands affecting daemons or background services |
DC0064 Command Execution | AN0047 | 1 |
launchd loading new LaunchDaemon or changes to existing daemon configuration |
DC0060 Service Creation | AN1126 | 1 |
launchd or cron spawning mining binaries |
DC0032 Process Creation | AN1491 | 1 |
launchd or osascript spawns process with delay command |
DC0032 Process Creation | AN1050 | 1 |
launchd services binding to non-standard ports |
DC0032 Process Creation | AN0635 | 1 |
launchd spawning processes tied to new or modified LaunchDaemon .plist entries |
DC0032 Process Creation | AN1126 | 1 |
launchservices events for misleading extensions |
DC0032 Process Creation | AN0632 | 1 |
launchservices or loginwindow events |
DC0032 Process Creation | AN1197 | 1 |
loading of unexpected dylibs compared to historical baselines |
DC0016 Module Load | AN1210 | 1 |
log |
DC0029 Script Execution | AN0313 | 1 |
log collect --predicate |
DC0032 Process Creation | AN1042 | 1 |
log collect from launchd and process start |
DC0034 Process Metadata | AN0985 | 1 |
log messages related to disk enumeration context or Terminal session |
DC0064 Command Execution | AN0538 | 1 |
log show --predicate 'eventMessage contains "Authentication"' |
DC0002 User Account Authentication | AN0592 | 1 |
log show --predicate 'process == <utility>' |
DC0064 Command Execution | AN1454 | 1 |
log stream |
DC0064 Command Execution | AN0115 AN0239 AN0280 AN0739 AN1218 AN1227 | 6 |
log stream 'eventMessage contains "dns_request"' |
DC0078 Network Traffic Flow | AN1123 | 1 |
log stream 'eventMessage contains pubsub or broker' |
DC0032 Process Creation | AN0004 | 1 |
log stream (subsystem: com.apple.system.networking) |
DC0085 Network Traffic Content | AN0369 | 1 |
log stream - file provider subsystem |
DC0055 File Access | AN1415 | 1 |
log stream - file subsystem |
DC0055 File Access | AN0425 | 1 |
log stream --info --predicate 'eventMessage CONTAINS "exec"' |
DC0032 Process Creation | AN1430 | 1 |
log stream --info --predicate 'subsystem == "com.apple.cfprefsd"' |
DC0032 Process Creation | AN0102 | 1 |
log stream --predicate |
DC0064 Command Execution | AN0077 AN1171 AN1590 AN1628 | 4 |
log stream --predicate 'eventMessage contains "USBMSC"' |
DC0042 Drive Creation | AN1412 | 1 |
log stream --predicate 'eventMessage contains "exec"' |
DC0032 Process Creation | AN1082 | 1 |
log stream --predicate 'eventMessage contains "loginwindow" or "pfctl"' |
DC0064 Command Execution | AN0135 | 1 |
log stream --predicate 'eventMessage contains "python"' |
DC0029 Script Execution | AN0173 | 1 |
log stream --predicate 'eventMessage contains "wscript" OR "vbs"' |
DC0029 Script Execution | AN0210 | 1 |
log stream --predicate 'processImagePath CONTAINS "curl" OR "osascript"' |
DC0032 Process Creation | AN0381 | 1 |
log stream --predicate 'processImagePath contains "zip" OR "base64"' |
DC0064 Command Execution | AN1066 | 1 |
log stream cleared or truncated |
DC0038 Application Log Content | AN0522 | 1 |
log stream network activity |
DC0082 Network Connection Creation | AN1391 | 1 |
log stream process subsystem |
DC0032 Process Creation | AN1391 | 1 |
log stream with predicate 'eventMessage CONTAINS "osascript"' |
DC0029 Script Execution | AN0734 | 1 |
logMessage contains pbpaste or osascript |
DC0032 Process Creation | AN0533 | 1 |
logd:file write |
DC0039 File Creation | AN0601 | 1 |
loginwindow or desktopservices modified settings or files |
DC0061 File Modification | AN0231 | 1 |
loginwindow or sshd |
DC0088 Logon Session Metadata | AN1139 | 1 |
loginwindow or sshd events with external IP |
DC0088 Logon Session Metadata | AN1624 | 1 |
loginwindow or sshd successful login events |
DC0067 Logon Session Creation | AN1346 | 1 |
loginwindow or tccd-related entries |
DC0032 Process Creation | AN0682 | 1 |
loginwindow, sshd |
DC0088 Logon Session Metadata | AN1545 | 1 |
looking for file access to scripts with abnormal encoding patterns |
DC0055 File Access | AN2065 | 1 |
memory mapping |
DC0020 Process Modification | AN0239 | 1 |
modification to /var/db/dslocal/nodes/Default/users/ |
DC0061 File Modification | AN1237 AN1606 | 2 |
mounted|appeared|DA: disk* attached |
DC0042 Drive Creation | AN0187 | 1 |
network |
DC0082 Network Connection Creation | AN1115 | 1 |
network connection events |
DC0082 Network Connection Creation | AN0333 AN2032 | 2 |
network flow |
DC0085 Network Traffic Content | AN0146 | 1 |
network sessions initiated by remote desktop apps |
DC0082 Network Connection Creation | AN0716 | 1 |
network stack resource exhaustion, tcp_accept queue overflow, repeated resets |
DC0018 Host Status | AN1014 | 1 |
network, socket, and http logs |
DC0085 Network Traffic Content | AN0566 | 1 |
networkd or com.apple.network |
DC0078 Network Traffic Flow | AN1120 | 1 |
networkd or socket |
DC0082 Network Connection Creation | AN1383 | 1 |
new DHCP configuration with anomalous DNS or router values |
DC0038 Application Log Content | AN1292 | 1 |
nohup, disown, or osascript execution patterns |
DC0064 Command Execution | AN0183 | 1 |
non-shell process tree accessing bash history |
DC0034 Process Metadata | AN1086 | 1 |
open URL|clicked link|LSQuarantineAttach |
DC0085 Network Traffic Content | AN0180 | 1 |
open/read access to private key files (id_rsa, *.pem, *.p12) |
DC0055 File Access | AN1518 | 1 |
open/read of *.plist or .env files |
DC0055 File Access | AN0858 | 1 |
open: Access to /var/log/system.log or related security event logs |
DC0055 File Access | AN0707 | 1 |
opendirectoryd crashes or abnormal authentication errors |
DC0038 Application Log Content | AN0495 | 1 |
opened document|clicked link|EXC_BAD_ACCESS|abort|LSQuarantine |
DC0038 Application Log Content | AN1316 | 1 |
osascript or AppleScript invocation modifying UI |
DC0029 Script Execution | AN0231 | 1 |
osascript, AppleScript, or Python execution triggered immediately after HID connection |
DC0029 Script Execution | AN1569 | 1 |
outbound HTTPS connections to cloud storage APIs |
DC0085 Network Traffic Content | AN1573 | 1 |
outbound HTTPS connections to code repository APIs |
DC0085 Network Traffic Content | AN0897 | 1 |
outbound TCP/UDP traffic over unexpected port |
DC0078 Network Traffic Flow | AN0635 | 1 |
outbound TLS connections to cloud storage providers |
DC0085 Network Traffic Content | AN1513 | 1 |
pfctl -d, socketfilterfw --setglobalstate off, or modifications to com.apple.alf |
DC0064 Command Execution | AN0408 | 1 |
pkginstalld/softwareupdated/Homebrew install transactions |
DC0059 File Metadata | AN0864 | 1 |
process |
DC0032 Process Creation DC0034 Process Metadata |
AN0146 AN0357 AN0394 AN0468 AN0561 AN0966 AN1017 AN1282 AN1439 AN1585 | 10 |
process 'crashed'|'EXC_BAD_ACCESS' for sshd, screensharingd, httpd; launchd restarts of these daemons. |
DC0038 Application Log Content | AN0330 | 1 |
process + network activity |
DC0085 Network Traffic Content | AN1191 | 1 |
process + network metrics correlation for bandwidth saturation |
DC0085 Network Traffic Content | AN0082 | 1 |
process = 'ssh' OR eventMessage CONTAINS 'ssh' |
DC0085 Network Traffic Content | AN1639 | 1 |
process = 'sshd' |
DC0088 Logon Session Metadata | AN1639 | 1 |
process activity, exec events |
DC0032 Process Creation | AN1383 | 1 |
process and file events via log stream |
DC0032 Process Creation | AN0294 | 1 |
process and signing chain events |
DC0032 Process Creation | AN0625 | 1 |
process calling security find-certificate, export, or import |
DC0064 Command Execution | AN0673 | 1 |
process command line contains base64, -enc, openssl enc -base64 |
DC0032 Process Creation | AN0347 | 1 |
process crash, abort, code signing violations |
DC0038 Application Log Content | AN0799 | 1 |
process created with repeated ICMP or UDP flood behavior |
DC0032 Process Creation | AN0971 | 1 |
process event |
DC0032 Process Creation | AN1614 | 1 |
process events |
DC0032 Process Creation | AN0659 AN0813 AN1027 | 3 |
process exec |
DC0032 Process Creation | AN1355 | 1 |
process exec events of systemsetup, date, ioreg with command_line parameters indicating time discovery |
DC0032 Process Creation | AN0432 | 1 |
process execution events for chmod, chown, chflags with parameter analysis and target path examination |
DC0032 Process Creation | AN0999 | 1 |
process execution events for chmod, chown, chflags with unusual parameters or targets |
DC0032 Process Creation | AN0836 | 1 |
process execution events for discovery utilities (system_profiler, sw_vers, dscl, networksetup) with command-line parameter analysis |
DC0032 Process Creation | AN1307 | 1 |
process execution events for system discovery utilities (system_profiler, sysctl, networksetup, ioreg) with parameter analysis |
DC0032 Process Creation | AN1553 | 1 |
process execution events with dylib load activity |
DC0016 Module Load | AN0435 | 1 |
process execution of ssh with -L/-R forwarding flags |
DC0032 Process Creation | AN1485 | 1 |
process launch |
DC0032 Process Creation | AN0097 AN0260 | 2 |
process launch of diskutil or system_profiler with SPStorageDataType |
DC0032 Process Creation | AN0538 | 1 |
process logs |
DC0032 Process Creation | AN0924 | 1 |
process writes or modifies files in excluded paths |
DC0032 Process Creation | AN0141 | 1 |
process, network |
DC0085 Network Traffic Content | AN1601 | 1 |
process, socket, and DNS logs |
DC0032 Process Creation | AN1022 | 1 |
process.*exit.*code |
DC0033 Process Termination | AN0374 AN0413 | 2 |
process: at, job runner |
DC0064 Command Execution | AN0945 | 1 |
process: code or jetbrains-gateway launching with --tunnel or --remote |
DC0032 Process Creation | AN0377 | 1 |
process: crontab edits, launch of cron job |
DC0001 Scheduled Job Creation | AN0806 | 1 |
process: exec |
DC0032 Process Creation | AN0981 AN1115 | 2 |
process: exec + filewrite: ~/.ssh/authorized_keys |
DC0032 Process Creation | AN0351 | 1 |
process: spawn, exec |
DC0032 Process Creation | AN1164 | 1 |
process::exec |
DC0032 Process Creation | AN0068 | 1 |
process:exec |
DC0032 Process Creation | AN0319 | 1 |
process:exec and kext load events |
DC0032 Process Creation | AN1421 | 1 |
process:launch |
DC0032 Process Creation | AN0509 | 1 |
process:spawn |
DC0032 Process Creation | AN1072 AN1530 | 2 |
process:spawn, process:exec |
DC0064 Command Execution | AN1396 | 1 |
process_create: Process creation where parent is Safari/Google Chrome and child is script interpreter or signed-but-unusual helper binary |
DC0032 Process Creation | AN0500 | 1 |
process_exec: image in {/bin/bash,/bin/zsh,/usr/bin/osascript,/usr/bin/python*,/usr/bin/curl,/usr/bin/ssh,/usr/bin/open} AND parent in {Preview, TextEdit, Microsoft Word, Microsoft Excel, AdobeReader, Archive Utility, Finder} |
DC0032 Process Creation | AN0820 | 1 |
process_name IN ("VBoxManage", "prlctl") AND command CONTAINS ("list", "show") |
DC0032 Process Creation | AN0575 | 1 |
profiles install -type=configuration |
DC0064 Command Execution | AN0124 | 1 |
ptrace or task_for_pid |
DC0035 Process Access | AN0156 | 1 |
ptrace: Processes invoking ptrace with PTRACE_TRACEME flag |
DC0021 OS API Execution | AN1047 | 1 |
pwpolicy|PasswordPolicy |
DC0064 Command Execution | AN0457 | 1 |
quarantine or AV-related subsystem |
DC0038 Application Log Content | AN0542 | 1 |
read access to ~/Library/Keychains or history files by terminal processes |
DC0055 File Access | AN1155 | 1 |
read access to ~/Library/Keychains/login.keychain-db |
DC0055 File Access | AN1112 | 1 |
read of user document directories |
DC0055 File Access | AN0897 | 1 |
read/write of user documents prior to upload |
DC0055 File Access | AN1513 | 1 |
read: File access to /System/Library/Extensions/ or related kernel extension paths |
DC0055 File Access | AN1597 | 1 |
replace existing dylibs |
DC0061 File Modification | AN0435 | 1 |
rule definitions written to emond rule plists |
DC0061 File Modification | AN1534 | 1 |
security OR injection attempts into 1Password OR LastPass |
DC0032 Process Creation | AN1643 | 1 |
shutdown -h now or reboot |
DC0032 Process Creation | AN1540 | 1 |
softwareupdated/homebrew/install logs, pkginstalld events |
DC0059 File Metadata | AN0023 | 1 |
spctl --master-disable, csrutil disable, or defaults write to disable Gatekeeper |
DC0064 Command Execution | AN0888 | 0 |
subsystem: com.apple.WebKit or com.apple.WebKit.Networking |
DC0085 Network Traffic Content | AN1409 | 1 |
subsystem: com.apple.network |
DC0085 Network Traffic Content | AN0160 | 1 |
subsystem:com.apple.Terminal |
DC0064 Command Execution | AN0256 | 1 |
subsystem:syspolicyd |
DC0059 File Metadata | AN0090 | 1 |
subsystem=com.apple.Security or com.apple.applescript |
DC0029 Script Execution | AN1442 | 1 |
subsystem=com.apple.TCC |
DC0034 Process Metadata | AN0245 AN0284 | 2 |
subsystem=com.apple.WebKit |
DC0085 Network Traffic Content | AN1322 | 1 |
subsystem=com.apple.kextd |
DC0016 Module Load | AN1063 | 1 |
subsystem=com.apple.launchservices |
DC0041 Service Metadata | AN0326 | 1 |
subsystem=com.apple.lsd |
DC0059 File Metadata | AN1462 | 1 |
subsystem=com.apple.process |
DC0034 Process Metadata | AN0013 | 1 |
subsystem=com.apple.security, library=libsystem_kernel.dylib |
DC0035 Process Access | AN1401 | 1 |
subsystem=launchservices |
DC0029 Script Execution | AN0533 | 1 |
successful sudo or authentication for account not normally associated with admin actions |
DC0002 User Account Authentication | AN0336 | 1 |
sudden burst in outgoing packets from same PID |
DC0078 Network Traffic Flow | AN0971 | 1 |
suspicious dlopen/dlsym usage in non-development processes |
DC0016 Module Load | AN0840 | 1 |
tcp/udp |
DC0078 Network Traffic Flow | AN0639 | 1 |
vm_read, task_for_pid, or file open to cookie databases |
DC0035 Process Access | AN1404 | 1 |
write |
DC0061 File Modification | AN0766 | 1 |
write of plist files in /Library/LaunchAgents or /Library/LaunchDaemons |
DC0061 File Modification | AN0736 | 1 |
write: File modification to com.apple.PowerManagement.plist or related system preference files |
DC0061 File Modification | AN1176 | 1 |
write: File modifications to *.plist within LaunchAgents, LaunchDaemons, Application Support, or Preferences directories |
DC0061 File Modification | AN0306 | 1 |
xattr -d com.apple.quarantine or similar attribute removal commands |
DC0059 File Metadata | AN0800 | 1 |
xattr -d com.apple.quarantine or similar removal commands |
DC0064 Command Execution | AN1248 | 1 |
xattr utility execution with -w or -p flags |
DC0064 Command Execution | AN1136 | 1 |
~/Library/Application Support/Google/Chrome/*/Login Data OR ~/Library/Application Support/Firefox/*/logins.json |
DC0055 File Access | AN0107 | 1 |
Techniques detectable from this source
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2007-5659 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2008-0655 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2008-2992 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2009-1862 | Adobe Acrobat and Reader, Flash Player | T1204.002 | Mapped |
| CVE-2009-3953 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2009-3960 | Adobe BlazeDS | T1190 T1486 | Mapped |
| CVE-2009-4324 | Adobe Acrobat and Reader | T1071.001 T1204.002 | Mapped |
| CVE-2010-0188 | Adobe Reader and Acrobat | T1105 T1189 | Mapped |
| CVE-2010-1297 | Adobe Flash Player | T1105 T1189 T1204.002 | Mapped |
| CVE-2010-2861 | Adobe ColdFusion | T1105 T1119 T1190 | Mapped |
| CVE-2010-2883 | Adobe Acrobat and Reader | T1027 T1059 T1204.002 | Mapped |
| CVE-2011-0611 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2011-2462 | Adobe Reader and Acrobat | T1204.002 | Mapped |
| CVE-2012-0754 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2012-0767 | Adobe Flash Player | T1098 T1204.001 | Mapped |
| CVE-2012-1535 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2012-2034 | Adobe Flash Player | T1189 | Mapped |
| CVE-2012-5054 | Adobe Flash Player | T1189 | Mapped |
| CVE-2013-0625 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0629 | Adobe ColdFusion | T1005 T1190 | Mapped |
| CVE-2013-0631 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0632 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2013-0640 | Adobe Reader and Acrobat | T1566.001 | Mapped |
| CVE-2013-0641 | Adobe Reader | T1048 T1105 T1204.002 | Mapped |
| CVE-2013-3346 | Adobe Reader and Acrobat | T1059.007 | Mapped |
| CVE-2014-0496 | Adobe Reader and Acrobat | T1204.002 | Mapped |
| CVE-2014-0546 | Adobe Reader and Acrobat | T1068 T1497 | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | T1059.004 T1133 T1190 | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | T1059.004 T1133 T1190 | Mapped |
| CVE-2014-8439 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0310 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-0313 | Adobe Flash Player | T1189 | Mapped |
| CVE-2015-3043 | Adobe Flash Player | T1189 T1204.002 T1499.004 | Mapped |
| CVE-2015-3113 | Adobe Flash Player | T1071.001 T1204.002 T1497 T1622 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1059.007 T1071.001 T1105 T1203 T1204.001 T1566.002 | Mapped |
| CVE-2015-7645 | Adobe Flash Player | T1204.002 | Mapped |
| CVE-2015-8651 | Adobe Flash Player | T1105 T1189 T1486 | Mapped |
| CVE-2016-0984 | Adobe Flash Player and AIR | T1105 T1204.002 | Mapped |
| CVE-2016-10033 | PHP PHPMailer | T1059.004 T1190 | Mapped |
| CVE-2016-1010 | Adobe Flash Player and AIR | T1574 | Mapped |
| CVE-2016-1019 | Adobe Flash Player | T1105 T1189 T1486 | Mapped |
| CVE-2016-4117 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2016-4437 | Apache Shiro | T1059 T1190 | Mapped |
| CVE-2016-7855 | Adobe Flash Player | T1189 | Mapped |
| CVE-2017-11292 | Adobe Flash Player | T1005 T1105 T1204.002 T1566.001 | Mapped |
| CVE-2017-11882 | Microsoft Office | T1059 T1566.001 | Mapped |
| CVE-2017-12637 | SAP NetWeaver | T1083 T1190 T1555 | Mapped |
| CVE-2017-5638 | Apache Struts | T1005 T1059 T1190 | Mapped |
| CVE-2017-6742 | Cisco IOS and IOS XE Software | T1048 T1059 T1574 | Mapped |
| CVE-2017-9805 | Apache Struts | T1059 T1190 | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | T1059 T1190 T1496 | Mapped |
| CVE-2018-0296 | Cisco Adaptive Security Appliance (ASA) | T1005 | Mapped |
| CVE-2018-11776 | Apache Struts | T1059 T1190 T1496 | Mapped |
| CVE-2018-13379 | Fortinet FortiOS | T1190 | Mapped |
| CVE-2018-15961 | Adobe ColdFusion | T1190 T1491.002 | Mapped |
| CVE-2018-15982 | Adobe Flash Player | T1105 T1204.002 | Mapped |
| CVE-2018-4878 | Adobe Flash Player | T1041 T1204.002 T1219 | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | T1133 T1190 T1203 | Mapped |
| CVE-2018-4990 | Adobe Acrobat and Reader | T1059.007 T1204.002 | Mapped |
| CVE-2018-6789 | Exim Exim | T1059 T1190 | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | T1059 T1190 T1485 T1496 | Mapped |
| CVE-2019-0211 | Apache HTTP Server | T1068 | Mapped |
| CVE-2019-0604 | Microsoft SharePoint | T1003 T1041 T1190 T1505.003 | Mapped |
| CVE-2019-0708 | Microsoft Remote Desktop Services | T1059.004 T1133 | Mapped |
| CVE-2019-11510 | Ivanti Pulse Connect Secure | T1059 T1083 T1133 T1552.001 | Mapped |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center | T1059 | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | T1003 T1005 T1046 T1059 T1078 T1190 T1486 | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | T1003 T1005 T1046 T1059 T1078 | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | T1005 T1007 T1082 T1190 | Mapped |
| CVE-2019-17558 | Apache Solr | T1059 T1190 | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | T1041 T1190 T1496 T1505.003 | Mapped |
| CVE-2019-19781 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1059 T1083 T1133 | Mapped |
| CVE-2019-3396 | Atlassian Confluence Server and Data Server | T1090 T1133 | Mapped |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center | T1059 | Mapped |
| CVE-2019-5591 | Fortinet FortiOS | T1005 T1133 T1557 | Mapped |
| CVE-2020-0069 | MediaTek Multiple Chipsets | T1068 | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | T1110 T1114 T1190 T1505.003 | Mapped |
| CVE-2020-0787 | Microsoft Windows | T1059 T1068 | Mapped |
| CVE-2020-12812 | Fortinet FortiOS | T1556 | Mapped |
| CVE-2020-1472 | Microsoft Netlogon | T1021 T1068 T1087.002 T1110 T1133 T1486 | Mapped |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products | T1059 T1190 | Mapped |
| CVE-2020-17530 | Apache Struts | T1059 T1190 | Mapped |
| CVE-2020-25506 | D-Link DNS-320 Device | T1059 T1133 | Mapped |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices | T1059 T1190 | Mapped |
| CVE-2020-29574 | Sophos CyberoamOS | T1055 T1059 | Mapped |
| CVE-2020-3452 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1005 | Mapped |
| CVE-2020-3580 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1059 T1204.001 T1217 | Mapped |
| CVE-2020-5735 | Amcrest Cameras and Network Video Recorder (NVR) | T1499 T1574 | Mapped |
| CVE-2020-5902 | F5 BIG-IP | T1003 T1005 T1059 T1070.004 T1133 T1190 T1552 | Stale |
| CVE-2020-8193 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 T1556 | Mapped |
| CVE-2020-8195 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 T1056 T1082 | Mapped |
| CVE-2020-8196 | Citrix Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | T1005 T1056 T1082 | Mapped |
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | T1059 T1133 T1496 | Mapped |
| CVE-2020-8657 | EyesOfNetwork EyesOfNetwork | T1106 | Mapped |
| CVE-2021-1497 | Cisco HyperFlex HX | T1059 T1133 | Mapped |
| CVE-2021-1498 | Cisco HyperFlex HX | T1059 T1133 | Mapped |
| CVE-2021-20035 | SonicWall SMA100 Appliances | T1059 T1078 | Mapped |
| CVE-2021-21017 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2021-21148 | Google Chromium V8 | T1059.007 T1203 | Mapped |
| CVE-2021-21166 | Google Chromium | T1059.007 T1203 | Mapped |
| CVE-2021-21206 | Google Chromium Blink | T1059.007 T1203 | Mapped |
| CVE-2021-21972 | VMware vCenter Server | T1059 T1190 | Mapped |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | T1046 T1190 | Mapped |
| CVE-2021-21975 | VMware vRealize Operations Manager API | T1190 | Mapped |
| CVE-2021-22005 | VMware vCenter Server | T1059 T1190 | Mapped |
| CVE-2021-22017 | VMware vCenter Server | T1090.001 T1190 | Mapped |
| CVE-2021-22204 | Perl Exiftool | T1059 T1190 | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | T1059 T1190 T1496 | Mapped |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | T1003 T1059 T1190 | Mapped |
| CVE-2021-22894 | Ivanti Pulse Connect Secure | T1059 T1078 | Mapped |
| CVE-2021-22899 | Ivanti Pulse Connect Secure | T1078 | Mapped |
| CVE-2021-22900 | Ivanti Pulse Connect Secure | T1059 T1068 | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | T1059 T1090 T1133 T1190 T1485 | Mapped |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center | T1059 T1496 | Mapped |
| CVE-2021-26085 | Atlassian Confluence Server | T1005 T1190 | Mapped |
| CVE-2021-26855 | Microsoft Exchange Server | T1005 T1090 T1133 T1505.003 | Mapped |
| CVE-2021-26857 | Microsoft Exchange Server | T1133 T1505.003 | Mapped |
| CVE-2021-26858 | Microsoft Exchange Server | T1190 T1505.003 | Mapped |
| CVE-2021-27059 | Microsoft Office | T1203 | Mapped |
| CVE-2021-27065 | Microsoft Exchange Server | T1190 T1505.003 | Mapped |
| CVE-2021-27101 | Accellion FTA | T1005 T1059 | Mapped |
| CVE-2021-27102 | Accellion FTA | T1005 T1059 T1190 | Mapped |
| CVE-2021-27103 | Accellion FTA | T1005 T1190 | Mapped |
| CVE-2021-27104 | Accellion FTA | T1005 T1059 T1190 | Mapped |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN software | T1190 T1505.003 | Mapped |
| CVE-2021-28550 | Adobe Acrobat and Reader | T1204.002 | Mapped |
| CVE-2021-29256 | Arm Mali Graphics Processing Unit (GPU) | T1005 T1068 T1203 | Mapped |
| CVE-2021-30554 | Google Chromium WebGL | T1059.007 T1203 | Mapped |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack | T1059 T1190 | Mapped |
| CVE-2021-31207 | Microsoft Exchange Server | T1565 | Mapped |
| CVE-2021-3129 | Laravel Ignition | T1059 T1190 | Mapped |
| CVE-2021-32030 | ASUS Routers | T1040 T1068 T1098 | Mapped |
| CVE-2021-33739 | Microsoft Windows | T1068 | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | T1048.003 T1136 T1190 T1486 | Mapped |
| CVE-2021-34523 | Microsoft Exchange Server | T1190 | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | T1059 T1071.001 T1105 T1190 T1496 T1499 | Mapped |
| CVE-2021-35464 | ForgeRock Access Management (AM) | T1059 T1190 | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | T1059.004 T1190 | Mapped |
| CVE-2021-36934 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2021-37415 | Zoho ManageEngine ServiceDesk Plus (SDP) | T1190 | Mapped |
| CVE-2021-37975 | Google Chromium V8 | T1059.007 T1203 | Mapped |
| CVE-2021-39144 | XStream XStream | T1190 T1203 | Mapped |
| CVE-2021-39226 | Grafana Labs Grafana | T1190 T1485 | Mapped |
| CVE-2021-4034 | Red Hat Polkit | T1068 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1016 T1027 T1068 T1071.001 T1082 T1566 T1573.001 | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | T1003 T1027 T1070.004 T1087.002 T1136 T1140 T1190 T1218 T1505.003 T1560.001 T1573.001 | Mapped |
| CVE-2021-40655 | D-Link DIR-605 Router | T1190 | Mapped |
| CVE-2021-41379 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2021-41773 | Apache HTTP Server | T1059 T1210 | Mapped |
| CVE-2021-42013 | Apache HTTP Server | T1059 T1210 | Mapped |
| CVE-2021-42237 | Sitecore XP | T1059 | Mapped |
| CVE-2021-42258 | BQE BillQuick Web Suite | T1059 T1486 | Mapped |
| CVE-2021-42321 | Microsoft Exchange | T1059 T1078 | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | T1003 T1027 T1070.004 T1087.002 T1136 T1140 T1190 T1218 T1505.003 T1560.001 T1573.001 | Mapped |
| CVE-2021-44168 | Fortinet FortiOS | T1078.003 | Mapped |
| CVE-2021-44228 | Apache Log4j2 | T1190 T1486 T1496 T1505.003 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | T1003 T1069 T1087 T1105 T1190 | Mapped |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | T1190 T1195.002 | Mapped |
| CVE-2021-45046 | Apache Log4j2 | T1059 T1486 | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | T1059 T1070 T1071 T1190 T1499.002 T1543 | Mapped |
| CVE-2022-0028 | Palo Alto Networks PAN-OS | T1190 | Mapped |
| CVE-2022-1040 | Sophos Firewall | T1040 T1059 T1078 T1190 T1557 T1574 | Mapped |
| CVE-2022-1388 | F5 BIG-IP | T1548 | Mapped |
| CVE-2022-20699 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 T1133 | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1059.004 T1190 | Mapped |
| CVE-2022-20701 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1078 T1203 | Mapped |
| CVE-2022-20703 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1203 | Mapped |
| CVE-2022-20708 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | T1068 T1190 | Mapped |
| CVE-2022-20821 | Cisco IOS XR | T1190 | Mapped |
| CVE-2022-21919 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2022-21971 | Microsoft Windows | T1059 T1204.001 | Mapped |
| CVE-2022-21999 | Microsoft Windows | T1059 T1068 T1078 T1136.001 T1211 | Mapped |
| CVE-2022-22047 | Microsoft Windows | T1059 T1068 T1078 | Mapped |
| CVE-2022-22718 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | T1059 T1190 T1486 | Mapped |
| CVE-2022-22948 | VMware vCenter Server | T1068 T1078 T1212 | Mapped |
| CVE-2022-22954 | VMware Workspace ONE Access and Identity Manager | T1505.003 | Mapped |
| CVE-2022-22960 | VMware Multiple Products | T1222 | Mapped |
| CVE-2022-22963 | VMware Tanzu Spring Cloud | T1059.007 T1190 T1505.003 | Mapped |
| CVE-2022-22965 | VMware Spring Framework | T1059 T1190 | Mapped |
| CVE-2022-23131 | Zabbix Frontend | T1059 T1078 T1190 T1548 | Mapped |
| CVE-2022-23748 | Audinate Dante Discovery | T1059 T1203 | Mapped |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | T1027 T1190 T1213 | Mapped |
| CVE-2022-24521 | Microsoft Windows | T1059 T1068 T1078 | Mapped |
| CVE-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) | T1059.007 T1204.001 | Mapped |
| CVE-2022-26134 | Atlassian Confluence Server/Data Center | T1190 | Mapped |
| CVE-2022-26138 | Atlassian Confluence | T1552.001 | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | T1059 T1190 T1499.002 | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | T1036 T1048 T1059 T1078 T1190 | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | T1036 T1048 T1059 T1190 | Mapped |
| CVE-2022-26904 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2022-28810 | Zoho ManageEngine | T1190 | Mapped |
| CVE-2022-29303 | SolarView Compact | T1059 T1496 T1505 | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | T1190 T1496 | Mapped |
| CVE-2022-30190 | Microsoft Windows | T1105 T1204.002 | Mapped |
| CVE-2022-3038 | Google Chromium Network Service | T1204.001 T1574 | Mapped |
| CVE-2022-3075 | Google Chromium Mojo | T1204.001 | Mapped |
| CVE-2022-34713 | Microsoft Windows | T1059 T1204.002 T1566 | Mapped |
| CVE-2022-35405 | Zoho ManageEngine | T1059 | Mapped |
| CVE-2022-35914 | Teclib GLPI | T1059 T1190 | Mapped |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center | T1059 T1190 | Mapped |
| CVE-2022-37969 | Microsoft Windows | T1059 T1068 T1078 | Mapped |
| CVE-2022-39197 | Fortra Cobalt Strike | T1059 T1190 | Mapped |
| CVE-2022-40684 | Fortinet Multiple Products | T1098.004 T1190 | Mapped |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service | T1068 T1566.001 | Mapped |
| CVE-2022-41073 | Microsoft Windows | T1068 T1078 T1574 | Mapped |
| CVE-2022-41082 | Microsoft Exchange Server | T1078 T1087 T1505.003 T1567 | Mapped |
| CVE-2022-41125 | Microsoft Windows | T1059 T1068 T1078 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1070 T1203 T1566 | Mapped |
| CVE-2022-41328 | Fortinet FortiOS | T1037 T1565.001 T1574 | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | T1071.001 T1190 T1574 T1622 | Mapped |
| CVE-2022-42948 | Fortra Cobalt Strike | T1059 T1190 | Mapped |
| CVE-2022-43769 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1059 T1203 | Mapped |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics (BA) Server | T1059 T1190 | Mapped |
| CVE-2022-47966 | Zoho ManageEngine | T1068 T1136.001 T1190 | Mapped |
| CVE-2023-0386 | Linux Kernel | T1543 T1548.001 | Stale |
| CVE-2023-0669 | Fortra GoAnywhere MFT | T1190 T1210 T1486 | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | T1041 T1070 T1106 T1496 | Mapped |
| CVE-2023-20109 | Cisco IOS and IOS XE | T1059 T1078 T1499 | Mapped |
| CVE-2023-20118 | Cisco Small Business RV Series Routers | T1059 T1068 T1078 T1505.003 | Mapped |
| CVE-2023-20198 | Cisco IOS XE Web UI | T1136 T1190 | Mapped |
| CVE-2023-20269 | Cisco Adaptive Security Appliance and Firepower Threat Defense | T1078 T1133 | Mapped |
| CVE-2023-20273 | Cisco Cisco IOS XE Web UI | T1059 T1068 T1078 | Mapped |
| CVE-2023-20867 | VMware Tools | T1059 T1078 T1105 | Mapped |
| CVE-2023-20887 | VMware Aria Operations for Networks | T1059 T1190 | Mapped |
| CVE-2023-2136 | Google Chromium Skia | T1204.001 | Mapped |
| CVE-2023-21608 | Adobe Acrobat and Reader | T1203 T1204.002 | Mapped |
| CVE-2023-21674 | Microsoft Windows | T1068 T1078 | Mapped |
| CVE-2023-21715 | Microsoft Office | T1204.002 | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | T1059 T1059.007 T1078 T1136 T1190 | Mapped |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | T1033 T1105 T1190 | Mapped |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server | T1496 | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | T1059 T1070.004 T1078 T1083 T1190 T1505.003 | Stale |
| CVE-2023-23397 | Microsoft Office | T1078 T1203 | Mapped |
| CVE-2023-2533 | PaperCut NG/MF | T1059 T1547 T1566.002 | Mapped |
| CVE-2023-26359 | Adobe ColdFusion | T1059 T1190 | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | T1036.005 T1046 T1059.007 T1071.001 T1105 T1190 T1505.003 | Mapped |
| CVE-2023-26369 | Adobe Acrobat and Reader | T1203 T1204.002 | Mapped |
| CVE-2023-27350 | PaperCut MF/NG | T1059 T1105 T1190 | Mapped |
| CVE-2023-27524 | Apache Superset | T1078 T1190 | Mapped |
| CVE-2023-27532 | Veeam Backup & Replication | T1087 T1087.001 T1133 T1486 T1555 | Mapped |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | T1136 T1190 T1574 | Mapped |
| CVE-2023-28229 | Microsoft Windows CNG Key Isolation Service | T1068 T1078 | Mapped |
| CVE-2023-28252 | Microsoft Windows | T1003 T1021 T1059 T1068 T1078 T1136 T1486 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1041 T1059 T1105 T1566.001 | Mapped |
| CVE-2023-29298 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-29300 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2023-29492 | Novi Survey Novi Survey | T1190 | Mapped |
| CVE-2023-32315 | Ignite Realtime Openfire | T1087.002 T1496 T1505.003 | Mapped |
| CVE-2023-33246 | Apache RocketMQ | T1059 T1190 | Mapped |
| CVE-2023-33538 | TP-Link Multiple Routers | T1059 T1068 | Mapped |
| CVE-2023-34048 | VMware vCenter Server | T1203 | Mapped |
| CVE-2023-34192 | Synacor Zimbra Collaboration Suite (ZCS) | T1055 T1059 | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | T1005 T1059 T1082 T1105 T1136 T1190 T1531 | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | T1136 T1190 T1213 | Mapped |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) | T1059 T1190 | Mapped |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | T1087.002 T1105 T1190 T1574 | Mapped |
| CVE-2023-36844 | Juniper Junos OS | T1190 T1203 | Mapped |
| CVE-2023-36845 | Juniper Junos OS | T1059 T1190 | Mapped |
| CVE-2023-36846 | Juniper Junos OS | T1059 T1190 | Mapped |
| CVE-2023-36847 | Juniper Junos OS | T1059 T1190 | Mapped |
| CVE-2023-36851 | Juniper Junos OS | T1059 T1190 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1005 T1204.002 T1486 T1489 T1566 | Stale |
| CVE-2023-38035 | Ivanti Sentry | T1018 T1046 T1059 T1071.001 T1105 T1190 T1496 T1571 | Mapped |
| CVE-2023-38203 | Adobe ColdFusion | T1105 T1190 | Mapped |
| CVE-2023-38205 | Adobe ColdFusion | T1190 | Mapped |
| CVE-2023-38831 | RARLAB WinRAR | T1005 T1041 T1053 T1059.004 T1105 T1204 T1486 | Mapped |
| CVE-2023-38950 | ZKTeco BioTime | T1005 T1190 | Mapped |
| CVE-2023-39780 | ASUS RT-AX55 Routers | T1021.004 T1059.004 T1078 T1133 | Mapped |
| CVE-2023-40044 | Progress WS_FTP Server | T1059 T1071.002 | Mapped |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security | T1059 T1078 | Mapped |
| CVE-2023-42793 | JetBrains TeamCity | T1190 | Mapped |
| CVE-2023-43770 | Roundcube Webmail | T1059 T1082 T1189 | Mapped |
| CVE-2023-44221 | SonicWall SMA100 Appliances | T1059.004 T1068 T1543 T1548 | Mapped |
| CVE-2023-44487 | IETF HTTP/2 | T1190 T1499 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | T1059.004 T1190 | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | T1078 T1190 T1505.003 T1555 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | T1203 T1496 | Mapped |
| CVE-2023-48365 | Qlik Sense | T1059 T1133 T1190 | Mapped |
| CVE-2023-48788 | Fortinet FortiClient EMS | T1059 T1105 T1190 | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | T1005 T1190 T1552 | Mapped |
| CVE-2023-4966 | Citrix NetScaler ADC and NetScaler Gateway | T1005 T1574 | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | T1203 T1496 | Mapped |
| CVE-2023-5217 | Google Chromium libvpx | T1204.001 T1574 | Mapped |
| CVE-2023-5631 | Roundcube Webmail | T1041 T1059.007 T1204.001 | Mapped |
| CVE-2023-6548 | Citrix NetScaler ADC and NetScaler Gateway | T1055 | Mapped |
| CVE-2023-6549 | Citrix NetScaler ADC and NetScaler Gateway | T1499 T1574 | Mapped |
| CVE-2023-7024 | Google Chromium WebRTC | T1189 T1574 | Mapped |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | T1059 T1105 T1190 | Mapped |
| CVE-2024-0769 | D-Link DIR-859 Router | T1005 T1190 | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | T1133 T1203 | Mapped |
| CVE-2024-11182 | MDaemon Email Server | T1059 T1566 T1567 | Mapped |
| CVE-2024-12686 | BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) | T1059 T1068 | Mapped |
| CVE-2024-12987 | DrayTek Vigor Routers | T1059 T1068 | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | T1087 T1190 T1558 | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | T1087 T1190 T1558 | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | T1087 T1190 T1558 | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 T1190 T1653 | Mapped |
| CVE-2024-20359 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | T1037 T1059 T1078 | Mapped |
| CVE-2024-20399 | Cisco NX-OS | T1059 T1078 | Mapped |
| CVE-2024-20439 | Cisco Smart Licensing Utility | T1106 T1552 | Mapped |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) | T1059 T1190 | Mapped |
| CVE-2024-21413 | Microsoft Office Outlook | T1059 T1566.002 | Mapped |
| CVE-2024-21762 | Fortinet FortiOS | T1190 T1574 | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | T1059 T1190 T1505.003 T1552 | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | T1078 T1190 T1505.003 T1555 | Mapped |
| CVE-2024-23692 | Rejetto HTTP File Server | T1005 T1082 T1105 T1496 | Mapped |
| CVE-2024-24919 | Check Point Quantum Security Gateways | T1005 T1059.004 | Mapped |
| CVE-2024-26169 | Microsoft Windows | T1059 T1203 | Mapped |
| CVE-2024-27198 | JetBrains TeamCity | T1059 T1190 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1041 T1059.004 T1114 T1566.002 | Mapped |
| CVE-2024-29059 | Microsoft .NET Framework | T1059 T1068 | Mapped |
| CVE-2024-30051 | Microsoft DWM Core Library | T1068 | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | T1005 T1059 T1190 | Mapped |
| CVE-2024-37085 | VMware ESXi | T1068 T1078 | Mapped |
| CVE-2024-38080 | Microsoft Windows | T1068 T1204.002 | Mapped |
| CVE-2024-38112 | Microsoft Windows | T1189 T1204.001 | Mapped |
| CVE-2024-38475 | Apache HTTP Server | T1005 T1059 T1190 | Mapped |
| CVE-2024-40890 | Zyxel DSL CPE Devices | T1011 T1055 | Mapped |
| CVE-2024-40891 | Zyxel DSL CPE Devices | T1011 T1055 | Mapped |
| CVE-2024-41710 | Mitel SIP Phones | T1059 T1068 | Mapped |
| CVE-2024-41713 | Mitel MiCollab | T1005 T1068 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1056 T1114 T1566.002 | Mapped |
| CVE-2024-4358 | Progress Telerik Report Server | T1190 | Mapped |
| CVE-2024-45195 | Apache OFBiz | T1059 T1133 T1203 T1498.001 | Mapped |
| CVE-2024-4577 | PHP Group PHP | T1003 T1033 T1041 T1053 T1059 T1068 T1071.001 T1190 T1543 T1570 | Mapped |
| CVE-2024-4671 | Google Chromium | T1059 T1189 | Mapped |
| CVE-2024-4761 | Google Chromium V8 | T1059 | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | T1003 T1005 T1190 | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 T1059 T1190 | Mapped |
| CVE-2024-4885 | Progress WhatsUp Gold | T1059 T1068 | Mapped |
| CVE-2024-49035 | Microsoft Partner Center | T1068 T1195 | Mapped |
| CVE-2024-4947 | Google Chromium V8 | T1059 T1189 | Mapped |
| CVE-2024-4978 | Justice AV Solutions Viewer | T1005 T1071.001 T1105 T1195.002 | Mapped |
| CVE-2024-50302 | Linux Kernel | T1005 T1011 | Mapped |
| CVE-2024-50603 | Aviatrix Controllers | T1055 T1059 | Mapped |
| CVE-2024-5217 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | T1005 T1059 | Mapped |
| CVE-2024-5274 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2024-53104 | Linux Kernel | T1059 T1068 | Mapped |
| CVE-2024-53150 | Linux Kernel | T1005 T1011 | Mapped |
| CVE-2024-53197 | Linux Kernel | T1059 T1068 | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | T1083 T1199 T1212 | Mapped |
| CVE-2024-54085 | AMI MegaRAC SPx | T1068 T1210 T1495 T1499 | Mapped |
| CVE-2024-55550 | Mitel MiCollab | T1005 T1041 T1190 | Mapped |
| CVE-2024-55591 | Fortinet FortiOS and FortiProxy | T1021 T1068 T1078 T1555 | Mapped |
| CVE-2024-56145 | Craft CMS Craft CMS | T1055 T1059 | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | T1003 T1059 T1190 T1552.001 T1552.004 | Mapped |
| CVE-2024-57968 | Advantive VeraCore | T1059 T1078 | Mapped |
| CVE-2024-58136 | Yiiframework Yii | T1055 T1059 | Mapped |
| CVE-2024-6047 | GeoVision Multiple Devices | T1055 T1059 | Mapped |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | T1055 T1190 T1565.001 | Mapped |
| CVE-2025-0111 | Palo Alto Networks PAN-OS | T1005 T1068 | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1003 T1018 T1046 T1055 T1190 | Mapped |
| CVE-2025-0411 | 7-Zip 7-Zip | T1566.001 | Mapped |
| CVE-2025-0994 | Trimble Cityworks | T1059 T1068 | Mapped |
| CVE-2025-1316 | Edimax IC-7100 IP Camera | T1055 T1190 | Mapped |
| CVE-2025-1976 | Broadcom Brocade Fabric OS | T1059 T1068 | Mapped |
| CVE-2025-20281 | Cisco Identity Services Engine | T1059 T1106 | Mapped |
| CVE-2025-20337 | Cisco Identity Services Engine | T1059 T1106 | Mapped |
| CVE-2025-21333 | Microsoft Windows | T1003 T1068 | Mapped |
| CVE-2025-21334 | Microsoft Windows | T1003 T1068 | Mapped |
| CVE-2025-21335 | Microsoft Windows | T1003 T1068 | Mapped |
| CVE-2025-21391 | Microsoft Windows | T1068 T1485 | Mapped |
| CVE-2025-21418 | Microsoft Windows | T1005 T1055 T1068 | Mapped |
| CVE-2025-21480 | Qualcomm Multiple Chipsets | T1055 T1495 | Mapped |
| CVE-2025-21590 | Juniper Junos OS | T1059 T1068 | Mapped |
| CVE-2025-22224 | VMware ESXi and Workstation | T1055 | Mapped |
| CVE-2025-22225 | VMware ESXi | T1068 | Mapped |
| CVE-2025-22226 | VMware ESXi, Workstation, and Fusion | T1005 | Mapped |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | T1059 T1190 | Mapped |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | T1059 T1190 | Mapped |
| CVE-2025-24016 | Wazuh Wazuh Server | T1059 T1078 T1203 | Mapped |
| CVE-2025-24054 | Microsoft Windows | T1555 T1566 | Mapped |
| CVE-2025-24085 | Apple Multiple Products | T1059 T1068 | Mapped |
| CVE-2025-24201 | Apple Multiple Products | T1059 T1189 | Mapped |
| CVE-2025-24985 | Microsoft Windows | T1059 | Mapped |
| CVE-2025-24991 | Microsoft Windows | T1005 | Mapped |
| CVE-2025-24993 | Microsoft Windows | T1055 T1068 T1203 T1204 T1565 | Mapped |
| CVE-2025-25181 | Advantive VeraCore | T1055 T1068 T1485 | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | T1055 T1059.004 T1068 T1190 T1485 | Mapped |
| CVE-2025-27038 | Qualcomm Multiple Chipsets | T1059 T1203 | Mapped |
| CVE-2025-27363 | FreeType FreeType | T1204.002 T1499.004 T1574 | Mapped |
| CVE-2025-2783 | Google Chromium Mojo | T1203 T1497 T1548 | Mapped |
| CVE-2025-30397 | Microsoft Windows | T1059 T1203 | Mapped |
| CVE-2025-30400 | Microsoft Windows | T1068 | Mapped |
| CVE-2025-30406 | Gladinet CentreStack | T1059 T1203 | Mapped |
| CVE-2025-31161 | CrushFTP CrushFTP | T1059 T1078 T1136 | Mapped |
| CVE-2025-31200 | Apple Multiple Products | T1001 T1059 T1105 T1106 T1203 T1557 | Stale |
| CVE-2025-31201 | Apple Multiple Products | T1001 T1059 T1105 T1106 T1203 T1557 | Stale |
| CVE-2025-31324 | SAP NetWeaver | T1055 T1059 T1505.003 | Mapped |
| CVE-2025-32433 | Erlang Erlang/OTP | T1021.004 T1059 | Mapped |
| CVE-2025-3248 | Langflow Langflow | T1059 T1203 | Mapped |
| CVE-2025-32701 | Microsoft Windows | T1059 T1068 T1543 | Mapped |
| CVE-2025-32706 | Microsoft Windows | T1059 T1068 T1543 | Mapped |
| CVE-2025-32709 | Microsoft Windows | T1003 T1059 T1068 T1543 | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | T1003 T1041 T1046 T1059 T1070.004 T1133 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1041 T1056.001 T1059 T1543 T1566.001 | Mapped |
| CVE-2025-34028 | Commvault Command Center | T1059.007 T1190 | Mapped |
| CVE-2025-35939 | Craft CMS Craft CMS | T1059 T1190 T1505.003 | Mapped |
| CVE-2025-3928 | Commvault Web Server | T1059 T1505.003 | Mapped |
| CVE-2025-3935 | ConnectWise ScreenConnect | T1059 T1203 | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | T1059 T1190 T1499 | Mapped |
| CVE-2025-42999 | SAP NetWeaver | T1059 T1190 T1203 T1505.003 | Mapped |
| CVE-2025-43200 | Apple Multiple Products | T1005 T1105 T1203 | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | T1059 T1190 T1203 T1505.003 | Mapped |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) | T1059 T1190 T1543 | Mapped |
| CVE-2025-4632 | Samsung MagicINFO 9 Server | T1059 T1068 T1496 | Mapped |
| CVE-2025-47812 | Wing FTP Server Wing FTP Server | T1059 T1068 | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | T1005 T1212 T1555 | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | T1005 T1212 T1555 | Mapped |
| CVE-2025-49704 | Microsoft SharePoint | T1190 | Mapped |
| CVE-2025-49706 | Microsoft SharePoint | T1190 T1505 | Mapped |
| CVE-2025-53770 | Microsoft SharePoint | T1059 T1190 | Mapped |
| CVE-2025-5419 | Google Chromium V8 | T1189 T1203 | Mapped |
| CVE-2025-54309 | CrushFTP CrushFTP | T1021 T1068 T1567 | Mapped |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | T1190 T1555 | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | T1059 T1203 | Mapped |
| CVE-2025-6554 | Google Chromium V8 | T1059 T1189 T1203 | Mapped |
| CVE-2025-6558 | Google Chromium | T1189 T1203 T1497 | Mapped |